mcp

DNS, IP, AS, domain reputation, and Lightning Network intelligence (44 tools)

Community: Submitted by a user or imported; check the owner before granting accessOnlineNo sign-inGlobalFreeRead-only

What it can do

    What data it sees

    Do you need an account

    No: the server works without sign-in

    DNS, IP, AS, domain reputation, and Lightning Network intelligence (44 tools)

    Server tool list (46)

    Raw names from tools/list. Only developers need these.

    latest_lightning_channelsReturns the most recently opened Lightning Network channels, sorted by open time descending.
    ip_reputationCheck an IP address reputation against 100+ real-time blocklists (DNSBLs). Returns listing status, threat categories, AS info, and blocklist details.
    lookup_dnsLookup DNS records (A, AAAA, MX, NS, TXT, CNAME, SOA) for a given hostname. Also returns domain reputation info (Majestic, Tranco rankings, blocklist status).
    reverse_lookup_dns_recordsFind hostnames that use a specific DNS record value. Query which hostnames point to an IP address, use a particular nameserver, or reference any DNS value. For example: 'which hostnames point to 1.2.3.4?' or 'which hostnames use chris.ns.cloudflare.com as their nameserver?'
    reverse_lookup_mxFind hostnames that use a specific mail server. For example: which hostnames use aspmx.l.google.com as their mail server?
    reverse_lookup_nsFind hostnames that use a specific nameserver. For example: which hostnames use chris.ns.cloudflare.com as their nameserver?
    reverse_lookup_ipFind hostnames that point to a specific IP address (IPv4 or IPv6). Searches both A and AAAA records. For example: which hostnames point to 1.2.3.4?
    historic_reverse_lookup_nsFind hostnames that *previously* used a specific nameserver but no longer do. Tracks infrastructure migrations and past delegation relationships.
    historic_reverse_lookup_mxFind hostnames that *previously* used a specific mail server but no longer do. Tracks email provider migrations and past MX relationships.
    historic_reverse_lookup_ipFind hostnames that *previously* pointed to a specific IP address but no longer do. Tracks hosting migrations and past IP relationships. Searches both A and AAAA records.
    lookup_macLook up the manufacturer/vendor of a network device by its MAC address. Uses the official IEEE OUI (Organizationally Unique Identifier) database with ~30K entries.
    lookup_as_whoisLookup WHOIS information for an Autonomous System (AS) number from the RADB routing database. Returns routing policy, network information, and administrative contacts.
    lookup_lightning_nodeLookup a Lightning Network node by public key. Returns node alias, peer count, channel count, and centrality ranking.
    lookup_lightning_channelLookup a Lightning channel by channel ID. Supports numeric, block x txn x vout, or block:txn:vout formats.
    lookup_lightning_channels_per_nodeLookup all Lightning Network channels for a given node by public key.
    get_recommended_lightning_peersGet recommended Lightning Network peers for a given node. Returns nodes that are NOT currently peered with the specified node but would improve its centrality score if connected.
    search_lightning_nodes_by_aliasSearch for Lightning Network nodes by partial alias match. Returns nodes whose aliases contain the search term (case-insensitive).
    domain_rdapQueries the authoritative RDAP registry for a domain. Returns availability status (HTTP 404 = available), and for registered domains: registrar name, registration/expiration dates, nameservers, DNSSEC status, and domain status flags. Uses IANA bootstrap to find the correct RDAP server per TLD. Covers 590+ TLDs.
    parse_hostnameParse a hostname into its constituent parts using the Mozilla Public Suffix List (9700+ entries). Returns eTLD (effective TLD), registered domain, subdomain, labels, and depth. Handles multi-level eTLDs (co.uk, co.jp, com.au) and platform suffixes (github.io, herokuapp.com).
    is_subdomainCheck whether a hostname is a subdomain (has labels beyond the registered domain). Uses the Mozilla Public Suffix List for accurate eTLD detection.
    registered_domainExtract the registered domain (eTLD+1) from a hostname. For example, www.mail.example.co.uk returns example.co.uk.
    tld_infoGet information about a top-level domain or effective TLD. Returns whether it is in the Public Suffix List, how many sub-suffixes exist, and classification (ccTLD, gTLD, or infrastructure).
    reverse_lookup_cnameFind hostnames that have a CNAME record pointing to the specified target. Useful for CDN and load balancer investigations.
