External Recon Server
FreeNot checkedAn external reconnaissnce MCP server for offensive security engagements
About
An external reconnaissnce MCP server for offensive security engagements
README
A Model Context Protocol (MCP) server for performing active external reconnaissance activities against a domain. This tool provides a simple suite of reconnaissance capabilities including DNS enumeration, subdomain discovery, email security analysis, and SSL certificate inspection.
Want to build your own?
This project was created as a PoC for my tutorial on creating your own MCP server here
[!CAUTION] This is intended solely as a demonstration and is not production-ready. Use at your own risk. Only use MCPs that you trust to run on your machine. While this is a relatively benign tool, it does run OS commands. Do not target systems that you do not have permission to target.
Features
- DNS Reconnaissance
- Comprehensive DNS record enumeration (A, AAAA, MX, NS, SOA, TXT, SRV)
- DNS zone transfer attempts
- Subdomain enumeration & bruteforcing
- Domain Information
- WHOIS lookups
- HTTP headers analysis
- Email Security Assessment
System Requirements
The following tools need to be installed on your system:
- dig (DNS lookup utility)
- whois
- dnsrecon
Required Files
A subdomain wordlist has been supplied for brute-forcing, add to the list or replace for your own. (Note there is currently a limitation with very long wordlists).
- dns-wordlist.txt
Usage
For using a pre-built server, instructions from here: https://modelcontextprotocol.io/quickstart/user
- Download Claude for Desktop
- Install uv
curl -LsSf https://astral.sh/uv/install.sh | sh
- Download this repo and add to Claude for Desktop config
- Claude for Desktop > Settings > Developer > Edit config This will create a configuration file at:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
Open up the configuration file in any text editor. Replace the file contents with this:
{
"mcpServers": {
"external-recon": {
"command": "/ABSOLUTE/PATH/TO/PARENT/FOLDER/uv",
"args": [
"--directory",
"/ABSOLUTE/PATH/TO/PARENT/FOLDER/mcp-external-recon-server",
"run",
"external-recon.py"
]
}
}}
Relaunch Claude for Desktop You should now see two icons in the chat bar, a hammer which shows the tools available and a connection icon which shows the prompt defined and the input required (domain name)
Select the external-recon setup prompt and supply the target domain, you can then ask Claude to peform external recon and away she goes!
Security Considerations
- Only use against authorised targets
- Follow responsible disclosure practices
- Respect target system's resources
Contributing
Contributions are welcome! Please feel free to submit pull requests.
Disclaimer
This tool is for educational and authorized testing purposes only. Users are responsible for ensuring they have permission to test target systems.
Installing External Recon Server
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/naebo/mcp-external-recon-serverFAQ
Is External Recon Server MCP free?
Yes, External Recon Server MCP is free — one-click install via Unyly at no cost.
Does External Recon Server need an API key?
No, External Recon Server runs without API keys or environment variables.
Is External Recon Server hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install External Recon Server in Claude Desktop, Claude Code or Cursor?
Open External Recon Server on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectCompare External Recon Server with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
