Domain SearchCAUTION
Zero-config domain availability MCP server for Claude & ChatGPT. Live pricing via Porkbun, premium/auction detection via GoDaddy, AI suggestions, RDAP/WHOIS fallback. Stdio + HTTP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/domain-search-mcp) [](https://www.npmjs.com/package/domain-search-mcp) [](LICENSE) [](https://www.npmjs.com/package/domain-search-mcp) [](https://registry.modelcontextprotocol.io) [](https://glama.ai/mcp/servers/@dorukardahan/domain-search-mcp) [](https://context7.com/dorukardahan/domain-search-mcp)
Naming engine with availability intelligence — an MCP server that scores the names your model generates and runs availability checks against domains, socials, and package registries. Works with zero configuration using public RDAP/WHOIS, and optionally enriches results with registrar pricing via a backend you control.
🆕 v1.12.0: name_project — a two-phase naming engine. Call it once to get generation instructions for your model, call it again with candidates[] to get anti-slop scoring, ranking, and live availability checks across domains, socials, and npm. See name_project below.
🆕 v1.10.0: GoDaddy public endpoint integration! Enhanced fallback chain (RDAP → GoDaddy → WHOIS) with premium/auction domain detection. Circuit breaker pattern ensures resilience.
🤖 v1.9.0+: AI-powered domain suggestions work out of the box! No API keys needed - suggest_domains_smart uses our public fine-tuned Qwen 7B-DPO model. Plus: Redis distributed caching and /metrics endpoint for observability.
Built on the Model Context Protocol for Claude, Codex, VS Code, Cursor, Cline, and other MCP-compatible clients.
Fe
24a77aad42f6OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add domain-search-mcp --env PRICING_API_TOKEN=${PRICING_API_TOKEN} --env PORKBUN_API_KEY=${PORKBUN_API_KEY} --env PORKBUN_API_SECRET=${PORKBUN_API_SECRET} --env NAMECHEAP_API_KEY=${NAMECHEAP_API_KEY} -- npx -y [email protected]Exposed tools (8)
8 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
bulk_search | read | Check availability for multiple domain names at once. Efficiently searches up to 100 domains in parallel with rate limiting. Use a single TLD for best performance. Returns: - Availability status for each domain - Pricing where available - Summary statistics Example: - bulk_search([ |
demo-proj | read | a demo |
domains | read | Domain availability and search operations |
name_project | read | Two-phase naming engine. Call without candidates to receive generation instructions for YOUR model |
search_domain | read | Search for domain availability and pricing across multiple TLDs. Returns: - Availability status for each domain - Pricing (first year and renewal) when Pricing API is configured - Whether WHOIS privacy is included - Human-readable insights and next steps Examples: - search_domain( |
social | read | Social media handle availability |
suggestions | read | AI-powered domain name suggestions |
tld_info | read | Get information about a Top Level Domain (TLD). Returns: - Description and typical use case - Price range - Any special restrictions - Popularity and recommendations Example: - tld_info( |
Trust audit
CAUTIONgrade C · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (10 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
__init__.cpython-314.pyc
constraint_satisfaction.cpython-314.pyc
diversity_metrics.cpython-314.pyc
premium_score.cpython-314.pyc
pronounceability.cpython-314.pyc
'prime', 'apex', 'elite', 'summit', 'vertex', 'titan', 'atlas', 'beacon',
'wallet', 'oracle', 'monitor', 'tracker', 'scan', 'pulse', 'beacon', 'sentry',
# QWEN_INFERENCE_ENDPOINT=http://127.0.0.1:8070
const apiVersion = version || require('../../package.json').version;import { AdaptiveConcurrencyLimiter } from '../../src/utils/adaptive-concurrency';import type { DomainResult } from '../../src/types';jest.mock('../../src/fallbacks/rdap', () => ({jest.mock('../../src/services/pricing-api', () => ({QWEN_INFERENCE_ENDPOINT=http://127.0.0.1:8070
QWEN_INFERENCE_ENDPOINT=http://127.0.0.1:8070
Environment=PRICING_API_BASE_URL=http://127.0.0.1:3000
process.env[QWEN_ENV] = 'http://127.0.0.1:8070';
fastify, @fastify/cors, @fastify/rate-limit, pg, ioredis, dotenv, zod, @types/node
@asteasolutions/zod-to-openapi, @modelcontextprotocol/sdk, axios, cors, dotenv, express, express-rate-limit, ioredis
torch, transformers, accelerate, peft, bitsandbytes, datasets, sentencepiece, trl
training/output-full/adapter_model.safetensors
training/output-full/checkpoint-2000/adapter_model.safetensors
training/output-full/checkpoint-2000/merges.txt
training/output-full/checkpoint-2000/optimizer.pt
training/output-full/checkpoint-2000/tokenizer.json
Gates applied: no_behavioural_pass.
24a77aad42f6full audit observations/trust-audit/mcp-server/dorukardahan__domain-search.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 24a77aad42f6 | CAUTION | C | 80 | first audit |
Questions
What is the Domain Search MCP server?
Zero-config domain availability MCP server for Claude & ChatGPT. Live pricing via Porkbun, premium/auction detection via GoDaddy, AI suggestions, RDAP/WHOIS fallback. Stdio + HTTP.
What tools does Domain Search expose?
8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Domain Search safe to connect to an agent?
With care. The audit graded it C (80/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Domain Search need?
It reads API_TOKEN, NAMECHEAP_API_KEY, OPENROUTER_API_KEY, PORKBUN_API_KEY, PORKBUN_API_SECRET, PRICING_API_TOKEN and TOGETHER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Domain Search run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as domain-search-mcp at 1.13.1.
How current is this page?
The grade is for one exact copy of the source (24a77aad42f6), read on 2026-10-09. The repository is watched and re-audited when it changes.