{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_kxqzd265q6yv","handle":"drwho-me-developer-tools","url":"https://wellknown.network/agents/drwho-me-developer-tools","links":{"self":"https://wellknown.network/agents/drwho-me-developer-tools/record.json","html":"https://wellknown.network/agents/drwho-me-developer-tools","markdown":"https://wellknown.network/agents/drwho-me-developer-tools/record.md","api":"https://wellknown.network/api/v1/agents/drwho-me-developer-tools","status":"https://wellknown.network/api/v1/agents/drwho-me-developer-tools/status","claim":"https://wellknown.network/agents/drwho-me-developer-tools/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/drwho-me-developer-tools/claim.json","badge":"https://wellknown.network/agents/drwho-me-developer-tools/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/drwho-me-developer-tools/history","tools":"https://wellknown.network/api/v1/agents/drwho-me-developer-tools/tools"},"ard":{"identifier":"urn:air:drwho.me:server:drwho-me-developer-tools","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"drwho.me network and developer tools","summary":"29 free tools: DNS, email auth (SPF, DKIM, DMARC), TLS, headers, WHOIS, dev utils.","description":"29 free tools: DNS, email auth (SPF, DKIM, DMARC), TLS, headers, WHOIS, dev utils.","publisher":{"name":"me.drwho","url":null},"homepage":"https://drwho.me/mcp","repository":"https://github.com/hikmahtech/drwhome","version":"2.0.0","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://drwho.me/mcp/mcp","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-09-17T15:15:05.809837Z","publishedAt":"2026-09-17T15:15:05.809837Z","registryName":"me.drwho/tools"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"data.database","name":"Databases","confidence":1,"provenance":"derived"},{"slug":"productivity.email","name":"Email","confidence":1,"provenance":"derived"},{"slug":"security.identity","name":"Identity & Access","confidence":0.95,"provenance":"derived"},{"slug":"code.security-review","name":"Security Review","confidence":0.583,"provenance":"derived"},{"slug":"infra.cloud","name":"Cloud Platforms","confidence":0.554,"provenance":"derived"},{"slug":"content.writing","name":"Writing & Editing","confidence":0.51,"provenance":"derived"},{"slug":"content.social","name":"Social Media","confidence":0.51,"provenance":"derived"},{"slug":"data.web-scraping","name":"Web Scraping","confidence":0.51,"provenance":"derived"}],"categories":["code","content","data","infra","productivity","security"],"language":"en"},"observed":{"status":"live","statusReason":"Responded 1h ago.","lastOkAt":"2026-10-10T21:25:23.771Z","lastProbedAt":"2026-10-10T21:25:23.771Z","statusComputedAt":"2026-10-10T21:26:56.552Z","reliability30d":{"probes":111,"successRate":0.991,"p50Ms":915,"basis":"service","measures":{"availability":"availability","latency":"response time","tools":"tool surface observed","summary":"Checks reached the service itself."},"checks":{"total":108,"ok":107,"authBoundaryOk":0,"serviceOk":107,"note":"Counted from the observation rows for the window, checks of the server only (HTTP, A2A card, MCP initialize). ok = authBoundaryOk + serviceOk. `probes` is the sum of daily rollups and includes registry checks, so it can differ from `total`."}},"latestObservations":[{"at":"2026-10-10T21:25:23.771Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":428,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-10T14:26:28.069Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":799,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-10T08:32:11.167Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":728,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-10T01:25:44.314Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":686,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T19:27:41.841Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":928,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T13:31:23.055Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":428,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T07:25:26.257Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":743,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T01:25:03.319Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":443,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T18:26:13.092Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":735,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T11:24:25.742Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":778,"error":null,"detail":{"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"toolCount":29,"toolsHash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","serverName":"drwho.me","capabilities":["tools"],"serverVersion":"2.0.