Back to Directory/Developer Tools

io.github.cyanheads/whois-mcp-server

Domain registration, availability, DNS records, and IP/ASN resolution via RDAP and DNS-over-HTTPS.

Developer ToolsTypeScriptv0.1.6

@cyanheads/whois-mcp-server

Look up domain registration, check availability, fetch DNS records, and resolve IPs and ASNs via RDAP and DNS-over-HTTPS via MCP. STDIO or Streamable HTTP.

6 Tools

Version License Docker MCP SDK npm TypeScript Bun

Install in Claude Desktop Install in Cursor Install in VS Code

Framework


Overview

Domain and network intelligence via RDAP and DNS-over-HTTPS. Look up domain registrations, check availability, fetch DNS records, and resolve IPs and ASNs to their registries — all via public, keyless data sources. Runs as a stdio process or a local Streamable HTTP server.

Tools

ToolDescription
whois_lookup_domainFull domain registration record — registrar, created/expiry dates, nameservers, EPP status, DNSSEC, registrant org
whois_check_availabilityCheck whether a domain is registered or available for registration
whois_get_dnsDNS records for any hostname via DNS-over-HTTPS (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, PTR)
whois_lookup_ipIP or CIDR netblock, org, country, abuse contact, and reverse DNS via RIR RDAP
whois_lookup_asnResolve an ASN to its org name, country, and RIR source
whois_get_dossierOne-call domain triage — registration + DNS in parallel, normalized into a single record with factual signals

Capability reference

whois_lookup_domain tool

  • RDAP-first via IANA auto-bootstrap — automatically selects the correct registry RDAP server per TLD
  • Returns registrar, creation/expiry dates, nameservers, EPP status codes, and DNSSEC delegation flag
  • Surfaces registrant_redacted: true when privacy redaction is in effect (standard post-GDPR for gTLDs)
  • Throws rdap_no_coverage when the TLD has no RDAP server in the IANA bootstrap — use whois_check_availability instead
  • Throws domain_not_found on an RDAP 404 (domain not registered) — use whois_check_availability to confirm

whois_check_availability tool

  • RDAP 404 response maps to available: true
  • Registered domains return available: false with registrar and expiry_date
  • available: null with rdap_coverage: false when the TLD has no RDAP coverage — availability cannot be determined
  • Thin response optimized for bulk name sweeps — no extra fields

whois_get_dns tool

  • Supports A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, PTR; multiple types fetched in parallel; defaults to A, AAAA, MX, TXT, NS when types is omitted
  • Cloudflare primary, NextDNS fallback per type (CAA always uses NextDNS — Cloudflare returns raw hex wire format for it)
  • Returns records with TTLs and the resolving source (cloudflare or nextdns)
  • nxdomain: true in the result (not an error) when the domain doesn't exist in DNS

whois_lookup_ip tool

  • Accepts an IPv4/IPv6 address or CIDR block; auto-routes to the correct RIR (ARIN, RIPE, APNIC, LACNIC, AFRINIC) via IANA IP bootstrap
  • Returns netblock CIDR, org name, country, abuse contact email
  • Fetches PTR (reverse DNS) via DoH as a best-effort step — ptr: null on failure, not an error
  • Throws private_range for RFC 1918, loopback, and link-local addresses — no RIR RDAP record exists for them
  • Throws ip_not_found on an RIR RDAP 404

whois_lookup_asn tool

  • Accepts AS15169 or bare integer 15169 format
  • Routes to the correct RIR RDAP endpoint via IANA ASN bootstrap
  • Returns name, org_name, country, rir, start_autnum, end_autnum
  • Throws asn_not_found on an RIR RDAP 404

whois_get_dossier tool

  • Runs RDAP domain lookup and DoH (A, MX, NS, TXT) in parallel via Promise.allSettled
  • Inferred signals: age_days, privacy_redacted, registrar, ns_provider (from NS records), mx_provider (from MX records)
  • No synthesized risk scores — factual signals only; the agent decides the verdict
  • Partial results surfaced when one leg fails (rdap_source_error / dns_source_error on the failed leg)
  • Throws both_legs_failed only when both RDAP and DNS fail; individual leg failures are data, not errors

Features

Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.

