MCP connector for Claude
Own It: who holds the keys?
Own It reads the public record of a business’s web presence and reports who controls each layer: the domain, the DNS, the website platform, the email, the tracking tags, the booking and CRM tools, and the profiles. For each one it says how hard it would be to leave, why in plain words, and the first step to take control. It is built for owners who inherited a website from an agency, a former employee or a relative, and want to know what they actually own.
Connector URL
https://mcp.modernmustardseed.com/own-it
Streamable HTTP. No sign-in. Every tool is read-only.
Connect it
- In Claude, open Settings, then Connectors.
- Choose Add custom connector, paste
https://mcp.modernmustardseed.com/own-it, and save. No account or key is needed. - In a chat, ask who controls a business’s website or domain. Claude calls the tools when the question needs them.
In Claude Code: claude mcp add --transport http own-it https://mcp.modernmustardseed.com/own-it
Try these
- “Who actually controls allbirds.com? Run an ownership audit and tell me the first thing to take back.”
- “If Glossier replaced its web team tomorrow, what would it have to take back? Audit glossier.com for lock-in.”
- “Check who holds the domain, DNS and email for patagonia.com, whether the registrant is Patagonia, and when the domain expires.”
The tools
audit_ownership
Audit who controls a business online
Maps who controls each layer of a business’s web presence from public data: domain registration (registrar, registrant if public, locks, expiry), DNS host, website platform (Wix, Squarespace, Shopify, WordPress, Webflow, GoDaddy, Duda, HighLevel, agency builders and more), email provider, analytics and ad tag IDs, call tracking, embedded booking, CRM and chat tools, and profile links including Google Business Profile. Each layer gets a portability rating, a plain-words reason and the first step to take control, and the whole presence gets a 0 to 100 portability score.
Inputs: domain (required, a domain or web address); business_name (optional, compared with the public registrant); profile_urls (optional, up to 10 links such as a Google Business Profile or Facebook page).
check_domain_control
Check domain, DNS and email control
The fast version: registrar, registrant if public, status codes and transfer locks, registration and expiry dates, DNSSEC, nameservers and DNS host, and mail provider, with a 0 to 100 control score and the first step. Does not read the website.
Inputs: domain (required); business_name (optional).
list_fingerprints
List detection rules
Lists every vendor Own It can name, the public marker that names it (DNS target, header, asset host or tag format), how portable it is, and the source for each marker. No network access.
Inputs: kind (optional): website, hosting, agency, dns, email, tags, call_tracking, widgets or profiles.
What it reads, layer by layer
Domain registration weight 30
The registry’s public RDAP record and the registrar’s: registrar, registrant when shown, EPP status codes, transfer locks, registration, transfer and expiry dates, DNSSEC.
Website platform weight 25
The homepage as any browser receives it, plus its DNS: response headers, generator tag, asset hosts, A and CNAME targets, and the footer credit.
Email weight 15
MX records name who receives mail; SPF includes name who may send it.
DNS host weight 10
The nameservers.
Analytics and ad tags weight 10
Tag IDs written in the homepage source: GA4, Tag Manager, Google Ads, Meta Pixel, TikTok, LinkedIn, Microsoft, Clarity, Hotjar, Pinterest, plus call tracking scripts.
Booking, CRM and chat weight 10
Embedded scheduling, ordering, CRM, chat, review, form and email signup tools.
Google Business Profile not scored
Classified from a link you supply or the site links to. Google does not publish who owns a profile, so this is always a check to make, never a score.
Other profiles not scored
Social and listing profiles linked from the homepage or supplied, each with the first step to confirm the login.
How the score works
The score is portability, not quality. 100 means the business holds the keys and can leave any vendor with its work; 0 means someone else holds them. Each vendor carries a portability level from our rules: easy (90), moderate (65), hard (35) or locked (15). The domain layer starts at 90 and loses points for an expiry inside 30 or 90 days, a registration or transfer in the last 60 days, a registry-level lock, a hold, a reseller or website-builder registrar, and a public registrant that does not match the business name you give. The overall score is the weighted average of the layers that could be read; a layer that could not be read is listed under not_measured and left out, never counted as zero. Bands: 80 and up, you hold the keys; 60 to 79, mostly yours; 40 to 59, hard to leave; under 40, locked in.
We recognise 19 website platforms and frameworks and 23 agency and franchise website vendors. The full rule set, with the marker and the source for each, is returned by list_fingerprints.
What it cannot see
- Inside any account. Who owns a Google Business Profile, an Analytics property, a Meta pixel or a booking account is private to each platform, so those layers name the login to confirm rather than guess.
- Most registrants. Since 2018 most registries redact the registrant, so the record usually shows a registrar and a privacy service. When an organisation is shown, we report it.
- Tags added after the page loads, for example inside a Tag Manager container. We report the container ID.
- Registries outside IANA’s RDAP bootstrap file (several country codes, including .co and .io at the time of writing). Those domains are marked not_measured for registration.
Data sources and licenses
- Domain registries and registrars over RDAP (RFC 9083), located through IANA’s public bootstrap file at data.iana.org. RDAP is the public registration data service ICANN requires of gTLD registries and registrars; we query one domain at a time on request and do not compile or resell the data, as their terms of use require.
- Public DNS through Cloudflare’s 1.1.1.1 and Google Public DNS resolvers, which are free for public use.
- The homepage you name, read once as any browser would, with our user agent named. We store detected vendor names and IDs, never the page itself.
- Our fingerprint rules, written by us from each vendor’s own help pages and the markers their platforms serve, each cited with the date we read it. No third-party fingerprint database is used.
Limits
- Results are saved for 24 hours per address. Asking again within a day returns the saved result instantly, marked cached, with the time it was read. A business name or profile links supplied later are applied to the saved facts without a new read.
- Fresh audits are limited across all users: 60 an hour and 600 a day, one per domain every 10 minutes. Over a limit the tool says so and gives the time to try again.
- An audit reads two RDAP records, five DNS answers and one homepage, and usually finishes in under five seconds.
- Only public names on ports 80 and 443 are read. Private, loopback, link-local and reserved addresses and private network names are refused before any request, and every redirect is checked again.
Troubleshooting
- Website layer says the source could not be read
- The site answered with a bot challenge or an error. The platform may still be named from DNS; tags and widgets are not measured in that case.
- Registration is not_measured
- The registry is not in IANA’s RDAP bootstrap or did not answer in time. Look the domain up at lookup.icann.org.
- “has no registry record, no DNS and no reachable homepage”
- The name is probably misspelled or not registered. The result is remembered for ten minutes.
For reviewers
No account, key or setup is needed. Add the connector URL above, then:
audit_ownershipwith domainallbirds.comreturns all eight layers: registration at MarkMonitor, Shopify, Microsoft 365 mail, a Tag Manager container and profile links.audit_ownershipwith domainglossier.comnames Shopify, Cloudflare DNS, Google Workspace mail and an embedded Klaviyo signup.check_domain_controlwith domainpatagonia.comand business_namePatagoniareturns the registrar, the public registrant (Patagonia, Inc.) matched to the business, expiry, status codes, DNS host and mail provider.audit_ownershipwith domainwarbyparker.comnames custom Next.js code on Vercel, Route 53 DNS and Google Workspace mail.list_fingerprintswith kindwebsitelists every platform rule with its source.- Refusals:
http://localhost,169.254.169.254and10.0.0.1each return a specific error and are never fetched.
Support and security
Questions, problems and security reports go to sarah@modernmustardseed.com. A machine-readable contact is at /.well-known/security.txt. How we handle data is in the privacy policy.