Domain Intelligence

com.oti-labsv1.1.0Updated Oct 3, 2026

WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.

Overview

AI-generated overview

Lets an assistant look up WHOIS/RDAP, DNS, SSL, live subdomains and email-security records for any domain.

What it does
Provides read-only domain intelligence tools. domain_lookup returns everything in one call; whois_lookup gives registrar, dates, nameservers and status via RDAP with a port-43 fallback; dns_records returns A, AAAA, MX, TXT, NS, CAA and SOA records. ssl_certificate performs a live TLS handshake for issuer, validity, days_until_expiry, SANs and signature algorithm; subdomains lists live hosts with IPs; email_security checks SPF, DMARC and DKIM across about 29 common selectors.
When to use it
Useful when checking who owns or registered a domain, whether a domain looks suspicious by age, SSL issuer and email authentication, which subdomains are live and what IPs they resolve to, or when a set of certificates expires. It suits reconnaissance and due-diligence questions rather than ongoing monitoring. All tools are read-only.
Requirements
A remote Streamable HTTP endpoint at no local runtime or package is needed. No key is required to start: 1,000 lookups a month per IP, up to 10 a minute, with a 2,000-call daily keyless ceiling. Higher quotas need a RapidAPI key sent in the X-RapidAPI-Key header (or Authorization: Bearer). Stdio-only clients need npx and mcp-remote.
Before you install
All tools are read-only, so nothing is written or deleted. The optional X-RapidAPI-Key header is a secret: supply it only through your client's header configuration and never paste it into prompts or shared config files. Lookups are sent to the provider's hosted endpoint, so the domains you query are visible to that third party. Keyless use is rate-limited and shared per provider pool, so heavy use may be throttled.

Installation

In SourceWeft

  1. Open Domain Intelligence in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "domain-intelligence": {
      "type": "http",
      "url": "https://oti-labs.com/mcp"
    }
  }
}

README

Domain Intelligence MCP server

An MCP server that gives AI agents and assistants WHOIS/RDAP, DNS, SSL, subdomain and email-security lookups for any domain.

  • Hosted endpoint: https://oti-labs.com/mcp (Streamable HTTP)
  • Registry name: com.oti-labs/domain-intelligence
  • No key to start: 1,000 lookups a month per IP (per /64 for IPv6), up to 10 a minute. Hosted connectors that call from their provider's shared addresses (Claude, ChatGPT) share one pool per provider: 10,000 a month, up to 120 a minute. Keyless use on the hosted server stops at 2,000 calls a day in total and resets at 00:00 UTC.
  • After that: add a RapidAPI key in the X-RapidAPI-Key header (or Authorization: Bearer <key>). Calls then count on your RapidAPI plan; the free plan adds another 1,000 a month: get a key.

Tools

ToolWhat it returns
domain_lookupEverything below in one call. Big subdomain lists are trimmed (subdomain_limit, default 50).
whois_lookupRegistrar, created/updated/expiry dates, nameservers, status. RDAP first, port-43 WHOIS fallback.
dns_recordsA, AAAA, MX, TXT, NS, CAA and SOA records.
ssl_certificateLive TLS handshake: issuer, validity dates, days_until_expiry, SANs, signature algorithm.
subdomainsLive hosts with IPs, all names found (live first), collapsed infrastructure pools. wait=true waits for every source.
email_securitySPF, DMARC, and DKIM keys from ~29 common selectors.

All tools are read-only.

Setup

These work without a key. To use a RapidAPI key, add the header shown at the end of this section.

Claude Code

bash
claude mcp add --transport http domain-intelligence https://oti-labs.com/mcp

Cursor (~/.cursor/mcp.json)

json
{  "mcpServers": {    "domain-intelligence": {      "url": "https://oti-labs.com/mcp"    }  }}

VS Code (.vscode/mcp.json)

json
{  "servers": {    "domain-intelligence": {      "type": "http",      "url": "https://oti-labs.com/mcp"    }  }}

Windsurf (~/.codeium/windsurf/mcp_config.json)

json
{  "mcpServers": {    "domain-intelligence": {      "serverUrl": "https://oti-labs.com/mcp"    }  }}

Claude Desktop and other stdio-only clients, through mcp-remote:

json
{  "mcpServers": {    "domain-intelligence": {      "command": "npx",      "args": ["-y", "mcp-remote", "https://oti-labs.com/mcp"]    }  }}

Adding a RapidAPI key. Claude Code: append --header "X-RapidAPI-Key: YOUR_KEY". Cursor, VS Code and Windsurf: add "headers": { "X-RapidAPI-Key": "YOUR_KEY" } next to the URL. mcp-remote: add "--header", "X-RapidAPI-Key:YOUR_KEY" to args.

Example prompts

  • "How old is example.com and who is the registrar?"
  • "Is this domain suspicious? Check its age, SSL issuer and SPF/DMARC."
  • "List the live subdomains of example.com with their IPs."
  • "When do the SSL certificates for these 10 domains expire?"

Self-hosting

The server is one file. Keyed calls go through RapidAPI with the caller's key; keyless calls go to DI_INTERNAL_BASE with RAPIDAPI_PROXY_SECRET and are counted in Redis (REDIS_URL):

bash
pip install -r requirements.txtuvicorn server:app --host 127.0.0.1 --port 8002

To send keyed calls to your own copy of the API instead of RapidAPI, set DI_API_BASE (and DI_PROXY_SECRET if your API checks one).

Keyless limits can be changed with MCP_KEYLESS_MONTHLY, MCP_KEYLESS_PER_MINUTE, MCP_PROVIDER_MONTHLY, MCP_PROVIDER_PER_MINUTE and MCP_KEYLESS_DAILY_CEILING. ChatGPT's connector addresses come from chatgpt-connectors.json, which refresh_openai_ranges.py downloads from OpenAI; run it once a day from cron. Without that file, ChatGPT calls are counted per IP. Claude's outbound range is built in.

Source: mcp/README.md at commit 9ce9e6f

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.1.0LatestOct 3, 2026