
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@nslookup-io/mcp-server
Advanced tools
MCP server for DNS lookups (53 record types), DNS health reports (39 checks), global propagation checks, RDAP registration data, hosting reports, DNS change review, SSL/TLS certificates, BIMI/VMC, security scans, GEO (AI readiness) scoring, multi-location
MCP Server for nslookup.io
DNS lookups, SSL certificate checks, security scanning, GEO (AI readiness) scoring, and domain intelligence — via the Model Context Protocol.
Website · API Docs · npm · Contact
| Tool | Description |
|---|---|
dns_lookup | Look up all common DNS records (A, AAAA, NS, MX, TXT, CNAME, SOA) for a domain |
dns_record | Look up a specific DNS record type — supports all 53 types (HTTPS, DNSKEY, TLSA, SPF, etc.) |
dns_propagation | Check DNS propagation across 18+ global servers (Cloudflare, Google, Quad9, regional, authoritative) |
webservers | Get IPv4 and IPv6 addresses for a domain |
dns_change_review | NEW — Review proposed DNS changes before applying them: diff vs current DNS, rule-based findings with fixes, and a 0–100 risk score |
| Tool | Description |
|---|---|
rdap_lookup | NEW — Registration data (RDAP) for an IP, AS number, or domain — owner org, network range, RIR, contacts, dates |
hosting_report | NEW — Who hosts a website: hosting provider, CDN/proxy, DNS provider, mail servers, server location, SSL issuer |
status_page | NEW — Read a public status page (by slug or custom domain): overall status, components, active incidents |
| Tool | Description |
|---|---|
dns_health | NEW — Run a DNS health audit (39 checks across DNSSEC, MX, hygiene, TTL, nameservers, CAA, operational maturity) with severity-weighted scoring |
ssl_certificate | Check SSL/TLS certificate — issuer, expiry, chain validity, cipher strength, SAN domains, TLS version |
bimi_vmc | Check BIMI record and VMC (Verified Mark Certificate) — logo URL, trademark info, certificate expiry |
bimi_check | NEW — Check only the BIMI DNS record (faster — skips the VMC certificate fetch) |
security_scan | Scan a domain for security issues — SPF/DKIM/DMARC, cookie security, DNS misconfigurations |
domain_scanner | NEW — Scan a domain's email security posture (SPF, DKIM, DMARC, BIMI) with per-indicator scores |
uptime_check | One-time HTTP uptime check — status, response time, HTTP status code |
uptime_check_multi | Check if a site is up from 7 global locations — Amsterdam, Sydney, London, Frankfurt, Delhi, Warsaw, South Carolina |
| Tool | Description |
|---|---|
geo_checker | Check a domain's GEO (Generative Engine Optimization) score — AI crawler access, structured data, entity signals, content extractability, and prioritized recommendations |
NEW in v1.5.0 — six my_ tools read your own NsLookup.io monitoring account (uptime, DNS, WHOIS, SSL, propagation, BIMI/VMC monitors). They are always listed, but require authentication to call.
| Tool | Description |
|---|---|
my_overview | Account health snapshot — aggregated 0–100 score with per-subsystem breakdown, plus your limits/quota |
my_monitors | List all your monitors across every type (uptime, API, DNS, WHOIS, propagation, certificates, VMC) |
my_incidents | Open (or all recent) incidents across all monitoring types, with a per-status/per-source summary |
my_uptime_history | Uptime + response-time history for one monitor (by id or URL) over a configurable window |
my_dns_changes | Recent DNS changes on your monitored domains with their risk reviews (0–100 score, severity counts) |
my_certificates | SSL certificate expiry overview — alert-level counts and certificates sorted by soonest expiry |
https://mcp.nslookup.io/mcp) — OAuth 2.1. The server is an OAuth resource server: calling a my_ tool without credentials returns a 401 with a WWW-Authenticate challenge pointing at /.well-known/oauth-protected-resource, and OAuth-capable MCP clients (Claude, etc.) then walk you through sign-in against the NsLookup.io identity provider. Everything else keeps working anonymously.
GET /.well-known/oauth-authorization-server returns an issuer equal to this server's own origin, with authorization_endpoint/token_endpoint pointing at the real Keycloak endpoints (fetched from the realm's OpenID configuration, cached with a static fallback) and registration_endpoint set to <origin>/register. Because the advertised issuer is this server, clients that compute {issuer}/register hit our Dynamic Client Registration (DCR) shim at POST /register (also POST /oauth/register), which ignores the submitted metadata and returns one pre-registered public Keycloak client (KEYCLOAK_CLIENT_ID, default nslookup-io-mcp) with token_endpoint_auth_method: "none", echoing back the requested redirect URIs. The browser sign-in and the PKCE code→token exchange still happen directly on Keycloak. A public client with KEYCLOAK_CLIENT_ID must already exist in the realm (redirect URIs allow-listed for your clients); no Keycloak DCR endpoint is used or exposed.nslk_...) as Authorization: Bearer nslk_....NSLOOKUP_API_TOKEN environment variable to an nslk_... token (or a raw access token) and the my_ tools pick it up.{
"mcpServers": {
"nslookup": {
"command": "npx",
"args": ["-y", "@nslookup-io/mcp-server"],
"env": { "NSLOOKUP_API_TOKEN": "nslk_..." }
}
}
}
The easiest way to get started. No installation required.
nslookuphttps://mcp.nslookup.io/mcpDone — Claude can now use all 17 public DNS, security, and health tools. Try asking "Run a DNS health check on github.com". The first time you use a my_ account tool, Claude will prompt you to sign in to your NsLookup.io account.
nslookuphttps://mcp.nslookup.io/mcpDone — ChatGPT can now perform DNS lookups, certificate checks, and security scans.
