dechonet.com MCP server by dechonet.com

MCP server · Email delivery APIs · indexed, not reviewed

HostedLocalvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.

What the official MCP registry says

Facts

MCP registry
com.dechonet/mcp · 1.2.4
Endpoint
https://dechonet.com/mcp
Packages
npm dechonet-mcp stdio
npm / week
271
GitHub stars
1
Registry entry
updated 2 Oct 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under dechonet.com, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 21 · about 11,031 tokens of context · checked 1 hour ago

ToolWhat it doesHint
dns_lookupDNS LookupQuery DNS records (A, AAAA, MX, TXT, NS, SOA, CAA) for a domain and validate email-related records, including DNSSEC presence and SPF/DMARC syntax, returning severity-rated diagnostics. Use this for a single…read-only
ssl_checkSSL Certificate CheckInspect a host's served TLS/SSL certificate and connection: expiry date, issuer, SAN list, chain integrity, TLS version, and HSTS, returning an A+ to F grade weighted by certificate validity (40%), TLS version (25%),…read-only
http_securityHTTP Security Headers AuditFollow a URL's HTTP redirect chain and audit response security headers (CSP, HSTS, X-Frame-Options, COOP, CORP, COEP, Permissions-Policy), grading A+ to F and flagging information leaks such as server-version…read-only
email_authEmail Authentication CheckAssess a domain's email authentication and deliverability posture: MX records, SPF, DMARC, DKIM (probes 15 common selectors), BIMI, MTA-STS, TLS-RPT, and DANE, plus a blacklist check across all MX hosts, returning a…read-only
port_scanOpen Port ScanProbe a host for a fixed set of common TCP ports (HTTP, HTTPS, SSH, FTP, SMTP, DNS, and common databases) and report which are open, the service name, and the response time. BEHAVIOR: this makes an ACTIVE TCP connection…read-only
dns_propagationDNS Propagation CheckQuery one DNS record across 8+ global public resolvers (Google, Cloudflare, Quad9, OpenDNS, and more) simultaneously and report which resolvers return stale versus updated values. Use this after changing a record to…read-only
reverse_dnsReverse DNS (PTR) LookupResolve the PTR (reverse DNS) record for an IPv4 or IPv6 address and verify forward-confirmed reverse DNS (FCrDNS) by checking that the PTR hostname resolves back to the same IP. Infers the hosting provider from PTR…read-only
asn_lookupASN / BGP LookupLook up Autonomous System (ASN) / BGP information for an IP address or AS number: the network operator, announced prefixes, abuse contact, and a classification (cloud, CDN, ISP, hosting, or enterprise). Use this to…read-only
whois_lookupWHOIS / RDAP Domain LookupRetrieve domain registration data via RDAP (with WHOIS fallback): registrar, creation/expiry/update dates, nameservers, and EPP status flags, highlighting risk states such as clientHold and pendingDelete. Use this for…read-only
subdomain_discoverySubdomain DiscoveryEnumerate the subdomains of a domain from Certificate Transparency logs — fully passive (no packets are sent to the target; CT logs are public records of every TLS certificate ever issued). Flags operational-looking…read-only
lookalike_domainsLookalike Domain CheckGenerate the typosquat/lookalike variants of a domain that phishers actually register — homoglyph swaps (l→1, o→0, rn→m), TLD swaps (.com→.co), character omissions, transpositions, repetitions, hyphenations — and check…read-only
ip_infoMy IP InfoReport information about the caller's own public IP as seen by the server: IPv4/IPv6 address, ISP, ASN, approximate geolocation, and proxy/VPN heuristics. Takes no input — it reflects the egress IP of THIS MCP server's…read-only
email_header_analysisEmail Header AnalysisParse raw email headers to reconstruct the delivery path (each Received hop in order), extract SPF/DKIM/DMARC authentication results, measure per-hop delays, and flag unencrypted (non-TLS) hops. Use this to diagnose a…read-only
subnet_calcIPv4 Subnet CalculatorCompute IPv4 subnet details from CIDR notation entirely locally — no network call: network and broadcast addresses, usable host range, total usable hosts, subnet mask, and wildcard mask. /31 and /32 are handled per RFC…read-only
security_scanFull Domain Security ScanOne-shot comprehensive audit of a domain: runs DNS, SSL, HTTP headers, email auth, port scan, DNS propagation, reverse DNS, and ASN/RDAP checks in parallel, then computes a 0-100 Health Score with an A-F grade and a…read-only
owasp_checkOWASP Security CheckupAssess a domain's OWASP posture from EXTERNAL OBSERVATION only: the OWASP Secure Headers Project plus the externally observable Top 10 subset — A02 Cryptographic Failures (TLS/cert), A05 Security Misconfiguration…read-only
impersonation_exposureBrand Impersonation ExposureAssess how exposed a domain is to brand impersonation and phishing, PASSIVELY: live typosquat/lookalike domains (homoglyph, omission, transposition, TLD swap) that actually resolve, operational subdomains…read-only
domain_changesDomain Change HistoryReport what has changed for a domain over time — the security regressions and drift that DechoNet's daily monitoring has recorded across every watch on the domain (SSL grade, headers, DNS, OWASP posture, impersonation…read-only
watch_domainWatch a Domain (daily re-check)Start (or reuse) a daily DechoNet watch on a domain so that changes are recorded over time — SSL grade/issuer/expiry, DNS records, HTTP security headers, domain registration, and optionally OWASP posture and…writes
golive_checkGo-Live Readiness ChecklistCheck whether a domain is ready to launch or migrate — a go/no-go verdict over five essentials: DNS resolves to an IP, has propagated consistently across global resolvers, SSL/TLS is ready, the site is reachable over…read-only
pqc_readinessPost-Quantum TLS ReadinessCheck whether a website's public TLS endpoint is ready for post-quantum cryptography: does it complete a TLS 1.3 handshake that offers only the hybrid X25519MLKEM768 key exchange (ML-KEM), and does the organisation's…read-only

What https://dechonet.com/mcp answered to tools/list, asked without credentials. answered without the initialize handshake. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 1 warning · 0 notes

  • warnTC14reverse_dnsallowed values are in the description, not an enum: ip

The checks from /check and anchor check, run each day on the list above: about 11,031 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.