Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
Look into all current and historical DNS / IP connections between domains and A, MX, NS, and other records. Monitor suspicious changes to DNS records.
Get detailed context on an IP address, including its user’s geolocation, time zone, connected domains, connection type, IP range, ASN, and other network ownership details.
Access our web-based solution to dig into and monitor all domain events of interest.
Get access to a web-based enterprise-grade solution to search and monitor domain registrations and ownership details for branded terms, fuzzy matches, registrants of interest, and more.
Independent, evidence-based DNS and abuse intelligence for applicants, advisors, governments, and counsel participating in the ICANN 2026 New gTLD Program.
Predictive threat intelligence is your best first line of defense. Subscribe to the feeds to strengthen your cybersecurity posture. Contact us today for more information.
Unlock integrated intelligence on Internet properties and their ownership, infrastructure, and other attributes.
Our complete set of domain, IP, and DNS intelligence available via API calls as an annual subscription with predictable pricing.
Offers complete access to WHOIS, IP, DNS, and subdomain data for product enrichment, threat hunting and more.
Uncover entire attack surfaces with this API to embed asset discovery, vulnerability scanning, and technology metadata into your platform. Now in early access.
Talk to our APIs using LLMs. Connect your preferred LLM to WhoisXML API and simply chat about WHOIS, DNS, threat intelligence, and more.
I’m your Domain Intelligence Assistant. I make it easy to explore WHOIS, DNS, and threat data from WhoisXML API — I’m cloud-based, fast, and always ready to help.
A custom GPT for WHOIS, DNS, IP, and threat intelligence research. Connects ChatGPT directly to WhoisXML API to enable fast, conversational investigations and domain insights.
Discover what you really pay for when buying commercial Internet intelligence data.
Download now{ "DNSData": { "domainName": "google.com", "types": [ 1, 6, 16 ], "dnsTypes": "A,SOA,TXT", "audit": { "createdDate": "2019-05-07 14:45:22.916 UTC", "updatedDate": "2019-05-07 14:45:22.916 UTC" }, "dnsRecords": [ { "type": 16, "dnsType": "TXT", "name": "google.com.", "ttl": 299, "rRsetType": 16, "rawText": "google.com.\t\t299\tIN\tTXT\t\"globalsign-smime-dv=CDYX+XFHUw2wml6/Gb8+59BsH31KzUr6c1l2BPvqKX8=\"", "strings": [ "globalsign-smime-dv=CDYX+XFHUw2wml6/Gb8+59BsH31KzUr6c1l2BPvqKX8=" ] }, { "type": 16, "dnsType": "TXT", "name": "google.com.", "ttl": 299, "rRsetType": 16, "rawText": "google.com.\t\t299\tIN\tTXT\t\"v=spf1 include:_spf.google.com ~all\"", "strings": [ "v=spf1 include:_spf.google.com ~all" ] }, { "type": 16, "dnsType": "TXT", "name": "google.com.", "ttl": 299, "rRsetType": 16, "rawText": "google.com.\t\t299\tIN\tTXT\t\"docusign=05958488-4752-4ef2-95eb-aa7ba8a3bd0e\"", "strings": [ "docusign=05958488-4752-4ef2-95eb-aa7ba8a3bd0e" ] }, { "type": 16, "dnsType": "TXT", "name": "google.com.", "ttl": 299, "rRsetType": 16, "rawText": "google.com.\t\t299\tIN\tTXT\t\"facebook-domain-verification=22rm551cu4k0ab0bxsw536tlds4h95\"", "strings": [ "facebook-domain-verification=22rm551cu4k0ab0bxsw536tlds4h95" ] }, { "type": 1, "dnsType": "A", "name": "google.com.", "ttl": 299, "rRsetType": 1, "rawText": "google.com.\t\t299\tIN\tA\t172.217.5.206", "address": "172.217.5.206" }, { "type": 6, "dnsType": "SOA", "name": "google.com.", "ttl": 59, "rRsetType": 6, "rawText": "google.com.