run.domani/domani
REMOTE · DOMANI.RUN · SCANNED AUG 3
Internet identity for AI agents: register or broker domains, email, DNS - pay by card or USDC.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security91
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability72
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 13023 tokens (~106/item across 122 items; 122 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · domani.run
claude mcp add --transport http run-domani-domani https://domani.run/mcp
[mcp_servers.run-domani-domani] url = "https://domani.run/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"run-domani-domani": {
"type": "remote",
"url": "https://domani.run/mcp",
"enabled": true
}
}
} openclaw mcp add run-domani-domani --url https://domani.run/mcp --transport streamable-http
mcp_servers:
run-domani-domani:
url: "https://domani.run/mcp" {
"mcpServers": {
"run-domani-domani": {
"type": "http",
"url": "https://domani.run/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +5
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes. Other categories moved too: Schema Quality & AI Usability rose 2.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 70
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://domani.run/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=domani.run | CN=YE2,O=Let's Encrypt,C=US | 6 Jul 2026 | 4 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 5e06f2de1b09b36aabe6b402d014b770fe8 |
| SANs: *.domani.run, domani.run | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC secure
Validation of domani.run. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| run. | present | 37315 | 8 | Verified |
| domani.run. | present | 2371 | 13 | Verified |
| domani.run. | Verified address RRset verified with the apex keys |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://js.stripe.com https://vercel.live https://va.vercel-scripts.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self'; connect-src 'self' https://api.stripe.com https://cloudflare-dns.com https://vercel.live https://va.vercel-scripts.com; frame-src https://js.stripe.com https://vercel.live |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Protected resource metadata
| Retrieved | No |
|---|---|
| Problem | no_resource_metadata |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://domani.run/mcp | Verified | 200 | |
| http (plaintext) | http://domani.run/mcp | HTTPS enforced | 308 | https://domani.run/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
set_listing_price Set Listing Price ~106
Set a 'For Sale' price on a parked domain, or remove the listing. When a price is set and parking is enabled, visitors see a 'For Sale' page with the price and a contact form to reach the domain owner. Set price to null to remove the listing.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to configure, e.g. example.com |
| price | — | yes | Sale price in USD (e.g. 499.99), or null to remove the listing |
No output schema declared.
No examples provided.
set_nameservers Set Nameservers ~109
Replace the nameservers for a domain you own. Requires 2–13 valid hostnames. Common values: OpenSRS DNS (ns1.systemdns.com, ns2.systemdns.com, ns3.systemdns.com), Cloudflare (assigned per account), custom NS.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to set nameservers for |
| nameservers | array | yes | Array of nameserver hostnames, e.g. ['ns1.systemdns.com', 'ns2.systemdns.com'] |
No output schema declared.
No examples provided.
set_parking Set Parking ~162
Enable or disable the parking page for a domain you own. When enabled, visitors to the domain see a default parking page (or a 'For Sale' page if a listing price is set). Parking is enabled by default for newly purchased domains. IMPORTANT: If the domain has existing DNS records, the response will include requires_confirmation=true and show the records that will be overwritten. You MUST inform the user and get their approval before calling again with confirm=true.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | — | Set to true to confirm overwriting existing DNS records. Only needed when the first call returns requires_confirmation=true. |
| domain | string | yes | Domain to configure, e.g. example.com |
| enabled | boolean | yes | true to enable the parking page, false to disable it |
No output schema declared.
No examples provided.
set_security_lock Set Security Lock ~66
Lock or unlock a domain's transfer lock (clientTransferProhibited). When locked, transfer requests are rejected. Unlock before transferring to another registrar.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to configure |
| locked | boolean | yes | true to lock (prevent transfers), false to unlock |
No output schema declared.
No examples provided.
set_whois_privacy Set WHOIS Privacy ~68
Enable or disable WHOIS privacy for a domain you own. When enabled, your personal contact information is hidden from public WHOIS lookups.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to configure |
| enabled | boolean | yes | true to enable WHOIS privacy, false to disable |
No output schema declared.
