<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>DomainTools Product Updates</title><link>https://docs.domaintools.com/changelog/</link><description>Latest updates to DomainTools products and services</description><docs>http://www.rssboard.org/rss-specification</docs><generator>python-feedgen</generator><language>en</language><lastBuildDate>Thu, 03 Sep 2026 00:00:00 +0000</lastBuildDate><item><title>DomainTools App for Splunk v5.8: IP Threat Feed searches</title><link>https://docs.domaintools.com/changelog/2026/09/03/splunk-app-v5-8-ip-threat-feed-searches/</link><description>Version 5.8 of the DomainTools App for Splunk adds IP Hotlist and IP Risk searches, scheduled indexing, and expanded Threat Feeds controls.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;IP Threat Feed searches&lt;/strong&gt;: The &lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/" rel="noopener noreferrer"&gt;DomainTools App for Splunk&lt;/a&gt; now includes &lt;code&gt;dtfeediphotlist&lt;/code&gt; and &lt;code&gt;dtfeediprisk&lt;/code&gt;. Use them to investigate high-risk hosting IP addresses and broader IP risk context with filters for threat activity, hosting density, ownership, and geography.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scheduled indexing&lt;/strong&gt;: Save an IP feed search as a Splunk report to write new results to an event index on a schedule. Use a persistent &lt;code&gt;sessionID&lt;/code&gt; so each scheduled run continues from the prior request.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Threat Feed query controls&lt;/strong&gt;: Existing feed commands now support time-window, session, and result-limit options that align with &lt;a href="https://docs.domaintools.com/api/threat-feeds/" rel="noopener noreferrer"&gt;Threat Feeds&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;IP feed validation&lt;/strong&gt;: The app now prevents incompatible IP feed session options.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Splunk compatibility&lt;/strong&gt;: This release corrects text overlap on the Iris Investigate Domain Profile page and improves Splunk AppInspect validation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/" rel="noopener noreferrer"&gt;DomainTools App for Splunk overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/components/search/#threat-feed-commands" rel="noopener noreferrer"&gt;IP threat feed commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/components/search/#index-ip-feed-results-on-a-schedule" rel="noopener noreferrer"&gt;Schedule IP feed indexing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/" rel="noopener noreferrer"&gt;IP Threat Feeds API reference&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/09/03/splunk-app-v5-8-ip-threat-feed-searches</guid><category>Integrations</category><category>Splunk</category><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate></item><item><title>DomainTools App for Splunk v5.7: IrisQL search support</title><link>https://docs.domaintools.com/changelog/2026/07/31/splunk-app-v5-7-irisql/</link><description>Version 5.7 of the DomainTools App for Splunk adds text-based IrisQL queries to the dtirisinvestigate custom search command.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;IrisQL searches&lt;/strong&gt;: The &lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/" rel="noopener noreferrer"&gt;DomainTools App for Splunk&lt;/a&gt; now supports IrisQL, the text-based query language for &lt;a href="https://docs.domaintools.com/iris/investigate/" rel="noopener noreferrer"&gt;Iris Investigate&lt;/a&gt;, through the &lt;code&gt;dtirisinvestigate&lt;/code&gt; custom search command. Start each query with &lt;code&gt;# IrisQL-1.0&lt;/code&gt;, use it in standard Splunk Search Processing Language (SPL), then pipe the results to later commands.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/components/search/#query-with-irisql" rel="noopener noreferrer"&gt;IrisQL queries in Splunk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/iris/investigate/irisql/" rel="noopener noreferrer"&gt;IrisQL field and operator reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/#release-notes" rel="noopener noreferrer"&gt;Splunk integration release notes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/07/31/splunk-app-v5-7-irisql</guid><category>Integrations</category><category>Splunk</category><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate></item><item><title>DomainTools Python SDK v2.9: Query IP Threat Feeds</title><link>https://docs.domaintools.com/changelog/2026/07/29/python-sdk-v2-8-1-v2-9-0/</link><description>Version 2.9.0 of the DomainTools Python SDK adds IP Hotlist and IP Risk feed methods, while version 2.8.1 improves Iris Enrich resilience.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;IP feed methods&lt;/strong&gt; (v2.9.0): Query the &lt;a href="https://docs.domaintools.com/api/threat-feeds/ip-hotlist/" rel="noopener noreferrer"&gt;IP Hotlist&lt;/a&gt; and &lt;a href="https://docs.domaintools.com/api/threat-feeds/ip-risk/" rel="noopener noreferrer"&gt;IP Risk&lt;/a&gt; feeds from the DomainTools Python SDK with &lt;code&gt;iphotlist()&lt;/code&gt; and &lt;code&gt;iprisk()&lt;/code&gt;. Use the same feed-session controls and response options available through the &lt;a href="https://docs.domaintools.com/api/threat-feeds/" rel="noopener noreferrer"&gt;Threat Feeds API&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Iris Enrich recovery&lt;/strong&gt; (v2.8.1): Iris Enrich calls can proceed when a temporary service response prevents the SDK from completing its rate-limit check.