Domain Intelligence

com.oti-labsv1.1.0更新于 Oct 3, 2026

WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.

概览

AI 生成的概览

让助手查询任意域名的 WHOIS/RDAP、DNS、SSL、实时子域名和邮件安全记录。

功能
提供只读的域名情报工具。domain_lookup 一次返回全部结果;whois_lookup 通过 RDAP(失败时回退到 43 端口 WHOIS)给出注册商、日期、名称服务器和状态;dns_records 返回 A、AAAA、MX、TXT、NS、CAA 和 SOA 记录。ssl_certificate 执行实时 TLS 握手,返回签发者、有效期、days_until_expiry、SAN 和签名算法;subdomains 列出带 IP 的在线主机;email_security 检查约 29 个常见选择器下的 SPF、DMARC 和 DKIM。
适用场景
适合查询域名归属或注册信息、通过域名年龄、SSL 签发者和邮件认证判断域名是否可疑、了解哪些子域名在线及其解析的 IP,或查看一批证书何时到期。它面向侦察与尽职调查类问题,而非持续监控。所有工具均为只读。
运行要求
需要远程 Streamable HTTP 端点 IP 每月 1,000 次查询,每分钟最多 10 次,无密钥每日总量上限 2,000 次。更高配额需要 RapidAPI 密钥,通过 X-RapidAPI-Key 请求头(或 Authorization: Bearer)发送。仅支持 stdio 的客户端需要 npx 和 mcp-remote。
安装前请注意
所有工具均为只读,不会写入或删除数据。可选的 X-RapidAPI-Key 请求头属于机密信息,应仅通过客户端的请求头配置提供,不要粘贴到提示词或共享配置文件中。查询会发送到提供方的托管端点,因此所查询的域名对该第三方可见。无密钥使用有速率限制且按提供方共享额度池,高频使用可能被限流。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Domain Intelligence,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "domain-intelligence": {
      "type": "http",
      "url": "https://oti-labs.com/mcp"
    }
  }
}

README

Domain Intelligence MCP server

An MCP server that gives AI agents and assistants WHOIS/RDAP, DNS, SSL, subdomain and email-security lookups for any domain.

  • Hosted endpoint: https://oti-labs.com/mcp (Streamable HTTP)
  • Registry name: com.oti-labs/domain-intelligence
  • No key to start: 1,000 lookups a month per IP (per /64 for IPv6), up to 10 a minute. Hosted connectors that call from their provider's shared addresses (Claude, ChatGPT) share one pool per provider: 10,000 a month, up to 120 a minute. Keyless use on the hosted server stops at 2,000 calls a day in total and resets at 00:00 UTC.
  • After that: add a RapidAPI key in the X-RapidAPI-Key header (or Authorization: Bearer <key>). Calls then count on your RapidAPI plan; the free plan adds another 1,000 a month: get a key.

Tools

ToolWhat it returns
domain_lookupEverything below in one call. Big subdomain lists are trimmed (subdomain_limit, default 50).
whois_lookupRegistrar, created/updated/expiry dates, nameservers, status. RDAP first, port-43 WHOIS fallback.
dns_recordsA, AAAA, MX, TXT, NS, CAA and SOA records.
ssl_certificateLive TLS handshake: issuer, validity dates, days_until_expiry, SANs, signature algorithm.
subdomainsLive hosts with IPs, all names found (live first), collapsed infrastructure pools. wait=true waits for every source.
email_securitySPF, DMARC, and DKIM keys from ~29 common selectors.

All tools are read-only.

Setup

These work without a key. To use a RapidAPI key, add the header shown at the end of this section.

Claude Code

bash
claude mcp add --transport http domain-intelligence https://oti-labs.com/mcp

Cursor (~/.cursor/mcp.json)

json
{  "mcpServers": {    "domain-intelligence": {      "url": "https://oti-labs.com/mcp"    }  }}

VS Code (.vscode/mcp.json)

json
{  "servers": {    "domain-intelligence": {      "type": "http",      "url": "https://oti-labs.com/mcp"    }  }}

Windsurf (~/.codeium/windsurf/mcp_config.json)

json
{  "mcpServers": {    "domain-intelligence": {      "serverUrl": "https://oti-labs.com/mcp"    }  }}

Claude Desktop and other stdio-only clients, through mcp-remote:

json
{  "mcpServers": {    "domain-intelligence": {      "command": "npx",      "args": ["-y", "mcp-remote", "https://oti-labs.com/mcp"]    }  }}

Adding a RapidAPI key. Claude Code: append --header "X-RapidAPI-Key: YOUR_KEY". Cursor, VS Code and Windsurf: add "headers": { "X-RapidAPI-Key": "YOUR_KEY" } next to the URL. mcp-remote: add "--header", "X-RapidAPI-Key:YOUR_KEY" to args.

Example prompts

  • "How old is example.com and who is the registrar?"
  • "Is this domain suspicious? Check its age, SSL issuer and SPF/DMARC."
  • "List the live subdomains of example.com with their IPs."
  • "When do the SSL certificates for these 10 domains expire?"

Self-hosting

The server is one file. Keyed calls go through RapidAPI with the caller's key; keyless calls go to DI_INTERNAL_BASE with RAPIDAPI_PROXY_SECRET and are counted in Redis (REDIS_URL):

bash
pip install -r requirements.txtuvicorn server:app --host 127.0.0.1 --port 8002

To send keyed calls to your own copy of the API instead of RapidAPI, set DI_API_BASE (and DI_PROXY_SECRET if your API checks one).

Keyless limits can be changed with MCP_KEYLESS_MONTHLY, MCP_KEYLESS_PER_MINUTE, MCP_PROVIDER_MONTHLY, MCP_PROVIDER_PER_MINUTE and MCP_KEYLESS_DAILY_CEILING. ChatGPT's connector addresses come from chatgpt-connectors.json, which refresh_openai_ranges.py downloads from OpenAI; run it once a day from cron. Without that file, ChatGPT calls are counted per IP. Claude's outbound range is built in.

来源:mcp/README.md,提交 9ce9e6f

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.1.0最新Oct 3, 2026