\t\t59\tIN\tSOA\tns1.google.com. dns-admin.google.com. 246997594 900 900 1800 60", "admin": "dns-admin.google.com.", "host": "ns1.google.com.", "expire": 1800, "minimum": 60, "refresh": 900, "retry": 900, "serial": 246997594 } ] } }<xml> <DNSData> <domainName>google.com</domainName> <types> <type>1</type> <type>6</type> <type>16</type> </types> <dnsTypes>A,SOA,TXT</dnsTypes> <audit> <createdDate>2019-05-07 14:45:48.363 UTC</createdDate> <updatedDate>2019-05-07 14:45:48.363 UTC</updatedDate> </audit> <dnsRecords> <dnsRecord> <type>16</type> <dnsType>TXT</dnsType> <name>google.com.</name> <ttl>299</ttl> <rRsetType>16</rRsetType> <rawText>google.com. 299 IN TXT "docusign=05958488-4752-4ef2-95eb-aa7ba8a3bd0e"</rawText> <strings> <string>docusign=05958488-4752-4ef2-95eb-aa7ba8a3bd0e</string> </strings> </dnsRecord> <dnsRecord> <type>16</type> <dnsType>TXT</dnsType> <name>google.com.</name> <ttl>299</ttl> <rRsetType>16</rRsetType> <rawText>google.com. 299 IN TXT "facebook-domain-verification=22rm551cu4k0ab0bxsw536tlds4h95"</rawText> <strings> <string>facebook-domain-verification=22rm551cu4k0ab0bxsw536tlds4h95</string> </strings> </dnsRecord> <dnsRecord> <type>16</type> <dnsType>TXT</dnsType> <name>google.com.</name> <ttl>299</ttl> <rRsetType>16</rRsetType> <rawText>google.com. 299 IN TXT "globalsign-smime-dv=CDYX+XFHUw2wml6/Gb8+59BsH31KzUr6c1l2BPvqKX8="</rawText> <strings> <string>globalsign-smime-dv=CDYX+XFHUw2wml6/Gb8+59BsH31KzUr6c1l2BPvqKX8=</string> </strings> </dnsRecord> <dnsRecord> <type>16</type> <dnsType>TXT</dnsType> <name>google.com.</name> <ttl>299</ttl> <rRsetType>16</rRsetType> <rawText>google.com. 299 IN TXT "v=spf1 include:_spf.google.com ~all"</rawText> <strings> <string>v=spf1 include:_spf.google.com ~all</string> </strings> </dnsRecord> <dnsRecord> <type>1</type> <dnsType>A</dnsType> <name>google.com.</name> <ttl>299</ttl> <rRsetType>1</rRsetType> <rawText>google.com. 299 IN A 172.217.14.110</rawText> <address>172.217.14.110</address> </dnsRecord> <dnsRecord> <type>6</type> <dnsType>SOA</dnsType> <name>google.com.</name> <ttl>59</ttl> <rRsetType>6</rRsetType> <rawText>google.com. 59 IN SOA ns1.google.com. dns-admin.google.com. 246997594 900 900 1800 60</rawText> <admin>dns-admin.google.com.</admin> <host>ns1.google.com.</host> <expire>1800</expire> <minimum>60</minimum> <refresh>900</refresh> <retry>900</retry> <serial>246997594</serial> </dnsRecord> </dnsRecords> </DNSData> </xml>
|
DNSData
|
The root element representing information about the domain's DNS records
|
|
domainName
|
The domain name being queried (e.g., google.com)
|
|
types
|
List of numeric DNS record types (e.g., A=1, SOA=6, TXT=16). Supported types are listed in the
Supported DNS Types section.
-1 indicates that all types are returned.
|
|
dnsTypes
|
Comma-separated list of DNS record types. _all indicates all types are returned.
|
|
audit
|
Audit information about when the data was created and updated
|
|
audit.createdDate
|
The timestamp when the data was created
|
|
audit.updatedDate
|
The timestamp when the data was last updated
|
|
dnsRecords
|
List of DNS records for the domain
|
These fields are present on every record in dnsRecords regardless of type.
type |
Numeric identifier for the DNS record type |
dnsType |
Textual representation of the DNS record type (e.g., A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, PTR, SRV) |
name |
Domain or subdomain associated with the record |
additionalName |
The name used for additional data processing |
ttl |
Time-to-live (TTL) value in seconds |
rRsetType |
Numeric identifier for the resource record set type. Equal to type for all types except SIG/RRSIG. |
rawText |
Raw text representation of the DNS record in uncompressed DNS wire format |
Click a record type to expand its specific fields. These appear in addition to the common fields above.
address |
The IPv4 address that the name refers to |
prefix |
The name of the prefix |
prefixBits |
The number of bits in the address prefix |
suffix |
The address suffix |
address |
The IPv6 address suffix |
host |
The host providing the service |
subtype |
Indicates the type of service provided by the host |
elements |
The list of APL elements |
flags |
The flags byte |
tag |
The tag (e.g., issue, issuewild, iodef) |
value |
The value associated with the tag |
algorithm |
The algorithm of the associated KEYRecord, if present |
cert |
Binary data representing the certificate |
certType |
The type of certificate |
keyTag |
The ID of the associated KEYRecord, if present |
alias |
The name to which the CNAME alias points |
target |
The target of the CNAME record |
data |
Binary data, opaque to DNS |
algorithm |
The original key algorithm |
digest |
A hash of the original key |
digestID |
The digest id code |
footprint |
The original KEY record's footprint (keyid) |
alias |
The name to which the DNAME alias points |
target |
The target of the DNAME record |
algorithm |
The original key algorithm |
digest |
A hash of the original key |
digestID |
The digest id code |
footprint |
The original KEY record's footprint (keyid) |
altitude |
The altitude component of the location, in meters above sea level |
altitudeString |
The altitude component as a string |
latitude |
The latitude component of the location |
latitudeString |
The latitude component as a string |
longitude |
The longitude component of the location |
longitudeString |
The longitude component as a string |
cpu |
A string describing the host's CPU |
os |
A string describing the host's OS |
algorithmType |
The record's algorithm type |
gateway |
The record's gateway |
gatewayType |
The record's gateway type |
address |
The ISDN number associated with the domain |
subAddress |
The subaddress, if any |
preference |
The preference of this KX. Records with lower preference are preferred. |
target |
The host that authority is delegated to |
altitude |
The altitude of the center of the sphere, in meters |
hPrecision |
The horizontal precision of the data, in meters |
latitude |
The latitude of the center of the sphere |
longitude |
The longitude of the center of the sphere |
size |
The diameter of a sphere enclosing the described entity, in meters |
vPrecision |
The vertical precision of the data, in meters |
mailbox |
The host containing the mailbox for the domain |
mailAgent |
The mail agent that delivers mail for the domain |
mailAgent |
The mail agent that forwards mail for the domain |
mailbox |
The mailbox that is a member of the group specified by the domain |
errorAddress |
The address to receive error messages relating to the mailing list/mailbox |
responsibleAddress |
The address responsible for the mailing list/mailbox |
newName |
The new name of the mailbox specified by the domain |
priority |
The priority of this MX. Records with lower priority are preferred. |
target |
The host that mail is sent to |
flags |
The control aspects of the NAPTR record |
order |
The order of this NAPTR. Records with lower order are preferred. |
preference |
The preference, used to select between records at the same order |
regexp |
The regular/substitution expression |
replacement |
The domain name to query for the next DNS resource record, depending on the value of the flags field |
service |
The service or protocol available down the rewrite path |
target |
The name server for the given domain |
address |
The NSAP address |
target |
The name of the host with this address |
next |
The following name in an ordered list of the zone |
types |
An array containing the types present |
flags |
The value of the flags field |
hashAlgorithm |
The hash algorithm |
iterations |
The number of hash iterations |
next |
The next hash (may not be null) |
salt |
The salt to use (may be null) |
types |
The types present at the original ownername |
flags |
The value of the flags field |
hashAlgorithm |
The hash algorithm |
iterations |
The number of hash iterations |
salt |
The salt to use (may be null) |
data |
The contents of the record |
bitmap |
The set of types for which records exist at this name |
next |
The following name in an ordered list of the zone |
target |
The name of the machine with this address |
map822 |
The RFC 822 component of the mail address |
mapX400 |
The X.400 component of the mail address |
preference |
The preference of this mail address |
mailbox |
The responsible person |
textDomain |
The address where TXT records can be found |
algorithm |
The cryptographic algorithm of the key that generated the signature |
expire |
The time at which the signature expires |
footprint |
The footprint/key id of the signing key |
labels |
The number of labels in the signed domain name |
origTTL |
The original TTL of the RRset |
signature |
Binary data representing the signature |
signer |
The owner of the signing key |
timeSigned |
The time at which this signature was generated |
typeCovered |
The RRset type covered by this signature |
intermediateHost |
The domain name of the host to use as a router |
preference |
The preference of the route. Smaller numbers indicate more preferred routes. |
algorithm |
The cryptographic algorithm of the key that generated the signature |
expire |
The time at which the signature expires |
footprint |
The footprint/key id of the signing key |
labels |
The number of labels in the signed domain name |
origTTL |
The original TTL of the RRset |
signature |
Binary data representing the signature |
signer |
The owner of the signing key |
timeSigned |
The time at which this signature was generated |
typeCovered |
The RRset type covered by this signature |
admin |
The zone administrator's address |
expire |
The amount of time until a secondary expires a zone, in seconds |
host |
The primary name server for the zone |
minimum |
The minimum TTL for records in the zone, used as the default TTL for negative caching |
refresh |
The amount of time until a secondary checks for a new serial number, in seconds |
retry |
The amount of time between a secondary's checks for a new serial number, in seconds |
serial |
The zone's serial number |
port |
The TCP/UDP port that the service uses |
priority |
The priority of this SRV. Records with lower priority are preferred. |
target |
The host running the service |
weight |
The weight, used to select between records at the same priority |
— |
SSHFP records carry only the common DNS record fields listed above; no additional type-specific attributes. |
certificateAssociationData |
The "certificate association data" to be matched |
certificateUsage |
The provided association used to match the certificate presented in the TLS handshake |
matchingType |
How the certificate association is presented |
selector |
The part of the TLS certificate presented by the server that will be matched against the association data |
strings |
The text strings |
address |
The IP address |
protocol |
The IP protocol number |
services |
An array of supported services, represented by port number |
address |
The X.25 PSDN address |
We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.