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Feed result limits&lt;/strong&gt; (v2.9.0): The &lt;code&gt;top&lt;/code&gt; option for Feeds methods is now correctly typed as an integer.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/python-sdk/#ip-threat-feeds" rel="noopener noreferrer"&gt;Python SDK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/ip-hotlist/" rel="noopener noreferrer"&gt;IP Hotlist feed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/ip-risk/" rel="noopener noreferrer"&gt;IP Risk feed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DomainTools/python_api/releases/tag/2.9.0" rel="noopener noreferrer"&gt;v2.9.0 release on GitHub&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/07/29/python-sdk-v2-8-1-v2-9-0</guid><category>Integrations</category><category>Python SDK</category><pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate></item><item><title>DomainTools Feeds Integration for Elastic v1.6.0: header-based authentication</title><link>https://docs.domaintools.com/changelog/2026/07/20/elastic-feeds-v1-6-0-header-auth/</link><description>Version 1.6.0 of the DomainTools Feeds Integration for Elastic sends your API credentials in a request header instead of the URL query string.</description><content:encoded>&lt;h2&gt;Changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Header-based authentication&lt;/strong&gt;: The integration now sends your DomainTools API credentials in a request header rather than in the URL query string. Configure your API username and key in the integration settings as before; no change to the credentials themselves is required.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/elastic/threat-feeds/" rel="noopener noreferrer"&gt;Elastic: DomainTools Real-time Threat Feeds&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/authentication/" rel="noopener noreferrer"&gt;Authentication&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/07/20/elastic-feeds-v1-6-0-header-auth</guid><category>Integrations</category><category>Elastic</category><pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate></item><item><title>Filter Iris Detect domains by First Seen date</title><link>https://docs.domaintools.com/changelog/2026/07/20/iris-detect-first-seen-filter/</link><description>You can now filter a monitor's domain list by a First Seen date range across all domain-state tabs.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;First Seen date range filter&lt;/strong&gt; — Filter a monitor's domains to those first seen within a start and end date. The filter applies across all domain-state tabs (New, Watched, Changed, Inactive, Escalated, Ignored) and works with "All Monitors" selected. It always evaluates each domain's First Seen date, regardless of the tab's default Sort By column.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/iris/detect/working-with-domains/#filter-and-sort-domains" rel="noopener noreferrer"&gt;Filter and sort domains&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/07/20/iris-detect-first-seen-filter</guid><category>Iris</category><category>Iris Detect</category><pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate></item><item><title>DomainTools App for Splunk v5.6.1 through v5.6.3</title><link>https://docs.domaintools.com/changelog/2026/07/01/splunk-app-v5-6-1-through-v5-6-3/</link><description>Three point releases of the DomainTools App for Splunk add Splunk Cloud 10.x support (including Cloud 10.2 with Enterprise Security), offline public suffix-list handling, the Iris Investigate (API only) SKU, and a fix for Iris Detect result imports on large ignore lists.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Splunk Cloud 10.x support, including Cloud 10.2 with Enterprise Security (v5.6.1)&lt;/strong&gt;: The app runs on Python 3.13 and is supported on Splunk Cloud Platform 10.x, including Cloud 10.2 running Enterprise Security (ES).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Offline public suffix list (v5.6.2)&lt;/strong&gt;: The app ships with a bundled public suffix list and no longer downloads an updated list at runtime. Environments that restrict outbound connections no longer break on domain extraction. You can update the bundled list manually if needed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Iris Investigate (API only) SKU support (v5.6.2)&lt;/strong&gt;: The Test Connection and &lt;a href="https://docs.domaintools.com/iris/investigate/" rel="noopener noreferrer"&gt;Iris Investigate&lt;/a&gt; dashboards now recognize the Iris Investigate (API only) SKU, so accounts on that entitlement no longer see incorrect "no access" messages for Domain Profile and pivoting features.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Iris Detect imports on large ignore lists (v5.6.3)&lt;/strong&gt;: Scheduled &lt;a href="https://docs.domaintools.com/iris/detect/" rel="noopener noreferrer"&gt;Iris Detect&lt;/a&gt; result imports no longer hang or exceed the hourly rate limit for accounts with large numbers of ignored domains. The import now fetches only recently changed ignored domains rather than the full history.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/splunk/" rel="noopener noreferrer"&gt;DomainTools App for Splunk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/" rel="noopener noreferrer"&gt;Splunk Enterprise, Cloud, and Enterprise Security guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/#release-notes" rel="noopener noreferrer"&gt;Release notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/splunk/enterprise/installation/" rel="noopener noreferrer"&gt;Installation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/07/01/splunk-app-v5-6-1-through-v5-6-3</guid><category>Integrations</category><category>Splunk</category><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate></item><item><title>MCP Server distinguishes WHOIS and RDAP registration data</title><link>https://docs.domaintools.com/changelog/2026/06/23/mcp-server-whois-rdap-provenance/</link><description>The DomainTools MCP Server now describes registration data as coming from WHOIS or RDAP and how the source is selected, so agents attribute it to the right protocol.