Iris Investigate search reference
This page provides a complete reference of all searchable fields, their shortcodes, and accepted operators in Iris Investigate.
Available search parameters
Section titled “Available search parameters”The following table lists all available search parameters organized by category. Each parameter supports specific match operators that determine how your search query compares against stored data.
Domain information
Section titled “Domain information”| Parameter | Shortcode | Accepted Operators |
|---|---|---|
| Domain Name | domain | Begins With, Contains, Does Not Contain, Does Not Exactly Match, Does Not Match, Ends With, Exactly In, Exactly Matches, In, Matches, Not Exactly In, Not In |
| Create Date | cre | Does Not Match, Greater Than, Greater Than or Equal To, Less Than, Less Than or Equal To, Matches, Within |
| Expiration Date | exp | Greater Than, Greater Than or Equal To, Less Than, Less Than or Equal To, Matches, Within |
| First Seen | current_lifecycle_first_seen | Greater Than, Greater Than or Equal To, Less Than, Less Than or Equal To, Matches, Within |
| Rank | popularity_rank | Does Not Match, Greater Than, Greater Than or Equal To, Less Than, Less Than or Equal To, Matches |
| Risk Score | cr | Does Not Match, Greater Than, Greater Than or Equal To, Less Than, Less Than or Equal To, Matches |
| Status | active | Matches |
| Tags | tags | Contains, Contains All, Does Not Contain, Does Not Contain All |
| TLD (Top-Level Domain) | tld | Begins With, Does Not Match, Exists, In, Matches, Not In |
| Website Title | title | Begins With, Contains, Contains All, Does Not Contain, Does Not Contain All, Does Not Exactly Match, Does Not Match, Exactly Matches, Exists, Matches |
| Server Type | server_type | Begins With, Contains, Contains All, Does Not Contain, Does Not Contain All, Does Not Exactly Match, Does Not Match, Exactly Matches, Exists, Matches |
| Redirect Domain | rdd | Begins With, Does Not Match, Exists, Matches |
| WHOIS Record | whois | Contains, Contains All |
Contact information
Section titled “Contact information”| Parameter | Shortcode | Accepted Operators |
|---|---|---|
| Contact Country Code | cons.cc | Begins With, Does Not Match, Exists, Matches |
| Contact Name | cons.nm | Begins With, Contains, Contains All, Does Not Contain, Does Not Contain All, Does Not Exactly Match, Exactly Matches, Exists |
| Contact Phone | cons.ph | Begins With, Does Not Match, Exists, Matches |
| Contact Street | cons.str | Begins With, Contains, Contains All, Does Not Contain, Does Not Contain All, Does Not Exactly Match, Exactly Matches, Exists |
| Registrant | r_n | Begins With, Contains, Contains All, Does Not Contain, Does Not Contain All, Does Not Exactly Match, Does Not Match, Exactly Matches, Exists, Matches |
| Registrant Organisation | r_o | Begins With, Contains, Contains All, Does Not Contain, Does Not Contain All, Does Not Exactly Match, Does Not Match, Exactly Matches, Exists, Matches |
| Registrar | reg | Begins With, Contains, Contains All, Does Not Contain, Does Not Contain All, Does Not Exactly Match, Does Not Match, Exactly Matches, Exists, Matches |
Email information
Section titled “Email information”| Parameter | Shortcode | Accepted Operators |
|---|---|---|
em | Begins With, Does Not Match, Exists, In, Matches, Not In | |
| Email - Administrator | empa | Begins With, Does Not Match, Exists, Matches |
| Email - Billing | empb | Begins With, Does Not Match, Exists, Matches |
| Email - DNS/SOA | ema | Begins With, Does Not Match, Exists, Matches |
| Email - Registrant | empr | Begins With, Does Not Match, Exists, Matches |
| Email - Technical | empt | Begins With, Does Not Match, Exists, Matches |
| Email - WHOIS | emw | Begins With, Does Not Match, Exists, Matches |
| Email Domain | emd | Begins With, Does Not Match, Exists, In, Matches, Not In |
IP information
Section titled “IP information”| Parameter | Shortcode | Accepted Operators |
|---|---|---|
