# Domain Search

POST /discovery/domain-search: Searches Deepinfo's whole domain dataset with filters on WHOIS, DNS, SSL, web data and more.

Source: https://docs.deepinfo.com/reference/discovery/domain-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/discovery/domain-search`

Searches Deepinfo's whole domain dataset with filters on WHOIS, DNS, SSL, web data and more. `result_count` is the true total; results page up to 10,000.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `export` | Optional | Default `false`. |  |
| `export_format` | Optional | One of: `json`, `csv`. |  |
| `export_scope` | Optional | One of: `basic`, `default`, `extended`. |  |
| `page` | Optional | Min `1`, max `400`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "fqdn",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "punycode",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400). Example: a worked example that filters by the field, with the request and the response it returns.

Operators: `eq`, `in`, `startswith`, `wildcard`, `fuzzy`, `exists`

| Field | Description | Example |
|---|---|---|
| `fqdn` | The full host name (FQDN) of the record in its ASCII (punycode) form, such as `www.example.com`. Search results return it as `punycode`. | [Example 1](/reference/discovery/domain-search/examples/fqdn/)<br>[Example 2](/reference/discovery/domain-search/examples/startswith-login-hosts/) |
| `subdomain_last` | The leftmost label of the subdomain, compared in its ASCII (punycode) form: `a` in `a.b.example.com`, and `www` in `www.example.com`. | [Example](/reference/discovery/domain-search/examples/subdomain-last/) |
| `subdomain_root` | The subdomain label directly in front of the registrable domain, compared in its ASCII (punycode) form: `b` in `a.b.example.com`, and `www` in `www.example.com`. | [Example](/reference/discovery/domain-search/examples/subdomain-root/) |
| `domain` | The registrable domain the FQDN belongs to (`example.com` for `www.example.com`), compared in its ASCII (punycode) form. A filter on it matches the domain itself and all its subdomains. | [Example 1](/reference/discovery/domain-search/examples/domain/)<br>[Example 2](/reference/discovery/domain-search/examples/look-alikes-excluding-the-real-domain/)<br>[Example 3](/reference/discovery/domain-search/examples/new-look-alikes-with-mail-servers/) |
| `domain.name.language` | The language detected for the domain name, as a two-letter ISO 639-1 code such as `en`, `de` or `tr`. Search results return it as `domain.name.lang`. | [Example](/reference/discovery/domain-search/examples/domain-name-language/) |
| `domain.name.keywords` | The words detected in the domain name, such as `deep` and `info` for `deepinfo`, so `cybersecurity` and `cyber-security` both contain the word `cyber`. | [Example 1](/reference/discovery/domain-search/examples/domain-name-keywords/)<br>[Example 2](/reference/discovery/domain-search/examples/all-three-new-shops-without-whois-privacy/) |
| `domain.extension` | The extension of the registrable domain, everything after the name, such as `com`, `io` or `co.uk`, compared in its ASCII (punycode) form. | [Example 1](/reference/discovery/domain-search/examples/domain-extension/)<br>[Example 2](/reference/discovery/domain-search/examples/in-one-of-several-extensions/)<br>[Example 3](/reference/discovery/domain-search/examples/range-name-length-between-3-and-4/)<br>[Example 4](/reference/discovery/domain-search/examples/must-and-should-together/)<br>[Example 5](/reference/discovery/domain-search/examples/must-not-registrable-domains-outside-com/)<br>[Example 6](/reference/discovery/domain-search/examples/sort-by-name/)<br>[Example 7](/reference/discovery/domain-search/examples/soonest-to-expire-first/)<br>[Example 8](/reference/discovery/domain-search/examples/latest-whois-changes-first/)<br>[Example 9](/reference/discovery/domain-search/examples/second-page-of-results/)<br>[Example 10](/reference/discovery/domain-search/examples/larger-pages/)<br>[Example 11](/reference/discovery/domain-search/examples/last-reachable-page/) |
| `domain.extension_root` | The top-level part of the extension, compared in its ASCII (punycode) form: `uk` for both `uk` and `co.uk`. | [Example](/reference/discovery/domain-search/examples/domain-extension-root/) |
| `domain.extension_sub` | The second-level part of a two-part extension, compared in its ASCII (punycode) form: `co` in `co.uk`. Single-part extensions such as `com` have none. | [Example](/reference/discovery/domain-search/examples/domain-extension-sub/) |
| `domain.whois.registrar` | The registrar the domain is registered through, as named in its WHOIS record and stored in lower case, such as `godaddy.com, llc`. | [Example 1](/reference/discovery/domain-search/examples/domain-whois-registrar/)<br>[Example 2](/reference/discovery/domain-search/examples/exists-false-domains-without-a-registrar/)<br>[Example 3](/reference/discovery/domain-search/examples/should-either-of-two-registrars/)<br>[Example 4](/reference/discovery/domain-search/examples/most-recently-updated-whois-first/) |
| `domain.whois.registrant.name` | The registrant's name (person or organization) from the domain's WHOIS record, stored in lower case. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-name/) |
| `domain.whois.registrant.organization` | The registrant's organization from the domain's WHOIS record, stored in lower case, such as `cloudflare, inc.`. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-organization/) |
| `domain.whois.registrant.street` | The registrant's street address from the domain's WHOIS record, stored in lower case. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-street/) |
| `domain.whois.registrant.city` | The registrant's city from the domain's WHOIS record, stored in lower case. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-city/) |
| `domain.whois.registrant.state` | The registrant's state or region from the domain's WHOIS record, stored in lower case. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-state/) |
| `domain.whois.registrant.postal_code` | The registrant's postal code from the domain's WHOIS record. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-postal-code/) |
| `domain.whois.registrant.country` | The registrant's country from the domain's WHOIS record, usually a two-letter ISO 3166-1 alpha-2 code in lower case, such as `de`. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-country/) |
| `domain.whois.registrant.phone` | The registrant's phone number as written in the domain's WHOIS record. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-phone/) |
| `domain.whois.registrant.email` | The registrant's e-mail address from the domain's WHOIS record; it can be the relay address of a privacy service instead of the owner's own. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-email/) |
| `domain.whois.name_servers` | The name servers listed in the domain's WHOIS record, as host names such as `ns1.example.com`. | [Example](/reference/discovery/domain-search/examples/domain-whois-name-servers/) |
| `domain.whois.domain_status` | The status codes in the domain's WHOIS record, mostly EPP codes, in lower case without spaces, such as `clienttransferprohibited`, `clientdeleteprohibited`, `clientupdateprohibited`, `clientrenewprohibited`, `clienthold` or `ok`. | [Example](/reference/discovery/domain-search/examples/domain-whois-domain-status/) |
| `domain.whois_normalized.registrant.organization` | The registrant's organization from WHOIS in normalized form: lower case with spaces and punctuation removed, so `cloudflare, inc.` becomes `cloudflareinc`. A pattern such as `*cloudflare*` finds it more reliably than an exact value. | [Example](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-organization/) |
| `domain.whois_normalized.registrant.phone` | The registrant's phone number from WHOIS in normalized form: digits only, with `+`, dots and other separators removed. | [Example](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-phone/) |
| `domain.whois_normalized.registrant.email` | The registrant's e-mail address as kept in `whois_normalized`; `email_fqdn_apex` and `email_domain_apex` hold its host and registrable domain. | [Example](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-email/) |
| `domain.whois_normalized.registrant.email_fqdn_apex` | The host part of the normalized registrant e-mail address, everything after the `@`: `mail.example.com` for `user@mail.example.com`. | [Example](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-email-fqdn-apex/) |
| `domain.whois_normalized.registrant.email_domain_apex` | The registrable domain of the normalized registrant e-mail address: `example.com` for `user@mail.example.com`. | [Example](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-email-domain-apex/) |
| `domain.whois_registrant_email_historical` | Every registrant e-mail address seen in the domain's WHOIS records over time. | [Example](/reference/discovery/domain-search/examples/domain-whois-registrant-email-historical/) |
| `domain.dns.a.ip_addresses` | The IPv4 addresses in the A record of the registrable domain (`domain.dns`); `dns.a.ip_addresses` holds those of the FQDN itself. | [Example](/reference/discovery/domain-search/examples/domain-dns-a-ip-addresses/) |
| `domain.ip_history` | Every IP address the registrable domain has resolved to over time, so it also finds domains that have since moved. | [Example](/reference/discovery/domain-search/examples/domain-ip-history/) |
| `dns.a.ip_addresses` | The IPv4 addresses in the FQDN's DNS A record. | [Example](/reference/discovery/domain-search/examples/dns-a-ip-addresses/) |
| `dns.aaaa.ip_addresses` | The IPv6 addresses in the FQDN's DNS AAAA record. | [Example](/reference/discovery/domain-search/examples/dns-aaaa-ip-addresses/) |
| `dns.ns.name_servers` | The name servers in the FQDN's DNS NS record, as host names. | [Example 1](/reference/discovery/domain-search/examples/dns-ns-name-servers/)<br>[Example 2](/reference/discovery/domain-search/examples/must-and-should-together/)<br>[Example 3](/reference/discovery/domain-search/examples/latest-dns-changes-first/) |
| `dns.mx.mail_servers` | The mail server host names in the FQDN's DNS MX record, such as `aspmx.l.google.com` for Google Workspace. | [Example 1](/reference/discovery/domain-search/examples/dns-mx-mail-servers/)<br>[Example 2](/reference/discovery/domain-search/examples/new-look-alikes-with-mail-servers/) |
| `dns.soa.mnames` | The MNAME of the FQDN's SOA record: the primary name server of the zone. | [Example](/reference/discovery/domain-search/examples/dns-soa-mnames/) |
| `dns.soa.rnames` | The RNAME of the FQDN's SOA record, the zone's responsible mailbox in DNS form: `dns.example.com` stands for the mailbox `dns` at `example.com`. | [Example](/reference/discovery/domain-search/examples/dns-soa-rnames/) |
| `dns.soa.rname_emails` | The RNAME of the FQDN's SOA record written as an e-mail address, such as `user@example.com`. | [Example](/reference/discovery/domain-search/examples/dns-soa-rname-emails/) |
| `dns.txt.values` | The text of the FQDN's DNS TXT records, such as SPF policies and site-verification tokens, stored as quoted text (each value starts with `"`). | [Example](/reference/discovery/domain-search/examples/dns-txt-values/) |
| `dns.cname.values` | The target of the FQDN's DNS CNAME record, stored as a fully qualified name with the final dot, such as `www.example.com.`. | [Example](/reference/discovery/domain-search/examples/dns-cname-values/) |
| `dns.others.type` | The type of a DNS record that has no field of its own (`dns.others`), in upper case; values seen include `DNSKEY`, `DS`, `SPF`, `HINFO`, `RRSIG`, `NSEC3`, `NSEC3PARAM`, `CAA`, `PTR` and `TYPE65`. | [Example](/reference/discovery/domain-search/examples/dns-others-type/) |
| `dns.others.values` | The data of a record in `dns.others`, as text in zone-file notation, such as the flags, protocol, algorithm and key of a `DNSKEY` record. | [Example](/reference/discovery/domain-search/examples/dns-others-values/) |
