23 security tools for AI agents: phishing links, exposure maps, DNS, SSL, PQC, headers, email.
Domain security reconnaissance for AI agents via the Model Context Protocol.
19 tools, free, no API key. DNS, SSL/TLS, HTTP security headers, email authentication, port scan, DNS propagation, reverse DNS, ASN/BGP, RDAP/WHOIS, subdomain discovery (CT logs), lookalike/typosquat detection, OWASP-mapped observable checks, brand-impersonation exposure, go-live readiness, and domain change history — what changed since the last check.
Every result comes back interpreted, not just as raw JSON: a status, the key numbers, each issue with severity and confidence, and the concrete action to take. That is what an agent needs to tell a human what to do next.
Part of DechoNet. Every tool here is also a free web tool at dechonet.com — no sign-up — backed by error-fix guides. This package brings the same checks to AI agents.
No npx, no install, no key. Point any MCP client that speaks Streamable HTTP at:
https://dechonet.com/mcp
Claude Desktop / Claude Code (claude mcp add --transport http dechonet https://dechonet.com/mcp), Cursor, and other HTTP-capable clients connect directly. The remote endpoint also serves 3 curated prompts (audit_domain, monitor_setup, investigate_changes) and 2 reference resources.
Add to your claude_desktop_config.json:
{
"mcpServers": {
"dechonet": {
"command": "npx",
"args": ["-y", "dechonet-mcp"]
}
}
}
Config file location:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.jsonRestart Claude Desktop. You'll see the DechoNet tools icon in the input area.
# Via npx (no install needed)
npx dechonet-mcp
# Or install globally
npm install -g dechonet-mcp
| Tool | Description |
|---|---|
security_scan | Comprehensive scan — 9 checks in parallel, 0-100 Health Score, A-F grade |
dns_lookup | DNS records + DNSSEC + SPF/DMARC validation |
ssl_check | SSL/TLS certificate, chain, expiry, HSTS, CT history, A-F grade |
http_security | HTTP redirect trace + 10 security headers audit, A-F grade |
email_auth | SPF, DMARC, DKIM, BIMI, MTA-STS, DANE + blacklist check |
port_scan | Open TCP ports with service identification |
dns_propagation | DNS propagation across 8+ global resolvers |
reverse_dns | PTR record + FCrDNS verification |
asn_lookup | ASN/BGP network identification + abuse contact |
whois_lookup | RDAP/WHOIS domain registration data |
subdomain_discovery | Passive subdomain enumeration from CT logs, operational-name flags (dev/staging/admin), wildcard detection |
lookalike_domains | Typosquat variants that are actually registered — homoglyph, affix (brand-login), TLD swap, keyboard slips — with the domain's own defensive registrations separated out |
owasp_check | OWASP-mapped checks that can be observed passively (headers, TLS, exposed files), honest about what is out of scope |
impersonation_exposure | Brand impersonation exposure grade: third-party lookalikes + exposed operational subdomains + wildcard certs |
golive_check | Go-live readiness — DNS, propagation, SSL, HTTP, registration in one READY / CAUTION / NOT READY verdict |
domain_changes | What changed since the last check — status, grade, issuer, DNS, issues. Time series from DechoNet monitoring |
ip_info | Public IP, ISP, ASN, proxy detection |
email_header_analysis | Email delivery route tracing + auth results |
subnet_calc | CIDR subnet calculator (offline) |
Every tool response ends with a link to the full interactive report on dechonet.com for the human behind the agent.
Once connected, try asking Claude:
For a self-hosted HTTP/SSE bridge (the hosted remote endpoint above is usually simpler):
npm run start:sse
# Server runs on http://localhost:3100
# SSE endpoint: http://localhost:3100/sse
npm install
npm run build # TypeScript → build/
npm run dev # Run with tsx (stdio)
npm run start:sse # Run SSE server
The MCP server calls DechoNet's public API (https://dechonet.com/api/util/*) — the same backend as the dechonet.com web tools — and returns structured results with:
All data comes from public sources (DNS, HTTP headers, SSL certificates, CT logs, RDAP). Passive by design: no active exploitation, and a registered lookalike is reported as a fact to verify, never as an accusation.
| Variable | Default | Description |
|---|---|---|
DECHONET_URL | https://dechonet.com | API base URL |
DECHONET_LOCALE | en | Response language (en or ko) |
PORT | 3100 | SSE server port |
DechoNet is a domain security reconnaissance platform — distributed observation, cross-verification. The same diagnostics ship three ways: free web tools, error-fix guides, and this MCP server.
MIT licensed. Issues and PRs welcome.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y dechonet-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"com-dechonet-mcp": {
"command": "npx",
"args": [
"-y",
"dechonet-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencedechonet-mcpnpmcom.dechonet/mcp works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.