Changelog
Stay informed about the latest improvements, new features, and changes to DomainTools products and services.
Integrations
Third-party platform integrations for seamless threat intelligence workflows.
Splunk , Python SDK , Cortex XSOAR , Cortex XSIAM , ServiceNow , Palo Alto Networks , Microsoft Sentinel , MISP , QRadar SOAR , Google Chronicle , Google SecOps , Anomali
Iris
Threat intelligence platform for investigating domains and detecting threats.
Threat Feeds
Real-time and daily threat intelligence feeds for proactive defense.
All updates
- Manage group API accounts from the Group Admin page
Group administrators can now view usage, rotate keys, deactivate accounts, and export a usage report for every API account in their company group — without contacting DomainTools support.
- Real-time IP Risk and IP Hotlist feeds now available
The DomainTools Real-time Threat Feeds suite now includes two new IP Threat Feeds: the Real-time IP Risk Feed and the Real-time IP Hotlist Feed.
- MCP Server — DNSDB Passive DNS, Domain History, and OAuth support
Three new capabilities are available in the DomainTools MCP Server: passive DNS lookups via DNSDB, domain registration history tools, and OAuth authentication support.
- FeedDomainTools Pack v1.0.7 for Cortex XSOAR: Risk score detail in feed indicators
FeedDomainTools Pack v1.0.7 is now available on the Cortex XSOAR Marketplace. This release enriches the
rawJSONpayload fordomainriskanddomainhotlistfeed indicators with full risk score details, giving analysts richer context directly in the XSOAR war room and indicator table without additional lookups. - IrisQL tool in the MCP Server
The MCP Server now exposes an
irisqltool for running IrisQL searches — text-based Iris Investigate queries with OR logic, nested conditions, field presence checks, and relative date ranges. - IrisQL available in the Iris Investigate API
IrisQL is now available in the Iris Investigate API, letting you build and submit domain searches programmatically.
- DomainTools integration for Google SecOps SOAR v11.0
Version 11.0 of the DomainTools integration for Google SecOps SOAR is now generally available. Version 11.0 adds four playbook actions to the Google SecOps SOAR marketplace, so you can pull domain intelligence straight into your SOAR workflows.
- Cortex XSOAR — command, pivot link, and verdict scoring fixes
Four bugs in the DomainTools Iris integration for Cortex XSOAR are resolved, covering command parameter handling, war room pivot links, dbot verdict speed, and the
domaintools-whoiscommand. - Anomali integration v1.1.0: RDAP enrichment and DNSDB passive DNS panel
v1.1.0 adds two new enrichment capabilities to the DomainTools App for Anomali ThreatStream: parsed RDAP registration data in the Iris Investigate domain enrichment panel, and a new DNSDB passive DNS enrichment panel for domain observables.
- Connect your AI client to DomainTools threat intelligence with the MCP Server
Connect your AI client to DomainTools domain threat intelligence using the Model Context Protocol (MCP).