MCP Server

domaindrift

io.domaindrift/domaindrift
Cloud & Infrastructure Security Public & reachable MCP 2026-07-28

What this MCP does

Reports signed DNS, TLS, WHOIS, reachability, and internet infrastructure observations with provenance receipts.

internet_tape
The 24-hour tape
The rolling 24-hour aggregate rollup: how many domains changed DNS provider, switched certificate authority, moved mail, went unreachable, and the other tape legs, each with a live count. Public and keyless.
Read only
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
lookup_domain
Look up one domain
The latest signed observation of one domain: who runs its nameservers, mail, and CDN; certificate issuer and expiry; HTTPS reachability; per-record-type counts; and the Ed25519 receipt pointer. Keyless calls get this reduced preview, throttled to 1 request per 15 seconds per IP under a shared daily ceiling. Connect with a DomainDrift API key in an Authorization: Bearer header to get the complete signed record instead, metered against your account like any API request.
Read only
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Registrable domain name, e.g. "example.com"'}}, 'additionalProperties': False}
resolve_receipt
Resolve a provenance receipt
Resolve any DomainDrift provenance receipt by id: the public Ed25519 commitment (output hash, signing key, timestamp, chain link) for one observation. Public and keyless. Verify the signing key against /.well-known/domaindrift-keys.json.
Read only
Input schema
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'Receipt id, as returned in any signed record or preview'}}, 'additionalProperties': False}
signing_keys
Published signing keys
The Ed25519 public keys that sign every DomainDrift observation, with derivation paths and validity windows. Public and keyless. Use these to verify receipts and signed records offline.
Read only
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
whats_changed_today
Today's change digest
The daily "what changed on the internet" digest: a ranked top-20 of the most significant DNS, TLS, WHOIS, and infrastructure changes observed across the tracked catalog in the last 24 hours. Public and keyless. The complete change wire with sync cursors is the keyed /v1/changes endpoint.
Read only
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Added
signing_keys
Sept. 17, 2026, 12:40 p.m.
Added
internet_tape
Sept. 17, 2026, 12:40 p.m.
Added
resolve_receipt
Sept. 17, 2026, 12:40 p.m.
Added
whats_changed_today
Sept. 17, 2026, 12:40 p.m.
Added
lookup_domain
Sept. 17, 2026, 12:40 p.m.