hijack_registrar_security

MCP tool from Dns Security MCP by badchars

Check domain registrar security posture via RDAP

How to use it

hijack_registrar_security is exposed by the Dns Security MCP MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the hijack_registrar_security tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.

Install Dns Security MCP

$npx -y dns-security-mcp
FULL DNS SECURITY MCP LISTING

Other tools in Dns Security MCP (39)

dns_cache_snoop

Perform DNS cache snooping by sending non-recursive query (RD=0) to a nameserver

dns_lookup

Resolve all DNS record types for a domain in parallel

dns_nsec_walk

Attempt DNSSEC NSEC zone walking to enumerate domain names in a signed zone

dns_propagation

Check DNS propagation by querying 20+ globally distributed public resolvers

dns_recursive_check

Test whether a nameserver is an open recursive resolver (RD=1 for external domain)

dns_reverse

Perform PTR (reverse DNS) lookup with Forward Confirmed rDNS (FCrDNS) validation

dns_server_fingerprint

Fingerprint a DNS server by querying CHAOS class TXT records (version.bind)

dns_split_horizon

Detect split-horizon (split-brain) DNS by comparing internal vs external resolver responses

dns_subdomain_enum

Enumerate subdomains using passive CT (Certificate Transparency) log lookups via crt.sh

dns_ttl_analysis

Analyze DNS TTL values across all record types for a domain

dns_wildcard_detect

Detect wildcard DNS configurations by resolving random non-existent subdomains

dns_zone_transfer

Attempt AXFR (full zone transfer) against a domain's nameserver via TCP

dnssec_algorithm_audit

Inventory all DNSSEC algorithms used in DS, DNSKEY, and RRSIG records

dnssec_check_dnskey

List all DNSKEY records for a domain

dnssec_check_ds

Check DS (Delegation Signer) records for a domain

dnssec_check_nsec

Check NSEC/NSEC3 records for a domain

dnssec_check_rrsig

Check RRSIG (Resource Record Signature) records and expiry

dnssec_full_audit

Comprehensive DNSSEC audit: all 7 checks combined with unified report

dnssec_key_rollover

Check for DNSSEC key rollover indicators

dnssec_validate

Full DNSSEC chain of trust validation from root to TLD to domain

email_check_bimi

Check BIMI (Brand Indicators for Message Identification) record

email_check_dane

Check DANE/TLSA records for a domain's MX hosts

email_check_dkim

Check DKIM records by probing common selectors (google, selector1, dkim, etc.)

email_check_dmarc

Check DMARC record with policy analysis and reporting configuration

email_check_mta_sts

Check MTA-STS (Mail Transfer Agent Strict Transport Security) configuration

email_check_ptr

Check PTR and FCrDNS (Forward-Confirmed reverse DNS) for MX hosts

email_check_spf

Check SPF (Sender Policy Framework) record with mechanism analysis

email_full_audit

Comprehensive email security audit across all protocols

email_spoofability_score

Calculate email spoofability score (0-100) based on SPF, DKIM, DMARC

hijack_bgp_impact

Assess BGP-level impact of domain hijacking via Team Cymru ASN lookup

hijack_change_monitor

Monitor DNS record changes by comparing against a stored baseline

hijack_dangling_cname

Detect dangling CNAME records that could allow subdomain takeover

hijack_dangling_mx

Detect dangling MX records that could allow email hijacking

hijack_dangling_ns

Detect dangling NS records that could allow full domain takeover

hijack_dns_rebinding

Detect DNS rebinding candidates via IP changes combined with low TTL

hijack_ns_delegation

Walk the DNS delegation chain and verify consistency

hijack_subdomain_takeover

Full subdomain takeover scan using CT logs and CNAME resolution

tunnel_entropy_analysis

Calculate Shannon entropy per subdomain label to detect tunneling

tunnel_query_length

Measure subdomain label and total query lengths for anomaly detection