MCP serverme.drwho/tools
29 free tools: DNS, email auth (SPF, DKIM, DMARC), TLS, headers, WHOIS, dev utils.
Overview
Score?
UNRATED 0.672
of what a free look can see, on 30 looks
Looks
35
last 11 hr ago
Tools
29
changed 16 days ago
More info
URL
drwho.me/mcp/mcp
streamable-http
Says it is
drwho.me 2.0.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.672 · highest on record 0.8561
Toolsfrom sha256:5965b87faf…3e4ee8 · +8 −1 16 days ago
| Tool | Schema |
|---|---|
| base64_decode added Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or does not decode to |
input · no output |
| base64_encode added Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns the encoded string. |
input · no output |
| dns_lookup Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on subdomains and name |
input · no output |
| dossier_ai_crawlers Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked or unspecified for |
input · no output |
| dossier_cors Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin requests from a given o |
input · no output |
| dossier_ct_log List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Queries crt.sh, then ce |
input · no output |
| dossier_dkim Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used by large mail provi |
input · no output |
| dossier_dmarc Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined or only reported. Que |
input · no output |
| dossier_dns Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX, CNAME and SRV. Send |
input · no output |
| dossier_dnssec Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DNS-over-HTTPS with DO |
input · no output |
| dossier_headers Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Po |
input · no output |
| dossier_llms_txt Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown heading, so a catch-all p |
input · no output |
| dossier_mta_sts Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TXT record, then fetch |
input · no output |
| dossier_mx List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudflare DNS-over-HTTPS, |
input · no output |
| dossier_redirects Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTTP to HTTPS or apex t |
input · no output |
| dossier_security_txt Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact and Expires fields. |
input · no output |
| dossier_spf Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossier_dmarc and dossier_ |
input · no output |
| dossier_summary added Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, TLS-RPT, MTA-STS and |
input · no output |
| dossier_tls Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whether the chain valida |
input · no output |
| dossier_tlsrpt Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Queries Cloudflare DN |
input · no output |
| dossier_web_surface Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or link-preview review |
input · no output |
| dossier_whois Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP over HTTPS when the re |
input · no output |
| ip_lookup Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need location or ownership cont |
input · no output |
| json_format added Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Runs locally. Returns |
input · no output |
| jwt_decode added Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspect claims such as exp |
input · no output |
| url_decode added Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came from an HTML form. R |
input · no output |
| url_encode added Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded). Runs locally. Retur |
input · no output |
| user_agent_parse Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no network call. Returns J |
input · no output |
| uuid_generate added Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs locally with a cryptograp |
input · no output |
Aggregate dossier check: Run all 10 Domain Dossier checks — dns, mx, spf, dmarc, dkim, tls, redirects, headers, cors, web-surface — in parallel and return all results in a single r |
— |
Verify it yourself
npx teppi-check https://drwho.me/mcp/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2Q02QJZ023K685D0YPZH