| `ip_history` | Every IP address the FQDN has resolved to over time, including addresses it no longer uses. | [Example](/reference/discovery/domain-search/examples/ip-history/) |
| `ssl.fqdns` | The host names the FQDN's TLS certificate is valid for, in lower case; wildcard names appear without the leading `*.`. | [Example](/reference/discovery/domain-search/examples/ssl-fqdns/) |
| `ssl.fingerprint.sha256` | The SHA-256 fingerprint of the FQDN's TLS certificate, as 64 lower-case hex characters; a fingerprint identifies one certificate, so it finds every host that serves it. | [Example](/reference/discovery/domain-search/examples/ssl-fingerprint-sha256/) |
| `ssl.fingerprint.sha1` | The SHA-1 fingerprint of the FQDN's TLS certificate, as 40 lower-case hex characters. | [Example](/reference/discovery/domain-search/examples/ssl-fingerprint-sha1/) |
| `ssl.fingerprint.md5` | The MD5 fingerprint of the FQDN's TLS certificate, as 32 lower-case hex characters. | [Example](/reference/discovery/domain-search/examples/ssl-fingerprint-md5/) |
| `ssl.signature.value` | The signature of the FQDN's TLS certificate, Base64-encoded. | [Example](/reference/discovery/domain-search/examples/ssl-signature-value/) |
| `ssl.issuer_dn` | The distinguished name of the certificate issuer as one string, such as `CN=YR2,O=Let's Encrypt,C=US`, compared exactly as the response shows it. | [Example](/reference/discovery/domain-search/examples/ssl-issuer-dn/) |
| `ssl.issuer.common_name` | The common name (CN) in the issuer's name, usually the name of the issuing CA certificate, such as `YR2`, `YR1` or `WE1`. | [Example](/reference/discovery/domain-search/examples/ssl-issuer-common-name/) |
| `ssl.issuer.country` | The country (C) in the issuer's name, as a two-letter code in the case the certificate uses, usually upper case such as `US` or `GB`. | [Example](/reference/discovery/domain-search/examples/ssl-issuer-country/) |
| `ssl.issuer.state` | The state or province (ST) in the issuer's name, as written in the certificate. | [Example](/reference/discovery/domain-search/examples/ssl-issuer-state/) |
| `ssl.issuer.locality` | The locality or city (L) in the issuer's name, as written in the certificate. | [Example](/reference/discovery/domain-search/examples/ssl-issuer-locality/) |
| `ssl.issuer.organization` | The organization (O) in the issuer's name, as written in the certificate, such as `Let's Encrypt`, `Google Trust Services` or `DigiCert Inc`. | [Example 1](/reference/discovery/domain-search/examples/ssl-issuer-organization/)<br>[Example 2](/reference/discovery/domain-search/examples/latest-certificate-changes-first/)<br>[Example 3](/reference/discovery/domain-search/examples/wildcard-certificates-from-lets-encrypt/) |
| `ssl.issuer.organizational_unit` | The organizational unit (OU) in the issuer's name, as written in the certificate. | [Example](/reference/discovery/domain-search/examples/ssl-issuer-organizational-unit/) |
| `ssl.subject_dn` | The distinguished name of the certificate subject as one string; a value that starts with `CN=*.` belongs to a wildcard certificate. | [Example 1](/reference/discovery/domain-search/examples/ssl-subject-dn/)<br>[Example 2](/reference/discovery/domain-search/examples/wildcard-certificates-from-lets-encrypt/) |
| `ssl.subject.common_name` | The common name (CN) in the subject's name, usually the host name the certificate was issued for, such as `example.com`. | [Example](/reference/discovery/domain-search/examples/ssl-subject-common-name/) |
| `ssl.subject.country` | The country (C) in the subject's name, as a two-letter code in the case the certificate uses, such as `DE`. | [Example](/reference/discovery/domain-search/examples/ssl-subject-country/) |
| `ssl.subject.state` | The state or province (ST) in the subject's name, as written in the certificate. | [Example](/reference/discovery/domain-search/examples/ssl-subject-state/) |
| `ssl.subject.locality` | The locality or city (L) in the subject's name, as written in the certificate. | [Example](/reference/discovery/domain-search/examples/ssl-subject-locality/) |
| `ssl.subject.organization` | The organization (O) in the subject's name, as written in the certificate: the company the certificate was issued to, when it names one. | [Example](/reference/discovery/domain-search/examples/ssl-subject-organization/) |
| `ssl.subject.organizational_unit` | The organizational unit (OU) in the subject's name, as written in the certificate. | [Example](/reference/discovery/domain-search/examples/ssl-subject-organizational-unit/) |
| `ssl.extensions.subject_alt_name.dns_names` | The DNS names in the certificate's Subject Alternative Name (SAN) extension, including wildcard names such as `*.example.com`. | [Example](/reference/discovery/domain-search/examples/ssl-extensions-subject-alt-name-dns-names/) |
| `webdata.url` | The URL recorded for Deepinfo's web visit to the FQDN (`webdata` is what Deepinfo saw over HTTP(S)); it takes filters, but search results do not return it. | [Example](/reference/discovery/domain-search/examples/webdata-url/) |
| `webdata.connection_status` | The outcome of Deepinfo's web visit to the FQDN: `success`, `not_resolved`, `timeout`, `thread_timeout`, `reset`, `refused`, `connection_error`, `ssl_error` or `too_many_redirects`. | [Example 1](/reference/discovery/domain-search/examples/webdata-connection-status/)<br>[Example 2](/reference/discovery/domain-search/examples/live-sites-without-hsts/)<br>[Example 3](/reference/discovery/domain-search/examples/missing-clickjacking-protection/) |
| `webdata.html.source_code_hash` | The SHA-256 hash of the HTML source Deepinfo received on its web visit to the FQDN, as 64 lower-case hex characters, so identical pages share the same value. | [Example](/reference/discovery/domain-search/examples/webdata-html-source-code-hash/) |
| `webdata.http.redirection_history.url` | The URL of one step of Deepinfo's web visit; `redirection_history` lists every URL requested, from the first one to the final page. | [Example](/reference/discovery/domain-search/examples/webdata-http-redirection-history-url/) |
| `webdata.http.final_url` | The URL Deepinfo's web visit ended on after all redirects, exactly as recorded, with or without a trailing `/`. | [Example](/reference/discovery/domain-search/examples/webdata-http-final-url/) |
| `webdata.http.final_fqdn` | The host name of the URL Deepinfo's web visit ended on after all redirects; an internationalized name is stored and compared in its readable (Unicode) form, not as punycode. | [Example](/reference/discovery/domain-search/examples/webdata-http-final-fqdn/) |
| `webdata.http.final_domain` | The registrable domain of the host Deepinfo's web visit ended on after all redirects, such as `cloudflare.com`; an internationalized name is stored and compared in its readable (Unicode) form, not as punycode. | [Example](/reference/discovery/domain-search/examples/webdata-http-final-domain/) |
| `webdata.http.headers.others.name` | The name of a response header that has no field of its own (`headers.others`), in lower case with dashes written as underscores: `cf-ray` becomes `cf_ray`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-others-name/) |
| `webdata.http.headers.others.value` | The value of a response header listed in `headers.others`, as text. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-others-value/) |
| `webdata.http.headers.access_control_allow_headers` | The value of the `Access-Control-Allow-Headers` response header on Deepinfo's web visit to the FQDN: the request headers the site accepts in cross-origin (CORS) requests. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-access-control-allow-headers/) |
| `webdata.http.headers.access_control_allow_methods` | The value of the `Access-Control-Allow-Methods` response header on Deepinfo's web visit to the FQDN: the HTTP methods the site allows in cross-origin (CORS) requests, such as `GET, POST, OPTIONS`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-access-control-allow-methods/) |
| `webdata.http.headers.access_control_allow_origin` | The value of the `Access-Control-Allow-Origin` response header on Deepinfo's web visit to the FQDN: the origins allowed to read the response in cross-origin (CORS) requests; `*` means any origin. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-access-control-allow-origin/) |
| `webdata.http.headers.cache_control` | The value of the `Cache-Control` response header on Deepinfo's web visit to the FQDN: the caching rules, such as `no-store` or `max-age=0`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-cache-control/) |
| `webdata.http.headers.clear_site_data` | The value of the `Clear-Site-Data` response header on Deepinfo's web visit to the FQDN: the browser data the site asks to clear, such as `cache`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-clear-site-data/) |
| `webdata.http.headers.content_encoding` | The value of the `Content-Encoding` response header on Deepinfo's web visit to the FQDN: the compression used, such as `gzip`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-content-encoding/) |
| `webdata.http.headers.content_security_policy` | The value of the `Content-Security-Policy` response header on Deepinfo's web visit to the FQDN: the sources the page may load scripts and other content from. | [Example 1](/reference/discovery/domain-search/examples/webdata-http-headers-content-security-policy/)<br>[Example 2](/reference/discovery/domain-search/examples/missing-clickjacking-protection/) |
| `webdata.http.headers.content_type` | The value of the `Content-Type` response header on Deepinfo's web visit to the FQDN: the media type and character set, such as `text/html; charset=UTF-8`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-content-type/) |
| `webdata.http.headers.cross_origin_embedder_policy` | The value of the `Cross-Origin-Embedder-Policy` response header on Deepinfo's web visit to the FQDN, such as `require-corp` or `credentialless`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-cross-origin-embedder-policy/) |
| `webdata.http.headers.cross_origin_opener_policy` | The value of the `Cross-Origin-Opener-Policy` response header on Deepinfo's web visit to the FQDN, such as `same-origin` or `unsafe-none`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-cross-origin-opener-policy/) |
| `webdata.http.headers.cross_origin_resource_policy` | The value of the `Cross-Origin-Resource-Policy` response header on Deepinfo's web visit to the FQDN, such as `same-origin` or `cross-origin`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-cross-origin-resource-policy/) |
| `webdata.http.headers.expect_ct` | The value of the `Expect-CT` response header on Deepinfo's web visit to the FQDN (Certificate Transparency enforcement), such as `max-age=86400, enforce`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-expect-ct/) |
| `webdata.http.headers.feature_policy` | The value of the `Feature-Policy` response header on Deepinfo's web visit to the FQDN: the older form of the policy that limits browser features such as camera or geolocation. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-feature-policy/) |
| `webdata.http.headers.last_modified` | The value of the `Last-Modified` response header on Deepinfo's web visit to the FQDN, stored as the header text (an HTTP date such as `Tue, 20 Jan 2026 04:02:54 GMT`), so it takes text operators, not date ranges. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-last-modified/) |
| `webdata.http.headers.permission_policy` | The value of the `Permission-Policy` response header on Deepinfo's web visit to the FQDN (singular spelling). The standard `Permissions-Policy` header is listed in `webdata.http.headers.others` as `permissions_policy`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-permission-policy/) |
| `webdata.http.headers.referrer_policy` | The value of the `Referrer-Policy` response header on Deepinfo's web visit to the FQDN, such as `strict-origin-when-cross-origin` or `no-referrer`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-referrer-policy/) |
