Skip to content
RequestGuard Documentation
Pricing
Domain Intelligence Updated Sep 8, 2026

Domain Intelligence API

Look up domain risk, observed hostnames, DNS posture, registration age, and RDAP ownership signals.

Use domain endpoints to inspect registration, DNS, email posture, parking, malware, and risk signals for a hostname or domain.

An active workspace API key and any Suite or Lookups plan are required. Each request consumes one shared lookup unit. See Authorization for limits and errors.

Endpoints

GET /domain/{domain}
GET /domain/{domain}/subdomains
GET /domain/{domain}/infrastructure
GET /domain/{domain}/rdap
POST /website-scans
GET /domain/{domain}/website-security
GET /website-leaderboard

Domain Risk

GET /domain/example.com

Returns domain intelligence used by RequestGuard assessments, including registration age, TLD risk, parking signals, DNS posture, email posture, malware resolver comparison, and decision context when available.

Observed Subdomains

GET /domain/chat.example.com/subdomains?limit=100&offset=0

This endpoint accepts a hostname and returns observations for its registrable apex. A request for chat.example.com searches example.com. RequestGuard also honors private suffix rules, so a request for api.tenant.pages.dev searches tenant.pages.dev.

limit accepts integers from 1 through 500. offset accepts non-negative integers. RequestGuard retains up to 10,000 hostnames and reports the source total, retained count, and truncation state in pagination.

{
  "domain": "chat.example.com",
  "apex_domain": "example.com",
  "subdomains": [
    {
      "hostname": "api.example.com",
      "first_seen": "2026-01-01T00:00:00Z"
    }
  ],
  "pagination": {
    "limit": 100,
    "offset": 0,
    "returned": 1,
    "total": 16,
    "available": 16,
    "has_more": false,
    "truncated": false
  },
  "sources": [
    {
      "name": "Certificate transparency index",
      "type": "dataset",
      "matched": true,
      "category": "subdomains"
    }
  ],
  "_meta": {
    "queried_at": "2026-08-23T08:44:32Z",
    "cached": true,
    "stale": false
  }
}

first_seen gives the first observation time stored in the certificate transparency index. Certificate issuance time is separate. Use observations as historical naming data, and check current DNS, activity, and risk through separate signals. RequestGuard does not add these observations to the domain threat score.

RequestGuard caches complete and empty responses for 24 hours. If the certificate transparency source becomes unavailable, RequestGuard can return a retained response for up to seven days and sets _meta.stale to true. The endpoint returns 503 SUBDOMAIN_SOURCE_UNAVAILABLE when no retained response is available.

Hostname Infrastructure

GET /domain/api.example.com/infrastructure

This endpoint resolves the hostname’s current A, AAAA, and CNAME records. Each address includes IP network registration and location fields when the configured data sources return them.

{
  "hostname": "api.example.com",
  "resolved": true,
  "cname_chain": ["edge.example.net"],
  "addresses": [
    {
      "ip": "104.26.14.60",
      "type": "A",
      "country_code": "US",
      "country": null,
      "region": null,
      "city": null,
      "latitude": null,
      "longitude": null,
      "asn": 13335,
      "organization": "Cloudflare, Inc.",
      "network": "Cloudflare",
      "edge_network": true
    }
  ],
  "edge_network": true,
  "sources": [
    {
      "name": "DNS resolution",
      "type": "dataset",
      "matched": true,
      "category": "dns"
    },
    {
      "name": "IP network registry",
      "type": "dataset",
      "matched": true,
      "category": "network_location"
    }
  ],
  "_meta": {
    "queried_at": "2026-08-23T08:44:32Z",
    "response_time_ms": 231
  }
}

edge_network marks recognized CDN and reverse-proxy addresses. Those addresses describe the public edge and do not expose the origin server. IP location describes the address allocation or a configured geolocation match; it may differ from the machine’s physical location.

The endpoint returns resolved: false with an empty addresses array when the hostname has no current A or AAAA records.

RDAP

GET /domain/example.com/rdap

Returns a normalized ownership summary for the domain, including registrar, status, registration dates, nameservers, and abuse-contact fields when available.

Response Shape

Common fields include:

FieldMeaning
domainQueried domain.
apex_domainRegistrable apex used for an observed-subdomain search.
subdomainsCertificate transparency hostname observations returned by the subdomains endpoint.
addressesCurrent A and AAAA addresses returned by the infrastructure endpoint.
edge_networkWhether a resolved address or CNAME belongs to a recognized CDN or reverse proxy.
paginationRequested page, source total, retained count, and truncation state.
risk_scoreNormalized 0-100 RequestGuard threat score when available.
domain_ratingAhrefs backlink-authority metric, returned separately from the threat score when available.
risk_levelLow, medium, high, or critical risk grouping.
is_new_domainNewly registered domain signal.
is_disposableDisposable or suspicious-use signal when applicable.
dnsDNS posture and resolver evidence.
emailMX, SPF, DMARC, MTA-STS, and SMTP TLS reporting posture when available.
sourcesSource metadata used to build the response.

For package-specific evidence, use Package Vulnerability Intelligence instead of the general domain endpoint.

The Website Security Score is higher-is-better and appears alongside the lower-is-better domain threat score on the public domain report. It does not change the existing GET /domain/{domain} API response.