Skip to main content
Glama
paulet4a-commits

WebDataTools Domain & website intelligence MCP server

subdomain_finder

Find all subdomains of a domain from Certificate Transparency logs, then resolve DNS to separate live hosts from dead records.

Instructions

Subdomain Finder enumerates every subdomain of a domain from Certificate Transparency logs (crt.sh, Cert Spotter) and resolves each one — one row per subdomain, no proxies needed. Billed to your own Apify account: ~$0.0005 per result (Apify free-plan price, lower on paid plans).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainsYesDomains — Enter the root domains to enumerate subdomains for, e.g. apify.com. Bare domains and full URLs both work — https://www.apify.com/pricing is reduced to apify.com. One row is returned per subdomain found. Example: ["apify.com"].
resolveDnsNoResolve DNS — Turn this on to look up an A record for every subdomain found, so you can tell live hosts from dead certificate records. Costs one extra DNS query per subdomain and fills in resolves, ipv4 and cname. Turn it off for a pure certificate list.
includeWildcardsNoInclude wildcard names — Turn this on to also return wildcard certificate names such as *.example.com. They cannot be resolved, so they are excluded by default.
maxSubdomainsPerDomainNoMax subdomains per domain — Enter the maximum number of subdomains to return per domain, e.g. 500. Big brands have thousands of certificate names; when the cap is hit the subdomains with the most recently issued certificates are kept.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations exist, so the description carries the full burden, and it does disclose meaningful traits: the two upstream CT sources, the one-row-per-subdomain contract, that no proxies are needed, and the cost model (~$0.0005 per result billed to the caller's own Apify account). It omits rate-limit/pagination behavior and any auth prerequisite detail beyond the Apify billing note.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two dense sentences, front-loaded with the core action and data sources, with pricing relegated to the end. No filler or restatement of the tool name.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema and no annotations, the description supplies the important context an agent needs: sources, row granularity, resolution semantics, and cost. Minor gaps remain around pagination/limits at the API level, but an agent can call this correctly from what is given.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all four parameters with defaults, ranges, and examples. The description adds no syntax or format information beyond what the schema provides, so the baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('enumerates every subdomain of a domain') plus the data sources (Certificate Transparency logs from crt.sh and Cert Spotter) and the output shape (one row per subdomain, DNS-resolved). This clearly separates it from siblings like dns_email_security_checker or domain_security_audit, which audit rather than enumerate.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied by the description (CT-log enumeration, optional DNS resolution) and the resolveDns flag is framed as 'turn it off for a pure certificate list', which is a mild when-to-use hint. However, no sibling alternative is named and no explicit when-not condition is given.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.