
Connects Claude to nslookup.io's DNS infrastructure with 11 tools covering lookups across all 53 DNS record types, propagation checks across 18 global servers, and SSL certificate validation. The standout is dns_health, which runs 39 automated checks across DNSSEC, MX configuration, nameserver hygiene, and CAA records with severity scoring. Also includes security scanning for SPF/DKIM/DMARC, multi-region uptime checks from 7 locations, and GEO scoring to measure how well a domain presents itself to AI crawlers. Available as a remote connector at mcp.nslookup.io/mcp or via npx locally. Reach for this when you're debugging DNS issues, auditing domain security posture, or need to verify propagation without leaving your editor.
claude mcp add --transport http nslookup https://mcp.nslookup.io/mcpRun in your terminal. Add --scope user to make it available in every project.
Review the command, arguments, and environment values before installing — MCP servers run with your local permissions.
Verified live against the running server on Jun 10, 2026.
dns_lookupLook up all common DNS records (A, AAAA, NS, MX, TXT, CNAME, SOA) for a domain. Returns results from a specified DNS server.2 paramsLook up all common DNS records (A, AAAA, NS, MX, TXT, CNAME, SOA) for a domain. Returns results from a specified DNS server.
domain*stringserverstringcloudflare · cloudflare2 · google · quad9 · opendns · authoritativedns_recordLook up a specific DNS record type for a domain. Supports 53 record types including A, AAAA, MX, TXT, CNAME, SOA, PTR, CAA, SRV, DNSKEY, DS, TLSA, HTTPS, SPF, and more.3 paramsLook up a specific DNS record type for a domain. Supports 53 record types including A, AAAA, MX, TXT, CNAME, SOA, PTR, CAA, SRV, DNSKEY, DS, TLSA, HTTPS, SPF, and more.
domain*stringserverstringcloudflare · cloudflare2 · google · quad9 · opendns · authoritativetype*stringA · AAAA · AFSDB · APL · AXFR · CAAdns_propagationCheck DNS propagation for a domain across 18+ global DNS servers (Cloudflare, Google, Quad9, OpenDNS, regional servers, and authoritative nameservers). Shows if DNS changes have propagated worldwide.2 paramsCheck DNS propagation for a domain across 18+ global DNS servers (Cloudflare, Google, Quad9, OpenDNS, regional servers, and authoritative nameservers). Shows if DNS changes have propagated worldwide.
domain*stringrecordType*stringA · AAAA · AFSDB · APL · AXFR · CAAwebserversGet the IP addresses (both IPv4 and IPv6) for a domain by looking up A and AAAA records. Also returns the punycode and unicode domain representations.1 paramsGet the IP addresses (both IPv4 and IPv6) for a domain by looking up A and AAAA records. Also returns the punycode and unicode domain representations.
domain*stringssl_certificateCheck the SSL/TLS certificate for a domain. Returns issuer, expiry date, days until expiry, certificate chain validity, cipher strength, SAN domains, fingerprint, and TLS protocol version.1 paramsCheck the SSL/TLS certificate for a domain. Returns issuer, expiry date, days until expiry, certificate chain validity, cipher strength, SAN domains, fingerprint, and TLS protocol version.
domain*stringbimi_vmcCheck BIMI (Brand Indicators for Message Identification) and VMC (Verified Mark Certificate) for a domain. Returns BIMI DNS record status, VMC certificate details, logo URL, trademark info, and expiry.1 paramsCheck BIMI (Brand Indicators for Message Identification) and VMC (Verified Mark Certificate) for a domain. Returns BIMI DNS record status, VMC certificate details, logo URL, trademark info, and expiry.
domain*stringsecurity_scanRun a security scan on a domain to detect DNS misconfigurations, missing SPF/DKIM/DMARC records, cookie security issues, and other web security vulnerabilities. Returns findings with severity levels (critical, high, medium, low, info).1 paramsRun a security scan on a domain to detect DNS misconfigurations, missing SPF/DKIM/DMARC records, cookie security issues, and other web security vulnerabilities. Returns findings with severity levels (critical, high, medium, low, info).
domain*stringuptime_checkPerform a one-time HTTP uptime check on a URL from a single location. Returns whether the site is up or down, HTTP status code, and response time in milliseconds. For multi-location checks, use uptime_check_multi instead.2 paramsPerform a one-time HTTP uptime check on a URL from a single location. Returns whether the site is up or down, HTTP status code, and response time in milliseconds. For multi-location checks, use uptime_check_multi instead.