No examples provided.
setup_billing Setup Billing ~115
Get a checkout URL for the user to add a payment card. Returns a URL - tell the user to open it in their browser. After they complete the form, call get_account to verify has_payment_method is true. Only needed for card payments - agents with crypto wallets can skip this and pay with USDC on Base via x402 protocol.
| Name | Type | Req | Description |
|---|---|---|---|
| mode | string | — | 'checkout' (default) returns a URL for the user to open in browser. 'setup_intent' returns a client_secret for Stripe.js integration. |
No output schema declared.
No examples provided.
setup_domain_email Setup Domain Email ~101
Pre-configure email DNS on a domain (optional). This is called automatically by create_mailbox when needed. Use this only to pre-configure DNS before creating mailboxes. Pass force=true to override existing email provider (Google Workspace, Fastmail, Proton).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to enable email on, e.g. mysite.com |
| force | boolean | — | Override existing MX records (e.g. Google Workspace). Default: false |
No output schema declared.
No examples provided.
snapshot_dns Snapshot DNS ~72
Capture all DNS records for a domain via public DNS lookups. Discovers subdomains from CT logs, SPF, and common names. Stores a server-side backup. Use before migrations or transfers.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to snapshot |
| extra_subdomains | array | — | Additional subdomains to include |
No output schema declared.
No examples provided.
suggest_domains Suggest Domains ~211
AI-powered domain suggestions. Given a project description, generates full domain names with creative TLDs (e.g. codebuddy.dev, wavify.fm), checks availability, and returns only available domains with pricing.
| Name | Type | Req | Description |
|---|---|---|---|
| count | number | — | Number of suggestions to return (default 10) |
| exclude | array | — | Domains to exclude from suggestions (e.g. from previous calls) |
| lang | string | — | Language/cultural inspiration: names will draw from this language's words, aesthetics, and culture |
| prompt | string | yes | Project description or keywords, e.g. 'AI coding assistant' |
| style | string | — | Name style: 'single' (one word), 'creative' (evocative/metaphorical single word), 'short' (3-6 chars), 'brandable' (invented names), 'keyword' (descriptive) |
| tlds | array | — | Preferred TLDs without dots (e.g. ['com', 'dev']). Results will prioritize these. |
No output schema declared.
No examples provided.
test_email_webhook Test Email Webhook ~63
Send a signed test payload to the mailbox webhook URL. Returns HTTP status and success/failure. API: POST /api/emails/{address}/webhook/test.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Mailbox domain |
| slug | string | yes | Mailbox slug |
No output schema declared.
No examples provided.
transfer_domain Transfer Domain ~235
Initiate a domain transfer from another provider. PAID. The transfer includes 1 year of renewal, preserves current nameservers, and does not migrate DNS. Call plan_domain_adoption first, show the exact price and continuity plan, then get explicit confirmation before calling this. Requires the authorization/EPP code from the current provider.
| Name | Type | Req | Description |
|---|---|---|---|
| auth_code | string | yes | Authorization/EPP code from the current provider |
| domain | string | yes | Domain to transfer, e.g. mysite.com |
| extra_subdomains | array | — | Additional subdomains to include in the pre-transfer DNS snapshot. We auto-discover subdomains via CT logs, SPF, MX/DKIM inference, and a common wordlist - use this for any custom subdomains we might… |
| payment_chain | string | — | Chain the USDC payment was sent on. |
| payment_method | string | — | Payment method: 'card' to charge card on file, 'usdc' to pay with USDC. Overrides the user's default preference for this request. |
| payment_tx | string | — | Transaction hash of a USDC payment already sent on-chain. |
No output schema declared.
No examples provided.
unsell_domain Unsell Domain ~61
Remove an active for-sale listing for a domain you own. The domain stays in your account but is no longer purchasable on the marketplace. Requires domains:write scope.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to unlist, e.g. premium.com |
No output schema declared.