| `webdata.http.headers.server` | The value of the `Server` response header on Deepinfo's web visit to the FQDN: the web server software the site reports, such as `nginx`, `Apache`, `LiteSpeed` or `cloudflare`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-server/) |
| `webdata.http.headers.set_cookie` | The value of the `Set-Cookie` response header on Deepinfo's web visit to the FQDN, as text starting with the cookie name, such as `PHPSESSID=`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-set-cookie/) |
| `webdata.http.headers.strict_transport_security` | The value of the `Strict-Transport-Security` response header on Deepinfo's web visit to the FQDN (HSTS), such as `max-age=31536000; includeSubDomains; preload`. | [Example 1](/reference/discovery/domain-search/examples/webdata-http-headers-strict-transport-security/)<br>[Example 2](/reference/discovery/domain-search/examples/live-sites-without-hsts/) |
| `webdata.http.headers.x_content_type_options` | The value of the `X-Content-Type-Options` response header on Deepinfo's web visit to the FQDN, usually `nosniff`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-x-content-type-options/) |
| `webdata.http.headers.x_download_options` | The value of the `X-Download-Options` response header on Deepinfo's web visit to the FQDN, usually `noopen`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-x-download-options/) |
| `webdata.http.headers.x_frame_options` | The value of the `X-Frame-Options` response header on Deepinfo's web visit to the FQDN: whether other sites may show the page in a frame, such as `SAMEORIGIN` or `DENY`, in the case the site sent. | [Example 1](/reference/discovery/domain-search/examples/webdata-http-headers-x-frame-options/)<br>[Example 2](/reference/discovery/domain-search/examples/missing-clickjacking-protection/) |
| `webdata.http.headers.x_permitted_cross_domain_policies` | The value of the `X-Permitted-Cross-Domain-Policies` response header on Deepinfo's web visit to the FQDN, such as `none`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-x-permitted-cross-domain-policies/) |
| `webdata.http.headers.x_powered_by` | The value of the `X-Powered-By` response header on Deepinfo's web visit to the FQDN: the technology the site reports, such as `PHP/8.2.32`, `ASP.NET` or `Next.js`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-x-powered-by/) |
| `webdata.http.headers.x_xss_protection` | The value of the `X-XSS-Protection` response header on Deepinfo's web visit to the FQDN, such as `1; mode=block` or `0`. | [Example](/reference/discovery/domain-search/examples/webdata-http-headers-x-xss-protection/) |
| `webdata.http.cookies.name` | The name of a cookie the site set on Deepinfo's web visit, such as `PHPSESSID` or `__cf_bm`. | [Example](/reference/discovery/domain-search/examples/webdata-http-cookies-name/) |
| `webdata.http.cookies.value` | The value of a cookie the site set on Deepinfo's web visit, as text. | [Example](/reference/discovery/domain-search/examples/webdata-http-cookies-value/) |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description | Example |
|---|---|---|
| `type` | Whether the record is a registrable domain or a subdomain: `1` = domain (such as `example.com`), `2` = subdomain (such as `www.example.com`). | [Example 1](/reference/discovery/domain-search/examples/type/)<br>[Example 2](/reference/discovery/domain-search/examples/exists-false-domains-without-a-registrar/)<br>[Example 3](/reference/discovery/domain-search/examples/must-not-registrable-domains-outside-com/)<br>[Example 4](/reference/discovery/domain-search/examples/sort-by-name/)<br>[Example 5](/reference/discovery/domain-search/examples/sort-by-extension/)<br>[Example 6](/reference/discovery/domain-search/examples/newest-registrations-first/)<br>[Example 7](/reference/discovery/domain-search/examples/latest-whois-changes-first/)<br>[Example 8](/reference/discovery/domain-search/examples/second-page-of-results/)<br>[Example 9](/reference/discovery/domain-search/examples/larger-pages/)<br>[Example 10](/reference/discovery/domain-search/examples/last-reachable-page/) |
| `subdomain.length` | The number of characters in the subdomain part (0 to 255), counted in its ASCII (punycode) form without the dots between labels: `6` for `api.dev.example.com`. | [Example](/reference/discovery/domain-search/examples/subdomain-length/) |
| `subdomain_level_count` | The number of labels in front of the registrable domain: `0` for the domain itself, `1` for `www.example.com`, `2` for `a.b.example.com`. | [Example](/reference/discovery/domain-search/examples/subdomain-level-count/) |
| `domain.name.length` | The number of characters in the domain name without its extension, counted in its ASCII (punycode) form (0 to 63). | [Example 1](/reference/discovery/domain-search/examples/domain-name-length/)<br>[Example 2](/reference/discovery/domain-search/examples/range-name-length-between-3-and-4/) |
| `domain.name.keyword_count` | The number of words detected in the domain name (the length of `domain.name.keywords`). | [Example](/reference/discovery/domain-search/examples/domain-name-keyword-count/) |
| `domain.extension_type` | The kind of extension: `1` = generic (gTLD, such as `.com`), `2` = country code (ccTLD, such as `.de` or `.co.uk`). | [Example](/reference/discovery/domain-search/examples/domain-extension-type/) |
| `domain.whois.create_date` | The date the registrable domain was created (registered), from its WHOIS record (UTC, ISO 8601). | [Example 1](/reference/discovery/domain-search/examples/domain-whois-create-date/)<br>[Example 2](/reference/discovery/domain-search/examples/all-three-new-shops-without-whois-privacy/)<br>[Example 3](/reference/discovery/domain-search/examples/newest-registrations-first/)<br>[Example 4](/reference/discovery/domain-search/examples/new-look-alikes-with-mail-servers/) |
| `domain.whois.update_date` | The last-updated date that the domain's WHOIS record itself reports (UTC, ISO 8601); `domain.whois_last_change_date` is when Deepinfo saw the record change. | [Example](/reference/discovery/domain-search/examples/domain-whois-update-date/) |
| `domain.whois.expiry_date` | The date the domain's registration expires, from its WHOIS record (UTC, ISO 8601). | [Example 1](/reference/discovery/domain-search/examples/domain-whois-expiry-date/)<br>[Example 2](/reference/discovery/domain-search/examples/soonest-to-expire-first/)<br>[Example 3](/reference/discovery/domain-search/examples/expiring-soon-with-whois-privacy/) |
| `domain.whois_create_date_historical` | Every creation date seen in the domain's WHOIS records over time (UTC, ISO 8601), so a domain that was registered again still matches on its earlier dates. | [Example](/reference/discovery/domain-search/examples/domain-whois-create-date-historical/) |
| `domain.whois_last_change_date` | The last time Deepinfo saw the domain's WHOIS record change (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/domain-whois-last-change-date/) |
| `domain.dns.a.update_date` | The update date Deepinfo recorded for the registrable domain's A records (UTC, ISO 8601); it is set even when the domain has no A record. | [Example](/reference/discovery/domain-search/examples/domain-dns-a-update-date/) |
| `domain.dns_update_date` | A DNS update date of the registrable domain (UTC, ISO 8601) that takes date filters; search results do not return this field. | [Example](/reference/discovery/domain-search/examples/domain-dns-update-date/) |
| `domain.dns_last_change_date` | The last time Deepinfo saw the DNS records of the registrable domain change (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/domain-dns-last-change-date/) |
| `domain.ssl.validity.start_date` | The date the registrable domain's TLS certificate became valid, its not-before date (UTC, ISO 8601). `ssl.validity.start_date` holds the same for the FQDN's own certificate. | [Example](/reference/discovery/domain-search/examples/domain-ssl-validity-start-date/) |
| `domain.ssl.validity.end_date` | The date the registrable domain's TLS certificate expires, its not-after date (UTC, ISO 8601). `ssl.validity.end_date` holds the same for the FQDN's own certificate. | [Example](/reference/discovery/domain-search/examples/domain-ssl-validity-end-date/) |
| `domain.ssl_last_change_date` | The last time Deepinfo saw the registrable domain's TLS certificate change (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/domain-ssl-last-change-date/) |
| `dns.a.update_date` | The update date Deepinfo recorded for the FQDN's A records (UTC, ISO 8601); it is set even when the FQDN has no A record. | [Example](/reference/discovery/domain-search/examples/dns-a-update-date/) |
| `dns.aaaa.update_date` | The update date Deepinfo recorded for the FQDN's AAAA records (UTC, ISO 8601); it is set even when the FQDN has no AAAA record. | [Example](/reference/discovery/domain-search/examples/dns-aaaa-update-date/) |
| `dns.ns.update_date` | The update date Deepinfo recorded for the FQDN's NS records (UTC, ISO 8601); it is set even when the FQDN has no NS record. | [Example](/reference/discovery/domain-search/examples/dns-ns-update-date/) |
| `dns.mx.update_date` | The update date Deepinfo recorded for the FQDN's MX records (UTC, ISO 8601); it is set even when the FQDN has no MX record. | [Example](/reference/discovery/domain-search/examples/dns-mx-update-date/) |
| `dns.soa.update_date` | The update date Deepinfo recorded for the FQDN's SOA records (UTC, ISO 8601); it is set even when the FQDN has no SOA record. | [Example](/reference/discovery/domain-search/examples/dns-soa-update-date/) |
| `dns.txt.update_date` | The update date Deepinfo recorded for the FQDN's TXT records (UTC, ISO 8601); it is set even when the FQDN has no TXT record. | [Example](/reference/discovery/domain-search/examples/dns-txt-update-date/) |
| `dns.cname.update_date` | The update date Deepinfo recorded for the FQDN's CNAME records (UTC, ISO 8601); it is set even when the FQDN has no CNAME record. | [Example](/reference/discovery/domain-search/examples/dns-cname-update-date/) |
| `dns.others.update_date` | The update date Deepinfo recorded for a record in `dns.others` (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/dns-others-update-date/) |
| `dns_update_date` | A DNS update date of the FQDN (UTC, ISO 8601) that takes date filters; search results do not return this field. | [Example](/reference/discovery/domain-search/examples/dns-update-date/) |
| `dns_last_change_date` | The last time Deepinfo saw the DNS records of the FQDN change (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/dns-last-change-date/) |
| `ssl.validity.start_date` | The date the FQDN's TLS certificate became valid, its not-before date (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/ssl-validity-start-date/) |
| `ssl.validity.end_date` | The date the FQDN's TLS certificate expires, its not-after date (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/ssl-validity-end-date/) |
| `ssl.validity.length` | The validity period of the FQDN's TLS certificate in seconds, from start date to end date: 7,776,000 seconds are 90 days. | [Example](/reference/discovery/domain-search/examples/ssl-validity-length/) |
| `ssl_last_change_date` | The last time Deepinfo saw the FQDN's TLS certificate change (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/ssl-last-change-date/) |
| `webdata.http.status_code_first` | The HTTP status code of the first response on Deepinfo's web visit to the FQDN, such as `200`, or `301` for a permanent redirect. | [Example 1](/reference/discovery/domain-search/examples/webdata-http-status-code-first/)<br>[Example 2](/reference/discovery/domain-search/examples/redirects-away-to-another-site/) |
| `webdata.http.status_code_last` | The HTTP status code of the final response on Deepinfo's web visit, after all redirects, such as `200`, `403` or `404`. | [Example](/reference/discovery/domain-search/examples/webdata-http-status-code-last/) |
| `webdata.http.redirection_history.status_code` | The HTTP status code returned at one step of Deepinfo's web visit, such as `301` or `302` for a redirect and `200` for the final page. | [Example](/reference/discovery/domain-search/examples/webdata-http-redirection-history-status-code/) |

