Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.cyanheads/whois-mcp-server

NPM · @CYANHEADS/WHOIS-MCP-SERVER · SCANNED AUG 7

Domain registration, availability, DNS records, and IP/ASN resolution via RDAP and DNS-over-HTTPS.

+50 this week 65 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security88
  • No malware found by supply-chain analysis.Pass
  • Known CVEs were checked across the 125 of 132 dependencies we could resolve, so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Dependency health was assessed across the 125 of 132 dependencies we could resolve, so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability72
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 1110 tokens (~185/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @cyanheads/whois-mcp-server

# add to Claude Code
claude mcp add cyanheads-whois-mcp-server -- npx -y @cyanheads/whois-mcp-server
# add to Codex CLI
codex mcp add cyanheads-whois-mcp-server -- npx -y @cyanheads/whois-mcp-server
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "cyanheads-whois-mcp-server": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@cyanheads/whois-mcp-server"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add cyanheads-whois-mcp-server --command npx --arg -y --arg @cyanheads/whois-mcp-server
# ~/.hermes/config.yaml
mcp_servers:
  cyanheads-whois-mcp-server:
    command: "npx"
    args: ["-y", "@cyanheads/whois-mcp-server"]
// mcp.json
{
  "mcpServers": {
    "cyanheads-whois-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@cyanheads/whois-mcp-server"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 6 Aug 26 +30
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • MCP protocol: unverified → pass functional
    • Tool coverage: unverified → 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: excellent functional
    • First check of Schema quality: fail functional
  • 2 Aug 26 +30
    • Provenance: unverified → fail security
    • Install scripts: unverified → pass security
    • Known CVEs: unverified → partial security
    • Malware scan: unverified → pass security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Maintenance: unverified → pass functional
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet. functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Licence: Apache-2.0 functional
  • 1 Aug 26 −10
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 −9
    • Provenance: unverified → fail security
    • Malware scan: pass → unverified security
    • Install scripts: unverified → pass security
    • Maintenance: unverified → pass functional
    • License: unverified → pass functional
    • Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess. functional
    • Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess. functional
    • Licence: Apache-2.0 functional
  • 29 Jul 26 −1
    • Dependency health: partial → unverified functional
  • 28 Jul 26 +1
    • Dependency health: unverified → partial functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
  • 27 Jul 26 24

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 7 Aug 2026 · Analysed npm/@cyanheads/[email protected]

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm
Dependencies 125 packages
Packages resolved 125
Deprecated 112
Stale 39
Tree resolution Partial

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools · 6 exposed · ~945 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
whois_check_availability ~129

Check whether a domain name is registered or available for registration. Returns available: true when the domain is not registered, available: false with registrar and expiry_date when it is registered, and available: null with rdap_coverage: false when the TLD has no RDAP coverage. Designed for "can I register X" and bulk name sweeps. For the full registration record use whois_lookup_domain.

NameTypeReqDescription
domainstringyesFully qualified domain name to check (e.g., "myfuturename.com"). Must be a valid FQDN — labels separated by dots.
NameTypeReqDescription
availableyesTrue = available for registration. False = registered. Null = rdap_coverage is false — cannot determine availability for this TLD.
domainstringyesNormalized domain name checked.
expiry_datestringExpiry date when available: false.
rdap_coveragebooleanyesTrue when a RDAP server was found for this TLD.
registrarstringRegistrar name when available: false.

No examples provided.

whois_get_dns ~153

Fetch DNS records for a domain via DNS-over-HTTPS. Supports A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, PTR. Multiple types are fetched in parallel. NXDOMAIN is returned as nxdomain: true in the result, not as an error — it means the domain does not exist in DNS.

NameTypeReqDescription
domainstringyesFully qualified domain name or hostname to query (e.g., "github.com", "mail.example.com").
typesarrayDNS record types to fetch. Defaults to [A, AAAA, MX, TXT, NS]. Specify more types to expand coverage (e.g., add CAA to check certificate authority authorization).
NameTypeReqDescription
domainstringyesDomain queried.
nxdomainbooleanyesTrue when the domain does not exist in DNS (NXDOMAIN / Status 3). Records will be empty. This is a valid data signal, not an error.
recordsarrayyesDNS records returned for the requested types.
sourcestringyesThe DoH resolver that provided results (cloudflare = primary used for most types, nextdns = fallback or CAA).

No examples provided.

whois_get_dossier ~185

One-call domain triage: fetches registration record (RDAP) and DNS records (A, MX, NS, TXT) in parallel, returning a single normalized record with factual signals — domain age in days, privacy-redacted flag, registrar, NS provider inferred from NS records, mail provider inferred from MX records. No synthesized scores — factual signals only. Partial results are surfaced when one leg fails (registration or DNS marked with source_error); only when both legs fail does the tool throw both_legs_failed. For the full registration record use whois_lookup_domain. For DNS types beyond A/MX/NS/TXT (e.g., CNAME, CAA, SOA) use whois_get_dns.

