Skip to content

    DomainTools docs: Find by task, product, or data

    New to DomainTools?

    Three steps to your first result:

    1. Get API credentials from your account portal
    2. Pick your tooling: Python SDK, MCP Server, or call the APIs directly
    3. Try the task for your role: see Find by task below

    Investigate a domain or infrastructure

    Trace connections across ownership, history, and hosting.

    Detect threats early

    Find malicious or lookalike domains as they register or become active.

    • Threat Feeds: discovery feeds (NOD, NAD, NOH) and predictive risk feeds (Domain Hotlist, IP Hotlist, and more)
    • Iris Detect: lookalike and impersonation detection
    • Domain Risk Score: ML-based domain classification
    • RPZ feeds: DNS firewalling against malicious domains

    Enrich alerts and indicators

    Add domain context to alerts in your SIEM, SOAR, or custom tooling.

    Registration data

    WHOIS and RDAP records: registrant identity, contacts, registrar, registration and expiry dates, EPP status codes. Current record and full history going back 20+ years.

    Passive DNS

    Historical DNS resolution records (A, AAAA, NS, MX, CNAME, and more) with first-seen/last-seen timestamps, observation counts, and bailiwick. Forward and inverse lookups; flex and regex search across 300+ billion records.

    Domain Risk Score

    ML-based 0–100 risk score with four components: Proximity (closeness to known-malicious domains), Malware Risk, Phishing Risk, and Spam Risk. Includes blocklist and zerolist status.

    Infrastructure and hosting

    Current DNS records (A, NS, MX, SOA) with ASN, ISP, and country enrichment. SSL/TLS certificate data. Hosting history showing IP, nameserver, MX, and registrar changes over time. Website metadata and web tracking codes.

    IP intelligence

    IP address geolocation (ASN, ISP, organization, country, city) and network ownership (CIDR ranges, RIR allocation). IP hosting threat profile showing the percentage of malicious domains resolving to an IP, broken down by phishing, malware, and spam categories.

    Domain discovery and monitoring

    Streams of newly observed and newly active domains and hostnames for early threat detection, plus newly registered domains via Domain Discovery. Monitoring by brand keyword, registrant attribute, nameserver, or IP.

    • Threat Feeds: Newly Observed Domains (NOD), Newly Active Domains (NAD), Newly Observed Hostnames (NOH), Domain Discovery feeds
    • Iris Detect: lookalike and impersonation monitoring
    • Monitor APIs: track new domains by brand, registrant, nameserver, or IP
    • RPZ feeds: DNS firewall lists in RPZ format

    Don’t see what you need? Email enterprisesupport@domaintools.com or contact your DomainTools representative. See the changelog for product updates.