domainintel-mcp
# @domainintel/mcp
An [MCP](https://modelcontextprotocol.io) server that gives AI agents live domain intelligence: WHOIS, DNS, SSL/TLS, HTTP security headers, reputation, and subdomain discovery for any domain. It is the same analysis engine that powers [DomainIntel.app](https://domainintel.app).
## Tools
| Tool | Returns |
|------|---------|
| `whois_lookup` | Registrar, creation/expiry/updated dates, registrant country, privacy status, nameservers |
| `dns_records` | A, AAAA, MX, TXT, NS, CNAME, CAA records + SPF/DMARC presence + misconfiguration warnings |
| `ssl_certificate` | Validity, issuer, expiration, days remaining, protocol, warnings |
| `security_headers` | HSTS, CSP, X-Frame-Options and others, scored with recommendations |
| `domain_reputation` | DNSBL / Spamhaus blocklist checks and a reputation score |
| `subdomain_discovery` | Subdomains via Certificate Transparency logs and common-prefix probing |
| `full_domain_report` | Every analyzer at once plus an overall A+ to F security score |
| `analyze_email_headers` | Parses a raw email header block: SPF/DKIM/DMARC results, the Received delivery path with timing, key envelope fields, and a From-vs-Return-Path spoofing flag |
Every tool except `analyze_email_headers` takes a single `domain` argument; protocol, `www.`, and paths are stripped automatically. `analyze_email_headers` takes a `headers` string (a pasted raw header block) instead.
## Requirements
- Node.js 18 or newer
## Install
### Claude Code
```bash
claude mcp add domainintel -- npx -y @domainintel/mcp
```
### Claude Desktop
Add to `claude_desktop_config.json` (Settings → Developer → Edit Config):
```json
{
"mcpServers": {
"domainintel": {
"command": "npx",
"args": ["-y", "@domainintel/mcp"]
}
}
}
```
### Any other MCP client
The server speaks MCP over stdio:
```bash
npx -y @domainintel/mcp
```
## Example prompts
- "Run a full domain report on stripe.com"
- "What are the MX records for github.com, and does it have DMARC?"
- "Is the SSL certificate for example.org close to expiring?"
## Development
Run from source (no build needed):
```bash
git clone <repo> && cd domainintel.app
npm install
npm run mcp # node mcp/server.mjs
```
## Building & publishing
The published package is a single self-contained bundle (the analyzers and all
JS dependencies are bundled with esbuild; Node built-ins resolve at runtime).
```bash
npm run build:mcp # from repo root -> mcp/dist/server.mjs
cd mcp && npm publish # prepublishOnly rebuilds the bundle
```
## License
MIT
TDQS
Scored across 7 tools
Each tool targets a distinct aspect of domain intelligence: DNS records, WHOIS, SSL, security headers, reputation, subdomain discovery, and a combined full report. There is no overlap in purpose; even the full report is a composite meta-tool, not a duplicate.
All tool names follow a consistent pattern: a domain-related noun followed by an operation noun (e.g., whois_lookup, subdomain_discovery, ssl_certificate). The naming is uniformly descriptive and predictable.
With 7 tools, the server covers the essential areas of domain intelligence (DNS, WHOIS, SSL, security headers, reputation, subdomains) without being bloated or sparse. Each tool serves a clear purpose.
The tool surface comprehensively covers domain analysis: DNS record types, WHOIS metadata, SSL certificate inspection, security header evaluation, blocklist reputation, subdomain enumeration, and a summarizing full report. No obvious gaps are present for the stated purpose.