Domain Intelligence

com.oti-labsv1.1.0更新於 Oct 3, 2026

WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.

概覽

AI 產生的概覽

讓助理查詢任何網域的 WHOIS/RDAP、DNS、SSL、即時子網域與郵件安全記錄。

功能
提供唯讀的網域情報工具。domain_lookup 一次回傳全部結果;whois_lookup 透過 RDAP(失敗時改用 43 埠 WHOIS)提供註冊商、日期、名稱伺服器與狀態;dns_records 回傳 A、AAAA、MX、TXT、NS、CAA 與 SOA 記錄。ssl_certificate 執行即時 TLS 握手,取得簽發者、有效期間、days_until_expiry、SAN 與簽章演算法;subdomains 列出含 IP 的線上主機;email_security 檢查約 29 個常見選擇器下的 SPF、DMARC 與 DKIM。
適用情境
適合查詢網域歸屬或註冊資訊、用網域年齡、SSL 簽發者與郵件驗證判斷網域是否可疑、了解哪些子網域仍在線及其解析的 IP,或查看一批憑證何時到期。它面向偵察與盡職調查類問題,而非持續監控。所有工具皆為唯讀。
執行需求
需要遠端 Streamable HTTP 端點 IP 每月 1,000 次查詢,每分鐘最多 10 次,無金鑰每日總量上限 2,000 次。更高額度需要 RapidAPI 金鑰,透過 X-RapidAPI-Key 標頭(或 Authorization: Bearer)送出。僅支援 stdio 的用戶端需要 npx 與 mcp-remote。
安裝前請注意
所有工具皆為唯讀,不會寫入或刪除資料。選用的 X-RapidAPI-Key 標頭屬於機密資訊,應只透過用戶端的標頭設定提供,不要貼進提示詞或共用設定檔。查詢會送往供應商的託管端點,因此你查詢的網域對該第三方可見。無金鑰使用有速率限制,且依供應商共用額度池,大量使用可能被限流。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Domain Intelligence,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "domain-intelligence": {
      "type": "http",
      "url": "https://oti-labs.com/mcp"
    }
  }
}

README

Domain Intelligence MCP server

An MCP server that gives AI agents and assistants WHOIS/RDAP, DNS, SSL, subdomain and email-security lookups for any domain.

  • Hosted endpoint: https://oti-labs.com/mcp (Streamable HTTP)
  • Registry name: com.oti-labs/domain-intelligence
  • No key to start: 1,000 lookups a month per IP (per /64 for IPv6), up to 10 a minute. Hosted connectors that call from their provider's shared addresses (Claude, ChatGPT) share one pool per provider: 10,000 a month, up to 120 a minute. Keyless use on the hosted server stops at 2,000 calls a day in total and resets at 00:00 UTC.
  • After that: add a RapidAPI key in the X-RapidAPI-Key header (or Authorization: Bearer <key>). Calls then count on your RapidAPI plan; the free plan adds another 1,000 a month: get a key.

Tools

ToolWhat it returns
domain_lookupEverything below in one call. Big subdomain lists are trimmed (subdomain_limit, default 50).
whois_lookupRegistrar, created/updated/expiry dates, nameservers, status. RDAP first, port-43 WHOIS fallback.
dns_recordsA, AAAA, MX, TXT, NS, CAA and SOA records.
ssl_certificateLive TLS handshake: issuer, validity dates, days_until_expiry, SANs, signature algorithm.
subdomainsLive hosts with IPs, all names found (live first), collapsed infrastructure pools. wait=true waits for every source.
email_securitySPF, DMARC, and DKIM keys from ~29 common selectors.

All tools are read-only.

Setup

These work without a key. To use a RapidAPI key, add the header shown at the end of this section.

Claude Code

bash
claude mcp add --transport http domain-intelligence https://oti-labs.com/mcp

Cursor (~/.cursor/mcp.json)

json
{  "mcpServers": {    "domain-intelligence": {      "url": "https://oti-labs.com/mcp"    }  }}

VS Code (.vscode/mcp.json)

json
{  "servers": {    "domain-intelligence": {      "type": "http",      "url": "https://oti-labs.com/mcp"    }  }}

Windsurf (~/.codeium/windsurf/mcp_config.json)

json
{  "mcpServers": {    "domain-intelligence": {      "serverUrl": "https://oti-labs.com/mcp"    }  }}

Claude Desktop and other stdio-only clients, through mcp-remote:

json
{  "mcpServers": {    "domain-intelligence": {      "command": "npx",      "args": ["-y", "mcp-remote", "https://oti-labs.com/mcp"]    }  }}

Adding a RapidAPI key. Claude Code: append --header "X-RapidAPI-Key: YOUR_KEY". Cursor, VS Code and Windsurf: add "headers": { "X-RapidAPI-Key": "YOUR_KEY" } next to the URL. mcp-remote: add "--header", "X-RapidAPI-Key:YOUR_KEY" to args.

Example prompts

  • "How old is example.com and who is the registrar?"
  • "Is this domain suspicious? Check its age, SSL issuer and SPF/DMARC."
  • "List the live subdomains of example.com with their IPs."
  • "When do the SSL certificates for these 10 domains expire?"

Self-hosting

The server is one file. Keyed calls go through RapidAPI with the caller's key; keyless calls go to DI_INTERNAL_BASE with RAPIDAPI_PROXY_SECRET and are counted in Redis (REDIS_URL):

bash
pip install -r requirements.txtuvicorn server:app --host 127.0.0.1 --port 8002

To send keyed calls to your own copy of the API instead of RapidAPI, set DI_API_BASE (and DI_PROXY_SECRET if your API checks one).

Keyless limits can be changed with MCP_KEYLESS_MONTHLY, MCP_KEYLESS_PER_MINUTE, MCP_PROVIDER_MONTHLY, MCP_PROVIDER_PER_MINUTE and MCP_KEYLESS_DAILY_CEILING. ChatGPT's connector addresses come from chatgpt-connectors.json, which refresh_openai_ranges.py downloads from OpenAI; run it once a day from cron. Without that file, ChatGPT calls are counted per IP. Claude's outbound range is built in.

來源:mcp/README.md,提交 9ce9e6f

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.1.0最新Oct 3, 2026