Atlas / MCP servers / rinadelph / Domain

DomainSAFE

mcp/rinadelph/domain

MCP server for domain research - WHOIS, DNS, SSL certs, expired domains. No API keys needed.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 8r · 0w · 0d
Transport
stdio
License
MIT
Stars
63
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A simple MCP server that lets AI assistants help you with domain research - checking availability, looking up WHOIS info, finding expired domains, and more.

No API keys needed. Everything works out of the box.

What it does

  • Check domain availability - See if a domain is available to register
  • WHOIS lookup - Get registration info, expiration dates, registrar details
  • DNS records - Look up A, MX, TXT, and other DNS records
  • SSL certificates - Check SSL cert info and expiration
  • Find expired domains - Search for recently expired or deleted domains
  • Domain age - See how old a domain is
  • Bulk checks - Check multiple domains at once

Quick Start

# Install uv (if you don't have it)
pip install uv

# Clone the repo
git clone https://github.com/yourusername/domain-mcp.git
cd domain-mcp

# Set up and install
uv venv
source .venv/bin/activate  # On Windows: .venv\Scripts\activate
uv pip install -e .

# Run it
python main.py

Using with Claude Desktop

Add this to your Claude Desktop config:

{
"mcp-servers": {
"domain-mcp": {
"command": "python",
"args": ["/path/to/domain-mcp/main.py", "--transport", "stdio"]
}
}
}

Example Usage

Just ask Claude things like:

  • "Is mydomain.com available?"
  • "Show me WHOIS info for google.com"
  • "Find expired domains with 'tech' in the name"
  • "What are the DNS records for example.com?"

How it works

Uses free, public APIs and services:

  • RDAP for WHOIS data (no auth needed)
  • Cloudflare DNS over HTTPS
  • crt.sh for SSL certificates
  • Public domain databases

Everything is fetched fresh when you ask - no caching, always current data.

License

MIT

Read from source at commit 9639d3351a88OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add domain-mcp -- uvx domain-mcp
claude-desktop
{
  "mcpServers": {
    "domain-mcp": {
      "command": "uvx",
      "args": [
        "domain-mcp"
      ]
    }
  }
}
03

Exposed tools (8)

8 read · 0 write · 0 destructive.

ToolRiskDescription
bulk_domain_checkreadCheck availability of multiple domains at once
check_domain_availabilityreadCheck if a domain is available for registration
dns_lookupreadGet DNS records for a domain
domain_age_checkreadCheck domain age and registration dates
get_dns_recordsreadGet all DNS records for a domain
search_expired_domainsreadSearch for expired or deleted domains
ssl_certificate_inforeadGet SSL certificate information for a domain
whois_lookupreadGet WHOIS information for a domain using RDAP protocol
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 9639d3351a88full audit observations/trust-audit/mcp-server/rinadelph__domain.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-089639d3351a88SAFEB89first audit
06

Questions

What is the Domain MCP server?

MCP server for domain research - WHOIS, DNS, SSL certs, expired domains. No API keys needed.

What tools does Domain expose?

8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Domain safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Domain need?

No credential environment variables were found in its source, so it appears to need none.

How does Domain run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as domain-mcp.

How current is this page?

The grade is for one exact copy of the source (9639d3351a88), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement