mcp

20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.

Sollte ich dies verwenden

Qualität und Sicherheit

A
Qualität der Beschreibung
100%
Vollständigkeit des Schemas
96%
Qualität der Benennung
80%
Risiko der Vergiftung
100%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~9,401Tokens (Tool-Definitionen)
~3.5 KBTypische Antwortgröße
Erhebliche Auswirkung auf die Aufmerksamkeit (7.34% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "mcp": {
      "command": "npx",
      "args": [
        "dechonet-mcp"
      ]
    }
  }
}

Ausführbare Pakete

npmdechonet-mcp1.2.3stdio

Remote-Endpunkte

https://dechonet.com/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (20)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
🟢dns_lookup(domain)

Query DNS records (A, AAAA, MX, TXT, NS, SOA, CAA) for a domain and validate email-related records, including DNSSEC presence and SPF/DMARC syntax, returning severity-rated diagnostics. Use this for a single authoritative answer about one domain. Use dns_propagation instead when you need to compare answers across multiple global resolvers (e.g., right after a change), or email_auth for a full SPF/DKIM/DMARC deliverability assessment. Read-only; requires no API key or authentication; subject to rate limiting. Returns a text report: status, KPI summary, detected issues, and recommended actions.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Registrable domain or hostname to query, without scheme or path (e.g., 'example.com' or 'mail.example.com'). Do not include 'http://' or a trailing slash."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢ssl_check(host, port)

Inspect a host's served TLS/SSL certificate and connection: expiry date, issuer, SAN list, chain integrity, TLS version, and HSTS, returning an A+ to F grade weighted by certificate validity (40%), TLS version (25%), chain trust (15%), and HSTS (20%). Use this to diagnose certificate or HTTPS-handshake problems for one host. Use http_security instead to audit response security headers, or security_scan for an all-in-one domain report. Read-only: it completes a TLS handshake but sends no application data; requires no API key; rate-limited. Returns a text report: grade, expiry/issuer KPIs, issues, and actions.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "host": {
      "type": "string",
      "description": "Hostname to inspect, without scheme (e.g., 'example.com'). The host portion of a pasted URL is also accepted."
    },
    "port": {
      "type": "number",
      "default": 443,
      "description": "TCP port for the TLS handshake. Defaults to 443 (standard HTTPS); set this only for a non-standard HTTPS port such as 8443."
    }
  },
  "required": [
    "host"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢http_security(url)

Follow a URL's HTTP redirect chain and audit response security headers (CSP, HSTS, X-Frame-Options, COOP, CORP, COEP, Permissions-Policy), grading A+ to F and flagging information leaks such as server-version disclosure. Use this for HTTP-layer/header posture. Use ssl_check instead for certificate or TLS-handshake issues, or security_scan for a full domain report. Read-only (an HTTP GET-style probe that sends no payload); requires no API key; rate-limited. Returns a text report: grade, header findings, redirect trace, issues, and actions.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Full URL including scheme (e.g., 'https://example.com/path'). If the scheme is omitted, https:// is assumed. Redirects are followed starting from this URL."
    }
  },
  "required": [
    "url"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢email_auth(domain)

Assess a domain's email authentication and deliverability posture: MX records, SPF, DMARC, DKIM (probes 15 common selectors), BIMI, MTA-STS, TLS-RPT, and DANE, plus a blacklist check across all MX hosts, returning a 0-100 deliverability score. Use this for a full sending/receiving readiness review of a domain. Use dns_lookup instead if you only need raw TXT/MX records, or email_header_analysis to diagnose a specific message that was already sent. Read-only; requires no API key; rate-limited. Returns a text report: score, per-mechanism KPIs, issues, and actions.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Email domain to assess — the part after '@' (e.g., 'example.com'). An IP address is also accepted for reverse/PTR-based checks."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢port_scan(host)

