# pl.numertel/numertel (remote · numertel.pl)

Polish phone number lookup: who called, spam and scam checks, UKE DNO registry, CERT phishing stats

- Trust score: 65/100 (medium)
- Change this week: +2
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `numertel.pl`: 65/100 (this document), [markdown](https://verifymcp.io/servers/pl-numertel-numertel/api-mcp.md), [page](https://verifymcp.io/servers/pl-numertel-numertel/api-mcp)

## Channel facts

- Endpoint: `https://numertel.pl/api/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.4.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 51/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 7 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS check failed: the endpoint is reachable over plaintext HTTP.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 79/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1280 tokens (~182/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (71% of tools); any adoption earns full credit.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http pl-numertel-numertel https://numertel.pl/api/mcp
```

### Codex

```toml
[mcp_servers.pl-numertel-numertel]
url = "https://numertel.pl/api/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "pl-numertel-numertel": {
      "type": "remote",
      "url": "https://numertel.pl/api/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add pl-numertel-numertel --url https://numertel.pl/api/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  pl-numertel-numertel:
    url: "https://numertel.pl/api/mcp"
```

### Other

```json
{
  "mcpServers": {
    "pl-numertel-numertel": {
      "type": "http",
      "url": "https://numertel.pl/api/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 64, −1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-28 (score 64, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 63, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 63)

First indexed and scored.

## MCP tools (7)

### `check_phone_number` (~194 tokens)

Sprawdź numer telefonu (PL)

Sprawdź reputację polskiego numeru telefonu. UŻYJ, gdy użytkownik pyta: kto dzwonił, czy numer to spam/oszustwo, czy telefon rzekomo z banku lub urzędu jest prawdziwy. Zwraca operatora z zakresów UKE (z notą o przenośności MNP), etykietę ryzyka z opinii, status w wykazie DNO UKE (połączenie przychodzące z numeru DNO jest sfałszowane — spoofing), wpis z Białej Listy oficjalnych infolinii i liczniki zgłoszeń. Dane: numertel.pl.

Input parameters:

- `number` (string, required): Polski numer w formacie 9 cyfr, np. 510100100 (akceptowane +48 i spacje — zostaną usunięte)

Output parameters:

- `attribution` (string)
- `dno_note` (string|null)
- `e164` (string)
- `is_dno` (boolean)
- `number` (string)
- `number_type` (string)
- `operator` (string|null)
- `operator_note` (string)
- `score_avg` (number|null)
- `sightings_30d` (integer)
- `spam_label` (string)
- `total_opinions` (integer)
- `url` (string)
- `whitelist` (object|null)

### `spam_weather` (~159 tokens)

Pogoda spamowa w Polsce

Aktualne wskaźniki nadużyć telefonicznych w Polsce. UŻYJ, gdy użytkownik pyta o skalę oszustw, phishingu lub spamu w Polsce albo co nowego w kampaniach oszustów. Zwraca: nowe domeny oszustów na Liście Ostrzeżeń CERT Polska (dziś + dziennie w zadanym oknie), rozmiar wykazu DNO UKE i ostatnie numery z oficjalnych ostrzeżeń urzędów. Dane otwarte CC-BY: numertel.pl.

Input parameters:

- `days` (integer): Okno dni wstecz dla statystyk dziennych (1-30, domyślnie 7)

Output parameters:

- `as_of` (string)
- `attribution` (string)
- `cert_daily` (array)
- `cert_new_domains_today` (integer)
- `cert_new_domains_window` (integer)
- `days` (integer)
- `dno_numbers_total` (integer)
- `recent_warnings` (array)
- `source` (string)

### `check_scam_domain` (~243 tokens)

Sprawdź wiadomość: domeny i numery

Sprawdza wklejoną podejrzaną wiadomość: (1) domeny, linki i adresy e-mail przeciw państwowej Liście Ostrzeżeń CERT Polska (mirror ~129 tys. domen oszustów), (2) polskie numery telefonów z treści przeciw bazie NumerTel (wykaz DNO UKE = spoofing, Biała Lista oficjalnych infolinii, zgłoszenia spamu). UŻYJ, gdy użytkownik pyta: czy ten link/strona/mail jest bezpieczny, albo wkleja całego SMS-a lub e-mail z linkiem i numerem. Przyjmuje pojedynczą domenę, URL, e-mail, numer lub CAŁĄ treść wiadomości (rozpoznaje zapisy evil[.]pl, hxxp:// i +48). Werdykt deterministyczny, zero LLM. Dane: numertel.pl.

