Bonafido: Business Domain Verification API
Server Details
Bonafido: is a domain a real business site? Verdict, trust score, risk flags.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
- Repository
- shawmena-dotcom/product-factory
- GitHub Stars
- 0
TDQS
Scored across 1 tool
Only one tool exists, so there is no possibility of tool confusion. The single tool has a clearly defined purpose, making misselection impossible.
The single tool follows a clear verb_noun pattern (verify_domain), consistent with standard API naming conventions. There are no other tools to create inconsistency.
The server has only one tool, which is borderline for an API. The tool is comprehensive and non-trivial, but one tool feels thin for a service that could potentially separate concerns like DNS checks, RDAP, or look-alike detection.
The verify_domain tool covers a wide range of verification aspects: DNS, RDAP, mail setup, homepage analysis, redirects, contact details, company match, and look-alike detection. The returned evidence and risk flags provide a complete verification workflow, with no obvious missing operations for the stated purpose.
Available Tools
1 toolverify_domainIs this business domain real and legit?ARead-onlyIdempotentInspect
Verify a business domain, URL or email domain: does it resolve, how old is it (RDAP), mail setup (MX/SPF/DMARC), live homepage vs parked/for-sale page, redirects, contact details, company-name match, Wikidata official website and look-alike detection. Returns verdict (verified/likely_legit/unverified/suspicious/not_found), trustScore 0-100, riskFlags and evidence. Pass company_name to check the domain belongs to that company. Up to 5 domains via "domains".
| Name | Required | Description | Default |
|---|---|---|---|
| domain | No | One domain, URL or email, e.g. "stripe.com" | |
| country | No | ISO-2 country hint | |
| domains | No | Or up to 5 domains at once (no company names) | |
| company_name | No | Expected company name for the single domain, e.g. "Stripe" |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, openWorldHint, idempotentHint, and destructiveHint=false, so the safety profile is covered. The description adds meaningful behavioral detail beyond annotations: the returned verdict values, trustScore range, riskFlags, evidence, and the batch limit of 5 domains.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense but every sentence earns its place: purpose, checks performed, output contract, and parameter usage are all covered in a compact block. It is front-loaded with the core purpose and avoids filler or repetition of the schema.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity and the absence of an output schema, the description does well to explain the verdict scale, trustScore, riskFlags, evidence, and batch behavior. Minor gaps remain, such as behavior when no domain parameter is provided and potential rate limits or network dependencies, but these are not critical for basic invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, but the description adds value by clarifying the relationship between parameters: company_name is for verifying domain-to-company ownership, and 'domains' is an alternative batch mode that excludes company names. This goes beyond the schema's field-level descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb and resource: 'Verify a business domain, URL or email domain', then enumerates the concrete checks performed (RDAP age, MX/SPF/DMARC, parked-page detection, Wikidata match, look-alike detection). This makes the tool's function unmistakable even without sibling tools to differentiate from.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There are no sibling tools, so alternatives are not applicable, but the description gives clear usage context: pass company_name for ownership checks and use the 'domains' array for batch verification. It does not explicitly state when not to use the tool, but the input modes and intended use are clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- First observed
verify_domain
Related MCP Connectors
Bonafido: is a domain a real business site? Verdict, trust score, risk flags.
11Verify business legitimacy by domain or name in <2s. Trust score, verdict, evidence. x402-payable.
AI URL safety validator: SAFE/SUSPICIOUS/DANGEROUS verdict, trust score, threat intel.
Scan a business website and see if AI agents can find it, trust it, and act on it.
Related MCP Servers
- FlicenseNot gradedqualityFmaintenancePay-per-call API that verifies whether a domain belongs to a real business. Returns a verdict (real/likely_real/uncertain/likely_fake/fake), a 0-100 score, and signals (WHOIS via RDAP, SSL via Certificate Transparency, homepage LLM judgment, contacts, social) — for KYB, vendor screening, fraud checks, and lead qualification.-
- FlicenseAqualityBmaintenanceEnables AI shopping agents to verify a storefront's legitimacy before committing payment by checking domain registration, SSL certificate history, HTTPS validity, and known-scam blocklists, returning a trust score with explainable reasons and a clear recommendation.1139 npm-
- AlicenseNot gradedqualityBmaintenanceProvides AI agents with zero-cost, zero-dependency trust evaluation for domains, URLs, wallets, APIs, and IPs, returning a 0-100 score with SSL, DNS, WHOIS, security header, and content sub-scores, plus batch comparison to rank multiple targets.MIT
- FlicenseNot gradedqualityBmaintenancePassive website security and trust auditor that checks for security, SEO, AI surface, email, and other exposures, producing a score and remediation plan.-
Glama MCP Gateway
Add one secure layer between your agents and this server.