Operators: `eq`, `in`, `exists`

| Field | Description | Example |
|---|---|---|
| `is_idn` | `true` when the FQDN is an internationalized domain name (IDN) with non-ASCII characters; `punycode` then holds its ASCII form and `unicode` the readable one. | [Example 1](/reference/discovery/domain-search/examples/is-idn/)<br>[Example 2](/reference/discovery/domain-search/examples/confusable-idn-domains/) |
| `subdomain.is_idn` | `true` when the subdomain part contains non-ASCII (internationalized) characters. | [Example](/reference/discovery/domain-search/examples/subdomain-is-idn/) |
| `subdomain.contains_letter` | `true` when the subdomain part contains at least one letter, checked on its readable (Unicode) form. | [Example](/reference/discovery/domain-search/examples/subdomain-contains-letter/) |
| `subdomain.contains_number` | `true` when the subdomain part contains at least one digit, checked on its readable (Unicode) form, so the digits of an `xn--` punycode form do not count. | [Example](/reference/discovery/domain-search/examples/subdomain-contains-number/) |
| `subdomain.contains_hyphen` | `true` when the subdomain part contains at least one hyphen, checked on its readable (Unicode) form, so the `xn--` prefix of an IDN does not count. | [Example](/reference/discovery/domain-search/examples/subdomain-contains-hyphen/) |
| `name.contains_confusable` | `true` when the FQDN's name (without its extension) contains confusable characters: letters that look like others, such as Cyrillic `а` and Latin `a`, a common trick in look-alike domains. | [Example 1](/reference/discovery/domain-search/examples/name-contains-confusable/)<br>[Example 2](/reference/discovery/domain-search/examples/confusable-idn-domains/) |
| `domain.is_idn` | `true` when the registrable domain contains non-ASCII (internationalized) characters. | [Example](/reference/discovery/domain-search/examples/domain-is-idn/) |
| `domain.name.contains_letter` | `true` when the domain name (without its extension) contains at least one letter, checked on its readable (Unicode) form. | [Example](/reference/discovery/domain-search/examples/domain-name-contains-letter/) |
| `domain.name.contains_number` | `true` when the domain name (without its extension) contains at least one digit, checked on its readable (Unicode) form, so the digits of an `xn--` punycode form do not count. | [Example](/reference/discovery/domain-search/examples/domain-name-contains-number/) |
| `domain.name.contains_hyphen` | `true` when the domain name (without its extension) contains at least one hyphen, checked on its readable (Unicode) form, so the `xn--` prefix of an IDN does not count. | [Example](/reference/discovery/domain-search/examples/domain-name-contains-hyphen/) |
| `domain.extension.is_idn` | `true` when the extension contains non-ASCII (internationalized) characters, such as `.рф` (`xn--p1ai`). | [Example](/reference/discovery/domain-search/examples/domain-extension-is-idn/) |
| `domain.whois_privacy_enabled` | `true` when the domain's WHOIS record hides the registrant's details, through a privacy service or redaction, `false` when it does not. | [Example 1](/reference/discovery/domain-search/examples/domain-whois-privacy-enabled/)<br>[Example 2](/reference/discovery/domain-search/examples/all-three-new-shops-without-whois-privacy/)<br>[Example 3](/reference/discovery/domain-search/examples/expiring-soon-with-whois-privacy/) |
| `ssl.signature.is_self_signed` | `true` when the FQDN's TLS certificate is self-signed, signed with its own key instead of by a certificate authority. | [Example 1](/reference/discovery/domain-search/examples/ssl-signature-is-self-signed/)<br>[Example 2](/reference/discovery/domain-search/examples/self-signed-or-invalid-certificates/) |
| `ssl.signature.is_valid` | `true` when the signature of the FQDN's TLS certificate validates, `false` when it does not. | [Example 1](/reference/discovery/domain-search/examples/ssl-signature-is-valid/)<br>[Example 2](/reference/discovery/domain-search/examples/self-signed-or-invalid-certificates/) |
| `webdata.http.external_redirection` | `true` when Deepinfo's web visit was redirected to a different registrable domain, `false` when it ended on the FQDN's own domain, for example on its `www.` host. | [Example 1](/reference/discovery/domain-search/examples/webdata-http-external-redirection/)<br>[Example 2](/reference/discovery/domain-search/examples/redirects-away-to-another-site/) |

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description | Example |
|---|---|---|
| `subdomain` | The subdomain part of the FQDN, everything in front of the registrable domain (`mail` in `mail.example.com`), compared in its ASCII (punycode) form. It is `null` for a registrable domain. | [Example](/reference/discovery/domain-search/examples/subdomain/) |
| `domain.name` | The name of the registrable domain without its extension, compared in its ASCII (punycode) form: `example` in `example.com`, and the same when the extension has two parts, such as `co.uk`. | [Example 1](/reference/discovery/domain-search/examples/domain-name/)<br>[Example 2](/reference/discovery/domain-search/examples/wildcard-names-containing-a-word/)<br>[Example 3](/reference/discovery/domain-search/examples/fuzzy-names-close-to-a-brand/)<br>[Example 4](/reference/discovery/domain-search/examples/endswith-names-ending-in-a-word/)<br>[Example 5](/reference/discovery/domain-search/examples/in-one-of-several-extensions/)<br>[Example 6](/reference/discovery/domain-search/examples/contains-any-phishing-style-keywords/)<br>[Example 7](/reference/discovery/domain-search/examples/contains-all-every-keyword-present/)<br>[Example 8](/reference/discovery/domain-search/examples/look-alikes-excluding-the-real-domain/)<br>[Example 9](/reference/discovery/domain-search/examples/must-not-registrable-domains-outside-com/)<br>[Example 10](/reference/discovery/domain-search/examples/sort-by-extension/)<br>[Example 11](/reference/discovery/domain-search/examples/sort-by-two-fields/)<br>[Example 12](/reference/discovery/domain-search/examples/new-look-alikes-with-mail-servers/) |

