Domain Security runs on your own machine — the client starts it, so there is no endpoint to ping. 377 installs a week from npm. Last commit 14 Sep 2026.
Audit a domain's email and web security: SPF, DKIM, DMARC, MTA-STS, DNSSEC, TLS, WHOIS. No API keys.
We read the source, 21 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
const presented = Buffer.from(/^Bearer\s+(.+)$/i.exec(header ?? "")?.[1] ?? "");
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Domain Security and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add domain-security-mcp-server -- npx -y domain-security-mcp-server
{
"mcpServers": {
"domain-security-mcp-server": {
"args": [
"-y",
"domain-security-mcp-server"
],
"command": "npx"
}
}
}
[mcp_servers.domain-security-mcp-server]
command = "npx"
args = ["-y", "domain-security-mcp-server"]
{
"mcpServers": {
"domain-security-mcp-server": {
"args": [
"-y",
"domain-security-mcp-server"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"domain-security-mcp-server": {
"args": [
"-y",
"domain-security-mcp-server"
],
"command": "npx"
}
}
}
DNS and email security scanner with 80 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.
DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.
74 paid web-analysis APIs (SEO, security, TLS, DNS, email) as MCP tools. USDC via x402.
SEO, performance, and security audits for any URL — no API keys required
Free passive security scanning - check any domain's DMARC, TLS, headers, and exposures.
Domain intelligence for agents: WHOIS, DNS, SSL/TLS, security headers, reputation, subdomains.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Scan websites for security vulnerabilities, headers, TLS, and email security.
Answers built from our own checks of this server.