</description><content:encoded>&lt;h2&gt;Changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Registration data attributed to WHOIS or RDAP&lt;/strong&gt;: The &lt;a href="https://docs.domaintools.com/mcp/" rel="noopener noreferrer"&gt;MCP Server&lt;/a&gt; explicitly describes registration fields (registrar, registrant, contacts, and registration dates) as &lt;em&gt;registration data&lt;/em&gt; drawn from a single source, WHOIS or RDAP, selected per domain by recency and completeness. Agents will be better able to attribute each field to the protocol that produced it, and to explain which source was used and why.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/tools/" rel="noopener noreferrer"&gt;MCP Server tools reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/iris/investigate/search/rdap-whois/" rel="noopener noreferrer"&gt;WHOIS and RDAP search in the Iris Investigate API&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/" rel="noopener noreferrer"&gt;MCP Server overview&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/06/23/mcp-server-whois-rdap-provenance</guid><category>AI</category><category>MCP Server</category><pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate></item><item><title>DomainTools Python SDK: v2.3—v2.8</title><link>https://docs.domaintools.com/changelog/2026/06/16/python-sdk-v2-3-v2-8/</link><description>Python SDK releases since v2.2: IrisQL and Domain History in iris_investigate, real-time Threat Feed support, and header authentication for Iris endpoints.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;IrisQL in &lt;code&gt;iris_investigate&lt;/code&gt;&lt;/strong&gt; (v2.8.0): Pass &lt;a href="https://docs.domaintools.com/iris/investigate/irisql/" rel="noopener noreferrer"&gt;IrisQL&lt;/a&gt; queries through the SDK's &lt;code&gt;iris_investigate&lt;/code&gt; interface to build structured domain searches with logical operators and field-level filters, instead of assembling parameter dictionaries by hand.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Domain History method&lt;/strong&gt; (v2.8.0): A new &lt;code&gt;domain_history&lt;/code&gt; method retrieves timestamped registration records through the &lt;a href="https://docs.domaintools.com/api/lookups/domain-history/" rel="noopener noreferrer"&gt;Domain History API&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Real-Time Threat Feeds&lt;/strong&gt; (v2.5.0, v2.6.0): Support for the &lt;a href="https://docs.domaintools.com/api/threat-feeds/domain-risk/" rel="noopener noreferrer"&gt;Domain Risk&lt;/a&gt; and &lt;a href="https://docs.domaintools.com/api/threat-feeds/domain-hotlist/" rel="noopener noreferrer"&gt;Domain Hotlist&lt;/a&gt; feeds, and streaming requests for &lt;a href="https://docs.domaintools.com/api/threat-feeds/" rel="noopener noreferrer"&gt;Real-Time Threat Feed&lt;/a&gt; endpoints so you can consume large feeds incrementally.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Newly Observed Hostnames feed&lt;/strong&gt; (v2.4.0): The &lt;a href="https://docs.domaintools.com/api/threat-feeds/newly-observed-hostnames/" rel="noopener noreferrer"&gt;Newly Observed Hostnames feed&lt;/a&gt; is now callable through the SDK.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Header authentication for Iris endpoints&lt;/strong&gt; (v2.5.3): Iris API calls can authenticate with the &lt;code&gt;X-Api-Key&lt;/code&gt; header instead of query-string credentials.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Iris Investigate API parity&lt;/strong&gt; (v2.7.0): Parameter and response handling brought in line with the current Iris Investigate API, with improved validation and error handling.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;code&gt;risk_score&lt;/code&gt; filter dropped in &lt;code&gt;iris_investigate&lt;/code&gt;&lt;/strong&gt; (v2.7.3): The &lt;code&gt;risk_score&lt;/code&gt; parameter wasn't forwarded, so filtered queries returned the full result set; it is now passed through.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;code&gt;ValidationError&lt;/code&gt; on &lt;code&gt;None&lt;/code&gt;-value arguments&lt;/strong&gt; (v2.7.4): Passing &lt;code&gt;None&lt;/code&gt; for an optional &lt;code&gt;iris_investigate&lt;/code&gt; argument (common when forwarding &lt;code&gt;**kwargs&lt;/code&gt;) raised an error instead of being ignored; &lt;code&gt;None&lt;/code&gt; values are now ignored.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;XML response handling&lt;/strong&gt; (v2.8.0): Responses requested in &lt;code&gt;xml&lt;/code&gt; format are now parsed correctly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/python-sdk/" rel="noopener noreferrer"&gt;DomainTools Python SDK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/iris/investigate/irisql/" rel="noopener noreferrer"&gt;IrisQL query language&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/" rel="noopener noreferrer"&gt;Real-Time Threat Feeds API&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DomainTools/python_api/releases" rel="noopener noreferrer"&gt;Release history on GitHub&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/06/16/python-sdk-v2-3-v2-8</guid><category>Integrations</category><category>Python SDK</category><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate></item><item><title>Manage group API accounts from the Group Admin page</title><link>https://docs.domaintools.com/changelog/2026/06/11/group-api-management/</link><description>Group administrators can now view usage, rotate keys, deactivate accounts, and export a usage report for every API account in their company group — without contacting DomainTools support.