DomScan MCP Server
DomScan MCP Server
Domain intelligence for AI agents. Connect DomScan to Claude, Cursor, VS Code and any Model Context Protocol client to run DNS, WHOIS/RDAP, SSL/TLS, subdomain, availability, valuation, email-security and brand-protection lookups straight from your assistant.
DomScan is a domain intelligence platform that exposes its data over one REST API and a hosted MCP server. This repository documents the MCP server: how to connect it, what tools it exposes, and how to use it in agent pipelines.
Website: https://domscan.net
MCP endpoint:
https://domscan.net/mcp(Streamable HTTP)Transport: Streamable HTTP (remote)
Auth: OAuth discovery (recommended) or a DomScan API key
Quick start
OAuth-aware clients
Add https://domscan.net/mcp as a remote MCP server. DomScan publishes OAuth protected-resource and authorization-server metadata, so compatible clients can discover and complete authentication without a manually configured API key.
{
"mcpServers": {
"domscan": {
"url": "https://domscan.net/mcp"
}
}
}Claude Desktop / Claude Code with an API key
Add to your MCP config (claude_desktop_config.json or .mcp.json):
{
"mcpServers": {
"domscan": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://domscan.net/mcp",
"--header",
"Authorization: Bearer ${DOMSCAN_API_KEY}"
],
"env": { "DOMSCAN_API_KEY": "your-api-key" }
}
}
}Native remote URL with an API key
{
"mcpServers": {
"domscan": {
"url": "https://domscan.net/mcp",
"headers": { "Authorization": "Bearer your-api-key" }
}
}
}Get an API key from the DomScan dashboard. OAuth is preferred when the client supports it. API keys remain available for clients that need explicit header authentication.
Related MCP server: nslookup.io MCP Server
Local MCP wrapper
This repository includes a runnable stdio wrapper for clients that cannot connect directly to the hosted Streamable HTTP endpoint. It forwards requests to https://domscan.net/mcp using DOMSCAN_API_KEY.
npm install
DOMSCAN_API_KEY=your-api-key npm startIf no API key is configured, the wrapper still starts and exposes only the read-only domscan_mcp_status tool. This lets MCP registries inspect and validate the server without granting access to domain-intelligence operations.
Docker
docker build -t domscan-mcp .
docker run --rm -i -e DOMSCAN_API_KEY=your-api-key domscan-mcpThe local wrapper uses API-key authentication. Clients that support remote Streamable HTTP and OAuth should continue connecting directly to https://domscan.net/mcp; OAuth remains the recommended option for those clients.
What it can do
The server exposes domain-intelligence tools across these areas:
DNS: record lookups (A, AAAA, MX, TXT, NS, CNAME, CAA), full record dumps, propagation checks, DNS security.
WHOIS / RDAP: registration data, WHOIS history, reverse WHOIS, RDAP.
SSL/TLS: certificate audit, chain inspection, grade, expiry checks, deep scan, certificate search.
Subdomains: subdomain enumeration and discovery.
Availability and valuation: domain availability (single and bulk), appraisal, name suggestions.
Email security: SPF, DKIM, DMARC validation and DNSSEC posture.
Brand protection: typosquatting detection, brand monitors and scans.
Infrastructure: IP lookup, hosting detection, ASN, technology/stack detection, MAC vendor lookup.
See the DomScan API documentation and MCP setup guide.
Why MCP
MCP lets an AI assistant call DomScan directly: ask "is acme.io available, and who owns the look-alikes?" and the agent runs availability, WHOIS and typosquatting tools and answers in one turn. The same server powers automated workflows (monitoring, due diligence, brand protection) without custom integration code.
Links
Product: https://domscan.net
API documentation: https://domscan.net/docs
MCP setup guide: https://domscan.net/mcp-domain-checker
MCP spec: https://modelcontextprotocol.io/
Datasets and APIs: https://domscan.net/tools
License
MIT. See LICENSE.
Available Tools
1 tooldomscan_mcp_statusDomScan MCP statusARead-onlyIdempotentInspect
Check whether this wrapper is configured with a DomScan API key and show setup details for the hosted domain-intelligence MCP endpoint.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate a safe read-only, idempotent operation. The description adds useful context by specifying that this checks API key presence and shows setup details for the hosted endpoint, going beyond the annotation metadata.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single sentence that is concise, front-loaded with the action, and contains no superfluous words. Every part of the description adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a zero-parameter, read-only status tool with no output schema, the description is mostly complete. It could specify what 'setup details' includes, but given the simplicity, the description is sufficient for an agent to understand and invoke the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters, so the schema coverage is complete. The description does not need to explain parameter semantics, and the baseline of 4 applies given the absence of parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states what the tool does: checks API key configuration and shows setup details. It uses specific verbs ('Check', 'show') and a specific resource ('wrapper', 'DomScan API key'), leaving no ambiguity about its purpose.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implicitly tells the agent when to use this tool: whenever there is a need to verify whether the wrapper is configured with a DomScan API key. It does not explicitly exclude alternatives, but no sibling tools exist, so the guidance is adequate.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
TDQS
With only one tool, there is no possibility of confusion or overlap between tools. The single tool has a clearly defined purpose of checking configuration status.
The single tool name 'domscan_mcp_status' follows a clear lowercase_with_underscores convention, and there are no other tools to create inconsistency.
The server is positioned as a domain-intelligence MCP endpoint, but it exposes only a status check tool. This is a trivial single tool that does not fulfill the apparent scope of providing domain intelligence functionality.
The tool surface is severely incomplete for a domain-intelligence server. There are no tools to actually query, scan, or analyze domains; only a configuration status check is provided.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Domain intel for AI agents: RDAP registration, DNS, email deliverability, tech stack.
Domain & company intel for AI agents: RDAP, DNS, email deliverability, tech stack. No API keys.
Domain & brand intelligence: company enrichment, tech stack detection, brand research.
Normalized JSON for any domain across 1,200+ TLDs. The modern WHOIS replacement.
Related MCP Servers
- AlicenseBqualityCmaintenanceEnables monitoring of domain registration information via WHOIS lookup and SSL certificate validity checking. Provides domain expiration dates, registrar details, certificate validity periods, and issuer information for website security monitoring.2264MIT
- AlicenseAqualityBmaintenanceProvides comprehensive tools for real-time DNS queries across 53 record types, global propagation checks, and SSL certificate analysis. It also enables domain security scans for SPF/DKIM/DMARC configurations and HTTP uptime monitoring.88822Apache 2.0
- AlicenseNot gradedqualityDmaintenanceProvides comprehensive IP and domain security intelligence, enabling analysis of IP addresses and domains for threat and reputation information.MIT
- AlicenseAqualityDmaintenanceProvides comprehensive domain research tools including RDAP, WHOIS, and DNS lookup capabilities, with automatic fallback and support for 50+ TLDs.1181MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/estevecastells/domscan-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server