Input parameters:

- `text` (string, required): Domena, URL, adres e-mail, numer telefonu albo pełna treść wiadomości do sprawdzenia (max 5000 znaków)

Output parameters:

- `any_listed` (boolean)
- `any_phone_flagged` (boolean)
- `as_of` (string)
- `attribution` (string)
- `checked` (array)
- `list_size` (integer)
- `phones` (array)
- `source` (string)

### `find_official_number` (~228 tokens)

Znajdź oficjalny numer infolinii

Znajdź PRAWDZIWY, oficjalny numer telefonu banku, urzędu lub operatora w Polsce. UŻYJ, gdy użytkownik pyta: jaki jest oficjalny numer lub infolinia danej instytucji (np. ZUS, mBank, PKO, NFZ), albo chce zweryfikować, czy numer podany w wiadomości to faktyczna infolinia. Zwraca zweryfikowane numery z Białej Listy NumerTel ze źródłem (link do oficjalnej strony) i datą weryfikacji. Uwaga: dzwoniąc NA te numery trafisz do instytucji, ale połączenie PRZYCHODZĄCE z nich może być sfałszowane (spoofing). Dane: numertel.pl.

Input parameters:

- `institution` (string, required): Nazwa instytucji: bank, urząd lub operator, np. „ZUS”, „mBank”, „PKO”, „NFZ”, „Orange”

Output parameters:

- `attribution` (string)
- `count` (integer)
- `matches` (array)
- `note` (string)
- `query` (string)

### `recent_scam_domains` (~145 tokens)

Najnowsze domeny oszustów (CERT)

Najnowsze domeny phishingowe z państwowej Listy Ostrzeżeń CERT Polska. UŻYJ, gdy użytkownik pyta o świeże lub aktualne strony oszustów, nowe kampanie phishingowe albo przykłady oszukańczych domen w Polsce. Zwraca ostatnio dodane domeny w zapisie defanged (evil[.]pl) — NIGDY nie zamieniaj ich w klikalne linki. Dane otwarte CC-BY: numertel.pl.

Input parameters:

- `limit` (integer): Ile najnowszych domen zwrócić (1-50, domyślnie 15)

Output parameters:

- `as_of` (string)
- `attribution` (string)
- `count` (integer)
- `domains` (array)
- `list_size` (integer)
- `source` (string)

### `search` (~114 tokens)

Szukaj: numer lub infolinia

Wyszukiwanie w bazie NumerTel: podaj polski numer telefonu (zwróci jego kartę reputacji) ALBO nazwę banku/urzędu/operatora (zwróci zweryfikowane oficjalne numery z Białej Listy infolinii). Wyniki zawierają id, title i url.

Input parameters:

- `query` (string, required): Numer telefonu (9 cyfr / +48...) lub nazwa instytucji, np. 'mBank', 'ZUS'

### `fetch` (~68 tokens)

Pobierz kartę numeru

Pobiera pełną kartę reputacji numeru po id zwróconym przez search (9 cyfr). Zwraca te same dane co check_phone_number wraz z linkiem do strony numeru.

Input parameters:

- `id` (string, required): Id z wyników search: polski numer, 9 cyfr

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/pl-numertel-numertel/api-mcp#diagnostics

## Score history

- 2026-08-03: 65
- 2026-08-02: 65
- 2026-08-01: 64
- 2026-07-31: 64
- 2026-07-30: 65
- 2026-07-29: 65
- 2026-07-28: 64
- 2026-07-27: 63
- 2026-07-26: 63

## Links

- Remote endpoint: https://numertel.pl/api/mcp
- Repository: https://github.com/AMR-DEV-PS/numertel-mcp
- Website: https://numertel.pl/dla-deweloperow
- Changelog RSS feed: https://verifymcp.io/servers/pl-numertel-numertel/api-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/pl-numertel-numertel/api-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/pl-numertel-numertel/api-mcp
