whois-mcp-server
Provides DNS-over-HTTPS resolution using Cloudflare's 1.1.1.1 service, and supports Cloudflare KV/R2/D1 as storage backends for session and auth state.
Provides DNS-over-HTTPS resolution using Google's 8.8.8.8 service, primarily for CAA records where Cloudflare returns raw hex.
Integrates with OpenTelemetry for structured logging and tracing.
Supports Supabase as a storage backend for persisting bootstrap cache and other state.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@whois-mcp-servercheck availability of example.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Overview
Domain and network intelligence via RDAP and DNS-over-HTTPS. Look up domain registrations, check availability, fetch DNS records, and resolve IPs and ASNs to their registries — all via public, keyless data sources. Runs as a stdio process or a local Streamable HTTP server.
Tools
Tool | Description |
| Full domain registration record — registrar, created/expiry dates, nameservers, EPP status, DNSSEC, registrant org |
| Check whether a domain is registered or available for registration |
| DNS records for any hostname via DNS-over-HTTPS (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, PTR) |
| IP or CIDR netblock, org, country, abuse contact, and reverse DNS via RIR RDAP |
| Resolve an ASN to its org name, country, and RIR source |
| One-call domain triage — registration + DNS in parallel, normalized into a single record with factual signals |
Related MCP server: domain-checker
Capability reference
whois_lookup_domain tool
Accepts a fully qualified domain name and selects the registry RDAP server through IANA bootstrap.
Returns registrar, registration dates, nameservers, EPP status, DNSSEC, and
registrant_redacted; throwsrdap_no_coverageordomain_not_foundwhen no record can be returned.
whois_check_availability tool
Accepts a fully qualified domain name for a registration check.
Returns
available: truefor RDAP 404,falsewith registrar and expiry for a registered domain, ornullwithrdap_coverage: falsewhen coverage is absent.
whois_get_dns tool
Accepts a hostname and optional nonempty
types: A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, PTR; omission defaults to A, AAAA, MX, TXT, NS. Duplicate types are queried once.Returns records with TTLs and ordered
query_sources: [{type, source}], including empty answers and NXDOMAIN. Legacysourceiscloudflareif any query consumed a successful Cloudflare response, otherwisenextdns; a nonexistent domain returnsnxdomain: trueas data.
whois_lookup_ip tool
Accepts a complete IPv4/IPv6 address with at most one decimal CIDR prefix (0–32 / 0–128); no whitespace, zone IDs, or brackets. Queries the base address and echoes the original
ip. IPv4-mapped IPv6 uses the embedded IPv4 for policy, RDAP, and PTR; other IPv6 uses 32 reversed PTR nibbles.Returns netblock CIDR, organization, country, abuse contact, and best-effort PTR (
nullon failure); throwsinvalid_ipfor malformed input orip_not_foundon an RIR RDAP 404.private_rangeenforces an explicit policy: IPv40.0.0.0/8,10.0.0.0/8,100.64.0.0/10,127.0.0.0/8,169.254.0.0/16,172.16.0.0/12,192.168.0.0/16,255.0.0.0/8; IPv6::1/128,fc00::/7,fe80::/10. Other special-use addresses remain eligible for registry records or normal no-coverage/not-found outcomes.
whois_lookup_asn tool
Accepts a decimal ASN from 1 to 4294967295 with an optional case-insensitive
ASprefix and leading+(e.g.,AS15169,AS 15169,+15169). Outer whitespace and whitespace afterASare allowed; whitespace inside digits or after+, suffixes, decimals, and out-of-range values returninvalid_asn.Returns
name,org_name,country,rir,start_autnum, andend_autnum; throwsasn_not_foundwhen no ASN record exists.
whois_get_dossier tool
Accepts a fully qualified domain name for parallel registration and A/MX/NS/TXT lookups.
Returns registration, DNS, domain age, privacy status, and inferred NS/MX providers. Individual failures remain partial data in
rdap_source_errorordns_source_error;both_legs_failedmeans neither source succeeded.
