Aggregate domain reconnaissance API — DNS, WHOIS/RDAP, SSL, subdomains, and email security in one parallel call. Live at https://oti-labs.com/domain-intelligence-api
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
- !Install pipes a remote script into a shell (curl | sh)
claude mcp add domain-intelligence-api -- python -m -r{
"mcpServers": {
"domain-intelligence-api": {
"command": "python",
"args": ["-m", "-r"]
}
}
}MCP Servers overview
# Domain Intelligence API
[](https://oti-labs.com/domain-intelligence-api)
[](https://rapidapi.com/osiris-technical-institute-osiris-technical-institute-default/api/domain-intelligence-api)
[](LICENSE)
[](#self-hosting)
> WHOIS/RDAP, DNS, SSL/TLS, subdomains and email security (SPF, DMARC, DKIM) for any domain, in one REST call.
A FastAPI service that runs the five lookups in parallel and returns one JSON object. Built and run in production by [Osiris Technical Institute](https://oti-labs.com).
- **Website and live demo:** <https://oti-labs.com/domain-intelligence-api>
- **Free web report for any domain:** `https://oti-labs.com/report/{domain}`, e.g. <https://oti-labs.com/report/stripe.com>
- **API key and pricing:** [RapidAPI listing](https://rapidapi.com/osiris-technical-institute-osiris-technical-institute-default/api/domain-intelligence-api)
- **OpenAPI spec:** [`rapidapi/openapi.json`](rapidapi/openapi.json)
---
## Try it (no key needed)
The public demo returns the full aggregate result, limited to 5 requests per IP per day:
```bash
curl -s https://oti-labs.com/demo/example.com | jq
```
## Use it (RapidAPI key)
```bash
curl -s "https://domain-intelligence-api.p.rapidapi.com/lookup/example.com" \
-H "X-RapidAPI-Host: domain-intelligence-api.p.rapidapi.com" \
-H "X-RapidAPI-Key: YOUR_RAPIDAPI_KEY"
```
```python
import requests
r = requests.get(
"https://domain-intelligence-api.p.rapidapi.com/lookup/example.com",
headers={
"X-RapidAPI-Host": "domain-intelligence-api.p.rapidapi.com",
"X-RapidAPI-Key": "YOUR_RAPIDAPI_KEY",
},
timeout=30,
)
data = r.json()
print(data["whois"]["registrar"], data["ssl"]["days_until_expiry"], data["subdomains"]["count"])
```
```javascript
// Node 18+ (built-in fetch)
const res = await fetch("https://domain-intelligence-api.p.rapidapi.com/lookup/example.com", {
headers: {
"X-RapidAPI-Host": "domain-intelligence-api.p.rapidapi.com",
"X-RapidAPI-Key": "YOUR_RAPIDAPI_KEY",
},
});
const data = await res.json();
```
---
## MCP server
AI agents and assistants can use the API as tools through the hosted MCP server at `https://oti-labs.com/mcp` (Streamable HTTP, registry name `com.oti-labs/domain-intelligence`). No key is needed for the first 1,000 lookups a month per IP. After that, send a RapidAPI key in the `X-RapidAPI-Key` header; its free plan adds 1,000 a month.
```bash
claude mcp add --transport http domain-intelligence https://oti-labs.com/mcp
```
Tools: `domain_lookup`, `whois_lookup`, `dns_records`, `ssl_certificate`, `subdomains`, `email_security`. Setup for Cursor, VS Code, Windsurf and Claude Desktop is in [`mcp/README.md`](mcp/README.md).
---
## Endpoints
| Method | Path | Returns |
|--------|------|---------|
| `GET` | `/lookup/{domain}` | All five sections below, fetched in parallel. Supports `?wait=1`. |
| `GET` | `/domain/{domain}/whois` | Registrar, registration/update/expiry dates, nameservers, status codes, registry handle, `_source` |
| `GET` | `/domain/{domain}/dns` | A, AAAA, MX, TXT, NS, CAA and SOA records (CNAME and PTR are not returned) |
| `GET` | `/domain/{domain}/ssl` | Live TLS handshake: issuer, subject, validity dates, `days_until_expiry`, serial number, every SAN, signature algorithm |
| `GET` | `/domain/{domain}/subdomains` | Subdomains from CT logs, passive DNS and DNS brute-force, with live hosts and their IPs separated from historical names. Supports `?wait=1`. |
| `GET` | `/domain/{domain}/email-security` | SPF and DMARC presence and records, plus DKIM keys found by probing 29 common selectors |
Pass the bare hostname as the path parameter (no scheme, no path). Punycode (`xn--`) domains work. An invalid domain returns `400 {"detail": "invalid domain"}`.