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"dossier_summary","description":"Run the nine DNS, email-authentication and TLS checks on a domain in parallel and return one graded line per check: DNS records, MX, SPF, DMARC, DKIM, DNSSEC, T"},{"name":"dossier_dns","description":"Fetch a domain's A, AAAA, NS, SOA, CAA and TXT records in one call. Use as the first step of a DNS review; prefer dns_lookup for a single record type or for MX,"},{"name":"dossier_mx","description":"List a domain's MX (mail exchanger) records sorted by priority. Use to see where a domain's inbound mail goes, or before checking SPF and DMARC. Queries Cloudfl"},{"name":"dossier_spf","description":"Find and parse a domain's SPF record into its mechanisms. Use to check which servers may send mail for a domain, or to debug delivery failures; pair with dossie"},{"name":"dossier_dmarc","description":"Find and parse the DMARC policy at _dmarc.<domain> into its tags (p, sp, pct, rua, ruf, adkim, aspf). Use to see whether spoofed mail is rejected, quarantined o"},{"name":"dossier_dkim","description":"Probe a domain for DKIM public keys at <selector>._domainkey.<domain>. Pass selectors when you know them; omit to probe a built-in list of common selectors used"},{"name":"dossier_dnssec","description":"Check whether a domain's zone is signed with DNSSEC and validates: DS and DNSKEY records plus the resolver's AD (authenticated data) flag. Queries Cloudflare DN"},{"name":"dossier_tlsrpt","description":"Look up a domain's SMTP TLS Reporting policy at _smtp._tls.<domain>. Use to confirm the domain receives reports about failed TLS delivery of its inbound mail. Q"},{"name":"dossier_mta_sts","description":"Fetch and validate a domain's MTA-STS policy (mode, mx, max_age). Use to confirm inbound mail to the domain must be delivered over TLS. Resolves the _mta-sts TX"},{"name":"dossier_tls","description":"Read the TLS certificate a domain presents on port 443: subject, issuer, validity dates, days remaining, subject alternative names, SHA-256 fingerprint and whet"},{"name":"dossier_redirects","description":"Trace the redirect chain from https://<domain>/, one entry per hop with its status code and target, up to 10 hops. Use to debug redirect loops or confirm an HTT"},{"name":"dossier_headers","description":"Fetch https://<domain>/ and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-"},{"name":"dossier_cors","description":"Send a CORS preflight (OPTIONS) to https://<domain>/ and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin req"},{"name":"dossier_web_surface","description":"Summarise a domain's public web surface: robots.txt, sitemap.xml and the home page's title, description, OpenGraph and Twitter card tags. Use for a quick SEO or"},{"name":"dossier_ai_crawlers","description":"Report what a domain's robots.txt says to the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, meta-externalagent): allowed, blocked"},{"name":"dossier_llms_txt","description":"Check whether a domain publishes an llms.txt, the markdown index some sites provide for AI agents. Requires a non-HTML content type and a leading markdown headi"},{"name":"dossier_security_txt","description":"Check whether a domain publishes /.well-known/security.txt (RFC 9116), the standard way to tell researchers where to report a vulnerability. Returns the Contact"},{"name":"dossier_whois","description":"Look up a domain's registrar, creation date, expiry date and registry statuses. Use for an ownership or expiry check. Tries WHOIS over TCP port 43, then RDAP ov"},{"name":"dossier_ct_log","description":"List subdomains of a domain that appear in Certificate Transparency logs. Use to map what hosts a domain has exposed through the certificates issued for it. Que"},{"name":"dns_lookup","description":"Resolve one DNS record type (A, AAAA, MX, TXT, NS, CNAME, SOA, CAA or SRV) for a name and return the raw answers. Use for a quick, targeted lookup, including on"},{"name":"ip_lookup","description":"Look up an IPv4 or IPv6 address: city, region, country, coordinates, timezone and the network (ASN and organisation) that announces it. Use when you need locati"},{"name":"user_agent_parse","description":"Parse a User-Agent header into browser, operating system, device and rendering engine. Use when reading server logs or request headers. Runs locally with no net"},{"name":"base64_encode","description":"Encode UTF-8 text as base64. Set url_safe for the URL-safe alphabet (- and _ in place of + and /, no padding), as used in JSON Web Tokens. Runs locally. Returns"},{"name":"base64_decode","description":"Decode base64 to UTF-8 text. Accepts the standard and the URL-safe alphabet, with or without padding or line breaks. Fails when the input is not valid base64 or"},{"name":"jwt_decode","description":"Decode a JSON Web Token's header and payload. It does NOT verify the signature, so never treat the claims as trusted on the strength of this tool. Use to inspec"},{"name":"json_format","description":"Validate JSON and re-print it with an indent of 2 or 4 spaces, or minified with indent 0. Use to check whether a string is valid JSON or to make it readable. Ru"},{"name":"url_encode","description":"Percent-encode text for use in a URL query value or path segment (encodeURIComponent rules: everything except letters, digits and - _ . ! ~ * ' ( ) is encoded)."},{"name":"url_decode","description":"Decode percent-encoded text. Fails on a malformed sequence such as a lone % sign. A plus sign is left as a plus; replace it with a space first if the text came "},{"name":"uuid_generate","description":"Generate UUIDs. Version 4 is fully random. Version 7 starts with a millisecond timestamp, so values sort by creation time, which suits database keys. Runs local"}],"package":null,"toolSurface":{"id":"ts_kx9bkm4uzdnt","endpointId":"ep_qyygpw469k4p","hash":"464bd43b16be8c2aa1233b8dfa80e42c75fc69a2b37e1be13567fd8c6c884864","toolCount":29,"serverName":"drwho.me","serverVersion":"2.0.0","protocolVersion":"2025-06-18","firstSeenAt":"2026-09-17T20:25:56.170Z","lastSeenAt":"2026-10-10T21:25:23.766Z","observations":85,"toolNames":["dossier_summary","dossier_dns","dossier_mx","dossier_spf","dossier_dmarc","dossier_dkim","dossier_dnssec","dossier_tlsrpt","dossier_mta_sts","dossier_tls","dossier_redirects","dossier_headers","dossier_cors","dossier_web_surface","dossier_ai_crawlers","dossier_llms_txt","dossier_security_txt","dossier_whois","dossier_ct_log","dns_lookup","ip_lookup","user_agent_parse","base64_encode","base64_decode","jwt_decode","json_format","url_encode","url_decode","uuid_generate"],"distinctSurfaces":2},"endpointFacts":[{"id":"ep_qyygpw469k4p","url":"https://drwho.me/mcp/mcp","type":"mcp_streamable_http","factsCheckedAt":"2026-10-08T18:26:13.092Z","auth":{"observedAt":"2026-10-08T18:26:13.968Z","authRequired":false,"scheme":null,"resourceMetadata":null,"authorizationServer":null,"conformance":{"dpop":false,"rfc8414":false,"rfc9728":false,"pkceS256":false,"clientIdMetadataDocument":false,"dynamicClientRegistration":false}},"tls":{"observedAt":"2026-10-08T18:26:14.002Z","protocol":"TLSv1.3","chainValid":true,"chainError":null,"hostMatches":true,"subject":"drwho.me","issuer":{"commonName":"WE1","organization":"Google Trust Services"},"validFrom":"2026-08-13T16:24:22.000Z","validTo":"2026-11-11T17:23:00.000Z","daysToExpiry":31,"sanCount":2,"fingerprint256":"86:DD:9D:18:24:34:F8:47:72:CC:7C:D9:4D:65:CC:A4:E9:86:BD:9E:9F:94:D8:19:1E:1F:9D:90:6D:A6:8F:A2"}}]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"me.drwho/tools","url":"https://registry.modelcontextprotocol.io/v0/servers/me.drwho%2Ftools","firstSeenAt":"2026-09-07T08:18:49.609Z","fetchedAt":"2026-10-08T18:22:08.131Z","normalizedAt":"2026-10-08T18:22:08.131Z"}]},"firstSeenAt":"2026-09-07T08:18:49.609Z","updatedAt":"2026-10-10T21:27:43.239Z"}