NameTypeReqDescription
domainstringyesFully qualified domain name for the triage (e.g., "github.com"). Must be a valid FQDN.
NameTypeReqDescription
a_recordsarrayyesIPv4 addresses (A records). Empty when DNS leg failed or NXDOMAIN.
age_daysyesDomain age in days since creation_date. Null when created_date is unavailable.
created_datestringISO 8601 registration creation date.
dns_nxdomainyesTrue when DNS says domain does not exist (NXDOMAIN). Null when DNS leg failed.
dns_source_errorstringError message from the DNS leg when it failed. Omitted on success.
dnssec_signedyesTrue when delegation-signed. Null when RDAP leg unavailable.
domainstringyesNormalized domain name.
expiry_datestringISO 8601 registration expiry date.
mx_provideryesMail provider inferred from MX record (e.g., "Google Workspace", "Microsoft 365"). Null when no MX or DNS leg failed.
mx_recordsarrayyesMail exchange hostnames (MX data). Empty when DNS leg failed or NXDOMAIN.
nameserversarrayyesAuthoritative nameservers. Empty when RDAP leg failed.
ns_provideryesDNS provider inferred from NS record (e.g., "Cloudflare", "AWS Route 53"). Null when unknown or DNS leg failed.
ns_recordsarrayyesDNS nameservers from live DNS (NS data). Empty when DNS leg failed or NXDOMAIN.
privacy_redactedyesTrue when registrant contact info is privacy-redacted. Null when RDAP leg unavailable.
rdap_coverageyesTrue = RDAP server found. False = no RDAP coverage. Null = RDAP leg failed (source_error set).
rdap_source_errorstringError message from the RDAP leg when it failed. Omitted on success.
registeredyesTrue when the domain has a registration record. False = RDAP 404 (not registered). Null when RDAP leg failed.
registrarstringRegistrar name from registration record.
statusarrayyesEPP status codes. Empty when RDAP leg failed.
txt_recordsarrayyesTXT record values (SPF, DKIM hints, etc.). Empty when DNS leg failed or NXDOMAIN.

No examples provided.

whois_lookup_asn ~123

Resolve an Autonomous System Number (ASN) to its org name, country, and RIR source via RIR RDAP. Accepts AS-prefixed format (e.g., "AS15169") or bare integer (e.g., "15169"). Distinct from IP lookup — the entry point is the ASN itself, not an IP within its block.

NameTypeReqDescription
asnstringyesAutonomous System Number to look up. Accepts AS-prefixed format (e.g., "AS15169") or bare integer (e.g., "15169").
NameTypeReqDescription
asnstringyesNormalized ASN identifier (AS-prefixed, e.g., "AS15169").
countrystringCountry code (ISO 3166-1 alpha-2). Omitted when not in RDAP data.
end_autnumnumberEnd ASN of the registered range.
handlestringRIR handle / object identifier.
namestringASN network name.
org_namestringOrganization name registered for this ASN.
rirstringRegional Internet Registry that manages this ASN (ARIN, RIPE, APNIC, LACNIC, AFRINIC).
start_autnumnumberStart ASN of the registered range.
typestringASN type (e.g., "DIRECT ALLOCATION").

No examples provided.

whois_lookup_domain ~166

Look up a domain's registration record — registrar, created/expiry dates, nameservers, EPP status codes, DNSSEC flag, and registrant org (where not privacy-redacted). Uses RDAP via IANA bootstrap to auto-select the correct per-TLD RDAP server, returning one normalized shape regardless of TLD. When the TLD has no RDAP coverage, returns rdap_coverage: false. If the domain is not registered, throws domain_not_found — use whois_check_availability to test availability without triggering an error.

NameTypeReqDescription
domainstringyesFully qualified domain name to look up (e.g., "example.com", "github.com"). Must be a valid FQDN — labels separated by dots, each label up to 63 chars.
NameTypeReqDescription
created_datestringISO 8601 domain registration date.
dnssec_signedbooleanyesTrue when the domain has DNSSEC delegation signed.
domainstringyesNormalized domain name (lowercased).
expiry_datestringISO 8601 registration expiry date.
handlestringRegistry handle / object identifier assigned by the registry.
nameserversarrayyesAuthoritative nameservers for this domain.
rdap_coveragebooleanyesTrue when a RDAP server was found for this TLD; false when RDAP coverage is absent.
rdap_last_updatedstringISO 8601 timestamp of last RDAP database update.
registrant_orgstringRegistrant organization name. Omitted when privacy-redacted.
registrant_redactedbooleanyesTrue when registrant contact data is privacy-redacted (common post-GDPR).
registrarstringName of the sponsoring registrar.
registrar_iana_idstringIANA registrar ID number.
statusarrayyesEPP status codes (e.g., clientTransferProhibited, serverDeleteProhibited).
updated_datestringISO 8601 date of last registration record change.

No examples provided.

whois_lookup_ip ~189

Look up an IP address or CIDR block via RIR RDAP (ARIN, RIPE, APNIC, LACNIC, AFRINIC — auto-routed via IANA bootstrap). Returns netblock, org, country, CIDR, abuse contact email, and reverse DNS (PTR) via DoH. PTR is best-effort — failure returns ptr: null. Private/reserved ranges (RFC 1918, loopback, link-local) return a validation error — no RIR RDAP record exists for them.

NameTypeReqDescription
ipstringyesIPv4 address (e.g., "8.8.8.8"), IPv6 address (e.g., "2001:4860:4860::8888"), or CIDR notation (e.g., "192.0.2.0/24"). Private/reserved ranges will return a validation error.
NameTypeReqDescription
abuse_emailstringAbuse contact email address.
cidrstringCIDR notation of the netblock (e.g., "8.8.8.0/24").
countrystringCountry code (ISO 3166-1 alpha-2). Omitted when not in RDAP data.
end_addressstringEnd address of the IP netblock.
handlestringRIR handle / object identifier.
ipstringyesThe IP or CIDR queried.
ip_versionstringIP version: "v4" or "v6".
namestringNetwork name assigned by the RIR.
org_namestringOrganization name holding the netblock.
ptryesReverse DNS hostname (PTR record). Null when PTR lookup fails, returns no answer, or domain is NXDOMAIN.
rdap_sourcestringRIR that provided the RDAP data (ARIN, RIPE, APNIC, LACNIC, AFRINIC).
start_addressstringStart address of the IP netblock.
typestringNetwork type (e.g., "DIRECT ALLOCATION").

No examples provided.