Any MCP-compatible client that supports Streamable HTTP transport can connect using:
https://mcp.nslookup.io/mcp
No API key or authentication required for the 17 public tools. The six my_ account tools respond with a standard OAuth 2.1 challenge (RFC 9728 protected-resource metadata), so OAuth-capable clients offer sign-in automatically; alternatively pass Authorization: Bearer nslk_... with an API token.
If you prefer running the server locally (requires Node.js 18+), add to your claude_desktop_config.json:
{
"mcpServers": {
"nslookup": {
"command": "npx",
"args": ["-y", "@nslookup-io/mcp-server"]
}
}
}
Available globally (all projects):
claude mcp add nslookup --scope user -- npx -y @nslookup-io/mcp-server
Or for a specific project only:
claude mcp add nslookup --scope project -- npx -y @nslookup-io/mcp-server
Add to your Cursor MCP settings (.cursor/mcp.json):
{
"mcpServers": {
"nslookup": {
"command": "npx",
"args": ["-y", "@nslookup-io/mcp-server"]
}
}
}
Add to your Windsurf MCP config (~/.codeium/windsurf/mcp_config.json):
{
"mcpServers": {
"nslookup": {
"command": "npx",
"args": ["-y", "@nslookup-io/mcp-server"]
}
}
}
A, AAAA, AFSDB, APL, AXFR, CAA, CDNSKEY, CDS, CERT, CNAME, CSYNC, DHCID, DLV, DNAME, DNSKEY, DS, EUI48, EUI64, HINFO, HIP, HTTPS, IPSECKEY, IXFR, KEY, KX, LOC, MX, NAPTR, NS, NSEC, NSEC3, NSEC3PARAM, NXT, OPENPGPKEY, OPT, PTR, RP, RRSIG, SIG, SMIMEA, SOA, SPF, SRV, SSHFP, SVCB, TA, TKEY, TLSA, TSIG, TXT, URI, ZONEMD
cloudflare, google, quad9, opendns, authoritative, and regional servers in South Africa, Australia, India, Netherlands, Canada, USA, Brazil, Ukraine, Russia.
| Environment Variable | Default | Description |
|---|---|---|
NSLOOKUP_API_URL | https://www.nslookup.io | Base URL for the nslookup.io API |
NSLOOKUP_API_TOKEN | — | Credential for the my_ account tools when running locally (stdio): an nslk_... API token or a raw access token |
MCP_RESOURCE_URL | (request-derived) | (HTTP server) Explicit public origin of this resource server, used as the issuer/resource/authorization_servers value in OAuth metadata. When unset, the origin is derived from the incoming request (X-Forwarded-Proto + host). Set it to the fixed public URL (e.g. https://mcp.nslookup.io) in production. |
KEYCLOAK_ISSUER | https://auth.nslookup.io/realms/nslookup-io | (HTTP server) OAuth token issuer used to validate sign-in JWTs (JWKS, issuer, exp) |
KEYCLOAK_REALM_URL | (= KEYCLOAK_ISSUER) | (HTTP server) Keycloak realm base URL whose /.well-known/openid-configuration supplies the real authorization_endpoint/token_endpoint. For Keycloak this equals the issuer, so it rarely needs setting. |
KEYCLOAK_CLIENT_ID | nslookup-io-mcp | (HTTP server) The pre-registered public Keycloak client id returned by the DCR shim. This client must already exist in the realm; no Keycloak DCR is enabled. |
Once connected, try asking your AI assistant:
And once signed in to your NsLookup.io account:
We'd love to hear from you! At nslookup.io, we're building a fast, reliable, and free DNS lookup tool and monitoring platform for everyone — from developers and sysadmins to everyday internet users.
Your feedback is what helps us improve. Whether you've spotted a bug, have a feature idea, or just want to share your thoughts — we're listening. Contact us.
Apache 2.0
FAQs
MCP server for DNS lookups (53 record types), DNS health reports (39 checks), global propagation checks, RDAP registration data, hosting reports, DNS change review, SSL/TLS certificates, BIMI/VMC, security scans, GEO (AI readiness) scoring, multi-location
The npm package @nslookup-io/mcp-server receives a total of 42 weekly downloads. As such, @nslookup-io/mcp-server popularity was classified as not popular.
We found that @nslookup-io/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.