Probe a host for a fixed set of common TCP ports (HTTP, HTTPS, SSH, FTP, SMTP, DNS, and common databases) and report which are open, the service name, and the response time. BEHAVIOR: this makes an ACTIVE TCP connection to the target. It is non-intrusive — a connect probe only; it does not authenticate, send exploits, or transfer data — and changes nothing on the target (read-only), but the connection is visible in the target's logs, so only scan hosts you own or are explicitly authorized to test. Use this to confirm which services are exposed. Use ssl_check or http_security instead to assess a specific service's configuration. Requires no API key; rate-limited. Returns a per-port open/closed list with service names.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "host": {
      "type": "string",
      "description": "Hostname or IP to probe (e.g., 'example.com' or '203.0.113.10'). A 'host:port' form is accepted to hint a specific port. Only supply targets you own or are authorized to test."
    }
  },
  "required": [
    "host"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢dns_propagation(domain, type)

Query one DNS record across 8+ global public resolvers (Google, Cloudflare, Quad9, OpenDNS, and more) simultaneously and report which resolvers return stale versus updated values. Use this after changing a record to confirm worldwide propagation. Use dns_lookup instead for a single authoritative answer with SPF/DMARC validation. Read-only; requires no API key; rate-limited. Returns per-resolver values and a consistency verdict.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain whose record to compare across resolvers (e.g., 'example.com'), without scheme or path."
    },
    "type": {
      "type": "string",
      "enum": [
        "A",
        "AAAA",
        "MX",
        "CNAME",
        "TXT",
        "NS"
      ],
      "default": "A",
      "description": "DNS record type to compare across resolvers. Defaults to A (IPv4 address), the most common propagation check."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢reverse_dns(ip)

Resolve the PTR (reverse DNS) record for an IPv4 or IPv6 address and verify forward-confirmed reverse DNS (FCrDNS) by checking that the PTR hostname resolves back to the same IP. Infers the hosting provider from PTR naming patterns. Use this to validate mail-server rDNS or identify a single IP's host. Use asn_lookup instead for network/BGP ownership of the IP. Read-only; requires no API key; rate-limited. Returns the PTR hostname, FCrDNS pass/fail, and a provider guess.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "ip": {
      "type": "string",
      "description": "IP address to reverse-resolve, IPv4 or IPv6 (e.g., '8.8.8.8' or '2001:4860:4860::8888'). Must be an IP, not a hostname."
    }
  },
  "required": [
    "ip"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢asn_lookup(query)

Look up Autonomous System (ASN) / BGP information for an IP address or AS number: the network operator, announced prefixes, abuse contact, and a classification (cloud, CDN, ISP, hosting, or enterprise). Use this to identify who runs a network or whether an IP is cloud/CDN-hosted. Use reverse_dns instead for the host-level PTR name of a single IP. Read-only; requires no API key; rate-limited. Returns operator, prefixes, classification, and abuse contact.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "An IP address (e.g., '1.1.1.1') or an AS number in 'AS####' form (e.g., 'AS13335')."
    }
  },
  "required": [
    "query"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢whois_lookup(domain)

Retrieve domain registration data via RDAP (with WHOIS fallback): registrar, creation/expiry/update dates, nameservers, and EPP status flags, highlighting risk states such as clientHold and pendingDelete. Use this for ownership, lifecycle, and expiry questions about a registered domain. Use dns_lookup instead for live DNS records, or reverse_dns/asn_lookup for IP-level ownership. Read-only; requires no API key; rate-limited. Returns registrar, key dates, nameservers, and status flags.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Registered domain name to look up (e.g., 'example.com'). A subdomain is normalized to its registrable domain."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢subdomain_discovery(domain)

Enumerate the subdomains of a domain from Certificate Transparency logs — fully passive (no packets are sent to the target; CT logs are public records of every TLS certificate ever issued). Flags operational-looking names (dev, staging, admin, vpn, legacy) and wildcard certificates, because forgotten subdomains are a common takeover path. Use this as the first recon step to map a domain's attack surface. Use dns_lookup to check whether a discovered name still resolves, or lookalike_domains for typosquat variants of the domain name itself. Read-only; requires no API key; rate-limited. Returns the subdomain count, risky-name count, wildcard flag, and the hostname list.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Registrable domain to enumerate (e.g., 'example.com'), without scheme or path. Subdomains found in CT logs for this domain are returned."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢lookalike_domains(domain)

