dev.toolvend/dns-whois-domain-tools

MCPcommunitylive
v0.1.3dev.toolvendUnknownUpdated 12d ago

DNS, RDAP, LEI, URL inspection, extraction, sitemaps, robots.txt, text, VAT and QR. x402 USDC.

Endpoint healthlive
checked 2 days ago · 180ms
100% of the last 6 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
12d agoLast update
Package
Authordev.toolvend
LicenseUnknown
Version0.1.3
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface11 tools · none privileged
Security scan✓ Cleanvlive · 13d agoHow well does this scan work?
EvalsNone
IndexedAug 11, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

11 tools · none privileged
Observed live from the vendor's endpoint13d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://toolvend.dev/mcp11 tools · 287ms
dnsDNS lookup over DoH. Common record types (A, AAAA, MX, TXT, NS, CAA, ...) as clean JSON. Paid per call: $0.005 in USDC via x402.

DNS lookup over DoH. Common record types (A, AAAA, MX, TXT, NS, CAA, ...) as clean JSON. Paid per call: $0.005 in USDC via x402.

ParameterTypeDescription
name*stringDNS name to resolve
typestringRecord type, default A
email-authEmail authentication posture for a domain: DMARC + SPF records fetched, parsed, scored 0-100, with findings and fix recommendations. Paid per call: $0.01 in USDC via x402.

Email authentication posture for a domain: DMARC + SPF records fetched, parsed, scored 0-100, with findings and fix recommendations. Paid per call: $0.01 in USDC via x402.

ParameterTypeDescription
domain*stringDomain to analyse (path parameter)
email-auth-analyzeEmail diagnosis bundle: exact-domain DMARC, SPF sending-IP evaluation, up to five supplied DKIM selectors and structured receiver evidence. Prioritized fixes, timestamped DNS sources and missing checks. No signature verification, inherited-policy discovery or inbox claims. Paid per call: $0.10 in U…

Email diagnosis bundle: exact-domain DMARC, SPF sending-IP evaluation, up to five supplied DKIM selectors and structured receiver evidence. Prioritized fixes, timestamped DNS sources and missing checks. No signature verification, inherited-policy discovery or inbox claims. Paid per call: $0.10 in U…

ParameterTypeDescription
domain*stringAuthor (visible From) domain; ASCII/punycode
sendingIpstringSending IPv4 or IPv6 address; never contacted
envelopeFromDomainstringMAIL FROM domain for SPF; required to evaluate sendingIp
dkimSelectorsarray—
messageobjectStructured results copied from a receiver you trust; treated as unverified caller evidence. No raw headers or message body.
rdapDomain registration data (modern WHOIS) via RDAP: registrar, created/expiry dates, status, nameservers, DNSSEC. Paid per call: $0.005 in USDC via x402.

Domain registration data (modern WHOIS) via RDAP: registrar, created/expiry dates, status, nameservers, DNSSEC. Paid per call: $0.005 in USDC via x402.

ParameterTypeDescription
domain*stringDomain to look up (path parameter)
leiGlobal legal-entity/KYB lookup by LEI: official identity, jurisdiction, addresses, registration and renewal standing, risk flags, and GLEIF data freshness. Paid per call: $0.008 in USDC via x402.

Global legal-entity/KYB lookup by LEI: official identity, jurisdiction, addresses, registration and renewal standing, risk flags, and GLEIF data freshness. Paid per call: $0.008 in USDC via x402.

ParameterTypeDescription
lei*string20-character Legal Entity Identifier (path parameter); checksum is verified before payment
sitemapFetch and parse sitemap XML or gzip into JSON. For an index, follow the first N children with ?follow=N. Caps merged output at 500 URLs. Paid per call: $0.005 in USDC via x402.

Fetch and parse sitemap XML or gzip into JSON. For an index, follow the first N children with ?follow=N. Caps merged output at 500 URLs. Paid per call: $0.005 in USDC via x402.

ParameterTypeDescription
url*stringPublic HTTP(S) sitemap URL, including .xml.gz, or a site origin to try /sitemap.xml
followintegerFor a sitemap index, fetch and merge the first N children (default 0)
robotsFetch and parse robots.txt (+ llms.txt if present) into structured JSON, including which AI crawlers are blocked. Paid per call: $0.005 in USDC via x402.

Fetch and parse robots.txt (+ llms.txt if present) into structured JSON, including which AI crawlers are blocked. Paid per call: $0.005 in USDC via x402.

ParameterTypeDescription
url*stringPublic HTTP(S) site origin or URL
extractFetch a web page and return structured content: title, meta/OpenGraph, canonical, headings, links, readable text (boilerplate stripped). Add ?render=true for JavaScript-rendered pages ($0.03). Paid per call: $0.01 ($0.03 Execute JavaScript with Cloudflare Browser Run before extracting content.) in…

Fetch a web page and return structured content: title, meta/OpenGraph, canonical, headings, links, readable text (boilerplate stripped). Add ?render=true for JavaScript-rendered pages ($0.03). Paid per call: $0.01 ($0.03 Execute JavaScript with Cloudflare Browser Run before extracting content.) in…

ParameterTypeDescription
url*stringPublic HTTP(S) page URL to extract
includeLinksbooleanInclude outbound links (default true)
maxTextCharsnumberCap on extracted text length, default 20000
renderstringPremium tier, charged more than the base price. true → $0.03: Execute JavaScript with Cloudflare Browser Run before extracting content.
text-cleanClean text: strip HTML, normalise unicode/whitespace, dedupe lines. Returns cleaned text plus stats. Paid per call: $0.003 in USDC via x402.

Clean text: strip HTML, normalise unicode/whitespace, dedupe lines. Returns cleaned text plus stats. Paid per call: $0.003 in USDC via x402.

ParameterTypeDescription
text*stringInput text (max 500,000 characters)
optionsobject—
vatVAT calculator for EU-27 + UK: net→gross or gross→net at standard or reduced rate. Includes rates table snapshot date. Paid per call: $0.002 in USDC via x402.

VAT calculator for EU-27 + UK: net→gross or gross→net at standard or reduced rate. Includes rates table snapshot date. Paid per call: $0.002 in USDC via x402.

ParameterTypeDescription
amount*number—
country*stringISO 3166-1 alpha-2, e.g. DE, FR, GB
directionstringdefault net_to_gross
ratestringdefault standard
qrQR code generator. Returns a crisp SVG for text/URL payloads up to 2,048 UTF-8 bytes that fit the selected error-correction level. Paid per call: $0.003 in USDC via x402.

QR code generator. Returns a crisp SVG for text/URL payloads up to 2,048 UTF-8 bytes that fit the selected error-correction level. Paid per call: $0.003 in USDC via x402.

ParameterTypeDescription
data*stringPayload to encode (max 2,048 UTF-8 bytes; QR capacity is lower at Q/H error correction)
sizenumberSVG width/height in px, default 256
eclstringError correction, default M

11 of 11 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

DNS, RDAP, LEI, URL inspection, extraction, sitemaps, robots.txt, text, VAT and QR. x402 USDC.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.