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Account list and usage&lt;/strong&gt;: View every API account in the group, with per-product usage, capacity, and quota reset dates on one page.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Key reset&lt;/strong&gt;: Rotate any account's API key from its detail view. The old key stops working immediately and the owner isn't emailed — update integrations before you reset.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Deactivation&lt;/strong&gt;: Deactivate an API account so its key stops working and it drops off the list.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CSV export&lt;/strong&gt;: Download the group's API usage as a comma-separated values (CSV) file; the export reflects the current filter and sort.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/user-management/api-accounts/" rel="noopener noreferrer"&gt;Manage group API accounts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/user-management/groups/" rel="noopener noreferrer"&gt;Group management&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/iris/account-info/" rel="noopener noreferrer"&gt;Account Information API&lt;/a&gt; to check a single account programmatically&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/authentication/credential-storage/" rel="noopener noreferrer"&gt;Storing credentials&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/06/11/group-api-management</guid><category>Account Management</category><category>API Management</category><pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate></item><item><title>Real-time IP Risk and IP Hotlist feeds now available</title><link>https://docs.domaintools.com/changelog/2026/05/19/real-time-ip-risk-hotlist-feeds/</link><description>The DomainTools Real-time Threat Feeds suite now includes two new IP Threat Feeds: the Real-time IP Risk Feed and the Real-time IP Hotlist Feed.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/ip-risk/" rel="noopener noreferrer"&gt;Real-time IP Risk Feed&lt;/a&gt;&lt;/strong&gt; — Continuously updated feed of high-risk IP addresses hosting domains, scored across threat type, geolocation, and ASN. Designed for integration into TIPs, SIEMs, and data lakes to enrich blocking and detection workflows with current IP risk context.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/ip-hotlist/" rel="noopener noreferrer"&gt;Real-time IP Hotlist Feed&lt;/a&gt;&lt;/strong&gt; — A curated subset of the IP Risk Feed containing only the highest-risk IPs: those where more than 50% of hosted domains are high-risk and show passive DNS activity. Suitable for high-confidence blocking and alerting use cases.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Both feeds are available alongside the existing domain-based Real-time Threat Feeds (Domain Risk, Domain Hotlist, Newly Observed Domains, Newly Observed Hostnames, Newly Active Domains, and Domain Discovery).&lt;/p&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/ip-risk/" rel="noopener noreferrer"&gt;Real-time IP Risk Feed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/ip-hotlist/" rel="noopener noreferrer"&gt;Real-time IP Hotlist Feed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/" rel="noopener noreferrer"&gt;Threat Feeds overview&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/05/19/real-time-ip-risk-hotlist-feeds</guid><category>Threat Feeds</category><category>IP Risk</category><category>IP Hotlist</category><pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate></item><item><title>MCP Server — DNSDB Passive DNS, Domain History, and OAuth support</title><link>https://docs.domaintools.com/changelog/2026/05/18/mcp-server-dnsdb-history-oauth/</link><description>Three new capabilities are available in the DomainTools MCP Server: passive DNS lookups via DNSDB, domain registration history tools, and OAuth authentication support.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;DNSDB passive DNS tools&lt;/strong&gt; — New tools expose passive DNS data from DNSDB directly through the MCP Server. Agents can run forward and inverse passive DNS lookups, time-fenced queries, and pattern-based searches to trace historical DNS resolution, identify infrastructure pivots, and surface related domains observed across the global DNS infrastructure.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Domain registration history tools&lt;/strong&gt; — New tools surface domain registration history via the Domain History API. Agents can retrieve timestamped WHOIS and registration records — including registrar changes, contact updates, and infrastructure transitions — as part of investigation workflows.