RDAP / DNS-specific:

  • RDAP over HTTPS — no port-43 TCP dependency
  • IANA bootstrap auto-selection — correct registry RDAP server picked per TLD, RIR, or ASN range; bootstrap JSON cached in-memory for 24h
  • DNS-over-HTTPS via Cloudflare and NextDNS — dual-provider with per-type routing (NextDNS for CAA; Cloudflare for all others) and automatic fallback
  • No API keys required — all sources (IANA, registry RDAP endpoints, RIR RDAP, Cloudflare DoH, NextDNS DoH) are public and keyless

Agent-friendly output:

  • Coverage signaled two ways — rdap_coverage: false returned as data by whois_check_availability and whois_get_dossier, while whois_lookup_domain throws rdap_no_coverage for the same case
  • Privacy redaction surfaced as a field — registrant_redacted: true rather than silently absent contact data
  • Partial failure model — whois_get_dossier marks individual legs with a source_error field and continues; only both-legs-fail escalates to an error
  • Factual signals, not scores — age_days, privacy_redacted, ns_provider, mx_provider are real data, not synthesized risk scores

Getting started

No API keys or accounts required. Add the following to your MCP client configuration file.

{
  "mcpServers": {
    "whois-mcp-server": {
      "type": "stdio",
      "command": "bunx",
      "args": ["@cyanheads/whois-mcp-server@latest"],
      "env": {
        "MCP_TRANSPORT_TYPE": "stdio",
        "MCP_LOG_LEVEL": "info"
      }
    }
  }
}

Or with npx (no Bun required):

{
  "mcpServers": {
    "whois-mcp-server": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@cyanheads/whois-mcp-server@latest"],
      "env": {
        "MCP_TRANSPORT_TYPE": "stdio",
        "MCP_LOG_LEVEL": "info"
      }
    }
  }
}

Or with Docker:

{
  "mcpServers": {
    "whois-mcp-server": {
      "type": "stdio",
      "command": "docker",
      "args": [
        "run", "-i", "--rm",
        "-e", "MCP_TRANSPORT_TYPE=stdio",
        "ghcr.io/cyanheads/whois-mcp-server:latest"
      ]
    }
  }
}

For Streamable HTTP, set the transport and start the server:

MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcp

Prerequisites

  • Bun v1.3.0 or higher (or Node.js v24+).
  • No API keys required — all data sources are public.

Installation

  1. Clone the repository:
git clone https://github.com/cyanheads/whois-mcp-server.git
  1. Navigate into the directory:
cd whois-mcp-server
  1. Install dependencies:
bun install
  1. Configure environment:
cp .env.example .env
# All vars are optional — defaults work for most use cases

Configuration

VariableDescriptionDefault
RDAP_TIMEOUT_MSHTTP timeout for RDAP requests in milliseconds.5000
DOH_TIMEOUT_MSHTTP timeout for DNS-over-HTTPS requests in milliseconds.3000
RDAP_MAX_RETRIESMax retry attempts on transient RDAP failures.2
DOH_MAX_RETRIESMax retry attempts on transient DoH failures.2
MCP_TRANSPORT_TYPETransport: stdio or http.stdio
MCP_HTTP_PORTPort for HTTP server.3010
MCP_AUTH_MODEAuth mode: none, jwt, or oauth.none
MCP_LOG_LEVELLog level (RFC 5424).info
OTEL_ENABLEDEnable OpenTelemetry instrumentation.false

See .env.example for the full list of optional overrides.


Running the server

Local development

  • Build and run:

    bun run rebuild
    bun run start:stdio
    # or
    bun run start:http
    
  • Run checks and tests:

    bun run devcheck   # Lint, format, typecheck, security
    bun run test       # Vitest test suite
    bun run lint:mcp   # Validate MCP definitions against spec
    

Docker

docker build -t whois-mcp-server .
docker run --rm -p 3010:3010 whois-mcp-server

The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/whois-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.


Project structure

PathPurpose
src/index.tsEntry point — starts the app.
src/app.tscreateApp() options — registers tools, inits services, declares the session mode.
src/config/Server-specific environment variable parsing and validation (Zod).
src/services/rdap/RDAP client — IANA bootstrap cache, domain/IP/ASN lookup, retry.
src/services/doh/DNS-over-HTTPS client — Cloudflare primary, NextDNS fallback.
src/mcp-server/tools/Tool definitions (*.tool.ts).
tests/Vitest tests mirroring src/.
docs/Design and API reference documents.

Development guide

See CLAUDE.md for development guidelines and architectural rules. The short version:

  • Handlers throw, framework catches — no try/catch in tool logic
  • Use ctx.log for request-scoped logging
  • Register new tools via src/app.ts's tools array
  • Wrap external API calls: validate raw → normalize to domain type → return output schema; never fabricate missing fields

Contributing

Issues are welcome. Run checks and tests before submitting:

bun run devcheck
bun run test

License

Apache-2.0 — see LICENSE for details.

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y @cyanheads/whois-mcp-server

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-cyanheads-whois-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@cyanheads/whois-mcp-server"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

@cyanheads/whois-mcp-servernpm

Compatible MCP Clients

io.github.cyanheads/whois-mcp-server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More