Domain registration, availability, DNS records, and IP/ASN resolution via RDAP and DNS-over-HTTPS.
Look up domain registration, check availability, fetch DNS records, and resolve IPs and ASNs via RDAP and DNS-over-HTTPS via MCP. STDIO or Streamable HTTP.
Domain and network intelligence via RDAP and DNS-over-HTTPS. Look up domain registrations, check availability, fetch DNS records, and resolve IPs and ASNs to their registries — all via public, keyless data sources. Runs as a stdio process or a local Streamable HTTP server.
| Tool | Description |
|---|---|
whois_lookup_domain | Full domain registration record — registrar, created/expiry dates, nameservers, EPP status, DNSSEC, registrant org |
whois_check_availability | Check whether a domain is registered or available for registration |
whois_get_dns | DNS records for any hostname via DNS-over-HTTPS (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, PTR) |
whois_lookup_ip | IP or CIDR netblock, org, country, abuse contact, and reverse DNS via RIR RDAP |
whois_lookup_asn | Resolve an ASN to its org name, country, and RIR source |
whois_get_dossier | One-call domain triage — registration + DNS in parallel, normalized into a single record with factual signals |
whois_lookup_domain toolregistrant_redacted: true when privacy redaction is in effect (standard post-GDPR for gTLDs)rdap_no_coverage when the TLD has no RDAP server in the IANA bootstrap — use whois_check_availability insteaddomain_not_found on an RDAP 404 (domain not registered) — use whois_check_availability to confirmwhois_check_availability toolavailable: trueavailable: false with registrar and expiry_dateavailable: null with rdap_coverage: false when the TLD has no RDAP coverage — availability cannot be determinedwhois_get_dns tooltypes is omittedsource (cloudflare or nextdns)nxdomain: true in the result (not an error) when the domain doesn't exist in DNSwhois_lookup_ip toolptr: null on failure, not an errorprivate_range for RFC 1918, loopback, and link-local addresses — no RIR RDAP record exists for themip_not_found on an RIR RDAP 404whois_lookup_asn toolAS15169 or bare integer 15169 formatname, org_name, country, rir, start_autnum, end_autnumasn_not_found on an RIR RDAP 404whois_get_dossier toolPromise.allSettledage_days, privacy_redacted, registrar, ns_provider (from NS records), mx_provider (from MX records)rdap_source_error / dns_source_error on the failed leg)both_legs_failed only when both RDAP and DNS fail; individual leg failures are data, not errorsBuilt on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
RDAP / DNS-specific:
Agent-friendly output:
rdap_coverage: false returned as data by whois_check_availability and whois_get_dossier, while whois_lookup_domain throws rdap_no_coverage for the same caseregistrant_redacted: true rather than silently absent contact datawhois_get_dossier marks individual legs with a source_error field and continues; only both-legs-fail escalates to an errorage_days, privacy_redacted, ns_provider, mx_provider are real data, not synthesized risk scoresNo API keys or accounts required. Add the following to your MCP client configuration file.
{
"mcpServers": {
"whois-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/whois-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with npx (no Bun required):
{
"mcpServers": {
"whois-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/whois-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with Docker:
{
"mcpServers": {
"whois-mcp-server": {
"type": "stdio",
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MCP_TRANSPORT_TYPE=stdio",
"ghcr.io/cyanheads/whois-mcp-server:latest"
]
}
}
}
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcp
git clone https://github.com/cyanheads/whois-mcp-server.git
cd whois-mcp-server
bun install
cp .env.example .env
# All vars are optional — defaults work for most use cases
| Variable | Description | Default |
|---|---|---|
RDAP_TIMEOUT_MS | HTTP timeout for RDAP requests in milliseconds. | 5000 |
DOH_TIMEOUT_MS | HTTP timeout for DNS-over-HTTPS requests in milliseconds. | 3000 |
RDAP_MAX_RETRIES | Max retry attempts on transient RDAP failures. | 2 |
DOH_MAX_RETRIES | Max retry attempts on transient DoH failures. | 2 |
MCP_TRANSPORT_TYPE | Transport: stdio or http. | stdio |
MCP_HTTP_PORT | Port for HTTP server. | 3010 |
MCP_AUTH_MODE | Auth mode: none, jwt, or oauth. | none |
MCP_LOG_LEVEL | Log level (RFC 5424). | info |
OTEL_ENABLED | Enable OpenTelemetry instrumentation. | false |
See .env.example for the full list of optional overrides.
Build and run:
bun run rebuild
bun run start:stdio
# or
bun run start:http
Run checks and tests:
bun run devcheck # Lint, format, typecheck, security
bun run test # Vitest test suite
bun run lint:mcp # Validate MCP definitions against spec
docker build -t whois-mcp-server .
docker run --rm -p 3010:3010 whois-mcp-server
The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/whois-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
| Path | Purpose |
|---|---|
src/index.ts | Entry point — starts the app. |
src/app.ts | createApp() options — registers tools, inits services, declares the session mode. |
src/config/ | Server-specific environment variable parsing and validation (Zod). |
src/services/rdap/ | RDAP client — IANA bootstrap cache, domain/IP/ASN lookup, retry. |
src/services/doh/ | DNS-over-HTTPS client — Cloudflare primary, NextDNS fallback. |
src/mcp-server/tools/ | Tool definitions (*.tool.ts). |
tests/ | Vitest tests mirroring src/. |
docs/ | Design and API reference documents. |
See CLAUDE.md for development guidelines and architectural rules. The short version:
try/catch in tool logicctx.log for request-scoped loggingsrc/app.ts's tools arrayIssues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run test
Apache-2.0 — see LICENSE for details.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y @cyanheads/whois-mcp-serverMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-cyanheads-whois-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/whois-mcp-server"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceio.github.cyanheads/whois-mcp-server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.