Mmcp.market

theHarvester Cloud - Email & Subdomain Finder MCP server

by AnshumanAtrey·io.github.AnshumanAtrey/theharvester-osint·v1.1.3

theHarvester Cloud - Email & Subdomain Finder

A97/100grade A
What users say
No reviews yet
Be the first
Safety scan
A97/100

full report

Adoption
Growing

0 stars

Reviews

Write one

Nobody has reviewed theHarvester Cloud - Email & Subdomain Finder yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

theHarvester Cloud - Email & Subdomain Finder tools

Tool list not cached yet. `describe` through the gateway fetches it live.

Public scan report

scanner v0.1.9 · 2026-09-24 · same rubric, same numbers if you re-run it

no findings
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 25ms (auth required)20/20
  • Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
  • Auth qualityOAuth resource metadata advertised on 40115/15
  • Maintenancelast push 0 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 97/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

What the publisher says

From the theHarvester Cloud - Email & Subdomain Finder repository's README, as published. We do not edit it. Read it on GitHub

theHarvester Cloud - Email & Subdomain Finder

Find the emails and subdomains tied to any domain. We harvest emails, subdomains, IPs, URLs and ASNs from 54+ public sources in one call - cloud-hosted theHarvester, no install.

Available as an Apify Actor. Pay only per record found. The upstream tool is free; you pay Apify compute plus a small per-record fee.

What does it do?

Enter a domain and get back the emails and subdomains connected to it, plus IPs, URLs and ASNs, pulled from 54+ public sources in parallel: crt.sh, HackerTarget, RapidDNS, CertSpotter, Shodan, Censys, VirusTotal, SecurityTrails, GitHub, DuckDuckGo and more. We auto-clean the domain you paste (so a full URL still works), normalize the output across sources, and return one clean dataset row per finding - ready for a CRM, a spreadsheet, or an OSINT pipeline.

How is it different from running theHarvester CLI locally?

Wraps theHarvester by laramies (11,000+ GitHub stars, the canonical OSINT recon tool in PTES and OWASP Testing Guide).

When should I use it?

  • Sales and lead gen - find the real email addresses behind a company domain
  • Recruiting - surface a company's people and contact addresses from its domain
  • Due diligence - profile a company's external footprint before a deal or partnership
  • Fraud and trust teams - map the subdomains and emails tied to a suspect site
  • Security and bug bounty - first-call attack-surface and subdomain mapping for a target

What does it cost?

Pay-per-event:

Typical scan costs

  • Small domain (50 findings): $0.15
  • Mid domain (300 findings): $0.90
  • Large domain (1500 findings): $4.50

Which inputs does it take?

What does the output look like?

Each dataset record:

{
  "recordType": "host",
  "domain": "example.com",
  "host": "api.example.com",
  "ip": "93.184.216.34",
  "raw": "api.example.com:93.184.216.34",
  "timestamp": "2026-06-29T14:00:00Z"
}

Common questions

Q: Does this scan actively? No. theHarvester is purely passive - it queries public data sources. Active scanning (DNS bruteforce, port scans) requires sibling actors nmap-scanner or active-mode tools.

Q: Which sources require API keys? The four defaults (crt.sh, HackerTarget, RapidDNS, CertSpotter) and 15+ other public sources are free. Premium sources like Shodan, Censys, SecurityTrails and Hunter need your own API key, added in the API keys section.

Q: Source missing? DM LinkedIn (linkedin.com/in/anshumanatrey). Custom source additions ship within 1-2 hours.

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Install directly

claude mcp add --transport http theharvester-osint https://mcp.apify.com/?tools=anshumanatrey/theharvester-osint
Add to Cursor

theHarvester Cloud - Email & Subdomain Finder: common questions

Is theHarvester Cloud - Email & Subdomain Finder MCP server safe?
Yes, by our scan: it is graded A (97/100). Read the theHarvester Cloud - Email & Subdomain Finder safety report
How do I install theHarvester Cloud - Email & Subdomain Finder?
It runs remotely at mcp.apify.com. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does theHarvester Cloud - Email & Subdomain Finder need an API key?
No key to paste: it signs you in with OAuth when your client connects.
Is theHarvester Cloud - Email & Subdomain Finder maintained?
The last commit was in the last day (2026-09-24). The latest release is v1.1.3.
Is theHarvester Cloud - Email & Subdomain Finder up?
100% of our last 1 checks got an answer. We check remote servers about four times a day.
What can I use instead of theHarvester Cloud - Email & Subdomain Finder?
Servers from other publishers that do the same job: OpenOSINT MCP server, Tomba MCP Server and MCP server. Compare all theHarvester Cloud - Email & Subdomain Finder alternatives.

Alternatives to theHarvester Cloud - Email & Subdomain Finder

Same job from other publishers: the closest match first, then the best rated.

All theHarvester Cloud - Email & Subdomain Finder alternatives →
  • OpenOSINT
    AI-powered OSINT agent & MCP server. 16 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.
    C
  • Tomba MCP Server
    MCP server for Tomba email finder, verification, and contact enrichment API
    A
  • MCP
    20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
    A
  • Mbox
    Search local email archives (.mbox/.eml) entirely on your machine. No OAuth, no cloud.
    A
  • Netintel
    MCP server for NetIntel — DNS, SSL, WHOIS, email security, OSINT via x402 micropayments
    B

More from AnshumanAtrey