Generate the typosquat/lookalike variants of a domain that phishers actually register — homoglyph swaps (l→1, o→0, rn→m), TLD swaps (.com→.co), character omissions, transpositions, repetitions, hyphenations — and check which of them are currently registered (live NS delegation via DoH). Use this to assess brand-impersonation and phishing exposure for a domain the user is responsible for. A registered variant is NOT proof of abuse (it may be an unrelated legitimate site) — follow up with whois_lookup on each hit for its owner and registration date. Read-only; requires no API key; rate-limited. Returns generated/checked counts and the registered variants with the technique that produced each.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to protect (e.g., 'example.com'), without scheme or path. Variants of its label and TLD are generated and checked."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢ip_info

Report information about the caller's own public IP as seen by the server: IPv4/IPv6 address, ISP, ASN, approximate geolocation, and proxy/VPN heuristics. Takes no input — it reflects the egress IP of THIS MCP server's network, which is usually NOT the end user's IP. Use this to discover the server's outbound IP or test connectivity. To inspect a specific, known IP instead, use asn_lookup or reverse_dns. Read-only; requires no API key; rate-limited.

Eingabe-Schema

{
  "type": "object",
  "properties": {}
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢email_header_analysis(headers)

Parse raw email headers to reconstruct the delivery path (each Received hop in order), extract SPF/DKIM/DMARC authentication results, measure per-hop delays, and flag unencrypted (non-TLS) hops. Use this to diagnose a specific message that was already delivered — spoofing, delays, or where mail was lost. Use email_auth instead to assess a domain's sending configuration before sending. Read-only; requires no API key; rate-limited. INPUT is the full raw header block. OUTPUT is a text report containing: the ordered hop route, per-mechanism auth results (pass/fail), detected inter-hop delays, and the encryption status of each hop.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "headers": {
      "type": "string",
      "description": "The complete raw email header block, copied verbatim — every line from the first 'Received:'/'From:' down to the blank line before the body. Paste as-is, including folded continuation lines; do not include the message body."
    }
  },
  "required": [
    "headers"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "description": "Overall verdict, e.g. 'good' | 'warning' | 'bad' | 'info' | 'unknown'"
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph interpretation of the result"
    },
    "kpis": {
      "type": "array",
      "description": "Key metrics as label/value pairs",
      "items": {
        "type": "object",
        "properties": {
          "label": {
            "type": "string"
          },
          "value": {
            "type": "string"
          }
        },
        "required": [
          "label",
          "value"
        ]
      }
    },
    "issues": {
      "type": "array",
      "description": "Detected problems, severity-rated",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string"
          },
          "key": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "key"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Recommended next actions, most important first",
      "items": {
        "type": "string"
      }
    },
    "grade": {
      "type": "string",
      "description": "Letter grade (A+ to F) when the tool grades the target"
    },
    "score": {
      "type": "number",
      "description": "0-100 score when the tool scores the target"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report for this exact lookup on dechonet.com"
    }
  },
  "required": [
    "status",
    "reportUrl"
  ]
}
🟢subnet_calc(cidr)

