Domain Intelligence API
Look up domain risk, observed hostnames, DNS posture, registration age, and RDAP ownership signals.
Use domain endpoints to inspect registration, DNS, email posture, parking, malware, and risk signals for a hostname or domain.
An active workspace API key and any Suite or Lookups plan are required. Each request consumes one shared lookup unit. See Authorization for limits and errors.
Endpoints
GET /domain/{domain}
GET /domain/{domain}/subdomains
GET /domain/{domain}/infrastructure
GET /domain/{domain}/rdap
POST /website-scans
GET /domain/{domain}/website-security
GET /website-leaderboard
Domain Risk
GET /domain/example.com
Returns domain intelligence used by RequestGuard assessments, including registration age, TLD risk, parking signals, DNS posture, email posture, malware resolver comparison, and decision context when available.
Observed Subdomains
GET /domain/chat.example.com/subdomains?limit=100&offset=0
This endpoint accepts a hostname and returns observations for its registrable apex. A request for chat.example.com searches example.com. RequestGuard also honors private suffix rules, so a request for api.tenant.pages.dev searches tenant.pages.dev.
limit accepts integers from 1 through 500. offset accepts non-negative integers. RequestGuard retains up to 10,000 hostnames and reports the source total, retained count, and truncation state in pagination.
{
"domain": "chat.example.com",
"apex_domain": "example.com",
"subdomains": [
{
"hostname": "api.example.com",
"first_seen": "2026-01-01T00:00:00Z"
}
],
"pagination": {
"limit": 100,
"offset": 0,
"returned": 1,
"total": 16,
"available": 16,
"has_more": false,
"truncated": false
},
"sources": [
{
"name": "Certificate transparency index",
"type": "dataset",
"matched": true,
"category": "subdomains"
}
],
"_meta": {
"queried_at": "2026-08-23T08:44:32Z",
"cached": true,
"stale": false
}
}
first_seen gives the first observation time stored in the certificate transparency index. Certificate issuance time is separate. Use observations as historical naming data, and check current DNS, activity, and risk through separate signals. RequestGuard does not add these observations to the domain threat score.
RequestGuard caches complete and empty responses for 24 hours. If the certificate transparency source becomes unavailable, RequestGuard can return a retained response for up to seven days and sets _meta.stale to true. The endpoint returns 503 SUBDOMAIN_SOURCE_UNAVAILABLE when no retained response is available.
Hostname Infrastructure
GET /domain/api.example.com/infrastructure
This endpoint resolves the hostname’s current A, AAAA, and CNAME records. Each address includes IP network registration and location fields when the configured data sources return them.
{
"hostname": "api.example.com",
"resolved": true,
"cname_chain": ["edge.example.net"],
"addresses": [
{
"ip": "104.26.14.60",
"type": "A",
"country_code": "US",
"country": null,
"region": null,
"city": null,
"latitude": null,
"longitude": null,
"asn": 13335,
"organization": "Cloudflare, Inc.",
"network": "Cloudflare",
"edge_network": true
}
],
"edge_network": true,
"sources": [
{
"name": "DNS resolution",
"type": "dataset",
"matched": true,
"category": "dns"
},
{
"name": "IP network registry",
"type": "dataset",
"matched": true,
"category": "network_location"
}
],
"_meta": {
"queried_at": "2026-08-23T08:44:32Z",
"response_time_ms": 231
}
}
edge_network marks recognized CDN and reverse-proxy addresses. Those addresses describe the public edge and do not expose the origin server. IP location describes the address allocation or a configured geolocation match; it may differ from the machine’s physical location.
The endpoint returns resolved: false with an empty addresses array when the hostname has no current A or AAAA records.
RDAP
GET /domain/example.com/rdap
Returns a normalized ownership summary for the domain, including registrar, status, registration dates, nameservers, and abuse-contact fields when available.
Response Shape
Common fields include:
| Field | Meaning |
|---|---|
domain | Queried domain. |
apex_domain | Registrable apex used for an observed-subdomain search. |
subdomains | Certificate transparency hostname observations returned by the subdomains endpoint. |
addresses | Current A and AAAA addresses returned by the infrastructure endpoint. |
edge_network | Whether a resolved address or CNAME belongs to a recognized CDN or reverse proxy. |
pagination | Requested page, source total, retained count, and truncation state. |
risk_score | Normalized 0-100 RequestGuard threat score when available. |
domain_rating | Ahrefs backlink-authority metric, returned separately from the threat score when available. |
risk_level | Low, medium, high, or critical risk grouping. |
is_new_domain | Newly registered domain signal. |
is_disposable | Disposable or suspicious-use signal when applicable. |
dns | DNS posture and resolver evidence. |
email | MX, SPF, DMARC, MTA-STS, and SMTP TLS reporting posture when available. |
sources | Source metadata used to build the response. |
For package-specific evidence, use Package Vulnerability Intelligence instead of the general domain endpoint.
The Website Security Score is higher-is-better and appears alongside the lower-is-better domain threat score on the public domain report. It does not change the existing GET /domain/{domain} API response.