No examples provided.
update_email_messages Update Email Messages ~161
Apply a retry-safe lifecycle action to up to 100 messages. Returns a durable per-item operation receipt. Reuse the exact idempotency key after timeouts; never invent a new key for the same logical action. Permanent deletion requires email:delete. API: POST /api/emails/{address}/messages/actions.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | — |
| destination | string | — | Required for move |
| domain | string | yes | Mailbox domain |
| idempotency_key | string | yes | Caller-stable key for this exact logical batch |
| message_ids | array | yes | Explicit message IDs |
| read | boolean | — | Required for mark_read |
| slug | string | yes | Mailbox slug |
| starred | boolean | — | Required for star |
No output schema declared.
No examples provided.
update_identity Update identity ~68
Update a free identity's name/bio/emoji/email/links.
| Name | Type | Req | Description |
|---|---|---|---|
| bio | string | — | — |
| string | — | — | |
| emoji | string | — | — |
| links | array | — | — |
| name | string | — | — |
| slug | string | yes | The handle to update |
No output schema declared.
No examples provided.
update_listing Update Listing ~65
Update the price and/or description of an active marketplace listing. Requires domains:write scope.
| Name | Type | Req | Description |
|---|---|---|---|
| description | — | — | New description (null to clear) |
| domain | string | yes | Domain with active listing, e.g. premium.com |
| price | number | — | New price in USD |
No output schema declared.
No examples provided.
update_webhook Update Webhook ~94
Update an existing webhook's URL, subscribed events, or active status. Use list_webhooks to get the webhook ID first.
| Name | Type | Req | Description |
|---|---|---|---|
| active | boolean | — | Set to false to pause the webhook, true to resume |
| events | array | — | New list of event types to subscribe to |
| url | string | — | New HTTPS URL for the webhook |
| webhook_id | string | yes | ID of the webhook to update |
No output schema declared.
No examples provided.
upgrade_plan Upgrade to Pro ~93
Get a Stripe checkout URL to upgrade the user to the Pro plan ($9/month). Returns a URL. Tell the user to open it in their browser to complete the upgrade. Pro includes 10,000 emails/month, unlimited mailboxes on custom domains, API/MCP/CLI access, webhooks, and forwarding. Use this when the user hits the free plan monthly send limit (MONTHLY_LIMIT_EXCEEDED error).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
verify_connection Verify Connection ~87
Verify that a provider connection is working by checking DNS propagation. Use after connect_domain to confirm records are live.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to verify |
| method | string | — | Method name if applicable |
| provider | string | — | Provider name, e.g. vercel |
| target | string | — | Target for auto-detection, e.g. my-app.vercel.app |
No output schema declared.
No examples provided.
verify_import Verify Import ~44
Verify DNS TXT record and complete domain import. Call after adding the TXT record from import_domain.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to verify, e.g. mysite.com |
No output schema declared.
No examples provided.
verify_service Verify Service ~113
Add DNS records to verify domain ownership for a third-party service (Stripe, Google Search Console, AWS SES, Postmark, Resend, Facebook, HubSpot, Microsoft 365). Unknown services fall back to a generic TXT record.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name |
| service | string | yes | Service name (e.g. stripe, google-search-console, aws-ses, postmark, resend, facebook, hubspot, microsoft-365) |
| token | string | yes | Verification token provided by the service |
No output schema declared.
No examples provided.
watch_transfer Watch Transfer ~91
Watch a domain and get notified (email + webhook) when it becomes eligible for transfer. Uses RDAP to check ICANN lock periods and EPP status codes. If the domain is already eligible, returns immediately without creating a watch. If not eligible but has a known date, creates a watch and notifies you when it's ready.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to watch, e.g. example.com |
No output schema declared.
No examples provided.
whois_lookup WHOIS Lookup ~80
Look up domain registration data via RDAP (modern WHOIS). Returns registrar, dates, status, nameservers, DNSSEC, and contact information (registrant, admin, tech, billing - often redacted for privacy). Works for any domain - no ownership required.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to look up, e.g. example.com |
No output schema declared.
No examples provided.