| IP | ip.ip | Does Not Match, Greater Than, Greater Than or Equal To, In, Less Than, Less Than or Equal To, Matches, Not In |
| IP ASN | ip.asn | Does Not Match, Greater Than, Greater Than or Equal To, Less Than, Less Than or Equal To, Matches |
| IP Country Code | ip.cc | Begins With, Does Not Match, Exists, Matches |
| ISP (Internet Service Provider) IP Information | ip.isp | Contains, Contains All, Does Not Contain, Does Not Contain All, Does Not Exactly Match, Exactly Matches, Exists |
DNS information
Section titled “DNS information”| Parameter | Shortcode | Accepted Operators |
|---|---|---|
| Name Server | ns.ns | Does Not Match, Exists, Matches |
| Name Server Domain | ns.nsd | Begins With, Does Not Match, Exists, Matches |
| Name Server IP | ns.nip | Does Not Match, Greater Than, Greater Than or Equal To, In, Less Than, Less Than or Equal To, Matches, Not In |
| MX (Mail Exchange) Server | mx.mx | Begins With, Does Not Match, Exists, Matches |
| MX Server Domain | mx.mxd | Begins With, Does Not Match, Exists, Matches |
| MX Server IP | mx.mip | Does Not Match, Greater Than, Greater Than or Equal To, In, Less Than, Less Than or Equal To, Matches, Not In |
SSL certificate information
Section titled “SSL certificate information”| Parameter | Shortcode | Accepted Operators |
|---|---|---|
| SSL Alt Names | ssl.alt_names | Begins With, Contains, Does Not Contain, Does Not Match, Exists, Matches |
| SSL Duration (days) | ssl.duration | Does Not Match, Greater Than, Greater Than or Equal To, Less Than, Less Than or Equal To, Matches |
| SSL Email | ssl.em | Begins With, Does Not Match, Exists, Matches |
| SSL Hash | ssl.sh | Begins With, Does Not Match, Exists, Matches |
| SSL Issuer Common Name | ssl.issuer_common_name | Begins With, Contains, Does Not Contain, Does Not Match, Ends With, Matches |
| SSL Not After Date | ssl.not_after | Does Not Match, Greater Than, Greater Than or Equal To, Less Than, Less Than or Equal To, Matches, Within |
| SSL Not Before Date | ssl.not_before | Does Not Match, Greater Than, Greater Than or Equal To, Less Than, Less Than or Equal To, Matches, Within |
| SSL Subject | ssl.s | Begins With, Does Not Match, Exists, Matches |
| SSL Subject Common Name | ssl.common_name | Begins With, Contains, Does Not Contain, Does Not Match, Ends With, Matches |
| SSL Subject Org Name | ssl.so | Begins With, Contains, Contains All, Does Not Contain, Does Not Contain All, Does Not Exactly Match, Does Not Match, Exactly Matches, Exists, Matches |
Web analytics and trackers
Section titled “Web analytics and trackers”| Parameter | Shortcode | Accepted Operators |
|---|---|---|
| Adsense | ad | Does Not Match, Exists, Matches |
| Baidu Analytics | — | Does Not Match, Exists, Does Not Exist, Matches |
| Facebook (Meta Pixel) | — | Does Not Match, Exists, Does Not Exist, Matches |
| Google Analytics | ga | Does Not Match, Exists, Does Not Exist, Matches |
| Google Analytics 4 | — | Does Not Match, Exists, Does Not Exist, Matches |
| Google Tag Manager | — | Does Not Match, Exists, Does Not Exist, Matches |
| Hotjar | — | Does Not Match, Exists, Does Not Exist, Matches |
| Matomo | — | Does Not Match, Exists, Does Not Exist, Matches |
| Statcounter - Project Codes | — | Does Not Match, Exists, Does Not Exist, Matches |
| Statcounter - Security Codes | — | Does Not Match, Exists, Does Not Exist, Matches |
| Yandex Metrica | — | Does Not Match, Exists, Does Not Exist, Matches |
Historical search support
Section titled “Historical search support”Three parameters support historical search, allowing you to find domains that matched your query at any point in their history:
- Email (
em): Search historical email addresses associated with domains. - Registrant (
r_n): Search historical registrant information. - WHOIS Record (
whois): Search the full text of historical WHOIS records.
For more information, see Historical Search.
See also
Section titled “See also”- Basic Search: Simple search techniques.
- Advanced Search: Using filters and operators.
- Match Operations: Understanding how operators work.