@cyanheads/whois-mcp-server
Look up domain registration, check availability, fetch DNS records, and resolve IPs and ASNs via RDAP and DNS-over-HTTPS via MCP. STDIO or Streamable HTTP.
6 Tools
Overview
Domain and network intelligence via RDAP and DNS-over-HTTPS. Look up domain registrations, check availability, fetch DNS records, and resolve IPs and ASNs to their registries β all via public, keyless data sources. Runs as a stdio process or a local Streamable HTTP server.
| Tool | Description |
|---|
whois_lookup_domain | Full domain registration record β registrar, created/expiry dates, nameservers, EPP status, DNSSEC, registrant org |
whois_check_availability | Check whether a domain is registered or available for registration |
whois_get_dns | DNS records for any hostname via DNS-over-HTTPS (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, PTR) |
whois_lookup_ip | IP or CIDR netblock, org, country, abuse contact, and reverse DNS via RIR RDAP |
whois_lookup_asn | Resolve an ASN to its org name, country, and RIR source |
whois_get_dossier | One-call domain triage β registration + DNS in parallel, normalized into a single record with factual signals |
Capability reference
whois_lookup_domain tool
- Accepts a fully qualified domain name and selects the registry RDAP server through IANA bootstrap.
- Returns registrar, registration dates, nameservers, EPP status, DNSSEC, and
registrant_redacted; throws rdap_no_coverage or domain_not_found when no record can be returned.
- Accepts a fully qualified domain name for a registration check.
- Returns
available: true for RDAP 404, false with registrar and expiry for a registered domain, or null with rdap_coverage: false when coverage is absent.
- Accepts a hostname and optional nonempty
types: A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, PTR; omission defaults to A, AAAA, MX, TXT, NS. Duplicate types are queried once.
- Returns records with TTLs and ordered
query_sources: [{type, source}], including empty answers and NXDOMAIN. Legacy source is cloudflare if any query consumed a successful Cloudflare response, otherwise nextdns; a nonexistent domain returns nxdomain: true as data.
- Accepts a complete IPv4/IPv6 address with at most one decimal CIDR prefix (0β32 / 0β128); no whitespace, zone IDs, or brackets. Queries the base address and echoes the original
ip. IPv4-mapped IPv6 uses the embedded IPv4 for policy, RDAP, and PTR; other IPv6 uses 32 reversed PTR nibbles.
- Returns netblock CIDR, organization, country, abuse contact, and best-effort PTR (
null on failure); throws invalid_ip for malformed input or ip_not_found on an RIR RDAP 404.
private_range enforces an explicit policy: IPv4 0.0.0.0/8, 10.0.0.0/8, 100.64.0.0/10, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16, 255.0.0.0/8; IPv6 ::1/128, fc00::/7, fe80::/10. Other special-use addresses remain eligible for registry records or normal no-coverage/not-found outcomes.
- Accepts a decimal ASN from 1 to 4294967295 with an optional case-insensitive
AS prefix and leading + (e.g., AS15169, AS 15169, +15169). Outer whitespace and whitespace after AS are allowed; whitespace inside digits or after +, suffixes, decimals, and out-of-range values return invalid_asn.
- Returns
name, org_name, country, rir, start_autnum, and end_autnum; throws asn_not_found when no ASN record exists.
- Accepts a fully qualified domain name for parallel registration and A/MX/NS/TXT lookups.
- Returns registration, DNS, domain age, privacy status, and inferred NS/MX providers. Individual failures remain partial data in
rdap_source_error or dns_source_error; both_legs_failed means neither source succeeded.
