← Back to Insights
ORIGINAL

Abandoned MCP Domains Are an Allowlist Problem

OX Security’s 24 September scan found MCP hostnames on home networks, in other jurisdictions, and six abandoned domains for about $4. Directories do not cause that. Standing approvals without owners do.

Operator clipboard allowlist in front of a map of MCP hostnames with abandoned domains marked

On 24 September 2026, OX Security published a scan of 15,465 MCP servers across public registries. The headline numbers are ugly on purpose: hostnames in China and Russia, consumer tunnels into home networks, and six abandoned domains still cheap enough to buy for the price of lunch.

The useful reading is not “MCP is over.” It is this: a directory listing is not a trust boundary. Agents will call whatever URL is already in the config. If that hostname expires, whoever registers it next inherits the standing approval.

That is an allowlist problem. Not a search problem.

What OX actually measured

OX started with listings in the official registry, Cline’s marketplace, and GitHub’s MCP registry, then reduced the set to 5,095 unique hostnames. From their 24 September write-up:

They also showed a standing-approval failure: once an agent has been allowed to read a sensitive path, a later malicious tool can reuse that permission. That is not a exotic exploit. It is how most MCP clients work today.

None of this should surprise anyone who has watched the long tail. Influzer’s own catalog is now about 12,150 MCP servers, with only about 386 listings that have indexed tools. Search is abundant. Governed surfaces are not.

What this is not

It is not an argument to unplug agents. It is not an argument that every remote MCP server in another country is hostile. Geography is a compliance input, not a morality score.

It is also not a reason to stamp a public directory SAFE. We already refused that badge in Not “safe” — just honest. A live handshake and an auth gate tell you what we observed. They do not tell you who will own the domain next quarter.

YellowMCP’s reliability work makes the same point from another angle: a large share of remote endpoints do not answer, and a meaningful slice answers with no auth at all. Dead plus open is not a catalog you install from.

The failure mode that actually ships

Here is the sequence that will show up in a real incident review:

  1. Someone pastes a remote URL into .cursor/mcp.json, Claude connectors, or a ChatGPT custom MCP because the listing looked official.
  2. The team never records owner, region, or a kill date. The Connect button was the review.
  3. The operator lets the domain lapse. DNS goes dark. The config still points at the name.
  4. A new registrant stands up a lookalike tools/list. The client already trusts the host.

That is domain takeover with a friendly JSON file. Stars, READMEs, and “works with Claude” copy do not survive step 3.

The operator response (this week, not this year)

Reuse the sequencing from policy before plugins. Search can stay open. Install stays default-deny for writes.

  1. Inventory every remote URL your agents already call. Cursor project configs, Claude Desktop / Claude Code, ChatGPT connectors, Slack Claude Tag. If it is not on a page, it does not exist.
  2. Resolve DNS and WHOIS for each hostname. NXDOMAIN, registrar expiry inside 90 days, or a consumer tunnel is a ticket — not a “watch item.”
  3. Require an owner and a region. If nobody can say who runs it and where it lives, it does not belong in shared config. Residency is a policy field even when the protocol does not enforce it.
  4. Prefer Ready surface + Auth required over Thin listing. Filter the directory for quality. A 401 on tools/list is a heartbeat. Zero tools is a rumor.
  5. Put write tools on a separate allowlist row from read-only search. Eyes before hands is still the first week that survives security review.
  6. Stop paste-a-key in team configs. Standing credentials plus an abandoned hostname is how takeover becomes exfil. See paste-a-key is dead.

How Influzer treats this as catalog work

We will keep indexing the long tail. Hiding 11,000 thin listings does not make the remaining ones honest. What we will keep doing:

If you maintain a server we list, the bar is the same as for buyers: a live URL, a tool surface, and an owner who will still be there when the domain invoice arrives.

A 45-minute drill you can run Monday

  1. Export every MCP URL from shared configs (15 min).
  2. For each host: dig, TLS cert expiry, and whether tools/list returns tools, 401, or silence (20 min).
  3. Write three columns on one page: keep / quarantine / kill. Quarantine means read-only or disconnected until an owner signs (10 min).

Anything that fails DNS this week is already the OX finding, just closer to home.

Quick answers

Does a public MCP directory cause domain takeover?

No. Directories surface URLs. Clients that keep calling expired names without an owner review cause takeover. Treat listings as leads.

Should we ban every non-US MCP hostname?

Only if your residency policy says so. Record region. Do not confuse “not in us-east-1” with “malicious.”

Is an unauthenticated remote ever acceptable?

For a public read-only demo, maybe. For anything that can see customer data or write to GitHub, no. Open 2xx with tools is an incident waiting for a crawler.

Where should we start in the Influzer catalog?

Ready surface first, then Discovery search, then an allowlist row. Skip Thin listing until someone handshakes it.

Final thought

Fifteen thousand listings is not governance. Six abandoned domains is not a fun fact. It is what happens when Connect is cheaper than an owner field.

Write the allowlist. Handshake the host. Kill anything you cannot name.

Start on the directory. Search from inside the agent with Discovery. And if a hostname in your config no longer resolves, do not wait for a research report to tell you what that means.

GET PRACTICAL AI PLAYBOOKS WEEKLY

One clear email each Thursday

Actionable frameworks on AI execution, agents, and MCP. Join 4,200+ builders.

✓ You're in — first briefing Thursday.

Leave a comment

Be the first to share your thoughts.

Related insights

2026-10-02
MCP Apps Are Not WebMCP
SEP-1865 puts a sandboxed widget inside Claude and ChatGPT. WebMCP puts tools on the live page. Classic MCP is still just JSON. Pick the surface before Toronto sells you all three as one demo.
2026-10-01
Pack an Allowlist for MCP Dev Summit
MCP Dev Summit opens in Toronto on 5–6 October. The hallway will sell you plugins. Bring a map of the remotes you already run — and a one-page allowlist — or you will come home with stickers.
2026-09-28
Your Website Is Not an MCP Server
ChatGPT site tools are WebMCP on a live page — not another remote connector. If you wrap your storefront as an MCP server, you built the wrong trust boundary.