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;OAuth 2.0 authentication&lt;/strong&gt; — The MCP Server now supports OAuth with pre-registered client credentials, so MCP clients sign in with a DomainTools account instead of an API key. OAuth pre-registration is available for the following clients:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Claude Code&lt;/strong&gt; — fixed callback port&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Claude Desktop&lt;/strong&gt; — Custom Connector with Advanced settings&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cursor&lt;/strong&gt; — &lt;code&gt;.cursor/mcp.json&lt;/code&gt; auth block&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Gemini CLI&lt;/strong&gt; — &lt;code&gt;~/.gemini/settings.json&lt;/code&gt; with static redirect URI&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;VS Code&lt;/strong&gt; — Command Palette &lt;strong&gt;MCP Add&lt;/strong&gt;, GitHub Copilot agent mode&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To request OAuth credentials, contact your DomainTools representative or email &lt;a href="mailto:enterprisesupport@domaintools.com" rel="noopener noreferrer"&gt;enterprisesupport@domaintools.com&lt;/a&gt; with your chosen client(s), redirect URIs, and an optional proposed client name. DomainTools returns a confirmed client name, client ID, and client secret.&lt;/p&gt;
&lt;p&gt;:::note[Client name match]&lt;/p&gt;
&lt;p&gt;Except for VS Code, the name you use in your MCP client configuration must exactly match the client name registered with DomainTools. The server rejects connections where the name doesn't match.&lt;br&gt;
:::&lt;br&gt;
Clients that don't support OAuth pre-registration — such as Codex and Goose Desktop — continue to use &lt;a href="https://docs.domaintools.com/mcp/api-key-auth/" rel="noopener noreferrer"&gt;API key authentication&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/oauth/" rel="noopener noreferrer"&gt;OAuth authentication&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/api-key-auth/" rel="noopener noreferrer"&gt;API key authentication&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/get-started/" rel="noopener noreferrer"&gt;Get started with the MCP Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/faq/" rel="noopener noreferrer"&gt;MCP Server FAQ&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/" rel="noopener noreferrer"&gt;MCP Server overview&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/05/18/mcp-server-dnsdb-history-oauth</guid><category>AI</category><category>MCP Server</category><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate></item><item><title>FeedDomainTools Pack v1.0.7 for Cortex XSOAR: Risk score detail in feed indicators</title><link>https://docs.domaintools.com/changelog/2026/05/10/cortex-xsoar-feeddomaintools-v1-0-7/</link><description>FeedDomainTools Pack v1.0.7 is now available on the Cortex XSOAR Marketplace. This release enriches the &lt;code&gt;rawJSON&lt;/code&gt; payload for &lt;code&gt;domainrisk&lt;/code&gt; and &lt;code&gt;domainhotlist&lt;/code&gt; feed indicators with full risk score details, giving analysts richer context directly in the XSOAR war room and indicator table without additional lookups.</description><content:encoded>&lt;h2&gt;Changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Risk score details in &lt;code&gt;rawJSON&lt;/code&gt; for feed indicators&lt;/strong&gt; — The &lt;code&gt;rawJSON&lt;/code&gt; payload for &lt;a href="https://docs.domaintools.com/api/threat-feeds/domain-risk/" rel="noopener noreferrer"&gt;&lt;code&gt;domainrisk&lt;/code&gt;&lt;/a&gt; and &lt;a href="https://docs.domaintools.com/api/threat-feeds/domain-hotlist/" rel="noopener noreferrer"&gt;&lt;code&gt;domainhotlist&lt;/code&gt;&lt;/a&gt; feed indicators now includes the full &lt;a href="https://docs.domaintools.com/riskscore/" rel="noopener noreferrer"&gt;risk score&lt;/a&gt; breakdown:&lt;ul&gt;
&lt;li&gt;Overall score&lt;/li&gt;
&lt;li&gt;Component scores (proximity, phishing, malware, spam)&lt;/li&gt;
&lt;li&gt;Threat type classifications&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Analysts can see the complete risk context directly in the XSOAR indicator table and war room without an additional lookup.&lt;/p&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/paloalto/xsoar-userguide/" rel="noopener noreferrer"&gt;Palo Alto XSOAR: DomainTools app&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/riskscore/" rel="noopener noreferrer"&gt;Domain Risk Score user guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/domain-risk/" rel="noopener noreferrer"&gt;Domain Risk feed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/threat-feeds/domain-hotlist/" rel="noopener noreferrer"&gt;Domain Hotlist feed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cortex.marketplace.pan.dev/marketplace/details/FeedDomainTools/" rel="noopener noreferrer"&gt;FeedDomainTools on Cortex Marketplace&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/paloalto/" rel="noopener noreferrer"&gt;Palo Alto Networks integrations&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/05/10/cortex-xsoar-feeddomaintools-v1-0-7</guid><category>Integrations</category><category>Cortex XSOAR</category><category>Threat Feeds</category><pubDate>Sun, 10 May 2026 00:00:00 +0000</pubDate></item><item><title>IrisQL tool in the MCP Server</title><link>https://docs.domaintools.com/changelog/2026/05/06/mcp-irisql-tool/</link><description>The MCP Server now exposes an &lt;code&gt;irisql&lt;/code&gt; tool for running IrisQL searches — text-based Iris Investigate queries with OR logic, nested conditions, field presence checks, and relative date ranges.