MCP Server

Domain Intelligence

com.oti-labs/domain-intelligence
Cloud & Infrastructure Security Public & reachable MCP 2025-11-25

What this MCP does

Profiles domains using WHOIS/RDAP, DNS, SSL certificate, subdomain, and email-security data.

dns_records
DNS records for a domain: A, AAAA, MX, TXT, NS, CAA and SOA, resolved in parallel.
Read only Open world Idempotent
Input schema
{'type': 'object', 'title': 'dns_recordsArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain'}}}
Output schema
{'type': 'object', 'title': 'dns_recordsDictOutput', 'additionalProperties': True}
domain_lookup
Full report on a domain in one call: WHOIS/RDAP registration, DNS records, live SSL certificate, subdomains (live hosts with IPs first) and email authentication (SPF, DMARC, DKIM). Use it to triage a suspicious domain or profile a company's domain. If one section fails it comes back as an object with an `error` field and the rest is unaffected. Set wait=true to wait for every subdomain source (up to about 20 s) instead of the fast first result.
Read only Open world Idempotent
Input schema
{'type': 'object', 'title': 'domain_lookupArguments', 'required': ['domain'], 'properties': {'wait': {'type': 'boolean', 'title': 'Wait', 'default': False}, 'domain': {'type': 'string', 'title': 'Domain'}, 'subdomain_limit': {'type': 'integer', 'title': 'Subdomain Limit', 'default': 50}}}
Output schema
{'type': 'object', 'title': 'domain_lookupDictOutput', 'additionalProperties': True}
email_security
Email authentication for a domain: SPF and DMARC records, and DKIM keys found by probing about 29 common selectors (Google, Microsoft 365, Mailchimp, SendGrid and others). Custom selectors may not be found.
Read only Open world Idempotent
Input schema
{'type': 'object', 'title': 'email_securityArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain'}}}
Output schema
{'type': 'object', 'title': 'email_securityDictOutput', 'additionalProperties': True}
ssl_certificate
The certificate a domain serves on port 443, from a live TLS handshake: issuer, subject, valid_from, valid_to, days_until_expiry, SANs, signature algorithm and serial number.
Read only Open world Idempotent
Input schema
{'type': 'object', 'title': 'ssl_certificateArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain'}}}
Output schema
{'type': 'object', 'title': 'ssl_certificateDictOutput', 'additionalProperties': True}
subdomains
Subdomains of a domain from certificate transparency logs, passive DNS and DNS brute force. `live` lists hosts that resolve now, each with its IP; `subdomains` lists every name found, live first; `pools` summarises large shared-infrastructure zones. The first lookup of a domain is a fast snapshot and later ones are fuller; set wait=true to wait for every source (up to about 20 s).
Read only Open world Idempotent
Input schema
{'type': 'object', 'title': 'subdomainsArguments', 'required': ['domain'], 'properties': {'wait': {'type': 'boolean', 'title': 'Wait', 'default': False}, 'limit': {'type': 'integer', 'title': 'Limit', 'default': 100}, 'domain': {'type': 'string', 'title': 'Domain'}}}
Output schema
{'type': 'object', 'title': 'subdomainsDictOutput', 'additionalProperties': True}
whois_lookup
Registration data for a domain: registrar, created, updated and expiry dates, nameservers and status. RDAP first (rdap.org, IANA bootstrap, 22 fallback servers), then port-43 WHOIS for 60+ TLDs. `_source` says which one answered. Use it for domain age, expiry or registrar checks.
Read only Open world Idempotent
Input schema
{'type': 'object', 'title': 'whois_lookupArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain'}}}
Output schema
{'type': 'object', 'title': 'whois_lookupDictOutput', 'additionalProperties': True}
Added
email_security
Oct. 4, 2026, 2:40 a.m.
Added
subdomains
Oct. 4, 2026, 2:40 a.m.
Added
ssl_certificate
Oct. 4, 2026, 2:40 a.m.
Added
dns_records
Oct. 4, 2026, 2:40 a.m.
Added
whois_lookup
Oct. 4, 2026, 2:40 a.m.
Added
domain_lookup
Oct. 4, 2026, 2:40 a.m.