The Deepinfo API gives you programmatic access to Deepinfo's internet-wide domain, DNS, WHOIS, SSL and vulnerability data, and to your Deepinfo Platform modules: External Attack Surface Management (EASM), Cyber Threat Intelligence (CTI), Brand Risk Protection (BRP) and Platform.

Every endpoint is served over HTTPS, and the API version is the first path segment:

Text
https://api.deepinfo.com/v1/<module>/<endpoint>

Note

Demo account? The examples use the Production addresses. Choose Demo in the Environment switch at the top of the API Reference sidebar (or open the API reference from the Demo card on the home page) to show the Demo addresses. See Environments & Base URL.

Quick Start

1. Get an API key. Your key authenticates every request and decides which endpoints you can call. Generate one in the Deepinfo Platform under Settings → Organization Settings → API Keys (see Get an API key). No platform access? Contact support@deepinfo.com.

2. Send it in the apikey header. Every request carries it. See Authentication.

3. Make your first call. Domain WHOIS returns the current WHOIS registration record of a domain:

Shell
curl "https://api.deepinfo.com/v1/lookup/whois?domain=deepinfo.com" \
  -H "apikey: YOUR_API_KEY" \
  -H "Accept: application/json"

A successful response returns the parsed WHOIS record together with the raw WHOIS text:

JSON
{
  "domain_name": "deepinfo.com",
  "raw": "Domain Name: DEEPINFO.COM\n   Registry Domain ID: 71858956_DOMAIN_COM-VRSN\n   ...",
  "parsed": {
    "create_date": "2001-06-05T02:57:08Z",
    "update_date": "2025-08-19T07:33:45Z",
    "expiry_date": "2028-10-20T11:59:59Z",
    "registrar": "godaddy online services cayman islands ltd.",
    "name_servers": ["may.ns.cloudflare.com", "simon.ns.cloudflare.com"],
    "whois_server": "whois.uniregistrar.com"
  },
  "check_date": "2026-09-22T12:25:50Z",
  "parse_code": null
}

Note

The response above is shortened: raw is truncated, and parsed.uid, the registrant contact and the domain status codes are left out. The full field list and the complete saved example are on the Domain WHOIS reference page.

Page What it covers
Authentication Getting and replacing a key, the apikey header, and what 401 and 403 mean
Environments & base URL Host, version, content types, date format, expiring download links
Rate limits Per-key and per-endpoint limits, the ratelimit-* headers, quota
Pagination page, page_size and the list envelope
Search & filters The filters body used by search endpoints, and query-parameter filters for list endpoints
Errors The error formats, the status codes and example responses

The Modules

Module What it covers
Lookup Real-time and historical lookups for a single domain, IP, host or website: WHOIS, DNS, IP WHOIS, SSL, port scan, technologies, screenshots, web data
Discovery Search Deepinfo's domain dataset: subdomains, associated domains, reverse WHOIS/NS/IP/MX, TLDs
Darkweb Search dark web sources
Vulnerability Vulnerability (CVE) search, details and insights
Domain Intelligence Domain registration statistics
Feeds Download domain and subdomain data feeds
EASM Your assets, discovery, issues, vulnerabilities and technologies
CTI Email breaches, compromised credentials and devices, threat actors, security news
BRP Fraudulent and suspicious domains, detection rules
Platform Notification rules, reports and scheduled reports

Which endpoints you can call depends on your plan. Browse them all in the API reference.

In Postman

Every endpoint of this reference is also in the Deepinfo Postman collection: download it with the buttons above, and Postman Collection shows how to set it up in a few steps.

Support

When you contact support@deepinfo.com about a request, include the value of the deepinfo-request-id response header. It identifies that exact call.

Last updated