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;p&gt;The new &lt;code&gt;irisql&lt;/code&gt; MCP tool lets AI clients run Iris Investigate searches written in &lt;a href="https://docs.domaintools.com/iris/investigate/irisql/" rel="noopener noreferrer"&gt;IrisQL&lt;/a&gt;, extending the MCP Server's search capabilities alongside the existing structured pivot tools:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Expressive query syntax&lt;/strong&gt;: OR logic across field values, nested AND/OR combinations, field presence checks, and relative date ranges (for example, "created in the last 30 days"). All queries must begin with the version comment &lt;code&gt;# IrisQL-1.0&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Pagination&lt;/strong&gt;: &lt;code&gt;position&lt;/code&gt; cursor, matching the &lt;code&gt;lookup_bulk&lt;/code&gt; response shape&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Built-in syntax guidance&lt;/strong&gt;: The server exposes the IrisQL reference as an MCP resource at &lt;code&gt;docs://irisql-reference&lt;/code&gt;, which conversational clients load automatically before constructing queries&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/" rel="noopener noreferrer"&gt;MCP Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/tools/#irisql---advanced-query-language" rel="noopener noreferrer"&gt;&lt;code&gt;irisql&lt;/code&gt; tool reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/iris/investigate/irisql/" rel="noopener noreferrer"&gt;IrisQL syntax reference&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/05/06/mcp-irisql-tool</guid><category>AI</category><category>MCP Server</category><category>Iris</category><category>Iris Investigate</category><pubDate>Wed, 06 May 2026 00:00:00 +0000</pubDate></item><item><title>IrisQL available in the Iris Investigate API</title><link>https://docs.domaintools.com/changelog/2026/05/04/iris-investigate-irisql-ga/</link><description>&lt;a href="/iris/investigate/irisql/"&gt;IrisQL&lt;/a&gt; is now available in the Iris Investigate API, letting you build and submit domain searches programmatically.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;p&gt;You can now send IrisQL queries to the Iris Investigate API:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Logical operators&lt;/strong&gt;: Combine conditions with &lt;code&gt;AND&lt;/code&gt;, &lt;code&gt;OR&lt;/code&gt;, and &lt;code&gt;NOT&lt;/code&gt; to express complex search logic in a single query.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Field-level filters&lt;/strong&gt;: Target specific domain attributes — registration data, infrastructure, risk scores, and more — using named field syntax.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Shareable queries&lt;/strong&gt;: IrisQL is plain text. Queries pass directly in API calls, paste into tickets, and reproduce consistently across tools and sessions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;UI and MCP parity&lt;/strong&gt;: The same queries that run in Advanced Search and the &lt;code&gt;irisql&lt;/code&gt; MCP tool work unmodified against the API endpoint.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All IrisQL queries must begin with the version comment &lt;code&gt;# IrisQL-1.0&lt;/code&gt;.&lt;/p&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/iris/investigate/irisql/" rel="noopener noreferrer"&gt;IrisQL: Iris Query Language&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/iris/investigate/search/" rel="noopener noreferrer"&gt;Iris Investigate search parameters&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/05/04/iris-investigate-irisql-ga</guid><category>Iris</category><category>Iris Investigate</category><category>Iris API</category><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate></item><item><title>DomainTools integration for Google SecOps SOAR v11.0</title><link>https://docs.domaintools.com/changelog/2026/04/23/google-secops-soar-ga/</link><description>Version 11.0 of the &lt;a href="/integrations/google-secops/soar/"&gt;DomainTools integration for Google SecOps SOAR&lt;/a&gt; is now generally available. Version 11.0 adds four playbook actions to the Google SecOps SOAR marketplace, so you can pull domain intelligence straight into your SOAR workflows.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Iris Investigate Enrichment&lt;/strong&gt;: Run a domain through &lt;a href="https://docs.domaintools.com/iris/investigate/" rel="noopener noreferrer"&gt;DomainTools Iris Investigate&lt;/a&gt; from a playbook; returns a comprehensive domain profile including connected infrastructure, related domains, and risk indicators.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Whois History&lt;/strong&gt;: Surface &lt;a href="https://docs.domaintools.com/iris/investigate/data-panels/whois-history/" rel="noopener noreferrer"&gt;historical WHOIS records&lt;/a&gt; to track ownership and registration changes over time.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Parsed RDAP Lookups&lt;/strong&gt;: Pull structured &lt;a href="https://docs.domaintools.com/api/lookups/parsed-rdap/" rel="noopener noreferrer"&gt;RDAP registration data&lt;/a&gt; for any domain.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Connectivity Validation&lt;/strong&gt;: Health check that validates &lt;a href="https://docs.domaintools.com/authentication/" rel="noopener noreferrer"&gt;DomainTools API credentials&lt;/a&gt; and confirms the integration is configured correctly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/google-secops/soar/" rel="noopener noreferrer"&gt;Google SecOps SOAR integration overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/domaintools" rel="noopener noreferrer"&gt;DomainTools — Google SecOps SOAR Marketplace&lt;/a&gt; — Google's setup and configuration documentation&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/04/23/google-secops-soar-ga</guid><category>Integrations</category><category>Google SecOps</category><pubDate>Thu, 23 Apr 2026 00:00:00 +0000</pubDate></item><item><title>Cortex XSOAR — command, pivot link, and verdict scoring fixes</title><link>https://docs.domaintools.com/changelog/2026/04/09/cortex-xsoar-bug-fixes/</link><description>Four bugs in the DomainTools Iris integration for Cortex XSOAR are resolved, covering command parameter handling, war room pivot links, dbot verdict speed, and the &lt;code&gt;domaintools-whois&lt;/code&gt; command.