Tomba MCP Server
REMOTE · MCP.TOMBA.IO · 2 COMPONENTS · SCANNED AUG 17
MCP server for Tomba email finder, verification, and contact enrichment API
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 22 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability88
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1806 tokens (~72/item across 25 items; 22 tools + 3 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management33
- Stability observed for 10 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · mcp.tomba.io
claude mcp add --transport http tomba-io-tomba-mcp-server https://mcp.tomba.io/mcp
[mcp_servers.tomba-io-tomba-mcp-server] url = "https://mcp.tomba.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"tomba-io-tomba-mcp-server": {
"type": "remote",
"url": "https://mcp.tomba.io/mcp",
"enabled": true
}
}
} openclaw mcp add tomba-io-tomba-mcp-server --url https://mcp.tomba.io/mcp --transport streamable-http
mcp_servers:
tomba-io-tomba-mcp-server:
url: "https://mcp.tomba.io/mcp" {
"mcpServers": {
"tomba-io-tomba-mcp-server": {
"type": "http",
"url": "https://mcp.tomba.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 16 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 9 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 8 Aug 26 0
- Stability: unverified → 0.03 ▲ functional
- 7 Aug 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 17 Aug 2026 · Probed https://mcp.tomba.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=tomba.io | CN=YE2,O=Let's Encrypt,C=US | 31 Jul 2026 | 29 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 6e7725830fd30ec9ba7dcc23cd2f62be66e |
| SANs: *.tomba.io, tomba.io | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of mcp.tomba.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| tomba.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.tomba.io/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.tomba.io/mcp | HTTPS enforced | 301 | https://mcp.tomba.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
author_finder Author Finder ~62
Find the email address of an article's author from a given URL. Useful for outreach to content creators and journalists.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The URL of the article or blog post |
| webhook_url | string | – | Optional webhook URL to receive results asynchronously |
No output schema declared.
No examples provided.
companies_search Companies Search ~129
Search for companies in the Tomba database. Filter by name, industry, country, and more to find target companies for outreach.
| Name | Type | Req | Description |
|---|---|---|---|
| filters | object | – | Filter options with include/exclude arrays for: location_country, location_city, location_state, industry, size, type, keywords, founded, technologies, similar, revenue, sic, naics |
| page | number | – | Page number for pagination (1-1000) |
| query | string | – | Search query for company name or keywords (8-100 characters) |
| webhook_url | string | – | Optional webhook URL to receive results asynchronously |
No output schema declared.
No examples provided.
domain_search Domain Search ~179
Search for all email addresses associated with a specific domain or company. Returns a list of email addresses found for the given company domain along with metadata about each contact.
| Name | Type | Req | Description |
|---|---|---|---|
| company | string | – | The company name to search for |
| country | string | – | Filter by country code (e.g., 'US', 'GB') |
| department | string | – | Filter by department (e.g., 'executive', 'it', 'marketing') |
| domain | string | – | The domain to search for emails (e.g., 'example.com') |
| enrich_mobile | boolean | – | Whether to enrich with mobile phone data |
| limit | string | – | Maximum number of results to return (10, 20, or 50) |
| page | number | – | Page number for pagination |
| webhook_url | string | – | Optional webhook URL to receive results asynchronously |
No output schema declared.
No examples provided.
email_count Email Count ~53
Get the count of email addresses available for a specific domain. Useful for estimating the potential reach before performing a full domain search.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The domain to count emails for (e.g., 'example.com') |
No output schema declared.
No examples provided.
email_enrichment Email Enrichment ~46
Enrich an email address with additional information about the person, including their name, position, company details, and social profiles.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The email address to enrich |
No output schema declared.
No examples provided.
email_finder Email Finder ~152
Find the email address of a specific person given their name and company domain or company name. Uses various techniques to generate and verify the most likely email format.
| Name | Type | Req | Description |
|---|---|---|---|
| company | string | – | The company name to search in |
| domain | string | – | The domain of the company (e.g., 'example.com') |
| enrich_mobile | boolean | – | Whether to enrich with mobile phone data |
| first_name | string | – | The first name of the person |
| full_name | string | – | The full name of the person (alternative to first_name/last_name) |
| last_name | string | – | The last name of the person |
| webhook_url | string | – | Optional webhook URL to receive results asynchronously |
No output schema declared.
No examples provided.
email_verifier Email Verifier ~78
Verify if an email address is valid and deliverable. Checks for proper format, domain validity, and mailbox existence without sending an email.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The email address to verify | |
| enrich_mobile | boolean | – | Whether to enrich with mobile phone data |
| webhook_url | string | – | Optional webhook URL to receive results asynchronously |
No output schema declared.