`/lookup` returns `domain`, `elapsed_ms`, `cached` (which sections came from cache) and the five sections `dns`, `ssl`, `whois`, `subdomains`, `email_security`. If one section fails, it comes back as an object with an `error` field and the rest of the response is unaffected. Full response schemas and real examples are in the [OpenAPI spec](rapidapi/openapi.json).
---
## How each lookup works
**WHOIS: 4-tier fallback.** The response's `_source` field names the tier that answered.
1. `rdap.org` universal redirect
2. IANA RDAP bootstrap, then the TLD's own RDAP server (bootstrap cached 24 h)
3. Fixed RDAP base URLs for 22 common TLDs, in case the bootstrap is slow
4. Port-43 socket WHOIS with 61 TLD-specific servers (all major gTLDs plus many ccTLDs without RDAP, such as .fr, .nl, .au, .ca, .jp, .ru, .cn, .br, .es, .it and .ch). For an unmapped TLD the client asks `whois.iana.org` and follows its referral.
Registrant contact details are not returned. Some registries (for example .uk and .nl) redact most fields by policy.
**DNS.** The seven record types are resolved in parallel through the server's resolver, each with a 3 s limit. Each type is an array of strings, empty when the domain has none.
**SSL.** A direct TLS handshake on port 443 with a 5 s socket timeout, no third-party scanner. The certificate is returned even if it is expired, self-signed or issued for another name, so you see what is actually deployed. `signature_algorithm` is a name such as `ecdsa-with-SHA384`.
**Subdomains.**
- **Sources, run concurrently:** crt.sh and certspotter (certificate transparency logs); hackertarget, rapiddns and VirusTotal v3 (passive DNS; VirusTotal paginated to about 120 results); DNS brute-force with a 773-name wordlist across 8 public resolvers (Cloudflare, Google, Quad9, OpenDNS), resolving A and CNAME. Each HTTP source has a 2.5 s connect timeout so an unreachable host fails fast.
- **Optional subfinder:** if the [`subfinder`](https://github.com/projectdiscovery/subfinder) binary is installed, it runs as a background source that adds 25+ more passive sources. If it is absent, `sources_used` shows `subfinder: skipped`.
- **Wildcard detection:** three random labels are resolved first. If the zone answers them, brute-force is skipped so a `*.domain` wildcard can't flood the results; the CT and passive-DNS sources still run.
- **Fast by default:** the response comes back after a ~3 s soft deadline. Slow sources keep running in the background and write the fuller result into the cache. `?wait=1` waits for every source (up to about 20 s) instead.
- **Live vs historical:** a background pass resolves every discovered name (wildcard-aware) and adds `live`, a list of `{host, ip}` for names that resolve now (IP or CNAME target), and `live_count`. `subdomains` is ordered live-first. On a domain's first lookup this pass finishes after the response, so `live` appears in the cached result shortly after; until then `sources_used` includes `liveness: enriching`.
- **Noise filtering:** large shared-infrastructure subtrees (for example `*.ns.cloudflare.com`) are collapsed into `pools` with a few representatives kept. DKIM/DMARC records and invalid hostnames are dropped.
- **Output:** up to 2,000 names per response; `count` is always the full total. `sources_used` gives each source's status (`N found`, `enriching`, `rate-limited`, `unavailable`, `skipped`). `warnings` appears only when fewer than 20 names were found and some sources failed.
No tool finds every subdomain; hosts that never appear in public data can't be discovered passively.