timeoutnumberurl*stringuptime_check_multiCheck if a website is up or down from 7 global locations simultaneously: Amsterdam, Sydney, London, Frankfurt, Delhi, Warsaw, and South Carolina. Returns status, response time, and HTTP status code for each location.2 paramsCheck if a website is up or down from 7 global locations simultaneously: Amsterdam, Sydney, London, Frankfurt, Delhi, Warsaw, and South Carolina. Returns status, response time, and HTTP status code for each location.
timeoutnumberurl*stringdns_healthRun a comprehensive DNS health audit on a domain — 39 checks across 7 categories: DNSSEC (chain of trust, algorithms, validation), MX & email (PTR, MTA-STS, redundancy), DNS hygiene (SPF conflicts, wildcards, apex CNAME), TTL & SOA configuration, nameserver setup (diversity, l...1 paramsRun a comprehensive DNS health audit on a domain — 39 checks across 7 categories: DNSSEC (chain of trust, algorithms, validation), MX & email (PTR, MTA-STS, redundancy), DNS hygiene (SPF conflicts, wildcards, apex CNAME), TTL & SOA configuration, nameserver setup (diversity, l...
domain*stringgeo_checkerCheck a domain's GEO (Generative Engine Optimization) score — how well the site is optimized for AI search engines like ChatGPT, Gemini, Claude, and Perplexity. Returns three scores (Technical Readiness, Entity Readiness, Answer Readiness), AI crawler access status, structured...1 paramsCheck a domain's GEO (Generative Engine Optimization) score — how well the site is optimized for AI search engines like ChatGPT, Gemini, Claude, and Perplexity. Returns three scores (Technical Readiness, Entity Readiness, Answer Readiness), AI crawler access status, structured...
domain*string
MCP Server for nslookup.io
DNS lookups, SSL certificate checks, security scanning, GEO (AI readiness) scoring, domain intelligence, and your own monitoring account — via the Model Context Protocol.
Website · API Docs · npm · Contact
The nslookup.io MCP server gives any MCP-capable AI assistant (Claude, ChatGPT, Cursor, Windsurf, …) direct access to nslookup.io's DNS, certificate, security, and monitoring tools. Ask in plain language — "Run a DNS health check on github.com" or "Which of my SSL certificates expire soonest?" — and the assistant calls the right tool for you.
23 tools total, in two groups:
my_ account tools — read your own nslookup.io monitoring account (uptime, DNS, WHOIS, SSL, propagation, BIMI/VMC monitors). These are always listed but require signing in.Jump to Connect to get set up, or the Tool reference for the full list.
There are two ways to connect. Pick one — see the note below.
| Hosted (recommended) | Local (npx / stdio) | |
|---|---|---|
| Endpoint | https://mcp.nslookup.io/mcp | npx -y @nslookup-io/mcp-server |
| Transport | Streamable HTTP (remote) | stdio (runs on your machine) |
| Install | Nothing to install | Requires Node.js 18+ |
| 17 public tools | ✅ Anonymous | ✅ Anonymous |
6 my_ account tools | ✅ Browser sign-in (OAuth) on first use | ❌ Not available locally — use the hosted connector |
Use the hosted endpoint if you want your own monitoring data — it's the only mode where the my_ account tools sign in for you, right in the browser. The local mode is great for the 17 public tools with zero setup.
To use your own NsLookup.io monitoring data (the 6 my_ account tools), add the hosted connector and sign in. There is no API key — authentication is a one-time browser sign-in (OAuth) against your nslookup.io account.
Claude Code (CLI)
claude mcp add --transport http nslookup https://mcp.nslookup.io/mcp
Then invoke an account tool — e.g. ask "show my monitoring overview". A browser sign-in window appears; after you sign in once, all 6 my_ tools work (the client remembers it).
Claude Desktop / claude.ai — add a custom connector with URL https://mcp.nslookup.io/mcp, then sign in when prompted.
.mcp.json (project) or any HTTP-capable client:
{ "mcpServers": { "nslookup": { "type": "http", "url": "https://mcp.nslookup.io/mcp" } } }
The 17 public tools work immediately over this same endpoint — you only sign in the first time you reach for your own data.
The hosted endpoint is a remote Streamable-HTTP server. Public tools work immediately; the first time you call a my_ tool, an OAuth-capable client opens a browser window to sign in to your nslookup.io account (see Signing in).