Features
Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
RDAP / DNS-specific:
- RDAP over HTTPS β no port-43 TCP dependency
- IANA bootstrap auto-selection β correct registry RDAP server picked per TLD, RIR, or ASN range; bootstrap JSON cached in-memory for 24h
- DNS-over-HTTPS via Cloudflare and NextDNS β dual-provider with per-type routing (NextDNS for CAA; Cloudflare for all others) and automatic fallback
- No API keys required β all sources (IANA, registry RDAP endpoints, RIR RDAP, Cloudflare DoH, NextDNS DoH) are public and keyless
Agent-friendly output:
- Coverage signaled two ways β
rdap_coverage: false returned as data by whois_check_availability and whois_get_dossier, while whois_lookup_domain throws rdap_no_coverage for the same case
- Privacy redaction surfaced as a field β
registrant_redacted: true rather than silently absent contact data
- Partial failure model β
whois_get_dossier marks individual legs with a source_error field and continues; only both-legs-fail escalates to an error
- Factual signals, not scores β
age_days, privacy_redacted, ns_provider, mx_provider are real data, not synthesized risk scores
Getting started
No API keys or accounts required. Add the following to your MCP client configuration file.
{
"mcpServers": {
"whois-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/whois-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with npx (no Bun required):
{
"mcpServers": {
"whois-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/whois-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with Docker:
{
"mcpServers": {
"whois-mcp-server": {
"type": "stdio",
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MCP_TRANSPORT_TYPE=stdio",
"ghcr.io/cyanheads/whois-mcp-server:latest"
]
}
}
}
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
Prerequisites
- Bun v1.4.0 or higher (or Node.js v24+).
- No API keys required β all data sources are public.
Installation
- Clone the repository:
git clone https://github.com/cyanheads/whois-mcp-server.git
- Navigate into the directory:
- Install dependencies:
- Configure environment:
Configuration
| Variable | Description | Default |
|---|
RDAP_TIMEOUT_MS | HTTP timeout for RDAP requests in milliseconds. | 5000 |
DOH_TIMEOUT_MS | HTTP timeout for DNS-over-HTTPS requests in milliseconds. | 3000 |
RDAP_MAX_RETRIES | Max retry attempts on transient RDAP failures. | 2 |
DOH_MAX_RETRIES | Max retry attempts on transient DoH failures. | 2 |
MCP_TRANSPORT_TYPE | Transport: stdio or http. | stdio |
MCP_HTTP_PORT | Port for HTTP server. | 3010 |
MCP_AUTH_MODE | Auth mode: none, jwt, or oauth. | none |
MCP_LOG_LEVEL | Log level (RFC 5424). | info |
OTEL_ENABLED | Enable OpenTelemetry instrumentation. | false |
See .env.example for the full list of optional overrides.
Running the server
Local development
-
Build and run:
bun run rebuild
bun run start:stdio
bun run start:http
-
Run checks and tests:
bun run devcheck
bun run test
bun run lint:mcp
Docker
docker build -t whois-mcp-server .
docker run --rm -p 3010:3010 whois-mcp-server
The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/whois-mcp-server. OpenTelemetry peer dependencies are installed by default β build with --build-arg OTEL_ENABLED=false to omit them.
Project structure
| Path | Purpose |
|---|
src/index.ts | Entry point β starts the app. |
src/app.ts | createApp() options β registers tools, inits services, declares the session mode. |
src/config/ | Server-specific environment variable parsing and validation (Zod). |
src/services/rdap/ | RDAP client β IANA bootstrap cache, domain/IP/ASN lookup, retry. |
src/services/doh/ | DNS-over-HTTPS client β Cloudflare primary, NextDNS fallback. |
src/mcp-server/tools/ | Tool definitions (*.tool.ts). |
tests/ | Vitest tests mirroring src/. |
docs/ | Design and API reference documents. |
Development guide
See CLAUDE.md for development guidelines and architectural rules. The short version:
- Handlers throw, framework catches β no
try/catch in tool logic
- Use
ctx.log for request-scoped logging
- Register new tools via
src/app.ts's tools array
- Wrap external API calls: validate raw β normalize to domain type β return output schema; never fabricate missing fields
Contributing
Issues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run test
License
Apache-2.0 β see LICENSE for details.