Compute IPv4 subnet details from CIDR notation entirely locally — no network call: network and broadcast addresses, usable host range, total usable hosts, subnet mask, and wildcard mask. /31 and /32 are handled per RFC 3021 (point-to-point / single host). Use this for IPv4 address planning. It does not query DNS or contact any host, so it is purely computational. Requires no API key and is NOT rate-limited (computed in-process). Returns the calculated fields as text.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "cidr": {
      "type": "string",
      "description": "IPv4 address with a CIDR prefix length 0-32 (e.g., '192.168.1.0/24'). IPv4 only; host bits may be any address inside the block."
    }
  },
  "required": [
    "cidr"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "network": {
      "type": "string",
      "description": "Network address"
    },
    "broadcast": {
      "type": "string",
      "description": "Broadcast address"
    },
    "firstHost": {
      "type": "string",
      "description": "First usable host"
    },
    "lastHost": {
      "type": "string",
      "description": "Last usable host"
    },
    "subnetMask": {
      "type": "string",
      "description": "Dotted-decimal subnet mask"
    },
    "wildcardMask": {
      "type": "string",
      "description": "Wildcard (inverse) mask"
    },
    "totalHosts": {
      "type": "number",
      "description": "Usable host count"
    },
    "prefix": {
      "type": "number",
      "description": "CIDR prefix length"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report on dechonet.com"
    }
  },
  "required": [
    "network",
    "broadcast",
    "subnetMask",
    "totalHosts",
    "prefix",
    "reportUrl"
  ]
}
🟢security_scan(domain)

One-shot comprehensive audit of a domain: runs DNS, SSL, HTTP headers, email auth, port scan, DNS propagation, reverse DNS, and ASN/RDAP checks in parallel, then computes a 0-100 Health Score with an A-F grade and a prioritized action list. Use this as the default starting point for "is this domain healthy/secure?" questions. Call the individual tools (e.g., ssl_check, email_auth) instead when you need depth on one area. BEHAVIOR: this includes an ACTIVE port_scan of the domain's host, so only run it on domains you own or are authorized to test. Read-only otherwise; requires no API key; rate-limited (it makes multiple backend calls). Returns the score, per-area breakdown, top actions, and per-area summaries.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to audit end-to-end (e.g., 'example.com'). Scheme and path are stripped. NOTE: the host is also port-scanned, so use only targets you are authorized to test."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "score": {
      "type": "number",
      "description": "Health Score 0-100"
    },
    "grade": {
      "type": "string",
      "description": "Letter grade A+ to F"
    },
    "areas": {
      "type": "array",
      "description": "Per-area verdicts (dns, ssl, http, email, port, propagation, rdap, reverseDns, asn)",
      "items": {
        "type": "object",
        "properties": {
          "area": {
            "type": "string"
          },
          "verdict": {
            "type": "string"
          }
        },
        "required": [
          "area",
          "verdict"
        ]
      }
    },
    "actions": {
      "type": "array",
      "description": "Top recommended actions",
      "items": {
        "type": "string"
      }
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report on dechonet.com"
    }
  },
  "required": [
    "score",
    "grade",
    "areas",
    "reportUrl"
  ]
}
🟢owasp_check(host)

Assess a domain's OWASP posture from EXTERNAL OBSERVATION only: the OWASP Secure Headers Project plus the externally observable Top 10 subset — A02 Cryptographic Failures (TLS/cert), A05 Security Misconfiguration (header/info leaks), and A06 Vulnerable & Outdated Components (version disclosure) — returning an A+ to F grade. Scope: A01 (Access Control), A03 (Injection), A04, A07 (Authentication), A08, A09 and A10 (SSRF) are not checked — they need authenticated access or active/injection testing, so the result lists them as out-of-scope rather than "pass". Present the result as an external-posture check, not a full OWASP Top 10 assessment. Unlike security_scan this is fully PASSIVE (a normal HTTP GET plus a public CT-log lookup, no port scan), so it is safe and lawful to run on domains you do not own. Use http_security or ssl_check for depth on one layer. Read-only; requires no API key; rate-limited. Returns a text report: grade, per-category findings, the out-of-scope list, and a shareable report link.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "host": {
      "type": "string",
      "description": "Hostname to assess, without scheme (e.g., 'example.com'). The host portion of a pasted URL is also accepted."
    }
  },
  "required": [
    "host"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "grade": {
      "type": "string",
      "description": "OWASP posture grade A+ to F, over the observable categories only"
    },
    "score": {
      "type": "number",
      "description": "0-100 across the categories that could be evaluated"
    },
    "checks": {
      "type": "array",
      "description": "Per observable category: Secure Headers, A02, A05, A06",
      "items": {
        "type": "object",
        "properties": {
          "code": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "description": "'pass' | 'warn' | 'fail'"
          },
          "findingCount": {
            "type": "number"
          }
        },
        "required": [
          "code",
          "status"
        ]
      }
    },
    "notObservable": {
      "type": "array",
      "description": "Top 10 categories NOT checked (need authenticated/active testing)",
      "items": {
        "type": "string"
      }
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report on dechonet.com"
    }
  },
  "required": [
    "grade",
    "score",
    "checks",
    "reportUrl"
  ]
}
🟢impersonation_exposure(domain)