    historic_reverse_lookup_cnameFind hostnames that previously had a CNAME record pointing to the specified target but no longer do. Tracks CDN and infrastructure migrations.
    ip_geolocationGet geographic location data for an IP address: country, city, region, latitude, longitude, timezone.
    ip_networkGet the containing network (BGP route), AS number, AS name, and route description for an IP address.
    ip_to_asnLightweight lookup: get just the AS number and netblock for an IP address. Fastest way to map IP to ASN.
    ip_blocklist_checkCheck an IP address against IPsum, FireHOL, Tor exit node lists, C2 indicators, Roskomnadzor (Russia), and other threat intelligence feeds. Returns which lists the IP appears on and threat scores.
    ip_threat_intelCombined threat intelligence: DNSBL listings, IPsum score, FireHOL lists, bad ASN flag, Tor exit status. Comprehensive threat assessment for an IP address.
    as_infoGet the name, organization, country, and description for an Autonomous System number. Lightweight version of as_whois.
    as_prefixesGet all IPv4 and IPv6 network prefixes (netblocks) announced by an Autonomous System. Returns BGP-visible routes.
    domain_reputationGet comprehensive domain reputation: Majestic rank, Tranco rank, HaGeZi blocklist status, Blackbook malware status, phishing database status, HSTS preload status, and disposable email detection.
    domain_rankingGet domain popularity rankings from five independent sources: Majestic Million (backlinks), Tranco top 1M (aggregated traffic), Cloudflare Radar (1.1.1.1 DNS query popularity), Cisco Umbrella (OpenDNS query popularity), and Chrome UX Report (real Chrome user traffic).
    domain_blocklist_checkCheck a domain against HaGeZi DNS blocklists, Steven Black unified hosts, Blackbook malware list, phishing databases, Roskomnadzor (Russia), and Citizen Lab censorship lists. Returns which lists the domain appears on.
    dns_differentialResolve a domain through filtered public DNS resolvers and their unfiltered controls to detect provider threat-feed blocks.
    domain_shared_ipFind other domains hosted on the same IP address(es) as the target domain. Resolves the domain's A records, then performs reverse IP lookups for each.
    domain_shared_nsFind other domains using the same nameserver(s) as the target domain. Resolves the domain's NS records, then performs reverse NS lookups for each.
    domain_shared_mxFind other domains using the same mail server(s) as the target domain. Resolves the domain's MX records, then performs reverse MX lookups for each.
    check_emailVerify an email address by connecting to its mail server via SMTP. Checks MX records, tests if the address is accepted (RCPT TO), detects catch-all domains, and reports TLS support. Results are RAM-cached for 1 hour.
    pingCheck if the API is responding. Returns status and server timestamp.
    lookup_bitcoin_transactionReturns full transaction details: inputs with addresses and values, outputs with spent status, fee, size/weight, SegWit flag, and Lightning Network channel correlation. Supports both confirmed and mempool transactions.
    lookup_bitcoin_addressReturns address balance, total received/sent, transaction counts, address type (P2PKH, P2SH, P2WPKH, P2TR), first/last seen block, and ransomware/abuse flags. Supports all Bitcoin address formats.
    lookup_bitcoin_blockReturns block header (hash, timestamp, version, merkle root, difficulty, nonce), transaction count, and list of transaction IDs. Supports lookup by block height.
    bitcoin_address_transactionsReturns a paginated list of transactions involving a Bitcoin address. Filter by direction: received (incoming funds), sent (outgoing funds), or all. Returns up to 100 transactions per call, sorted by block height descending (most recent first).
    bitcoin_transaction_spendsFor a given transaction, returns which subsequent transactions consumed its outputs. Useful for UTXO tracking and chain analysis. Shows the spending txid for each output.
    bitcoin_blockchain_statsReturns cumulative blockchain metrics over a configurable block range. Available metrics include: txs, fees, segwittx, inputs, outputs, insats, outsats, btcusd, volusd, unspentoutputs, fullyspent, unspentsats, addresses, satoshiblocks, clnopen, clnclose, satlnopen, satlnclose, basereward, blockreward, batched, rbf, version2tx, lowestfee, and more. Returns sampled data points suitable for charting.
    mcp: connect to Claude, ChatGPT, Cursor · Connectors.fun