Query our complete domain dataset via a fast, consistent REST API. Filter by TLD, registration date, DNS records, name servers, and more. Designed for threat intelligence platforms, SIEM integrations, and automated detection pipelines.
Your SIEM fires an alert with a suspicious domain. Is it two hours old? Does it resolve to a bulletproof host? Is it typosquatting your brand? Analysts waste 10+ minutes pivoting across WHOIS, DNS, and passive feeds for a single indicator. The Primitive Host Domain Intelligence API answers in one call. Built for SOC and threat-intel teams, it exposes 276M+ domains refreshed daily from zone files, enriched with DNS, WHOIS, and risk signals. Filter by TLD, registration window, name server, or substring — full-text search included. One consistent JSON schema, paginated results, and bulk export mean you stop stitching zone files and start enriching alerts, blocking threats, and hunting infrastructure at machine speed.
What you can do
Enrich SIEM & SOAR Alerts
Push domain age, DNS and risk signals into Splunk, Sentinel or Chronicle in milliseconds to auto-triage phishing and C2.
Monitor New Registrations
Detect brand lookalikes minutes after registration across 5,625+ TLDs — before the phishing email is sent.
Bulk Threat-Intel Enrichment
Score and cluster thousands of IOCs at once for investigations, blocklists, and threat-hunting notebooks.
Key features
- Full-text search across domain names with substring and pattern filters
- Filter by TLD, registration date, DNS records, name servers & hosting
- Paginated JSON with bulk CSV/JSON/NDJSON export for pipelines
- Consistent schema across every zone file — no per-TLD parsing
- Millisecond response for SIEM/SOAR inline enrichment
GET /v1/domains?contains=paypa1®istered_since=2025-01-01&tlds=com,net,io
Authorization: Bearer <token>
{
"domains": [{"domain": "paypa1-secure.com", "tld": "com", "age_days": 2, "dns": {"a": ["198.51.100.42"]}}],
"total": 3
}