</description><content:encoded>&lt;h2&gt;Fixed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;code&gt;bypass_auto_enrich&lt;/code&gt; not honored on &lt;code&gt;domaintoolsiris-investigate&lt;/code&gt;&lt;/strong&gt; — When auto-enrichment was disabled at the instance level, passing &lt;code&gt;bypass_auto_enrich="true"&lt;/code&gt; to the &lt;code&gt;domaintoolsiris-investigate&lt;/code&gt; command was ignored. The parameter now overrides the instance default.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;War room pivot links failing&lt;/strong&gt; — IP, SSL email, and website title pivot links generated in the Cortex XSOAR war room produced malformed URLs from incorrect character escaping. Links now resolve correctly in Iris Investigate.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Slow dbot verdict scoring&lt;/strong&gt; — The &lt;code&gt;domain&lt;/code&gt; command saved the full Iris Investigate payload to XSOAR context, delaying the dbot verdict (benign, suspicious, or malicious) on indicators. Context writes are now optimized to reduce the delay.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;code&gt;domaintools-whois&lt;/code&gt; command error&lt;/strong&gt; — Running &lt;code&gt;!domaintools-whois query=&amp;lt;IP&amp;gt; debug-mode=true&lt;/code&gt; threw an error. The command now runs correctly with debug mode enabled.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/paloalto/xsoar-userguide/" rel="noopener noreferrer"&gt;Palo Alto XSOAR: DomainTools app&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/paloalto/" rel="noopener noreferrer"&gt;Palo Alto Networks integrations&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/04/09/cortex-xsoar-bug-fixes</guid><category>Integrations</category><category>Cortex XSOAR</category><pubDate>Thu, 09 Apr 2026 00:00:00 +0000</pubDate></item><item><title>Anomali integration v1.1.0: RDAP enrichment and DNSDB passive DNS panel</title><link>https://docs.domaintools.com/changelog/2026/03/31/anomali-v1-1-0/</link><description>v1.1.0 adds two new enrichment capabilities to the DomainTools App for Anomali ThreatStream: parsed RDAP registration data in the Iris Investigate domain enrichment panel, and a new DNSDB passive DNS enrichment panel for domain observables.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Parsed RDAP data in Iris Investigate enrichment&lt;/strong&gt;: The Iris Investigate domain enrichment panel now includes structured RDAP registration data — registrar, registrant organization, contact email, creation and expiration dates, and abuse contact information — retrieved directly from the &lt;a href="https://docs.domaintools.com/api/lookups/parsed-rdap/" rel="noopener noreferrer"&gt;Parsed RDAP API&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;DNSDB passive DNS enrichment panel&lt;/strong&gt;: A new &lt;strong&gt;DNSDB&lt;/strong&gt; tab is available in the enrichment panel for domain observables. The panel displays historical and near-real-time passive DNS records from &lt;a href="https://docs.domaintools.com/dnsdb/" rel="noopener noreferrer"&gt;Farsight DNSDB&lt;/a&gt;, including DNS resolution history, infrastructure changes, and related domains observed across the global DNS infrastructure. Requires an active DNSDB subscription.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/anomali/iris-app/" rel="noopener noreferrer"&gt;Anomali integration — Iris App&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/lookups/parsed-rdap/" rel="noopener noreferrer"&gt;Parsed Domain RDAP API&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/dnsdb/" rel="noopener noreferrer"&gt;DNSDB&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/03/31/anomali-v1-1-0</guid><category>Integrations</category><category>Anomali</category><category>Iris</category><category>Iris Investigate</category><pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate></item><item><title>Connect your AI client to DomainTools threat intelligence with the MCP Server</title><link>https://docs.domaintools.com/changelog/2026/03/31/mcp-server/</link><description>Connect your AI client to DomainTools domain threat intelligence using the &lt;a href="https://modelcontextprotocol.io/"&gt;Model Context Protocol&lt;/a&gt; (MCP).</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;p&gt;The DomainTools MCP Server enables LLM applications to access domain threat intelligence through the &lt;a href="https://modelcontextprotocol.io/" rel="noopener noreferrer"&gt;Model Context Protocol&lt;/a&gt;. DomainTools hosts the server. Connect using your own MCP-compatible client such as &lt;a href="https://www.claude.com/product/claude-code" rel="noopener noreferrer"&gt;Claude Code CLI&lt;/a&gt;, &lt;a href="https://code.visualstudio.com/docs/copilot/chat/mcp-servers" rel="noopener noreferrer"&gt;VS Code with GitHub Copilot&lt;/a&gt;, &lt;a href="https://cline.bot/" rel="noopener noreferrer"&gt;Cline&lt;/a&gt;, or &lt;a href="https://github.com/google-gemini/gemini-cli" rel="noopener noreferrer"&gt;Gemini CLI&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The server provides 15 tools across three product areas:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://docs.domaintools.com/api/iris/" rel="noopener