Operators: `eq`, `in`, `startswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description | Example |
|---|---|---|
| `name.latinized` | Latin look-alike forms of the FQDN's name (the FQDN without its extension) when it has non-Latin or accented letters: each character becomes the Latin letter it resembles (Cyrillic `р` becomes `p`), so `istanbul` also finds names written with `İ`. | [Example](/reference/discovery/domain-search/examples/name-latinized/) |

### Sortable Fields

Example: a worked example that sorts by the field, with the request and the response it returns.

| Field | Description | Example |
|---|---|---|
| `punycode` | The FQDN in its ASCII (punycode) form, such as `www.example.com`; sorting on it lists results alphabetically. Filters use the same value under the name `fqdn`. | [Example](/reference/discovery/domain-search/examples/sort-by-name/) |
| `domain.extension.punycode` | The extension of the registrable domain in its ASCII (punycode) form, such as `com` or `co.uk`; sorting on it lists results by extension. | [Example 1](/reference/discovery/domain-search/examples/sort-by-extension/)<br>[Example 2](/reference/discovery/domain-search/examples/sort-by-two-fields/) |
| `domain.whois.create_date` | The date the registrable domain was created (registered), from its WHOIS record (UTC, ISO 8601). | [Example 1](/reference/discovery/domain-search/examples/newest-registrations-first/)<br>[Example 2](/reference/discovery/domain-search/examples/sort-by-two-fields/) |
| `domain.whois.expiry_date` | The date the domain's registration expires, from its WHOIS record (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/soonest-to-expire-first/) |
| `domain.whois.update_date` | The last-updated date that the domain's WHOIS record itself reports (UTC, ISO 8601); `domain.whois_last_change_date` is when Deepinfo saw the record change. | [Example](/reference/discovery/domain-search/examples/most-recently-updated-whois-first/) |
| `domain.whois_last_change_date` | The last time Deepinfo saw the domain's WHOIS record change (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/latest-whois-changes-first/) |
| `dns_last_change_date` | The last time Deepinfo saw the DNS records of the FQDN change (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/latest-dns-changes-first/) |
| `ssl_last_change_date` | The last time Deepinfo saw the FQDN's TLS certificate change (UTC, ISO 8601). | [Example](/reference/discovery/domain-search/examples/latest-certificate-changes-first/) |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].punycode` | string |  |
| `results[].unicode` | string |  |
| `results[].is_idn` | boolean |  |
| `results[].subdomain` | object |  |
| `results[].subdomain_last` | object |  |
| `results[].subdomain_root` | object |  |
| `results[].name` | object |  |
| `results[].domain` | object |  |
| `results[].type` | integer |  |
| `results[].subdomain_level_count` | integer |  |
| `results[].dns` | object |  |
| `results[].dns_last_change_date` | string | date-time |
| `results[].ip_history` | array of string |  |
| `results[].ssl` | object |  |
| `results[].ssl_last_change_date` | string | date-time |
| `results[].webdata` | object |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].punycode` | string |
| `results[].unicode` | string |
| `results[].is_idn` | boolean |
| `results[].subdomain` | null |
| `results[].subdomain_last` | null |
| `results[].subdomain_root` | null |
| `results[].name` | object |
| `results[].name.punycode` | string |
| `results[].name.unicode` | string |
| `results[].name.is_idn` | boolean |
| `results[].name.contains_letter` | boolean |
| `results[].name.contains_number` | boolean |
| `results[].name.contains_hyphen` | boolean |
| `results[].name.length` | number |
| `results[].name.lang` | string |
| `results[].name.keywords` | array<string> |
| `results[].name.keyword_count` | number |
| `results[].name.latinized` | array |
| `results[].name.contains_confusable` | boolean |
| `results[].domain` | object |
| `results[].domain.punycode` | string |
| `results[].domain.unicode` | string |
| `results[].domain.is_idn` | boolean |
| `results[].domain.name` | object |
| `results[].domain.name.punycode` | string |
| `results[].domain.name.unicode` | string |
| `results[].domain.name.is_idn` | boolean |
| `results[].domain.name.contains_letter` | boolean |
| `results[].domain.name.contains_number` | boolean |
| `results[].domain.name.contains_hyphen` | boolean |
| `results[].domain.name.length` | number |
| `results[].domain.name.lang` | string |
| `results[].domain.name.keywords` | array<string> |
| `results[].domain.name.keyword_count` | number |
| `results[].domain.extension` | object |
| `results[].domain.extension.punycode` | string |
| `results[].domain.extension.unicode` | string |
| `results[].domain.extension.is_idn` | boolean |
| `results[].domain.extension_root` | object |
| `results[].domain.extension_root.punycode` | string |
| `results[].domain.extension_root.unicode` | string |
| `results[].domain.extension_root.is_idn` | boolean |
| `results[].domain.extension_sub` | null |
| `results[].domain.extension_type` | number |
| `results[].domain.reserved` | null |
| `results[].domain.premium` | null |
| `results[].domain.registered` | boolean |
| `results[].domain.whois` | object |
| `results[].domain.whois.create_date` | string \| null |
| `results[].domain.whois.update_date` | string |
| `results[].domain.whois.expiry_date` | string \| null |
| `results[].domain.whois.registrar` | string \| null |
| `results[].domain.whois.registrant` | object |
| `results[].domain.whois.registrant.name` | null |
| `results[].domain.whois.registrant.organization` | null |
| `results[].domain.whois.registrant.street` | null |
| `results[].domain.whois.registrant.city` | null |
| `results[].domain.whois.registrant.state` | null |
| `results[].domain.whois.registrant.postal_code` | null |
| `results[].domain.whois.registrant.country` | null |
| `results[].domain.whois.registrant.phone` | null |
| `results[].domain.whois.registrant.email` | null |
| `results[].domain.whois.name_servers` | array<string> |
| `results[].domain.whois.domain_status` | array<string> |
| `results[].domain.whois.whois_server` | string \| null |
| `results[].domain.whois.check_date` | string |
| `results[].domain.whois_normalized` | object |
| `results[].domain.whois_normalized.registrant` | null |
| `results[].domain.whois_last_check_date` | string |
| `results[].domain.whois_create_date_historical` | array<string> |
| `results[].domain.whois_last_change_date` | string \| null |
| `results[].domain.whois_registrant_email_historical` | array<string> |
| `results[].domain.whois_privacy_enabled` | null |
| `results[].domain.dns` | object |
| `results[].domain.dns.a` | object |
| `results[].domain.dns.a.update_date` | string |
| `results[].domain.dns.a.ip_addresses` | array<string> |
| `results[].domain.dns_last_change_date` | string |
| `results[].domain.ip_history` | array<string> |
| `results[].domain.ssl` | object |
| `results[].domain.ssl.validity` | object |
| `results[].domain.ssl.validity.start_date` | string |
| `results[].domain.ssl.validity.end_date` | string |
| `results[].domain.ssl.serial_number` | string |
| `results[].domain.ssl.check_date` | string |
| `results[].domain.ssl_last_change_date` | string |
| `results[].type` | number |
| `results[].subdomain_level_count` | number |
| `results[].dns` | object |
| `results[].dns.a` | object |
| `results[].dns.a.update_date` | string |
| `results[].dns.a.ip_addresses` | array<string> |
| `results[].dns.aaaa` | object |
| `results[].dns.aaaa.update_date` | string |
| `results[].dns.aaaa.ip_addresses` | array |
| `results[].dns.ns` | object |
| `results[].dns.ns.update_date` | string |
| `results[].dns.ns.name_servers` | array<string> |
| `results[].dns.mx` | object |
| `results[].dns.mx.update_date` | string |
| `results[].dns.mx.mail_servers` | array<string> |
| `results[].dns.soa` | object |
| `results[].dns.soa.update_date` | string |
| `results[].dns.soa.mnames` | array<string> |
| `results[].dns.soa.rnames` | array<string> |
| `results[].dns.soa.rname_emails` | array<string> |
| `results[].dns.txt` | object |
| `results[].dns.txt.update_date` | string |
| `results[].dns.txt.values` | array<string> |
| `results[].dns.cname` | object |
| `results[].dns.cname.update_date` | string |
| `results[].dns.cname.values` | array |
| `results[].dns.others` | array |
| `results[].dns_last_change_date` | string |
| `results[].ip_history` | array<string> |
| `results[].ssl` | object |
| `results[].ssl.tags` | array<string> |
| `results[].ssl.fqdns` | array<string> |
| `results[].ssl.version` | number |
| `results[].ssl.serial_number` | string |
| `results[].ssl.fingerprint` | object |
| `results[].ssl.fingerprint.sha256` | string |
| `results[].ssl.fingerprint.sha1` | string |
| `results[].ssl.fingerprint.md5` | string |
| `results[].ssl.validity` | object |
| `results[].ssl.validity.start_date` | string |
| `results[].ssl.validity.end_date` | string |
| `results[].ssl.validity.length` | number |
| `results[].ssl.signature` | object |
| `results[].ssl.signature.is_self_signed` | boolean |
| `results[].ssl.signature.is_valid` | boolean |
| `results[].ssl.signature.value` | string |
| `results[].ssl.signature.algorithm` | object |
| `results[].ssl.signature.algorithm.oid` | string |
| `results[].ssl.signature.algorithm.name` | string |
| `results[].ssl.issuer_dn` | string |
| `results[].ssl.issuer` | object |
| `results[].ssl.issuer.common_name` | string |
| `results[].ssl.issuer.country` | string |
| `results[].ssl.issuer.state` | null |
| `results[].ssl.issuer.locality` | null |
| `results[].ssl.issuer.organization` | string |
| `results[].ssl.issuer.organizational_unit` | null |
| `results[].ssl.subject_dn` | string |
| `results[].ssl.subject` | object |
| `results[].ssl.subject.common_name` | string |
| `results[].ssl.subject.country` | null |
| `results[].ssl.subject.state` | null |
| `results[].ssl.subject.locality` | null |
| `results[].ssl.subject.organization` | null |
| `results[].ssl.subject.organizational_unit` | null |
| `results[].ssl.extensions` | object |
| `results[].ssl.extensions.authority_key_id` | string |
| `results[].ssl.extensions.basic_constraints` | object |
| `results[].ssl.extensions.basic_constraints.is_ca` | boolean |
| `results[].ssl.extensions.certificate_policies` | array<string> |
| `results[].ssl.extensions.extended_key_usage` | object |
| `results[].ssl.extensions.extended_key_usage.client_auth` | null |
| `results[].ssl.extensions.extended_key_usage.server_auth` | boolean |
| `results[].ssl.extensions.key_usage` | object |
| `results[].ssl.extensions.key_usage.digital_signature` | boolean |
| `results[].ssl.extensions.key_usage.content_commitment` | boolean |
| `results[].ssl.extensions.key_usage.key_agreement` | boolean |
| `results[].ssl.extensions.key_usage.data_encipherment` | boolean |
| `results[].ssl.extensions.key_usage.key_encipherment` | boolean |
| `results[].ssl.extensions.key_usage.key_cert_sign` | boolean |
| `results[].ssl.extensions.key_usage.crl_sign` | boolean |
| `results[].ssl.extensions.signed_certificate_timestamps` | array<string> |
| `results[].ssl.extensions.subject_alt_name` | object |
| `results[].ssl.extensions.subject_alt_name.dns_names` | array<string> |
| `results[].ssl.extensions.subject_key_id` | string |
| `results[].ssl.check_date` | string |
| `results[].ssl_last_change_date` | string |
| `results[].webdata` | object |
| `results[].webdata.connection_status` | string |
| `results[].webdata.html` | object |
| `results[].webdata.html.source_code_hash` | string |
| `results[].webdata.http` | object |
| `results[].webdata.http.status_code_first` | number |
| `results[].webdata.http.status_code_last` | number |
| `results[].webdata.http.redirection_history` | array<object> |
| `results[].webdata.http.redirection_history[].url` | string |
| `results[].webdata.http.redirection_history[].status_code` | number |
| `results[].webdata.http.external_redirection` | null |
| `results[].webdata.http.final_url` | string |
| `results[].webdata.http.final_fqdn` | string |
| `results[].webdata.http.final_domain` | string |
| `results[].webdata.http.headers` | object |
| `results[].webdata.http.headers.others` | array<object> |
| `results[].webdata.http.headers.others[].name` | string |
| `results[].webdata.http.headers.others[].value` | string |
| `results[].webdata.http.headers.access_control_allow_headers` | null |
| `results[].webdata.http.headers.access_control_allow_methods` | null |
| `results[].webdata.http.headers.access_control_allow_origin` | null |
| `results[].webdata.http.headers.cache_control` | null |
| `results[].webdata.http.headers.clear_site_data` | null |
| `results[].webdata.http.headers.content_encoding` | string \| null |
| `results[].webdata.http.headers.content_security_policy` | null |
| `results[].webdata.http.headers.content_type` | string \| null |
| `results[].webdata.http.headers.cross_origin_embedder_policy` | null |
| `results[].webdata.http.headers.cross_origin_opener_policy` | null |
| `results[].webdata.http.headers.cross_origin_resource_policy` | null |
| `results[].webdata.http.headers.expect_ct` | null |
| `results[].webdata.http.headers.feature_policy` | null |
| `results[].webdata.http.headers.last_modified` | string \| null |
| `results[].webdata.http.headers.permission_policy` | null |
| `results[].webdata.http.headers.referrer_policy` | null |
| `results[].webdata.http.headers.server` | string |
| `results[].webdata.http.headers.set_cookie` | string \| null |
| `results[].webdata.http.headers.strict_transport_security` | null |
| `results[].webdata.http.headers.x_content_type_options` | null |
| `results[].webdata.http.headers.x_download_options` | null |
| `results[].webdata.http.headers.x_frame_options` | null |
| `results[].webdata.http.headers.x_permitted_cross_domain_policies` | null |
| `results[].webdata.http.headers.x_powered_by` | null |
| `results[].webdata.http.headers.x_xss_protection` | null |
| `results[].webdata.http.cookies` | array<object> |
| `results[].webdata.http.cookies[].name` | string |
| `results[].webdata.http.cookies[].value` | string |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/domain-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 1932808835,
  "results": [
    {
      "punycode": "jjcyyl.com",
      "unicode": "jjcyyl.com",
      "is_idn": false,
      "subdomain": null,
      "subdomain_last": null,
      "subdomain_root": null,
      "name": {
        "punycode": "jjcyyl",
        "unicode": "jjcyyl",
        "is_idn": false,
        "contains_letter": true,
        "contains_number": false,
        "contains_hyphen": false,
        "length": 6,
        "lang": "en",
        "keywords": [
          "jjc",
          "yyl"
        ],
        "keyword_count": 2,
        "latinized": [],
        "contains_confusable": false
      },
      "domain": {
        "punycode": "jjcyyl.com",
        "unicode": "jjcyyl.com",
