POSThttps://api.deepinfo.com/v1/discovery/domain-search

Searches Deepinfo's whole domain dataset with filters on WHOIS, DNS, SSL, web data and more. result_count is the true total; results page up to 10,000.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
page_sizeOptional
Min 25, max 100. Default 100.
Example25
exportOptional
Default false.
export_formatOptional
One of: json, csv.
export_scopeOptional
One of: basic, default, extended.
pageOptional
Min 1, max 400. Default 1.
Example1

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "fqdn",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "punycode",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400). Example: a worked example that filters by the field, with the request and the response it returns.

Operators eq in startswith wildcard fuzzy exists

FieldDescriptionExample
fqdnThe full host name (FQDN) of the record in its ASCII (punycode) form, such as www.example.com. Search results return it as punycode.
subdomain_lastThe leftmost label of the subdomain, compared in its ASCII (punycode) form: a in a.b.example.com, and www in www.example.com.Last Subdomain Label
subdomain_rootThe subdomain label directly in front of the registrable domain, compared in its ASCII (punycode) form: b in a.b.example.com, and www in www.example.com.Root Subdomain Label
domainThe registrable domain the FQDN belongs to (example.com for www.example.com), compared in its ASCII (punycode) form. A filter on it matches the domain itself and all its subdomains.
domain.name.languageThe language detected for the domain name, as a two-letter ISO 639-1 code such as en, de or tr. Search results return it as domain.name.lang.Domain Names in German
domain.name.keywordsThe words detected in the domain name, such as deep and info for deepinfo, so cybersecurity and cyber-security both contain the word cyber.
domain.extensionThe extension of the registrable domain, everything after the name, such as com, io or co.uk, compared in its ASCII (punycode) form.
domain.extension_rootThe top-level part of the extension, compared in its ASCII (punycode) form: uk for both uk and co.uk.Every Extension Under .uk
domain.extension_subThe second-level part of a two-part extension, compared in its ASCII (punycode) form: co in co.uk. Single-part extensions such as com have none.Second-Level Extensions Like co.uk
domain.whois.registrarThe registrar the domain is registered through, as named in its WHOIS record and stored in lower case, such as godaddy.com, llc.
domain.whois.registrant.nameThe registrant's name (person or organization) from the domain's WHOIS record, stored in lower case.Registrant Name Present
domain.whois.registrant.organizationThe registrant's organization from the domain's WHOIS record, stored in lower case, such as cloudflare, inc..Registrant Organization Is Cloudflare
domain.whois.registrant.streetThe registrant's street address from the domain's WHOIS record, stored in lower case.Registrant Street Present
domain.whois.registrant.cityThe registrant's city from the domain's WHOIS record, stored in lower case.Registrants in One City
domain.whois.registrant.stateThe registrant's state or region from the domain's WHOIS record, stored in lower case.Registrants in One State
domain.whois.registrant.postal_codeThe registrant's postal code from the domain's WHOIS record.Registrant Postal Code Present
domain.whois.registrant.countryThe registrant's country from the domain's WHOIS record, usually a two-letter ISO 3166-1 alpha-2 code in lower case, such as de.Registrants in Germany
domain.whois.registrant.phoneThe registrant's phone number as written in the domain's WHOIS record.Registrant Phone Present
domain.whois.registrant.emailThe registrant's e-mail address from the domain's WHOIS record; it can be the relay address of a privacy service instead of the owner's own.Registrant E-mail at a Privacy Service
domain.whois.name_serversThe name servers listed in the domain's WHOIS record, as host names such as ns1.example.com.Name Servers at Cloudflare
domain.whois.domain_statusThe status codes in the domain's WHOIS record, mostly EPP codes, in lower case without spaces, such as clienttransferprohibited, clientdeleteprohibited, clientupdateprohibited, clientrenewprohibited, clienthold or ok.Domains on Client Hold
domain.whois_normalized.registrant.organizationThe registrant's organization from WHOIS in normalized form: lower case with spaces and punctuation removed, so cloudflare, inc. becomes cloudflareinc. A pattern such as *cloudflare* finds it more reliably than an exact value.Normalized Registrant Organization
domain.whois_normalized.registrant.phoneThe registrant's phone number from WHOIS in normalized form: digits only, with +, dots and other separators removed.Normalized Registrant Phone Present
domain.whois_normalized.registrant.emailThe registrant's e-mail address as kept in whois_normalized; email_fqdn_apex and email_domain_apex hold its host and registrable domain.Normalized Registrant E-mail Present
domain.whois_normalized.registrant.email_fqdn_apexThe host part of the normalized registrant e-mail address, everything after the @: mail.example.com for user@mail.example.com.Registrant E-mail Host
domain.whois_normalized.registrant.email_domain_apexThe registrable domain of the normalized registrant e-mail address: example.com for user@mail.example.com.Registrant E-mail Domain
domain.whois_registrant_email_historicalEvery registrant e-mail address seen in the domain's WHOIS records over time.Past Registrant E-mails at a Privacy Service
