Skip to main content
Glama
Bishop81
by Bishop81
README.md
# @domainintel/mcp

An [MCP](https://modelcontextprotocol.io) server that gives AI agents live domain intelligence: WHOIS, DNS, SSL/TLS, HTTP security headers, reputation, and subdomain discovery for any domain. It is the same analysis engine that powers [DomainIntel.app](https://domainintel.app).

## Tools

| Tool | Returns |
|------|---------|
| `whois_lookup` | Registrar, creation/expiry/updated dates, registrant country, privacy status, nameservers |
| `dns_records` | A, AAAA, MX, TXT, NS, CNAME, CAA records + SPF/DMARC presence + misconfiguration warnings |
| `ssl_certificate` | Validity, issuer, expiration, days remaining, protocol, warnings |
| `security_headers` | HSTS, CSP, X-Frame-Options and others, scored with recommendations |
| `domain_reputation` | DNSBL / Spamhaus blocklist checks and a reputation score |
| `subdomain_discovery` | Subdomains via Certificate Transparency logs and common-prefix probing |
| `full_domain_report` | Every analyzer at once plus an overall A+ to F security score |
| `analyze_email_headers` | Parses a raw email header block: SPF/DKIM/DMARC results, the Received delivery path with timing, key envelope fields, and a From-vs-Return-Path spoofing flag |

Every tool except `analyze_email_headers` takes a single `domain` argument; protocol, `www.`, and paths are stripped automatically. `analyze_email_headers` takes a `headers` string (a pasted raw header block) instead.

## Requirements

- Node.js 18 or newer

## Install

### Claude Code

```bash
claude mcp add domainintel -- npx -y @domainintel/mcp
```

### Claude Desktop

Add to `claude_desktop_config.json` (Settings → Developer → Edit Config):

```json
{
  "mcpServers": {
    "domainintel": {
      "command": "npx",
      "args": ["-y", "@domainintel/mcp"]
    }
  }
}
```

### Any other MCP client

The server speaks MCP over stdio:

```bash
npx -y @domainintel/mcp
```

## Example prompts

- "Run a full domain report on stripe.com"
- "What are the MX records for github.com, and does it have DMARC?"
- "Is the SSL certificate for example.org close to expiring?"

## Development

Run from source (no build needed):

```bash
git clone <repo> && cd domainintel.app
npm install
npm run mcp        # node mcp/server.mjs
```

## Building & publishing

The published package is a single self-contained bundle (the analyzers and all
JS dependencies are bundled with esbuild; Node built-ins resolve at runtime).

```bash
npm run build:mcp          # from repo root -> mcp/dist/server.mjs
cd mcp && npm publish       # prepublishOnly rebuilds the bundle
```

## License

MIT

TDQS

A4.1/5.0

Scored across 7 tools

Disambiguation5/5

Each tool targets a distinct aspect of domain intelligence: DNS records, WHOIS, SSL, security headers, reputation, subdomain discovery, and a combined full report. There is no overlap in purpose; even the full report is a composite meta-tool, not a duplicate.

Naming Consistency5/5

All tool names follow a consistent pattern: a domain-related noun followed by an operation noun (e.g., whois_lookup, subdomain_discovery, ssl_certificate). The naming is uniformly descriptive and predictable.

Tool Count5/5

With 7 tools, the server covers the essential areas of domain intelligence (DNS, WHOIS, SSL, security headers, reputation, subdomains) without being bloated or sparse. Each tool serves a clear purpose.

Completeness5/5

The tool surface comprehensively covers domain analysis: DNS record types, WHOIS metadata, SSL certificate inspection, security header evaluation, blocklist reputation, subdomain enumeration, and a summarizing full report. No obvious gaps are present for the stated purpose.

Maintenance

ActivitySlowing
ResponsivenessNo issues