        "is_idn": false,
        "name": {
          "punycode": "jjcyyl",
          "unicode": "jjcyyl",
          "is_idn": false,
          "contains_letter": true,
          "contains_number": false,
          "contains_hyphen": false,
          "length": 6,
          "lang": "en",
          "keywords": [
            "jjc",
            "yyl"
          ],
          "keyword_count": 2
        },
        "extension": {
          "punycode": "com",
          "unicode": "com",
          "is_idn": false
        },
        "extension_root": {
          "punycode": "com",
          "unicode": "com",
          "is_idn": false
        },
        "extension_sub": null,
        "extension_type": 1,
        "reserved": null,
        "premium": null,
        "registered": true,
        "whois": {
          "create_date": "2018-07-23T06:35:52Z",
          "update_date": "2026-07-03T00:55:38Z",
          "expiry_date": "2027-07-23T06:35:52Z",
          "registrar": "spaceship, inc.",
          "registrant": {
            "name": null,
            "organization": null,
            "street": null,
            "city": null,
            "state": null,
            "postal_code": null,
            "country": null,
            "phone": null,
            "email": null
          },
          "name_servers": [
            "launch1.spaceship.net",
            "launch2.spaceship.net"
          ],
          "domain_status": [
            "clienttransferprohibited"
          ],
          "whois_server": "whois.spaceship.com",
          "check_date": "2026-07-20T03:16:08Z"
        },
        "whois_normalized": {
          "registrant": null
        },
        "whois_last_check_date": "2026-07-20T03:16:08Z",
        "whois_create_date_historical": [
          "2018-07-23T06:35:52Z"
        ],
        "whois_last_change_date": "2026-07-20T03:16:15Z",
        "whois_registrant_email_historical": [
          "redacted for privacy",
          "link at http://whois.xinnet.com/sendemail/jjcyyl.com"
        ],
        "whois_privacy_enabled": null,
        "dns": {
          "a": {
            "update_date": "2026-08-25T16:43:01Z",
            "ip_addresses": [
              "192.238.152.241"
            ]
          }
        },
        "dns_last_change_date": "2026-07-07T22:28:35Z",
        "ip_history": [
          "154.23.207.42",
          "170.106.49.50"
        ],
        "ssl": {
          "validity": {
            "start_date": "2026-08-09T01:02:19Z",
            "end_date": "2026-11-07T01:02:18Z"
          },
          "serial_number": "490802588813011265731042502391990937973573",
          "check_date": "2026-09-03T16:34:41Z"
        },
        "ssl_last_change_date": "2026-09-03T16:35:23Z"
      },
      "type": 1,
      "subdomain_level_count": 0,
      "dns": {
        "a": {
          "update_date": "2026-08-25T16:43:01Z",
          "ip_addresses": [
            "192.238.152.241"
          ]
        },
        "aaaa": {
          "update_date": "2026-08-25T16:43:01Z",
          "ip_addresses": []
        },
        "ns": {
          "update_date": "2026-08-25T16:43:01Z",
          "name_servers": [
            "launch1.spaceship.net",
            "launch2.spaceship.net"
          ]
        },
        "mx": {
          "update_date": "2026-08-25T16:43:01Z",
          "mail_servers": []
        },
        "soa": {
          "update_date": "2026-08-25T16:43:01Z",
          "mnames": [
            "launch1.spaceship.net"
          ],
          "rnames": [
            "support.spaceship.com"
          ],
          "rname_emails": [
            "user@spaceship.com"
          ]
        },
        "txt": {
          "update_date": "2026-08-25T16:43:01Z",
          "values": []
        },
        "cname": {
          "update_date": "2026-08-25T16:43:01Z",
          "values": []
        },
        "others": []
      },
      "dns_last_change_date": "2026-07-07T22:28:33Z",
      "ip_history": [
        "154.23.207.42",
        "170.106.49.50"
      ],
      "ssl": {
        "tags": [
          "dla"
        ],
        "fqdns": [
          "50eg.com",
          "danyangwm.com"
        ],
        "version": 3,
        "serial_number": "490802588813011265731042502391990937973573",
        "fingerprint": {
          "sha256": "e16b523f54d2d0cb217eec73a8e1f0cc649aa6724cce3efa626d4070f9dfad18",
          "sha1": "268e336c2a11d649c5e61844a518cf0763f68ef3",
          "md5": "a5e51f43b7b8a264e84222a37850485d"
        },
        "validity": {
          "start_date": "2026-08-09T01:02:19Z",
          "end_date": "2026-11-07T01:02:18Z",
          "length": 7775999
        },
        "signature": {
          "is_self_signed": false,
          "is_valid": true,
          "value": "Xd+e75rjvwgjbY/rRYB4FnTY9g3N3k0bWkDRValRnM8wROuPegP0gVTK94o3GDEM3Xz2A10+mbzBFnjV8G2eK1b6Dtv9FoAYSMMLP03QEenJuDXwa47rOtvhdpDpiKfK9y9shXmzOGpzjzFYDePeXkZ5yE9nvbyKaWBUv8PW0z//BPApBH3FyypNPzmPF5pd3oAL1hboGwq9UoPle24oKl/vAOP5qc0h39Vz4w+6oyjivtuU5qAj+qa5SIQcM3KkKySnr4scF9GZF/LXsWe64NJEJQp0w2SErXhWse6ooMbeInW05CXWgsqHZlzCGOe2mDmKsB0fNb74V1K17ubx0Q==",
          "algorithm": {
            "oid": "1.2.840.113549.1.1.11",
            "name": "sha256"
          }
        },
        "issuer_dn": "CN=YR2,O=Let's Encrypt,C=US",
        "issuer": {
          "common_name": "YR2",
          "country": "US",
          "state": null,
          "locality": null,
          "organization": "Let's Encrypt",
          "organizational_unit": null
        },
        "subject_dn": "CN=job0758.com.cn",
        "subject": {
          "common_name": "job0758.com.cn",
          "country": null,
          "state": null,
          "locality": null,
          "organization": null,
          "organizational_unit": null
        },
        "extensions": {
          "authority_key_id": "QBUtJnntMiCe35pyHdYyH4EMgQw=",
          "basic_constraints": {
            "is_ca": false
          },
          "certificate_policies": [
            "2.23.140.1.2.1"
          ],
          "extended_key_usage": {
            "client_auth": null,
            "server_auth": true
          },
          "key_usage": {
            "digital_signature": true,
            "content_commitment": false,
            "key_agreement": false,
            "data_encipherment": false,
            "key_encipherment": true,
            "key_cert_sign": false,
            "crl_sign": false
          },
          "signed_certificate_timestamps": [
            "2026-08-09T02:00:49Z",
            "2026-08-09T02:00:50Z"
          ],
          "subject_alt_name": {
            "dns_names": [
              "50eg.com",
              "danyangwm.com"
            ]
          },
          "subject_key_id": "+IodGf7ET61TYCE90DG1Gw5dXtA="
        },
        "check_date": "2026-09-03T16:34:41Z"
      },
      "ssl_last_change_date": "2026-09-03T16:35:22Z",
      "webdata": {
        "connection_status": "success",
        "html": {
          "source_code_hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
        },
        "http": {
          "status_code_first": 444,
          "status_code_last": 444,
          "redirection_history": [
            {
              "url": "http://jjcyyl.com/",
              "status_code": 444
            }
          ],
          "external_redirection": null,
          "final_url": "http://jjcyyl.com/",
          "final_fqdn": "jjcyyl.com",
          "final_domain": "jjcyyl.com",
          "headers": {
            "others": [
              {
                "name": "date",
                "value": "Tue, 16 Jun 2026 13:57:19 GMT"
              },
              {
                "name": "content_length",
                "value": "0"
              }
            ],
            "access_control_allow_headers": null,
            "access_control_allow_methods": null,
            "access_control_allow_origin": null,
            "cache_control": null,
            "clear_site_data": null,
            "content_encoding": null,
            "content_security_policy": null,
            "content_type": null,
            "cross_origin_embedder_policy": null,
            "cross_origin_opener_policy": null,
            "cross_origin_resource_policy": null,
            "expect_ct": null,
            "feature_policy": null,
            "last_modified": null,
            "permission_policy": null,
            "referrer_policy": null,
            "server": "nginx",
            "set_cookie": "server_session_ced1ee40=69710d2dc1bd2c646038eaabd7dda5b9; Max-Age=864000; httponly; path=/",
            "strict_transport_security": null,
            "x_content_type_options": null,
            "x_download_options": null,
            "x_frame_options": null,
            "x_permitted_cross_domain_policies": null,
            "x_powered_by": null,
            "x_xss_protection": null
          },
          "cookies": [
            {
              "name": "server_session_ced1ee40",
              "value": "69710d2dc1bd2c646038eaabd7dda5b9"
            }
          ]
        }
      }
    },
    {
      "punycode": "reiber-schreinerei.de",
      "unicode": "reiber-schreinerei.de",
      "is_idn": false,
      "subdomain": null,
      "subdomain_last": null,
      "subdomain_root": null,
      "name": {
        "punycode": "reiber-schreinerei",
        "unicode": "reiber-schreinerei",
        "is_idn": false,
        "contains_letter": true,
        "contains_number": false,
        "contains_hyphen": true,
        "length": 18,
        "lang": "de",
        "keywords": [
          "reiber",
          "schreinerei"
        ],
        "keyword_count": 2,
        "latinized": [],
        "contains_confusable": false
      },
      "domain": {
        "punycode": "reiber-schreinerei.de",
        "unicode": "reiber-schreinerei.de",
        "is_idn": false,
        "name": {
          "punycode": "reiber-schreinerei",
          "unicode": "reiber-schreinerei",
          "is_idn": false,
          "contains_letter": true,
          "contains_number": false,
          "contains_hyphen": true,
          "length": 18,
          "lang": "de",
          "keywords": [
            "reiber",
            "schreinerei"
          ],
          "keyword_count": 2
        },
        "extension": {
          "punycode": "de",
          "unicode": "de",
          "is_idn": false
        },
        "extension_root": {
          "punycode": "de",
          "unicode": "de",
          "is_idn": false
        },
        "extension_sub": null,
        "extension_type": 2,
        "reserved": null,
        "premium": null,
        "registered": true,
        "whois": {
          "create_date": null,
          "update_date": "2020-09-07T11:22:57Z",
          "expiry_date": null,
          "registrar": null,
          "registrant": {
            "name": null,
            "organization": null,
            "street": null,
            "city": null,
            "state": null,
            "postal_code": null,
            "country": null,
            "phone": null,
            "email": null
          },
          "name_servers": [
            "ns3.ai-dns.de",
            "ns5.kasserver.com"
          ],
          "domain_status": [
            "connect"
          ],
          "whois_server": null,
          "check_date": "2026-07-20T14:09:18Z"
        },
        "whois_normalized": {
          "registrant": null
        },
        "whois_last_check_date": "2026-07-20T14:09:18Z",
        "whois_create_date_historical": [],
        "whois_last_change_date": null,
        "whois_registrant_email_historical": [],
        "whois_privacy_enabled": null,
        "dns": {
          "a": {
            "update_date": "2026-09-03T16:35:21Z",
            "ip_addresses": [
              "85.13.161.47"
            ]
          }
        },
        "dns_last_change_date": "2026-09-03T16:35:27Z",
        "ip_history": [
          "85.13.161.47"
        ],
        "ssl": {
          "validity": {
            "start_date": "2025-12-04T00:00:00Z",
            "end_date": "2027-01-04T23:59:59Z"
          },
          "serial_number": "317195471285221077770134240717494399807",
          "check_date": "2026-08-11T07:27:21Z"
        },
        "ssl_last_change_date": "2026-01-19T22:58:00Z"
      },
      "type": 1,
      "subdomain_level_count": 0,
      "dns": {
        "a": {
          "update_date": "2026-09-03T16:35:21Z",
          "ip_addresses": [
            "85.13.161.47"
          ]
        },
        "aaaa": {
          "update_date": "2026-09-03T16:35:21Z",
          "ip_addresses": []
        },
        "ns": {
          "update_date": "2026-09-03T16:35:21Z",
          "name_servers": [
            "ns3.ai-dns.de",
            "ns5.kasserver.com"
          ]
        },
        "mx": {
          "update_date": "2026-09-03T16:35:21Z",
          "mail_servers": [
            "w0176a57.kasserver.com"
          ]
        },
        "soa": {
          "update_date": "2026-09-03T16:35:21Z",
          "mnames": [
            "ns5.kasserver.com"
          ],
          "rnames": [
            "hostmaster.kasserver.com"
          ],
          "rname_emails": [
            "user@kasserver.com"
          ]
        },
        "txt": {
          "update_date": "2026-09-03T16:35:21Z",
          "values": [
            "\"v=spf1 a mx include:spf.kasserver.com ~all\""
          ]
        },
        "cname": {
          "update_date": "2026-09-03T16:35:21Z",
          "values": []
        },
        "others": []
      },
      "dns_last_change_date": "2026-09-03T16:35:27Z",
      "ip_history": [
        "85.13.161.47"
      ],
      "ssl": {
        "tags": [
          "dla"
        ],
        "fqdns": [
          "kasserver.com"
        ],
        "version": 3,
        "serial_number": "317195471285221077770134240717494399807",
        "fingerprint": {
          "sha256": "b5d3da253cbb3253028a6428ed66712eee4abdd9c31463ccc464889085f4168b",
          "sha1": "20b933213a2fa939b9d8ca1aac07b319715cb2ac",
          "md5": "e5cc5a62a853408f3e5bf2875c1283a7"
        },
        "validity": {
          "start_date": "2025-12-04T00:00:00Z",
          "end_date": "2027-01-04T23:59:59Z",
          "length": 34300799
        },
        "signature": {
          "is_self_signed": false,
          "is_valid": false,
          "value": "lIfkdWtRsqPvpKHoiuQqgH8rjVF8K3Ebdv2Pha5N38EF06LiDzWmPomcX0zRitVla6x1ozaIy2+YMGW+T4e9jLq6/sneKBxQO/rhEZaFvqQPWFLqwza2ET7+gAiUsg5dLH5e1gYdHBMsKQvvcxhBs8z0zBiF7Dw/0gPJUclyicN4hWKE1GlRiur4xn1TjB6wqMs5d39hXUtKlYotxp/ntzlBTi1wEMRk/Rh1CsAf6lVz/Y0kG02EjtVBoGcrJ1VO5FFtguo0LRT5zN8lgiIqtH/lYPRlxtJobNsGj9Y2OOZPpTSs0emNNYQaPnvSFMvrtLxJ+C+J/roWrSiGsKDia8aRKBvy018nvSs9RoW50WrD2YTPnXrs4HsraqQEmeJrjpIcrwHExnBW9N8j…",
          "algorithm": {
            "oid": "1.2.840.113549.1.1.11",
            "name": "sha256"
          }
        },
        "issuer_dn": "CN=Sectigo Public Server Authentication CA DV R36,O=Sectigo Limited,C=GB",
        "issuer": {
          "common_name": "Sectigo Public Server Authentication CA DV R36",
          "country": "GB",
          "state": null,
          "locality": null,