Assess how exposed a domain is to brand impersonation and phishing, PASSIVELY: live typosquat/lookalike domains (homoglyph, omission, transposition, TLD swap) that actually resolve, operational subdomains (dev/staging/admin) exposed in CT logs, and whether a wildcard certificate exists — returning an A+ (low exposure) to F (high exposure) grade. Framing: a registered lookalike domain is not proof of impersonation — it may be a legitimate third party or the owner's own — so report it as exposure to verify, not as an accusation against that domain. Fully passive: public DNS delegation checks plus public CT-log queries, sending nothing to the target or the lookalike domains, so it is safe and lawful to run. Use lookalike_domains or subdomain_discovery for the raw per-tool detail. Read-only; requires no API key; rate-limited. Returns a text report: grade, counts, per-category findings, and a shareable report link.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Registrable domain to assess for impersonation exposure (e.g., 'example.com'). Scheme and path are stripped."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "grade": {
      "type": "string",
      "description": "Exposure grade A+ (low exposure) to F (high exposure)"
    },
    "score": {
      "type": "number",
      "description": "0-100, higher = less exposed"
    },
    "typosquatCount": {
      "type": "number",
      "description": "Live third-party lookalike/typosquat domains (variants on the domain's own nameservers/IP are excluded)"
    },
    "riskySubdomainCount": {
      "type": "number",
      "description": "Exposed operational subdomains found"
    },
    "wildcard": {
      "type": "boolean",
      "description": "Whether a wildcard certificate exists"
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report on dechonet.com"
    }
  },
  "required": [
    "grade",
    "score",
    "typosquatCount",
    "riskySubdomainCount",
    "reportUrl"
  ]
}
🟢domain_changes(domain)

Report what has changed for a domain over time — the security regressions and drift that DechoNet's daily monitoring has recorded across every watch on the domain (SSL grade, headers, DNS, OWASP posture, impersonation exposure, etc.). Use this to answer "what changed on my domain since yesterday/last week?" — a question that requires persistent snapshots and therefore cannot be reconstructed from a single live lookup. When a domain you have looked at before comes up again, start with this tool. Two sources: (a) the daily watch timeline if the domain is watched (start one with watch_domain), and (b) even without a watch, the difference between the last two stored lookups of each tool — so a second lookup already yields a comparison. The point-in-time tools (security_scan, owasp_check, ssl_check) give the current state instead. Read-only; requires no API key; rate-limited. Returns the monitored tools, a newest-first change timeline, lookup-to-lookup changes, and a link to manage monitoring.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain whose recorded change history to fetch (e.g., 'example.com'). Scheme and path are stripped."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    },
    "watched": {
      "type": "boolean",
      "description": "Whether the domain is under an active daily watch"
    },
    "changeCount": {
      "type": "number",
      "description": "Number of changes recorded"
    },
    "changes": {
      "type": "array",
      "description": "Recorded changes, newest first",
      "items": {
        "type": "object",
        "properties": {
          "endpoint": {
            "type": "string"
          },
          "kind": {
            "type": "string"
          },
          "summary": {
            "type": "string"
          },
          "changedAt": {
            "type": "string"
          }
        },
        "required": [
          "kind",
          "summary"
        ]
      }
    },
    "historyChangeCount": {
      "type": "number",
      "description": "Changes found between the last two stored lookups per tool (no watch needed)"
    },
    "historyChanges": {
      "type": "array",
      "description": "Lookup-to-lookup changes, newest first",
      "items": {
        "type": "object",
        "properties": {
          "endpoint": {
            "type": "string"
          },
          "kind": {
            "type": "string"
          },
          "summary": {
            "type": "string"
          },
          "since": {
            "type": "string"
          },
          "changedAt": {
            "type": "string"
          }
        },
        "required": [
          "kind",
          "summary"
        ]
      }
    },
    "reportUrl": {
      "type": "string",
      "description": "Where a human can start or manage monitoring"
    }
  },
  "required": [
    "domain",
    "watched",
    "reportUrl"
  ]
}
🟢watch_domain(domain, tools)