No examples provided.
linkedin_finder Linkedin Finder ~72
Find the email address associated with a LinkedIn profile URL. Extracts contact information from LinkedIn profiles.
| Name | Type | Req | Description |
|---|---|---|---|
| enrich_mobile | boolean | – | Whether to enrich with mobile phone data |
| url | string | yes | The LinkedIn profile URL |
| webhook_url | string | – | Optional webhook URL to receive results asynchronously |
No output schema declared.
No examples provided.
mpp_author_finder Mpp Author Finder ~56
Find the email address of the author of a blog post or article using MPP (Machine Payments Protocol). Pay-per-request, no API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The URL of the article or blog post |
No output schema declared.
No examples provided.
mpp_domain_search Mpp Domain Search ~144
Search for all email addresses associated with a specific domain using MPP (Machine Payments Protocol). Pay-per-request, no API key required — only an InFlow buyer key.
| Name | Type | Req | Description |
|---|---|---|---|
| company | string | – | The company name to search for |
| country | string | – | Filter by country code (e.g., 'US', 'GB') |
| department | string | – | Filter by department (e.g., 'executive', 'it', 'marketing') |
| domain | string | – | The domain to search for emails (e.g., 'example.com') |
| limit | string | – | Maximum number of results to return |
| page | number | – | Page number for pagination |
No output schema declared.
No examples provided.
mpp_email_count Mpp Email Count ~51
Get the count of email addresses available for a specific domain using MPP (Machine Payments Protocol). Pay-per-request, no API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The domain to count emails for |
No output schema declared.
No examples provided.
mpp_email_enrichment Mpp Email Enrichment ~51
Enrich an email address with detailed contact and company information using MPP (Machine Payments Protocol). Pay-per-request, no API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The email address to enrich |
No output schema declared.
No examples provided.
mpp_email_finder Mpp Email Finder ~97
Find a person's email address given their name and company domain using MPP (Machine Payments Protocol). Pay-per-request, no API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| company | string | – | The company name |
| domain | string | – | The domain of the company |
| first_name | string | – | The first name |
| full_name | string | – | The full name of the person |
| last_name | string | – | The last name |
No output schema declared.
No examples provided.
mpp_email_verifier Mpp Email Verifier ~50
Verify if an email address is valid and deliverable using MPP (Machine Payments Protocol). Pay-per-request, no API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The email address to verify |
No output schema declared.
No examples provided.
mpp_linkedin_finder Mpp Linkedin Finder ~52
Find a person's email address from their LinkedIn profile URL using MPP (Machine Payments Protocol). Pay-per-request, no API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The LinkedIn profile URL |
No output schema declared.
No examples provided.
mpp_phone_finder Mpp Phone Finder ~93
Find phone numbers associated with an email address, domain, or LinkedIn profile using MPP (Machine Payments Protocol). Pay-per-request, no API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | The domain to look up |
| string | – | The email address to look up | |
| full | boolean | – | Whether to return full phone details |
| string | – | The LinkedIn profile URL |
No output schema declared.
No examples provided.
mpp_phone_validator Mpp Phone Validator ~54
Validate a phone number and get carrier and location details using MPP (Machine Payments Protocol). Pay-per-request, no API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| phone | string | yes | The phone number to validate in E.164 format |
No output schema declared.
No examples provided.
mpp_similar_finder Mpp Similar Finder ~50
Find domains similar to a given domain using MPP (Machine Payments Protocol). Pay-per-request, no API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The domain to find similar domains for |
No output schema declared.
No examples provided.
phone_finder Phone Finder ~104
Find phone numbers associated with an email address, domain, or LinkedIn profile. Returns direct and company phone numbers when available.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Domain to search for phone numbers |
| string | – | Email address to search for phone numbers | |
| full | boolean | – | Whether to return full phone details |
| string | – | LinkedIn URL to search for phone numbers | |
| webhook_url | string | – | Optional webhook URL to receive results asynchronously |
No output schema declared.
No examples provided.
phone_validator Phone Validator ~60
Validate and get information about a phone number. Returns the carrier, line type, country, and whether the number is valid.
| Name | Type | Req | Description |
|---|---|---|---|
| phone | string | yes | The phone number to validate (E.164 format recommended, e.g., +14155552671) |
No output schema declared.
No examples provided.
similar_finder Similar Finder ~56
Find companies similar to a given domain. Returns a list of competitor or similar businesses based on industry, size, and other factors.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The domain to find similar companies for (e.g., 'example.com') |
No output schema declared.
No examples provided.
technology_finder Technology Finder ~53
Discover the technologies used by a website. Returns information about the tech stack including CMS, frameworks, analytics, and more.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The domain to analyze for technologies (e.g., 'example.com') |
No output schema declared.
No examples provided.