          "organization": "Sectigo Limited",
          "organizational_unit": null
        },
        "subject_dn": "CN=*.kasserver.com",
        "subject": {
          "common_name": "*.kasserver.com",
          "country": null,
          "state": null,
          "locality": null,
          "organization": null,
          "organizational_unit": null
        },
        "extensions": {
          "authority_key_id": "aMASFhgOr872h6YyV6NGUV3LByc=",
          "basic_constraints": {
            "is_ca": false
          },
          "certificate_policies": [
            "1.3.6.1.4.1.6449.1.2.2.7",
            "2.23.140.1.2.1"
          ],
          "extended_key_usage": {
            "client_auth": null,
            "server_auth": true
          },
          "key_usage": {
            "digital_signature": true,
            "content_commitment": false,
            "key_agreement": false,
            "data_encipherment": false,
            "key_encipherment": true,
            "key_cert_sign": false,
            "crl_sign": false
          },
          "signed_certificate_timestamps": [
            "2025-12-04T10:48:45Z",
            "2025-12-04T10:48:46Z"
          ],
          "subject_alt_name": {
            "dns_names": [
              "*.kasserver.com",
              "kasserver.com"
            ]
          },
          "subject_key_id": "LOgkkb5w5gk/5C9zPisFzz+cNiA="
        },
        "check_date": "2026-08-11T07:27:21Z"
      },
      "ssl_last_change_date": "2026-01-19T22:57:57Z",
      "webdata": {
        "connection_status": "success",
        "html": {
          "source_code_hash": "d0ff221705793c5ec26742d3ef0d91958f4c3e33f6b17d1b87f7dc09de2fc8b6"
        },
        "http": {
          "status_code_first": 200,
          "status_code_last": 200,
          "redirection_history": [
            {
              "url": "http://reiber-schreinerei.de/",
              "status_code": 200
            }
          ],
          "external_redirection": null,
          "final_url": "http://reiber-schreinerei.de/",
          "final_fqdn": "reiber-schreinerei.de",
          "final_domain": "reiber-schreinerei.de",
          "headers": {
            "others": [
              {
                "name": "date",
                "value": "Mon, 23 Feb 2026 08:26:27 GMT"
              },
              {
                "name": "upgrade",
                "value": "h2,h2c"
              }
            ],
            "access_control_allow_headers": null,
            "access_control_allow_methods": null,
            "access_control_allow_origin": null,
            "cache_control": null,
            "clear_site_data": null,
            "content_encoding": "gzip",
            "content_security_policy": null,
            "content_type": "text/html",
            "cross_origin_embedder_policy": null,
            "cross_origin_opener_policy": null,
            "cross_origin_resource_policy": null,
            "expect_ct": null,
            "feature_policy": null,
            "last_modified": "Sat, 07 Oct 2017 00:18:24 GMT",
            "permission_policy": null,
            "referrer_policy": null,
            "server": "Apache",
            "set_cookie": null,
            "strict_transport_security": null,
            "x_content_type_options": null,
            "x_download_options": null,
            "x_frame_options": null,
            "x_permitted_cross_domain_policies": null,
            "x_powered_by": null,
            "x_xss_protection": null
          },
          "cookies": []
        }
      }
    }
  ]
}
```

### 400 · Invalid Parameter (invalid export=notabool)

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/domain-search?export=notabool' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "export",
      "details": [
        "Must be a valid boolean."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/domain-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "fqdn",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "subdomain_last",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "subdomain_root",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.name.language",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.name.keywords",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.extension",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.extension_root",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.extension_sub",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrar",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrant.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrant.organization",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrant.street",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrant.city",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrant.state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrant.postal_code",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrant.country",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrant.phone",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.registrant.email",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.name_servers",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois.domain_status",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois_normalized.registrant.organization",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois_normalized.registrant.phone",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois_normalized.registrant.email",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois_normalized.registrant.email_fqdn_apex",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois_normalized.registrant.email_domain_apex",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.whois_registrant_email_historical",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.dns.a.ip_addresses",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.ip_history",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.a.ip_addresses",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.aaaa.ip_addresses",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.ns.name_servers",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.mx.mail_servers",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.soa.mnames",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.soa.rnames",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.soa.rname_emails",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.txt.values",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.cname.values",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.others.type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.others.values",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ip_history",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.fqdns",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.fingerprint.sha256",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.fingerprint.sha1",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.fingerprint.md5",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.signature.value",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.issuer_dn",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.issuer.common_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.issuer.country",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.issuer.state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.issuer.locality",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.issuer.organization",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.issuer.organizational_unit",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.subject_dn",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.subject.common_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.subject.country",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.subject.state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.subject.locality",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.subject.organization",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.subject.organizational_unit",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "ssl.extensions.subject_alt_name.dns_names",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.connection_status",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.html.source_code_hash",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.redirection_history.url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.final_url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.final_fqdn",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.final_domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.others.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.others.value",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.access_control_allow_headers",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.access_control_allow_methods",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.access_control_allow_origin",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.cache_control",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.clear_site_data",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.content_encoding",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.content_security_policy",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.content_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.cross_origin_embedder_policy",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.cross_origin_opener_policy",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.cross_origin_resource_policy",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.expect_ct",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.feature_policy",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.last_modified",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.permission_policy",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.referrer_policy",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.server",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.set_cookie",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.strict_transport_security",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.x_content_type_options",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.x_download_options",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.x_frame_options",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.x_permitted_cross_domain_policies",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.x_powered_by",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.headers.x_xss_protection",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.cookies.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "webdata.http.cookies.value",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "type",
        "type": "eq",
        "value": 0
      },
      {
        "name": "subdomain.length",
        "type": "eq",
        "value": 0
      },
      {
        "name": "subdomain_level_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "domain.name.length",
        "type": "eq",
        "value": 0
      },
      {
        "name": "domain.name.keyword_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "domain.extension_type",
        "type": "eq",
        "value": 0
      },
      {
        "name": "domain.whois.create_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.whois.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.whois.expiry_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.whois_create_date_historical",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.whois_last_change_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.dns.a.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.dns_update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.dns_last_change_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.ssl.validity.start_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.ssl.validity.end_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "domain.ssl_last_change_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns.a.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns.aaaa.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns.ns.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns.mx.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns.soa.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns.txt.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns.cname.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns.others.update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns_update_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "dns_last_change_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "ssl.validity.start_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "ssl.validity.end_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "ssl.validity.length",
        "type": "eq",
        "value": 0
      },
      {
        "name": "ssl_last_change_date",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "webdata.http.status_code_first",
        "type": "eq",
        "value": 0
      },
      {
        "name": "webdata.http.status_code_last",
        "type": "eq",
        "value": 0
      },
      {
        "name": "webdata.http.redirection_history.status_code",
        "type": "eq",
        "value": 0
      },
      {
        "name": "is_idn",
        "type": "eq",
        "value": true
      },
      {
        "name": "subdomain.is_idn",
        "type": "eq",
        "value": true
      },
      {
        "name": "subdomain.contains_letter",
        "type": "eq",
        "value": true
      },
      {
        "name": "subdomain.contains_number",
        "type": "eq",
        "value": true
      },
      {
        "name": "subdomain.contains_hyphen",
        "type": "eq",
        "value": true
      },
      {
        "name": "name.contains_confusable",
        "type": "eq",
        "value": true
      },
      {
        "name": "domain.is_idn",
        "type": "eq",
        "value": true
      },
      {
        "name": "domain.name.contains_letter",
        "type": "eq",
        "value": true
      },
      {
        "name": "domain.name.contains_number",
        "type": "eq",
        "value": true
      },
      {
        "name": "domain.name.contains_hyphen",
        "type": "eq",
        "value": true
      },
      {
        "name": "domain.extension.is_idn",
        "type": "eq",
        "value": true
      },
      {
        "name": "domain.whois_privacy_enabled",
        "type": "eq",
        "value": true
      },
      {
        "name": "ssl.signature.is_self_signed",
        "type": "eq",
        "value": true
      },
      {
        "name": "ssl.signature.is_valid",
        "type": "eq",
        "value": true
      },
      {
        "name": "webdata.http.external_redirection",
        "type": "eq",
        "value": true
      },
      {
        "name": "subdomain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "name.latinized",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "punycode",
      "order": "desc"
    }
  ]
}'
```