noreferrer"&gt;Iris Investigate&lt;/a&gt;&lt;/strong&gt;: Domain lookups, risk scoring, and pivot searches across shared infrastructure, registration, and web properties&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://docs.domaintools.com/api/dnsdb/" rel="noopener noreferrer"&gt;Farsight DNSDB&lt;/a&gt;&lt;/strong&gt;: Forward and inverse passive DNS lookups with pattern-based search&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://docs.domaintools.com/api/lookups/domain-history/" rel="noopener noreferrer"&gt;Domain History&lt;/a&gt;&lt;/strong&gt;: Timestamped registration, infrastructure, and website change records&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For an investigation walkthrough and SOC integration use cases, see the &lt;a href="https://www.domaintools.com/blog/integrating-domaintools-into-the-ai-powered-soc" rel="noopener noreferrer"&gt;announcement blog post&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/" rel="noopener noreferrer"&gt;MCP Server overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/get-started/" rel="noopener noreferrer"&gt;Get started&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/api-key-auth/" rel="noopener noreferrer"&gt;API key authentication&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/oauth/" rel="noopener noreferrer"&gt;OAuth authentication&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/tools/" rel="noopener noreferrer"&gt;Tools reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/mcp/faq/" rel="noopener noreferrer"&gt;FAQ&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/03/31/mcp-server</guid><category>AI</category><category>MCP Server</category><pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate></item><item><title>Cortex XSOAR Iris pack: new domain enrichment controls</title><link>https://docs.domaintools.com/changelog/2026/03/03/cortex-xsoar-enrichment-controls/</link><description>The DomainTools Iris pack for Cortex XSOAR adds controls for how the domain command returns results, which enrichment method it uses, and whether ingested domains are enriched automatically.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Domain Result Type (v2.2.6)&lt;/strong&gt;: The &lt;code&gt;domain&lt;/code&gt; command takes a result-type setting that controls what it returns. &lt;code&gt;iris&lt;/code&gt; returns full Iris Investigate results; &lt;code&gt;verdict&lt;/code&gt; returns only the domain risk score, for faster indicator triage.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Domain Enrichment Method (v2.2.7)&lt;/strong&gt;: Choose which DomainTools method enriches domains. Defaults to Iris Investigate.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Domain Auto-Enrich on Ingestion (v2.2.7)&lt;/strong&gt;: Enable automatic enrichment of domains as they are ingested, so incoming indicators arrive already enriched. Automatic enrichment consumes Iris API queries; leave it off if you want to control query volume manually.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/paloalto/xsoar-userguide/" rel="noopener noreferrer"&gt;Palo Alto XSOAR: DomainTools app&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/integrations/paloalto/" rel="noopener noreferrer"&gt;Palo Alto Networks integrations&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/03/03/cortex-xsoar-enrichment-controls</guid><category>Integrations</category><category>Cortex XSOAR</category><pubDate>Tue, 03 Mar 2026 00:00:00 +0000</pubDate></item><item><title>Create, update, and delete monitors via the Iris Detect API</title><link>https://docs.domaintools.com/changelog/2026/03/03/iris-detect-monitors-crud/</link><description>You can now create, update, and delete Iris Detect monitors through the API, making it possible to manage your watchlists programmatically.</description><content:encoded>&lt;h2&gt;Added&lt;/h2&gt;
&lt;p&gt;Three new operations are available on the &lt;code&gt;/v1/iris-detect/monitors/&lt;/code&gt; endpoint:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Create&lt;/strong&gt;: Add a new monitor with a term and optional exclusions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Update&lt;/strong&gt;: Modify exclusions on an existing monitor.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Delete&lt;/strong&gt;: Permanently remove a monitor.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All three operations require the &lt;a href="https://docs.domaintools.com/api/iris/detect/guide/#authorization-and-permissions" rel="noopener noreferrer"&gt;manage monitors permission&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Documentation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/iris/detect/guide/" rel="noopener noreferrer"&gt;Iris Detect API guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/iris/detect/guide/#create-monitor" rel="noopener noreferrer"&gt;Create monitor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/iris/detect/guide/#update-monitor" rel="noopener noreferrer"&gt;Update monitor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/api/iris/detect/guide/#delete-monitor" rel="noopener noreferrer"&gt;Delete monitor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.domaintools.com/iris/detect/monitors/" rel="noopener noreferrer"&gt;Monitors in Iris Detect&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><guid isPermaLink="false">https://docs.domaintools.com/changelog/2026/03/03/iris-detect-monitors-crud</guid><category>Iris</category><category>Iris Detect</category><category>Iris API</category><pubDate>Tue, 03 Mar 2026 00:00:00 +0000</pubDate></item></channel></rss>