DomainSAFE
MCP server for domain research - WHOIS, DNS, SSL certs, expired domains. No API keys needed.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A simple MCP server that lets AI assistants help you with domain research - checking availability, looking up WHOIS info, finding expired domains, and more.
No API keys needed. Everything works out of the box.
What it does
- Check domain availability - See if a domain is available to register
- WHOIS lookup - Get registration info, expiration dates, registrar details
- DNS records - Look up A, MX, TXT, and other DNS records
- SSL certificates - Check SSL cert info and expiration
- Find expired domains - Search for recently expired or deleted domains
- Domain age - See how old a domain is
- Bulk checks - Check multiple domains at once
Quick Start
# Install uv (if you don't have it) pip install uv # Clone the repo git clone https://github.com/yourusername/domain-mcp.git cd domain-mcp # Set up and install uv venv source .venv/bin/activate # On Windows: .venv\Scripts\activate uv pip install -e . # Run it python main.py
Using with Claude Desktop
Add this to your Claude Desktop config:
{
"mcp-servers": {
"domain-mcp": {
"command": "python",
"args": ["/path/to/domain-mcp/main.py", "--transport", "stdio"]
}
}
}Example Usage
Just ask Claude things like:
- "Is mydomain.com available?"
- "Show me WHOIS info for google.com"
- "Find expired domains with 'tech' in the name"
- "What are the DNS records for example.com?"
How it works
Uses free, public APIs and services:
- RDAP for WHOIS data (no auth needed)
- Cloudflare DNS over HTTPS
- crt.sh for SSL certificates
- Public domain databases
Everything is fetched fresh when you ask - no caching, always current data.
License
MIT
9639d3351a88OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add domain-mcp -- uvx domain-mcp
{
"mcpServers": {
"domain-mcp": {
"command": "uvx",
"args": [
"domain-mcp"
]
}
}
}Exposed tools (8)
8 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
bulk_domain_check | read | Check availability of multiple domains at once |
check_domain_availability | read | Check if a domain is available for registration |
dns_lookup | read | Get DNS records for a domain |
domain_age_check | read | Check domain age and registration dates |
get_dns_records | read | Get all DNS records for a domain |
search_expired_domains | read | Search for expired or deleted domains |
ssl_certificate_info | read | Get SSL certificate information for a domain |
whois_lookup | read | Get WHOIS information for a domain using RDAP protocol |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
9639d3351a88full audit observations/trust-audit/mcp-server/rinadelph__domain.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 9639d3351a88 | SAFE | B | 89 | first audit |
Questions
What is the Domain MCP server?
MCP server for domain research - WHOIS, DNS, SSL certs, expired domains. No API keys needed.
What tools does Domain expose?
8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Domain safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Domain need?
No credential environment variables were found in its source, so it appears to need none.
How does Domain run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as domain-mcp.
How current is this page?
The grade is for one exact copy of the source (9639d3351a88), read on 2026-10-08. The repository is watched and re-audited when it changes.