## Worked Examples

Worked examples of this endpoint, each on its own page with the exact request and its response: [Domain Search Examples](/reference/discovery/domain-search/examples/).

- [Registered Through GoDaddy](/reference/discovery/domain-search/examples/domain-whois-registrar/): Matches records whose `domain.whois.registrar` equals `godaddy.com, llc`.
- [Name Servers at Cloudflare](/reference/discovery/domain-search/examples/domain-whois-name-servers/): Matches records whose `domain.whois.name_servers` matches the pattern `*.ns.cloudflare.com` (`*` stands for any characters).
- [Fuzzy: Names Close to a Brand](/reference/discovery/domain-search/examples/fuzzy-names-close-to-a-brand/): `fuzzy` matches values that differ from the given one by a few characters: typos, swapped letters and look-alike spellings of `deepinfo`.
- [Contains Any: Phishing-Style Keywords](/reference/discovery/domain-search/examples/contains-any-phishing-style-keywords/): `contains_any` takes a list and matches when the value contains at least one of its strings, anywhere: here domain names with `login`, `verify` or `secure` in them.
- [Look-Alikes Excluding the Real Domain](/reference/discovery/domain-search/examples/look-alikes-excluding-the-real-domain/): A typical brand-protection query: every name close to `deepinfo` (`must`), minus the brand's own domain (`must_not`).
- [Newest Registrations First](/reference/discovery/domain-search/examples/newest-registrations-first/): Domains registered since 2025, most recent first: a simple newly-registered-domains feed.
