# Domain RDAP MCP

> Free, keyless domain registration lookup via RDAP: registered, available, registrar, expiration.

- name: io.github.Lulu-The-Narwhal/domain-rdap-mcp
- version: 0.1.1
- connection class: R0 (autonomous)
- trust: 87/100 flags: duplicate-repo
- quality: 82/100 (good)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/io.github.Lulu-The-Narwhal%2Fdomain-rdap-mcp
- tools: https://api.protogrid.dev/v1/servers/io.github.Lulu-The-Narwhal%2Fdomain-rdap-mcp/tools

**An agent can connect right now, no human step.** Remote endpoint, no authentication, reachable on the last probe.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "domain-rdap-mcp": {
      "type": "http",
      "url": "https://ads.getlulu.dev/domain/mcp"
    }
  }
}
```


## Trust

- hygiene: 80
- liveness: 100
- freshness: 85
- provenance: 80
- drivers: +repository +namespace-matches-repo +reachable +uptime-100% ~updated-62d-ago -duplicate-repo(8 names)
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality 82/100 (good)

### protocol: 75 (weight 25)

- warn `protocol.modern`: newest supported version is 2025-11-25; 2026-07-28 not supported, older versions are deprecated until 2027-07-28
- n/a `protocol.stateless`: only applies to 2026-07-28 servers
- pass `protocol.transport`: streamable HTTP
- n/a `protocol.list_ttl`: only applies to 2026-07-28 servers

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: 79 (weight 30)

- pass `tools.descriptions`: every tool has a description
- warn `tools.description_length`: 1 tools have descriptions over 1,024 characters, which crowds the context
- pass `tools.schemas`: every tool has an object input schema
- pass `tools.annotations`: 1 of 1 tools declare readOnlyHint or destructiveHint
- fail `tools.directory_hints`: no tool declares all four of readOnlyHint, destructiveHint, idempotentHint and openWorldHint; missing: check_domain (destructiveHint, idempotentHint, openWorldHint)
- pass `tools.token_cost`: about 293 tokens to load every tool
- pass `tools.api_dump`: tools are not a one-to-one API dump

### stability: 100 (weight 15)

- pass `stability.changes`: no tool changes in 30 days
- pass `stability.rug_pull`: no tool changed its meaning under the same name

### dependencies: n/a (weight 15)

- n/a `deps.known_vulns`, `deps.mcp_sdk_version`, `deps.resolvable`: no npm or PyPI package

- tools: 1, about 293 tokens to load them all
- tool set hash: eabe88f69051cbc9519e7ab4b294a521
- badge: [![protogrid quality](https://protogrid.dev/badge/io.github.Lulu-The-Narwhal/domain-rdap-mcp.svg)](https://protogrid.dev/servers/io.github.Lulu-The-Narwhal/domain-rdap-mcp)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

_No tool definition changes recorded._

## Remotes

- https://ads.getlulu.dev/domain/mcp (streamable-http, auth none, reachable true, uptime30d 1)

## Packages

_none_

## Tools (1)

- `check_domain`: Check whether a domain name is registered, using real-time RDAP data
(the IETF-standardized successor to WHOIS). Use for "is domain-x.com
available/registered", "who is domain-x.com registered with", or "when
does domain-x.com expire" style questions.

`domain` is a bare domain like "example.com" -- no protocol prefix, no
path, no spaces.

If the domain is NOT registered, returns `{"domain": ..., "registered":
false}` -- this is a normal, meaningful answer (the domain is
available), not an error.

If the domain IS registered, returns `{"domain", "registered": true,
"status", "registered_date", "expiration_date", "last_changed_date",
"registrar"}`. `status` is a list of RDAP status codes (e.g. "active",
"client transfer prohibited"). Dates are ISO 8601. `registrar` is the
registrar's name, or null if the registry redacts it for privacy.

For obviously malformed input (not a domain -- e.g. missing a dot, has
spaces, or includes a protocol like "https://"), returns a clean
`{"error": ...}` instead of calling the API.