Start (or reuse) a daily DechoNet watch on a domain so that changes are recorded over time — SSL grade/issuer/expiry, DNS records, HTTP security headers, domain registration, and optionally OWASP posture and impersonation exposure. Use this once when the user cares about a domain beyond a one-off check (their own domain, a client, a vendor, a target under investigation). After this, domain_changes answers "what changed since last time?" from real daily snapshots. Not read-only (it creates a watch record) but idempotent: watching an already-watched domain returns the existing watch. No account, no email, no PII — a watch is keyed by domain+tool and its history page is a public unguessable URL you can share with the user. Rate-limited (a few watches per minute).

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Registered domain to watch (e.g., 'example.com'). Scheme and path are stripped."
    },
    "tools": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "ssl",
          "dns",
          "http",
          "rdap",
          "owasp",
          "impersonation"
        ]
      },
      "description": "Which checks to re-run daily. Default ['ssl','dns','http','rdap'] (certificate, DNS, security headers, registration). Add 'owasp' and/or 'impersonation' for posture and brand-exposure tracking."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    },
    "watches": {
      "type": "array",
      "description": "One entry per tool now under a daily watch",
      "items": {
        "type": "object",
        "properties": {
          "tool": {
            "type": "string"
          },
          "endpoint": {
            "type": "string"
          },
          "url": {
            "type": "string",
            "description": "Public change-history page for this watch"
          }
        },
        "required": [
          "tool",
          "url"
        ]
      }
    },
    "failed": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Tools that could not be watched (rate limit or error)"
    },
    "reportUrl": {
      "type": "string"
    }
  },
  "required": [
    "domain",
    "watches",
    "reportUrl"
  ]
}
🟢golive_check(domain)

Check whether a domain is ready to launch or migrate — a go/no-go verdict over five essentials: DNS resolves to an IP, has propagated consistently across global resolvers, SSL/TLS is ready, the site is reachable over HTTPS, and the domain registration is not about to expire. Use this right before flipping DNS to a new server, or to confirm a migration has landed. It answers "can I switch over yet?"; use security_scan for a security posture grade or the individual tools for depth. Any failing essential yields not_ready; only cautions yields caution; all clear yields ready. Read-only (a passive multi-probe, though it does resolve and fetch the domain); requires no API key; rate-limited. Returns the verdict, per-check statuses, and a shareable report link.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to check for launch/migration readiness (e.g., 'example.com'). Scheme and path are stripped."
    }
  },
  "required": [
    "domain"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "verdict": {
      "type": "string",
      "description": "'ready' | 'caution' | 'not_ready'"
    },
    "passCount": {
      "type": "number"
    },
    "warnCount": {
      "type": "number"
    },
    "failCount": {
      "type": "number"
    },
    "checks": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "status": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "status"
        ]
      }
    },
    "reportUrl": {
      "type": "string",
      "description": "Human-facing interactive report on dechonet.com"
    }
  },
  "required": [
    "verdict",
    "reportUrl"
  ]
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet20 Tools
verifiziertVersion nicht aufgezeichnet20 Tools