Features
Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
RDAP / DNS-specific:
RDAP over HTTPS — no port-43 TCP dependency
IANA bootstrap auto-selection — correct registry RDAP server picked per TLD, RIR, or ASN range; bootstrap JSON cached in-memory for 24h
DNS-over-HTTPS via Cloudflare and NextDNS — dual-provider with per-type routing (NextDNS for CAA; Cloudflare for all others) and automatic fallback
No API keys required — all sources (IANA, registry RDAP endpoints, RIR RDAP, Cloudflare DoH, NextDNS DoH) are public and keyless
Agent-friendly output:
Coverage signaled two ways —
rdap_coverage: falsereturned as data bywhois_check_availabilityandwhois_get_dossier, whilewhois_lookup_domainthrowsrdap_no_coveragefor the same casePrivacy redaction surfaced as a field —
registrant_redacted: truerather than silently absent contact dataPartial failure model —
whois_get_dossiermarks individual legs with asource_errorfield and continues; only both-legs-fail escalates to an errorFactual signals, not scores —
age_days,privacy_redacted,ns_provider,mx_providerare real data, not synthesized risk scores
Getting started
No API keys or accounts required. Add the following to your MCP client configuration file.
{
"mcpServers": {
"whois-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/whois-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with npx (no Bun required):
{
"mcpServers": {
"whois-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/whois-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with Docker:
{
"mcpServers": {
"whois-mcp-server": {
"type": "stdio",
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MCP_TRANSPORT_TYPE=stdio",
"ghcr.io/cyanheads/whois-mcp-server:latest"
]
}
}
}For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcpPrerequisites
Bun v1.4.0 or higher (or Node.js v24+).
No API keys required — all data sources are public.
Installation
Clone the repository:
git clone https://github.com/cyanheads/whois-mcp-server.gitNavigate into the directory:
cd whois-mcp-serverInstall dependencies:
bun installConfigure environment:
cp .env.example .env
# All vars are optional — defaults work for most use casesConfiguration
Variable | Description | Default |
| HTTP timeout for RDAP requests in milliseconds. |
|
| HTTP timeout for DNS-over-HTTPS requests in milliseconds. |
|
| Max retry attempts on transient RDAP failures. |
|
| Max retry attempts on transient DoH failures. |
|
| Transport: |
|
| Port for HTTP server. |
|
| Auth mode: |
|
| Log level (RFC 5424). |
|
| Enable OpenTelemetry instrumentation. |
|
See .env.example for the full list of optional overrides.
Running the server
Local development
Build and run:
bun run rebuild bun run start:stdio # or bun run start:httpRun checks and tests:
bun run devcheck # Lint, format, typecheck, security bun run test # Vitest test suite bun run lint:mcp # Validate MCP definitions against spec
Docker
docker build -t whois-mcp-server .
docker run --rm -p 3010:3010 whois-mcp-serverThe Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/whois-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
Project structure
Path | Purpose |
| Entry point — starts the app. |
|
|
| Server-specific environment variable parsing and validation (Zod). |
| RDAP client — IANA bootstrap cache, domain/IP/ASN lookup, retry. |
| DNS-over-HTTPS client — Cloudflare primary, NextDNS fallback. |
| Tool definitions ( |
| Vitest tests mirroring |
| Design and API reference documents. |
Development guide
See CLAUDE.md for development guidelines and architectural rules. The short version:
Handlers throw, framework catches — no
try/catchin tool logicUse
ctx.logfor request-scoped loggingRegister new tools via
src/app.ts'stoolsarrayWrap external API calls: validate raw → normalize to domain type → return output schema; never fabricate missing fields
Contributing
Issues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run testLicense
Apache-2.0 — see LICENSE for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
RDAP MCP — Registration Data Access Protocol via IANA bootstrap.
MCP server for DNSimple — domains, DNS zone records, availability, pricing and contacts.
Network, domain and website diagnostics for AI clients via MCP.
WhoisXML MCP — wraps WhoisXML API (whoisxmlapi.com)
Related MCP Servers
- AlicenseAqualityDmaintenanceEnables domain lookups using the RDAP protocol, returning structured registration data, nameservers, and contacts from over 50 supported TLDs.114 npm1MIT
- AlicenseBqualityDmaintenanceEnables domain name checking and related services through a standardized MCP interface.2MIT
- AlicenseNot gradedqualityBmaintenanceEnables RDAP domain lookup via ICANN standard, free, no authentication required.299 npmMIT
- AlicenseAqualityDmaintenanceMCP server for checking domain name availability across 500+ TLDs using RDAP with WHOIS fallback for specific TLDs.2MIT