# XposedOrNot Breach Intelligence > XposedOrNot Breach Intelligence, an MCP server by xposedornot.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Real-time data-breach lookup and analytics for emails and domains from XposedOrNot. - Canonical: https://www.anchorterminal.com/tools/xposedornot - Markdown: https://www.anchorterminal.com/tools/xposedornot.md (~850 tokens) - Slim: https://www.anchorterminal.com/tools/xposedornot.min.md (~780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/xposedornot.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-05 # XposedOrNot Breach Intelligence > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by xposedornot.com (https://xposedornot.com/mcp) - Category: Email delivery APIs (https://www.anchorterminal.com/categories/email.md) - Listed because: It's published in the registry under xposedornot.com, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: Real-time data-breach lookup and analytics for emails and domains from XposedOrNot. ## Facts - MCP registry: `com.xposedornot/xposedornot` 2.0.0 - Endpoint: https://api.xposedornot.com/mcp (streamable HTTP) - Source: https://github.com/XposedOrNot/XposedOrNot-API - Website: https://xposedornot.com/mcp - GitHub stars: 98 - Registry entry updated: 2026-10-03 ## Tools - Tools it lists (6, about 827 tokens of context, `tools/list` without credentials, checked 2026-10-04 22:24 UTC): - `check_email_breaches` (read-only): Check whether an email address appears in the XposedOrNot index of known public data breaches. Returns the list of breach names only. Never returns passwords. - `get_breach_analytics` (read-only): Get a detailed breach history for one email address: the breaches it appeared in with dates and descriptions, exposure broken down by industry and by year,… - `list_breaches` (read-only): List breaches in the XposedOrNot catalog, optionally filtered by the breached company domain or by a specific breach ID. Returns breach name, date, industry,… - `domain_breach_summary` (read-only): Get an aggregate breach summary for a domain, including the number of breaches, affected email accounts, pastes, and the most recent breach date. Returns only… - `get_breach_metrics` (read-only): Get system-wide breach statistics: total breaches and records indexed, breaches per year and industry, the largest and most recent breaches, and when the… - `get_recent_breaches` (read-only): Get the breaches most recently added to XposedOrNot, newest first. Returns title, date, a short summary and a URL for each. - How its tools read to an agent (0 errors, 0 warnings, 1 note, about 827 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - note TC24 server: 6 of 6 tools have no outputSchema - JSON: https://www.anchorterminal.com/api/v1/tools/xposedornot.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming