Getting Started
The Deepinfo API gives you programmatic access to Deepinfo's internet-wide domain, DNS, WHOIS, SSL and vulnerability data, and to your Deepinfo Platform modules: External Attack Surface Management (EASM), Cyber Threat Intelligence (CTI), Brand Risk Protection (BRP) and Platform.
Every endpoint is served over HTTPS, and the API version is the first path segment:
https://api.deepinfo.com/v1/<module>/<endpoint>
Note
Demo account? The examples use the Production addresses. Choose Demo in the Environment switch at the top of the API Reference sidebar (or open the API reference from the Demo card on the home page) to show the Demo addresses. See Environments & Base URL.
Quick Start
1. Get an API key. Your key authenticates every request and decides which endpoints you can call. Generate one in the Deepinfo Platform under Settings → Organization Settings → API Keys (see Get an API key). No platform access? Contact support@deepinfo.com.
2. Send it in the apikey header. Every request carries it. See
Authentication.
3. Make your first call. Domain WHOIS returns the current WHOIS registration record of a domain:
curl "https://api.deepinfo.com/v1/lookup/whois?domain=deepinfo.com" \
-H "apikey: YOUR_API_KEY" \
-H "Accept: application/json"
A successful response returns the parsed WHOIS record together with the raw WHOIS text:
{
"domain_name": "deepinfo.com",
"raw": "Domain Name: DEEPINFO.COM\n Registry Domain ID: 71858956_DOMAIN_COM-VRSN\n ...",
"parsed": {
"create_date": "2001-06-05T02:57:08Z",
"update_date": "2025-08-19T07:33:45Z",
"expiry_date": "2028-10-20T11:59:59Z",
"registrar": "godaddy online services cayman islands ltd.",
"name_servers": ["may.ns.cloudflare.com", "simon.ns.cloudflare.com"],
"whois_server": "whois.uniregistrar.com"
},
"check_date": "2026-09-22T12:25:50Z",
"parse_code": null
}
Note
The response above is shortened: raw is truncated, and parsed.uid, the registrant contact and the
domain status codes are left out. The full field list and the complete saved example are on the
Domain WHOIS reference page.
What to Read Next
| Page | What it covers |
|---|---|
| Authentication | Getting and replacing a key, the apikey header, and what 401 and 403 mean |
| Environments & base URL | Host, version, content types, date format, expiring download links |
| Rate limits | Per-key and per-endpoint limits, the ratelimit-* headers, quota |
| Pagination | page, page_size and the list envelope |
| Search & filters | The filters body used by search endpoints, and query-parameter filters for list endpoints |
| Errors | The error formats, the status codes and example responses |
The Modules
| Module | What it covers |
|---|---|
| Lookup | Real-time and historical lookups for a single domain, IP, host or website: WHOIS, DNS, IP WHOIS, SSL, port scan, technologies, screenshots, web data |
| Discovery | Search Deepinfo's domain dataset: subdomains, associated domains, reverse WHOIS/NS/IP/MX, TLDs |
| Darkweb | Search dark web sources |
| Vulnerability | Vulnerability (CVE) search, details and insights |
| Domain Intelligence | Domain registration statistics |
| Feeds | Download domain and subdomain data feeds |
| EASM | Your assets, discovery, issues, vulnerabilities and technologies |
| CTI | Email breaches, compromised credentials and devices, threat actors, security news |
| BRP | Fraudulent and suspicious domains, detection rules |
| Platform | Notification rules, reports and scheduled reports |
Which endpoints you can call depends on your plan. Browse them all in the API reference.
In Postman
Every endpoint of this reference is also in the Deepinfo Postman collection: download it with the buttons above, and Postman Collection shows how to set it up in a few steps.
Support
When you contact support@deepinfo.com about a request, include the value of
the deepinfo-request-id response header. It identifies that exact call.