**Email security.** SPF from the domain's TXT records, DMARC from `_dmarc.{domain}`, and DKIM by probing 29 selectors used by Google Workspace, Microsoft 365, Mailchimp, SendGrid, Postmark, Mandrill, Klaviyo, Mailgun and generic names. Records are returned raw; SPF and DMARC are not parsed. Custom or hash-based DKIM selectors (for example Amazon SES) can't be discovered this way. BIMI, MTA-STS and blocklist checks are not included.
**Timeouts.** Each section has an overall limit: DNS 5 s, WHOIS 8 s, SSL 8 s, subdomains 10 s, email 6 s. A section that times out returns `{"error": "timeout", ...}`.
## Caching
Successful results are cached in Redis per section. Failed lookups are not cached.
| Section | TTL |
|---------|-----|
| DNS | 5 min |
| WHOIS | 1 hour |
| SSL | 6 hours |
| Subdomains | 24 hours |
| Email security | 1 hour |
## Pricing (RapidAPI)
| Plan | Price | Requests / month | Rate limit | Overage |
|------|-------|------------------|------------|---------|
| **BASIC** | Free | 1,000 (hard limit) | 10 / min | none |
| **PRO** | $9.99/mo | 50,000 | 60 / min | $0.0005 / request |
| **ULTRA** | $39.99/mo | 500,000 | 300 / min | $0.0002 / request |
| **MEGA** | $149.99/mo | 5,000,000 | 1,000 / min | $0.0001 / request |
Every plan includes every endpoint. Cached responses count toward the quota like fresh ones. RapidAPI also applies its own bandwidth fee above 10 GB a month. Subscribe on the [RapidAPI pricing page](https://rapidapi.com/osiris-technical-institute-osiris-technical-institute-default/api/domain-intelligence-api/pricing).
---
## Self-hosting
```bash
git clone https://github.com/osiris-technical-institute/domain-intelligence-api.git
cd domain-intelligence-api
pip install -r requirements.txt
uvicorn app.main:app --host 127.0.0.1 --port 8001
```
Needs Redis; the default is `redis://127.0.0.1:6379/0`. Put Caddy or nginx in front for TLS. The included [`domain-intel.service`](domain-intel.service) is the systemd unit used in production.
| Variable | Purpose |
|----------|---------|
| `REDIS_URL` | Redis connection URL |
| `RAPIDAPI_PROXY_SECRET` | If set, every non-public route requires a matching `X-RapidAPI-Proxy-Secret` header and returns `401` otherwise. Public routes: `/health`, `/metrics`, `/docs`, `/demo/*`, `/demo-preview/*`, `/report/*`, `/reports`, `/sitemap.xml`, `/robots.txt`. |
| `VT_API_KEY` | Enables the VirusTotal subdomain sourcWhat people ask about domain-intelligence-api
What is osiris-technical-institute/domain-intelligence-api?
+
osiris-technical-institute/domain-intelligence-api is mcp servers for the Claude AI ecosystem. Aggregate domain reconnaissance API — DNS, WHOIS/RDAP, SSL, subdomains, and email security in one parallel call. Live at https://oti-labs.com/domain-intelligence-api It has 14 GitHub stars and its last recorded update is dated 2026-10-03.
How do I install domain-intelligence-api?
+
You can install domain-intelligence-api by cloning the repository (https://github.com/osiris-technical-institute/domain-intelligence-api) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is osiris-technical-institute/domain-intelligence-api safe to use?
+
Our security agent has analyzed osiris-technical-institute/domain-intelligence-api and assigned a Trust Score of 87/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains osiris-technical-institute/domain-intelligence-api?
+
osiris-technical-institute/domain-intelligence-api is maintained by osiris-technical-institute. The last recorded GitHub activity is dated 2026-10-03, with 0 open issues.
Are there alternatives to domain-intelligence-api?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy domain-intelligence-api to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/osiris-technical-institute-domain-intelligence-api)<a href="https://claudewave.com/repo/osiris-technical-institute-domain-intelligence-api"><img src="https://claudewave.com/api/badge/osiris-technical-institute-domain-intelligence-api" alt="Featured on ClaudeWave: osiris-technical-institute/domain-intelligence-api" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.