# dechonet.com MCP server (slim) > dechonet.com MCP server, an MCP server by dechonet.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. 20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes. - Full: https://www.anchorterminal.com/tools/dechonet-mcp.md (~1,600 tokens) · this version ~1,530 tokens · JSON https://www.anchorterminal.com/tools/dechonet-mcp.json · canonical https://www.anchorterminal.com/tools/dechonet-mcp - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 # dechonet.com MCP server > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by dechonet.com (https://dechonet.com/mcp) - Category: Email delivery APIs (https://www.anchorterminal.com/categories/email.md) - Listed because: It's published in the registry under dechonet.com, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: 20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes. ## Facts - MCP registry: `com.dechonet/mcp` 1.2.4 - Endpoint: https://dechonet.com/mcp (streamable HTTP) - Package: npm `dechonet-mcp` (stdio) - Source: https://github.com/node-man/dechonet-mcp - Website: https://dechonet.com/mcp - npm downloads a week: 271 - GitHub stars: 1 - Registry entry updated: 2026-10-02 ## Tools - Tools it lists (21, about 11,031 tokens of context, `tools/list` without credentials, checked 2026-10-04 22:22 UTC): - `dns_lookup` (read-only): Query DNS records (A, AAAA, MX, TXT, NS, SOA, CAA) for a domain and validate email-related records, including DNSSEC presence and SPF/DMARC syntax, returning… - `ssl_check` (read-only): Inspect a host's served TLS/SSL certificate and connection: expiry date, issuer, SAN list, chain integrity, TLS version, and HSTS, returning an A+ to F grade… - `http_security` (read-only): Follow a URL's HTTP redirect chain and audit response security headers (CSP, HSTS, X-Frame-Options, COOP, CORP, COEP, Permissions-Policy), grading A+ to F and… - `email_auth` (read-only): Assess a domain's email authentication and deliverability posture: MX records, SPF, DMARC, DKIM (probes 15 common selectors), BIMI, MTA-STS, TLS-RPT, and DANE,… - `port_scan` (read-only): Probe a host for a fixed set of common TCP ports (HTTP, HTTPS, SSH, FTP, SMTP, DNS, and common databases) and report which are open, the service name, and the… - `dns_propagation` (read-only): Query one DNS record across 8+ global public resolvers (Google, Cloudflare, Quad9, OpenDNS, and more) simultaneously and report which resolvers return stale… - `reverse_dns` (read-only): Resolve the PTR (reverse DNS) record for an IPv4 or IPv6 address and verify forward-confirmed reverse DNS (FCrDNS) by checking that the PTR hostname resolves… - `asn_lookup` (read-only): Look up Autonomous System (ASN) / BGP information for an IP address or AS number: the network operator, announced prefixes, abuse contact, and a classification… - `whois_lookup` (read-only): Retrieve domain registration data via RDAP (with WHOIS fallback): registrar, creation/expiry/update dates, nameservers, and EPP status flags, highlighting risk… - `subdomain_discovery` (read-only): Enumerate the subdomains of a domain from Certificate Transparency logs — fully passive (no packets are sent to the target; CT logs are public records of every… - `lookalike_domains` (read-only): Generate the typosquat/lookalike variants of a domain that phishers actually register — homoglyph swaps (l→1, o→0, rn→m), TLD swaps (.com→.co), character… - `ip_info` (read-only): Report information about the caller's own public IP as seen by the server: IPv4/IPv6 address, ISP, ASN, approximate geolocation, and proxy/VPN heuristics.… - `email_header_analysis` (read-only): Parse raw email headers to reconstruct the delivery path (each Received hop in order), extract SPF/DKIM/DMARC authentication results, measure per-hop delays,… - `subnet_calc` (read-only): Compute IPv4 subnet details from CIDR notation entirely locally — no network call: network and broadcast addresses, usable host range, total usable hosts,… - `security_scan` (read-only): One-shot comprehensive audit of a domain: runs DNS, SSL, HTTP headers, email auth, port scan, DNS propagation, reverse DNS, and ASN/RDAP checks in parallel,… - `owasp_check` (read-only): Assess a domain's OWASP posture from EXTERNAL OBSERVATION only: the OWASP Secure Headers Project plus the externally observable Top 10 subset — A02… - `impersonation_exposure` (read-only): Assess how exposed a domain is to brand impersonation and phishing, PASSIVELY: live typosquat/lookalike domains (homoglyph, omission, transposition, TLD swap)… - `domain_changes` (read-only): Report what has changed for a domain over time — the security regressions and drift that DechoNet's daily monitoring has recorded across every watch on the… - `watch_domain` (writes): Start (or reuse) a daily DechoNet watch on a domain so that changes are recorded over time — SSL grade/issuer/expiry, DNS records, HTTP security headers,… - `golive_check` (read-only): Check whether a domain is ready to launch or migrate — a go/no-go verdict over five essentials: DNS resolves to an IP, has propagated consistently across… - `pqc_readiness` (read-only): Check whether a website's public TLS endpoint is ready for post-quantum cryptography: does it complete a TLS 1.3 handshake that offers only the hybrid… - How its tools read to an agent (0 errors, 1 warning, 0 notes, about 11,031 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - warn TC14 reverse_dns: allowed values are in the description, not an enum: ip - JSON: https://www.anchorterminal.com/api/v1/tools/dechonet-mcp.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming