mcp server
mcp
DNS, IP, AS, domain reputation, and Lightning Network intelligence (44 tools)
Description as published by the maintainer. Source
- version 1.0.0
- slowing
slowing — Registry entry last updated 2026-02-18.
What this server can do
46 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
as_info(asn)- Get the name, organization, country, and description for an Autonomous System number. Lightweight version of as_whois. Required: asn.
as_prefixes(asn)- Get all IPv4 and IPv6 network prefixes (netblocks) announced by an Autonomous System. Returns BGP-visible routes. Required: asn.
bitcoin_address_transactions(address, direction)- Returns a paginated list of transactions involving a Bitcoin address. Filter by direction: received (incoming funds), sent (outgoing funds), or all. Returns up to 100 transactions per call, sorted by block height descending (most recent first). Required: address.
bitcoin_blockchain_stats(metric, samples, endBlock, startBlock)- Returns cumulative blockchain metrics over a configurable block range. Available metrics include: txs, fees, segwittx, inputs, outputs, insats, outsats, btcusd, volusd, unspentoutputs, fullyspent, unspentsats, addresses, satoshiblocks, clnopen, clnclose, satlnopen, satlnclose, basereward, blockreward, batched, rbf, version2tx, lowestfee, and more. Returns sampled data points suitable for charting. Required: metric.
bitcoin_transaction_spends(txid)- For a given transaction, returns which subsequent transactions consumed its outputs. Useful for UTXO tracking and chain analysis. Shows the spending txid for each output. Required: txid.
check_email(email)- Verify an email address by connecting to its mail server via SMTP. Checks MX records, tests if the address is accepted (RCPT TO), detects catch-all domains, and reports TLS support. Results are RAM-cached for 1 hour. Required: email.
dns_differential(domain)- Resolve a domain through filtered public DNS resolvers and their unfiltered controls to detect provider threat-feed blocks. Required: domain.
domain_blocklist_check(hostname)- Check a domain against HaGeZi DNS blocklists, Steven Black unified hosts, Blackbook malware list, phishing databases, Roskomnadzor (Russia), and Citizen Lab censorship lists. Returns which lists the domain appears on. Required: hostname.
domain_ranking(hostname)- Get domain popularity rankings from five independent sources: Majestic Million (backlinks), Tranco top 1M (aggregated traffic), Cloudflare Radar (1.1.1.1 DNS query popularity), Cisco Umbrella (OpenDNS query popularity), and Chrome UX Report (real Chrome user traffic). Required: hostname.
domain_rdap(domain)- Queries the authoritative RDAP registry for a domain. Returns availability status (HTTP 404 = available), and for registered domains: registrar name, registration/expiration dates, nameservers, DNSSEC status, and domain status flags. Uses IANA bootstrap to find the correct RDAP server per TLD. Covers 590+ TLDs. Required: domain.
domain_reputation(hostname)- Get comprehensive domain reputation: Majestic rank, Tranco rank, HaGeZi blocklist status, Blackbook malware status, phishing database status, HSTS preload status, and disposable email detection. Required: hostname.
domain_shared_ip(limit, hostname)- Find other domains hosted on the same IP address(es) as the target domain. Resolves the domain's A records, then performs reverse IP lookups for each. Required: hostname.
domain_shared_mx(limit, hostname)- Find other domains using the same mail server(s) as the target domain. Resolves the domain's MX records, then performs reverse MX lookups for each. Required: hostname.
domain_shared_ns(limit, hostname)- Find other domains using the same nameserver(s) as the target domain. Resolves the domain's NS records, then performs reverse NS lookups for each. Required: hostname.
get_recommended_lightning_peers(limit, offset, pubkey)- Get recommended Lightning Network peers for a given node. Returns nodes that are NOT currently peered with the specified node but would improve its centrality score if connected. Required: pubkey.
historic_reverse_lookup_cname(limit, offset, target)- Find hostnames that previously had a CNAME record pointing to the specified target but no longer do. Tracks CDN and infrastructure migrations. Required: target.
historic_reverse_lookup_ip(ip, limit, offset)- Find hostnames that *previously* pointed to a specific IP address but no longer do. Tracks hosting migrations and past IP relationships. Searches both A and AAAA records. Required: ip.
historic_reverse_lookup_mx(limit, offset, mx_server)- Find hostnames that *previously* used a specific mail server but no longer do. Tracks email provider migrations and past MX relationships. Required: mx_server.
historic_reverse_lookup_ns(limit, offset, nameserver)- Find hostnames that *previously* used a specific nameserver but no longer do. Tracks infrastructure migrations and past delegation relationships. Required: nameserver.
ip_blocklist_check(ip)- Check an IP address against IPsum, FireHOL, Tor exit node lists, C2 indicators, Roskomnadzor (Russia), and other threat intelligence feeds. Returns which lists the IP appears on and threat scores. Required: ip.
ip_geolocation(ip)- Get geographic location data for an IP address: country, city, region, latitude, longitude, timezone. Required: ip.
ip_network(ip)- Get the containing network (BGP route), AS number, AS name, and route description for an IP address. Required: ip.
ip_reputation(ip)- Check an IP address reputation against 100+ real-time blocklists (DNSBLs). Returns listing status, threat categories, AS info, and blocklist details. Required: ip.
ip_threat_intel(ip)- Combined threat intelligence: DNSBL listings, IPsum score, FireHOL lists, bad ASN flag, Tor exit status. Comprehensive threat assessment for an IP address. Required: ip.
ip_to_asn(ip)- Lightweight lookup: get just the AS number and netblock for an IP address. Fastest way to map IP to ASN. Required: ip.
is_subdomain(hostname)- Check whether a hostname is a subdomain (has labels beyond the registered domain). Uses the Mozilla Public Suffix List for accurate eTLD detection. Required: hostname.
latest_lightning_channels(count)- Returns the most recently opened Lightning Network channels, sorted by open time descending.
lookup_as_whois(asn)- Lookup WHOIS information for an Autonomous System (AS) number from the RADB routing database. Returns routing policy, network information, and administrative contacts. Required: asn.
lookup_bitcoin_address(address)- Returns address balance, total received/sent, transaction counts, address type (P2PKH, P2SH, P2WPKH, P2TR), first/last seen block, and ransomware/abuse flags. Supports all Bitcoin address formats. Required: address.
lookup_bitcoin_block(height)- Returns block header (hash, timestamp, version, merkle root, difficulty, nonce), transaction count, and list of transaction IDs. Supports lookup by block height. Required: height.
lookup_bitcoin_transaction(txid)- Returns full transaction details: inputs with addresses and values, outputs with spent status, fee, size/weight, SegWit flag, and Lightning Network channel correlation. Supports both confirmed and mempool transactions. Required: txid.
lookup_dns(hostname)- Lookup DNS records (A, AAAA, MX, NS, TXT, CNAME, SOA) for a given hostname. Also returns domain reputation info (Majestic, Tranco rankings, blocklist status). Required: hostname.
lookup_lightning_channel(channel_id)- Lookup a Lightning channel by channel ID. Supports numeric, block x txn x vout, or block:txn:vout formats. Required: channel_id.
lookup_lightning_channels_per_node(node, limit, offset)- Lookup all Lightning Network channels for a given node by public key. Required: node.
lookup_lightning_node(pubkey)- Lookup a Lightning Network node by public key. Returns node alias, peer count, channel count, and centrality ranking. Required: pubkey.
lookup_mac(mac_address)- Look up the manufacturer/vendor of a network device by its MAC address. Uses the official IEEE OUI (Organizationally Unique Identifier) database with ~30K entries. Required: mac_address.
parse_hostname(hostname)- Parse a hostname into its constituent parts using the Mozilla Public Suffix List (9700+ entries). Returns eTLD (effective TLD), registered domain, subdomain, labels, and depth. Handles multi-level eTLDs (co.uk, co.jp, com.au) and platform suffixes (github.io, herokuapp.com). Required: hostname.
ping- Check if the API is responding. Returns status and server timestamp.
registered_domain(hostname)- Extract the registered domain (eTLD+1) from a hostname. For example, www.mail.example.co.uk returns example.co.uk. Required: hostname.
reverse_lookup_cname(limit, offset, target)- Find hostnames that have a CNAME record pointing to the specified target. Useful for CDN and load balancer investigations. Required: target.
reverse_lookup_dns_records(limit, value, offset, record_type)- Find hostnames that use a specific DNS record value. Query which hostnames point to an IP address, use a particular nameserver, or reference any DNS value. For example: 'which hostnames point to 1.2.3.4?' or 'which hostnames use chris.ns.cloudflare.com as their nameserver?' Required: value.
reverse_lookup_ip(ip, limit, offset)- Find hostnames that point to a specific IP address (IPv4 or IPv6). Searches both A and AAAA records. For example: which hostnames point to 1.2.3.4? Required: ip.
reverse_lookup_mx(limit, offset, mx_server)- Find hostnames that use a specific mail server. For example: which hostnames use aspmx.l.google.com as their mail server? Required: mx_server.
reverse_lookup_ns(limit, offset, nameserver)- Find hostnames that use a specific nameserver. For example: which hostnames use chris.ns.cloudflare.com as their nameserver? Required: nameserver.
search_lightning_nodes_by_alias(alias, limit, offset)- Search for Lightning Network nodes by partial alias match. Returns nodes whose aliases contain the search term (case-insensitive). Required: alias.
tld_info(tld)- Get information about a top-level domain or effective TLD. Returns whether it is in the Public Suffix List, how many sub-suffixes exist, and classification (ccTLD, gTLD, or infrastructure). Required: tld.
Last successful function declaration observed on . Source: https://mcp.robtex.com/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://mcp.robtex.com/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 1.0.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-02-18 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-02-18 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| mcp tools declared | 46 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | mcp.robtex.com | |
| mcp endpoint status | ok | The server listed 46 functions when asked. | as of probe | mcp.robtex.com |
Where to get it
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json