MCP server exposing 6 free domain-intelligence APIs as tools: sanctions screening (OFAC/UN/EU/UK/BIS), IP geolocation + VPN/Tor detection, email validation with HIBP breach status, company intelligence with Health Score, WHOIS + email-security scoring, and a one-call domain investigation dossier.
Strong tool definitions with clear use-case-first descriptions (avg 180 chars, well within 10-1024 range). All 6 tools have explicit schemas with typed parameters and descriptions. Naming follows verb_noun convention (screen_, geolocate_, validate_, company_, whois_, investigate_). However, some parameter descriptions lack format constraints (e.g., 'domain' accepts any string; no validation that it's a valid domain). Output schemas are not documented, LLMs cannot predict response structure. Error handling is basic (upstream timeout/unreachable messages exist but lack recovery guidance). No tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite all tools being read-only.
Get a company profile from a domain or name: Wikipedia + Wikidata + SEC EDGAR + GitHub org + UK Companies House. Includes a Company Health Score (0-100 from 6 free signals), tech stack, financials, CEO/founders. Use it for CRM enrichment, prospecting, or due-diligence research. Free, no key.
Geolocate an IP address: country, city, lat/lon, timezone, ISP, ASN — plus VPN/proxy/Tor detection and country metadata (currency, calling code, flag). Use it for fraud checks, analytics, or geo-restrict logic. Free, no key.
One-call domain investigation dossier: runs WHOIS + IP geolocation + company info + sanctions screening + email validation in parallel and returns a unified report with a plain-English verdict (e.g. 'Low-risk domain - legitimate company, sanctions CLEAN, email security grade A'). Includes subdomain takeover scan and email-security grade. Graceful degradation: if one upstream is down that section is null, the rest still returns. This is the flagship tool — use it whenever you need a full picture of a domain instead of calling the single-purpose tools one by one. Free, no key.
Screen a person or company name against 5 sanctions lists (OFAC SDN, UN Consolidated, EU FSF, UK FCDO, BIS CSL) in one call. Returns an explainable match (matched field, match type, tokens matched) and a plain-English risk verdict (HIGH/MEDIUM/LOW/CLEAN). Use it for KYC checks, partner screening, or crypto AML. Free, no key.
Output schemas not documented. LLMs cannot predict response structure (fields, types, nested objects). Forces agents to guess what data is available after each call.
Parameter format constraints missing. 'domain' and 'ip' parameters accept any string; no validation that inputs are valid domains/IPs. Descriptions lack regex patterns, length limits, or format hints.
Error handling lacks recovery guidance. Upstream timeout/unreachable errors are reported but do not tell the LLM what to do next (retry? ask user? try alternative?). No error categorization (retryable vs fatal).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 79 | 2026-07-28+ | v2 |
Validate an email address with SMTP verification, disposable-domain detection, catch-all probe, free-mail classification — AND Have-I-Been-Pwned breach status (breached?, breach count, first/last breach date). Returns is_trusted_identity: a composite verdict (SMTP-verified + not disposable + not breached). One call replaces a validator + a breach lookup. Use it for signup checks, lead scoring, or bounce prevention. Free, no key.
WHOIS via RDAP + DNS records + SSL certificate + subdomain discovery (CT logs) + takeover-risk scoring + email-security score (SPF/DMARC/DKIM/DNSSEC/MTA-STS, 0-100 with a letter grade). Use it for domain research, bug bounty recon, or email-security posture checks. Free, no key.
Tool annotations missing. All 6 tools are read-only (no side effects), but readOnlyHint is not set in schemas. Agents cannot infer safety/idempotency without explicit hints.
'company_info' parameter 'domain' is ambiguous. Description says 'Domain to look up, e.g. github.com' but tool also accepts company names per description. Unclear whether to pass 'github.com' or 'GitHub Inc', forces LLM to guess.