Claude Code (CLI)
claude mcp add --transport http nslookup https://mcp.nslookup.io/mcp
Claude Desktop / claude.ai (custom connector)
nslookup — URL: https://mcp.nslookup.io/mcpOr drop it into an .mcp.json (project) / your client's MCP config:
{
"mcpServers": {
"nslookup": {
"type": "http",
"url": "https://mcp.nslookup.io/mcp"
}
}
}
ChatGPT
nslookup — URL: https://mcp.nslookup.io/mcpCursor / Windsurf (and any HTTP-capable client)
Add to your MCP config (.cursor/mcp.json, ~/.codeium/windsurf/mcp_config.json, etc.):
{
"mcpServers": {
"nslookup": {
"type": "http",
"url": "https://mcp.nslookup.io/mcp"
}
}
}
Runs the server on your machine over stdio. Public tools only — all 17 public tools work with no auth. For your own monitoring data (the my_ account tools), use the hosted connector and sign in — the account tools are not available on the local transport.
Claude Code (CLI)
# Global (all projects)
claude mcp add nslookup --scope user -- npx -y @nslookup-io/mcp-server
# Or for a single project
claude mcp add nslookup --scope project -- npx -y @nslookup-io/mcp-server
Claude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"nslookup": {
"command": "npx",
"args": ["-y", "@nslookup-io/mcp-server"]
}
}
}
Cursor (.cursor/mcp.json) / Windsurf (~/.codeium/windsurf/mcp_config.json):
{
"mcpServers": {
"nslookup": {
"command": "npx",
"args": ["-y", "@nslookup-io/mcp-server"]
}
}
}
Configure either the hosted entry or the local entry — not both. If two MCP servers named nslookup are registered at once (e.g. a hosted connector plus a local npx entry), tool calls can route to the wrong server and behave unpredictably. Pick the mode you want and remove the other.
my_ account tools — read your private monitoring data, so they require sign-in:
my_ tool without credentials returns a 401 with a WWW-Authenticate challenge, and OAuth-capable clients (Claude web/desktop, Claude Code, …) then walk you through a browser sign-in against the nslookup.io identity provider (Keycloak). There is no API key — sign in once and the client remembers it. Everything else keeps working anonymously — you only sign in when you first reach for your own data. See Connect for your account (portal) tools.| Tool | Description |
|---|---|
dns_lookup | Look up all common DNS records (A, AAAA, NS, MX, TXT, CNAME, SOA) for a domain |
dns_record | Look up a specific DNS record type — supports all 53 types (HTTPS, DNSKEY, TLSA, SPF, etc.) |
dns_propagation | Check DNS propagation across 18+ global servers (Cloudflare, Google, Quad9, regional, authoritative) |
webservers | Get IPv4 and IPv6 addresses for a domain |
dns_change_review | Review proposed DNS changes before applying them: diff vs current DNS, rule-based findings with fixes, and a 0–100 risk score |
| Tool | Description |
|---|---|
rdap_lookup | Registration data (RDAP) for an IP, AS number, or domain — owner org, network range, RIR, contacts, dates |
hosting_report | Who hosts a website: hosting provider, CDN/proxy, DNS provider, mail servers, server location, SSL issuer |
status_page | Read a public status page (by slug or custom domain): overall status, components, active incidents |
| Tool | Description |
|---|---|
dns_health | Run a DNS health audit (39 checks across DNSSEC, MX, hygiene, TTL, nameservers, CAA, operational maturity) with severity-weighted scoring |
ssl_certificate | Check SSL/TLS certificate — issuer, expiry, chain validity, cipher strength, SAN domains, TLS version |
bimi_vmc | Check BIMI record and VMC (Verified Mark Certificate) — logo URL, trademark info, certificate expiry |
bimi_check | Check only the BIMI DNS record (faster — skips the VMC certificate fetch) |
security_scan | Scan a domain for security issues — SPF/DKIM/DMARC, cookie security, DNS misconfigurations |
domain_scanner | Scan a domain's email security posture (SPF, DKIM, DMARC, BIMI) with per-indicator scores |
uptime_check | One-time HTTP uptime check — status, response time, HTTP status code |
uptime_check_multi | Check if a site is up from 7 global locations — Amsterdam, Sydney, London, Frankfurt, Delhi, Warsaw, South Carolina |
| Tool | Description |
|---|---|
geo_checker | Check a domain's GEO (Generative Engine Optimization) score — AI crawler access, structured data, entity signals, content extractability, and prioritized recommendations |
These my_ tools read your own nslookup.io monitoring account. They are always listed but require signing in to call.
