Skip to main content
For SOC Analysts & Threat Intel Teams

Domain Intelligence API for Security Teams

Query DNS, WHOIS & risk scores via REST API for 276M+ domains. For SOC & threat-intel teams. Enrich SIEM alerts and monitor new registrations. Free tier.

Query our complete domain dataset via a fast, consistent REST API. Filter by TLD, registration date, DNS records, name servers, and more. Designed for threat intelligence platforms, SIEM integrations, and automated detection pipelines.

Your SIEM fires an alert with a suspicious domain. Is it two hours old? Does it resolve to a bulletproof host? Is it typosquatting your brand? Analysts waste 10+ minutes pivoting across WHOIS, DNS, and passive feeds for a single indicator. The Primitive Host Domain Intelligence API answers in one call. Built for SOC and threat-intel teams, it exposes 276M+ domains refreshed daily from zone files, enriched with DNS, WHOIS, and risk signals. Filter by TLD, registration window, name server, or substring — full-text search included. One consistent JSON schema, paginated results, and bulk export mean you stop stitching zone files and start enriching alerts, blocking threats, and hunting infrastructure at machine speed.

What you can do

Enrich SIEM & SOAR Alerts

Push domain age, DNS and risk signals into Splunk, Sentinel or Chronicle in milliseconds to auto-triage phishing and C2.

Monitor New Registrations

Detect brand lookalikes minutes after registration across 5,625+ TLDs — before the phishing email is sent.

Bulk Threat-Intel Enrichment

Score and cluster thousands of IOCs at once for investigations, blocklists, and threat-hunting notebooks.

Key features

  • Full-text search across domain names with substring and pattern filters
  • Filter by TLD, registration date, DNS records, name servers & hosting
  • Paginated JSON with bulk CSV/JSON/NDJSON export for pipelines
  • Consistent schema across every zone file — no per-TLD parsing
  • Millisecond response for SIEM/SOAR inline enrichment
Example: Find suspicious brand lookalikes primitive.host
GET /v1/domains?contains=paypa1&registered_since=2025-01-01&tlds=com,net,io Authorization: Bearer <token>
Response
{ "domains": [{"domain": "paypa1-secure.com", "tld": "com", "age_days": 2, "dns": {"a": ["198.51.100.42"]}}], "total": 3 }
REST API JSON Bulk Export

Frequently asked questions

What is a domain intelligence API?

A domain intelligence API lets you query structured data about registered domains — age, DNS records, name servers, WHOIS signals and risk scores — via REST. Primitive Host covers 276M+ domains refreshed daily, so your tools can enrich IOCs without scraping WHOIS or parsing zone files.

How is this different from WHOIS or passive DNS?

WHOIS is rate-limited and inconsistent per TLD; passive DNS only sees domains after they are queried. Our API is built from daily zone files and enriched proactively, so you can search for every domain matching a pattern the day it is registered, with a consistent schema.

Can I enrich SIEM alerts automatically?

Yes. The API is designed for inline enrichment — 50-150ms median response, Bearer token auth, and bulk endpoints. Teams push results into Splunk, Microsoft Sentinel, Chronicle and SOAR playbooks via a single HTTP call.

Is there a free tier?

Yes. Start with free filtered list previews and the free blacklist checker, then upgrade for full API access. See pricing for rate limits and bulk export inclusions.

Ready to try Domain Intelligence API for Security Teams?

Start free with previews and the blacklist checker — no sales call required.