| Tool | Description |
|---|---|
my_overview | Account health snapshot — aggregated 0–100 score with per-subsystem breakdown, plus your limits/quota |
my_monitors | List all your monitors across every type (uptime, API, DNS, WHOIS, propagation, certificates, VMC) |
my_incidents | Open (or all recent) incidents across all monitoring types, with a per-status/per-source summary |
my_uptime_history | Uptime + response-time history for one monitor (by id or URL) over a configurable window |
my_dns_changes | Recent DNS changes on your monitored domains with their risk reviews (0–100 score, severity counts) |
my_certificates | SSL certificate expiry overview — alert-level counts and certificates sorted by soonest expiry |
A, AAAA, AFSDB, APL, AXFR, CAA, CDNSKEY, CDS, CERT, CNAME, CSYNC, DHCID, DLV, DNAME, DNSKEY, DS, EUI48, EUI64, HINFO, HIP, HTTPS, IPSECKEY, IXFR, KEY, KX, LOC, MX, NAPTR, NS, NSEC, NSEC3, NSEC3PARAM, NXT, OPENPGPKEY, OPT, PTR, RP, RRSIG, SIG, SMIMEA, SOA, SPF, SRV, SSHFP, SVCB, TA, TKEY, TLSA, TSIG, TXT, URI, ZONEMD
cloudflare, google, quad9, opendns, authoritative, and regional servers in South Africa, Australia, India, Netherlands, Canada, USA, Brazil, Ukraine, Russia.
| Environment Variable | Default | Description |
|---|---|---|
NSLOOKUP_API_URL | https://www.nslookup.io | Base URL for the nslookup.io API |
MCP_RESOURCE_URL | (request-derived) | (HTTP server) Explicit public origin of this resource server, used as the issuer/resource/authorization_servers value in OAuth metadata. When unset, the origin is derived from the incoming request (X-Forwarded-Proto + host). Set it to the fixed public URL (e.g. https://mcp.nslookup.io) in production. |
KEYCLOAK_ISSUER | https://auth.nslookup.io/realms/nslookup-io | (HTTP server) OAuth token issuer used to validate sign-in JWTs (JWKS, issuer, exp) |
KEYCLOAK_REALM_URL | (= KEYCLOAK_ISSUER) | (HTTP server) Keycloak realm base URL whose /.well-known/openid-configuration supplies the real authorization_endpoint/token_endpoint. For Keycloak this equals the issuer, so it rarely needs setting. |
KEYCLOAK_CLIENT_ID | nslookup-io-mcp | (HTTP server) The pre-registered public Keycloak client id returned by the DCR shim. This client must already exist in the realm; no Keycloak DCR is enabled. |
The hosted server is an OAuth 2.1 resource server: calling a my_ tool without credentials returns a 401 with a WWW-Authenticate challenge pointing at /.well-known/oauth-protected-resource, and OAuth-capable MCP clients then walk you through sign-in against the nslookup.io identity provider.
Sign-in works for DCR-only clients (Claude web/desktop, Claude Code) without enabling Keycloak DCR. The server also acts as its own OAuth authorization server for metadata: GET /.well-known/oauth-authorization-server returns an issuer equal to this server's own origin, with authorization_endpoint/token_endpoint pointing at the real Keycloak endpoints (fetched from the realm's OpenID configuration, cached with a static fallback) and registration_endpoint set to <origin>/register. Because the advertised issuer is this server, clients that compute {issuer}/register hit our Dynamic Client Registration (DCR) shim at POST /register (also POST /oauth/register), which ignores the submitted metadata and returns one pre-registered public Keycloak client (KEYCLOAK_CLIENT_ID, default nslookup-io-mcp) with token_endpoint_auth_method: "none", echoing back the requested redirect URIs. The browser sign-in and the PKCE code→token exchange happen directly on Keycloak. A public client with KEYCLOAK_CLIENT_ID must already exist in the realm; no Keycloak DCR endpoint is used or exposed.
Once connected, try asking your AI assistant:
And once signed in to your nslookup.io account:
We'd love to hear from you! At nslookup.io, we're building a fast, reliable, and free DNS lookup tool and monitoring platform for everyone — from developers and sysadmins to everyday internet users.
Your feedback is what helps us improve. Whether you've spotted a bug, have a feature idea, or just want to share your thoughts — we're listening. Contact us.
Apache 2.0