domain.dns.a.ip_addressesThe IPv4 addresses in the A record of the registrable domain (domain.dns); dns.a.ip_addresses holds those of the FQDN itself.Domain IPv4 (A) Record Pointing to an IP
domain.ip_historyEvery IP address the registrable domain has resolved to over time, so it also finds domains that have since moved.Domain Once Resolved to an IP
dns.a.ip_addressesThe IPv4 addresses in the FQDN's DNS A record.FQDN IPv4 (A) Record Pointing to an IP
dns.aaaa.ip_addressesThe IPv6 addresses in the FQDN's DNS AAAA record.AAAA Record Pointing to an IPv6 Address
dns.ns.name_serversThe name servers in the FQDN's DNS NS record, as host names.
dns.mx.mail_serversThe mail server host names in the FQDN's DNS MX record, such as aspmx.l.google.com for Google Workspace.
dns.soa.mnamesThe MNAME of the FQDN's SOA record: the primary name server of the zone.SOA Primary Name Server
dns.soa.rnamesThe RNAME of the FQDN's SOA record, the zone's responsible mailbox in DNS form: dns.example.com stands for the mailbox dns at example.com.SOA Responsible Mailbox
dns.soa.rname_emailsThe RNAME of the FQDN's SOA record written as an e-mail address, such as user@example.com.SOA Contact E-mail Domain
dns.txt.valuesThe text of the FQDN's DNS TXT records, such as SPF policies and site-verification tokens, stored as quoted text (each value starts with ").TXT Record Starting With a Verification Token
dns.cname.valuesThe target of the FQDN's DNS CNAME record, stored as a fully qualified name with the final dot, such as www.example.com..CNAME Pointing to GitHub Pages
dns.others.typeThe type of a DNS record that has no field of its own (dns.others), in upper case; values seen include DNSKEY, DS, SPF, HINFO, RRSIG, NSEC3, NSEC3PARAM, CAA, PTR and TYPE65.Other Record Type: DNSKEY
dns.others.valuesThe data of a record in dns.others, as text in zone-file notation, such as the flags, protocol, algorithm and key of a DNSKEY record.Other Record Values Present
ip_historyEvery IP address the FQDN has resolved to over time, including addresses it no longer uses.FQDN Once Resolved to Any of Several IPs
ssl.fqdnsThe host names the FQDN's TLS certificate is valid for, in lower case; wildcard names appear without the leading *..Certificates Covering a Name
ssl.fingerprint.sha256The SHA-256 fingerprint of the FQDN's TLS certificate, as 64 lower-case hex characters; a fingerprint identifies one certificate, so it finds every host that serves it.Certificate by SHA-256 Fingerprint
ssl.fingerprint.sha1The SHA-1 fingerprint of the FQDN's TLS certificate, as 40 lower-case hex characters.Certificate by SHA-1 Fingerprint
ssl.fingerprint.md5The MD5 fingerprint of the FQDN's TLS certificate, as 32 lower-case hex characters.Certificate by MD5 Fingerprint
ssl.signature.valueThe signature of the FQDN's TLS certificate, Base64-encoded.Certificate Signature Present
ssl.issuer_dnThe distinguished name of the certificate issuer as one string, such as CN=YR2,O=Let's Encrypt,C=US, compared exactly as the response shows it.Issuer Distinguished Name
ssl.issuer.common_nameThe common name (CN) in the issuer's name, usually the name of the issuing CA certificate, such as YR2, YR1 or WE1.Issuer Common Name
ssl.issuer.countryThe country (C) in the issuer's name, as a two-letter code in the case the certificate uses, usually upper case such as US or GB.Issuer Country
ssl.issuer.stateThe state or province (ST) in the issuer's name, as written in the certificate.Issuer State
ssl.issuer.localityThe locality or city (L) in the issuer's name, as written in the certificate.Issuer Locality
ssl.issuer.organizationThe organization (O) in the issuer's name, as written in the certificate, such as Let's Encrypt, Google Trust Services or DigiCert Inc.
ssl.issuer.organizational_unitThe organizational unit (OU) in the issuer's name, as written in the certificate.Issuer Organizational Unit Present
ssl.subject_dnThe distinguished name of the certificate subject as one string; a value that starts with CN=*. belongs to a wildcard certificate.
ssl.subject.common_nameThe common name (CN) in the subject's name, usually the host name the certificate was issued for, such as example.com.Subject Common Name
ssl.subject.countryThe country (C) in the subject's name, as a two-letter code in the case the certificate uses, such as DE.Subject Country
ssl.subject.stateThe state or province (ST) in the subject's name, as written in the certificate.Subject State
ssl.subject.localityThe locality or city (L) in the subject's name, as written in the certificate.Subject Locality
ssl.subject.organizationThe organization (O) in the subject's name, as written in the certificate: the company the certificate was issued to, when it names one.Subject Organization
ssl.subject.organizational_unitThe organizational unit (OU) in the subject's name, as written in the certificate.Subject Organizational Unit Present
ssl.extensions.subject_alt_name.dns_namesThe DNS names in the certificate's Subject Alternative Name (SAN) extension, including wildcard names such as *.example.com.Subject Alternative Names
webdata.urlThe URL recorded for Deepinfo's web visit to the FQDN (webdata is what Deepinfo saw over HTTP(S)); it takes filters, but search results do not return it.Web URL Starting With https://
webdata.connection_statusThe outcome of Deepinfo's web visit to the FQDN: success, not_resolved, timeout, thread_timeout, reset, refused, connection_error, ssl_error or too_many_redirects.
webdata.html.source_code_hashThe SHA-256 hash of the HTML source Deepinfo received on its web visit to the FQDN, as 64 lower-case hex characters, so identical pages share the same value.Pages With an Empty HTML Body
webdata.http.redirection_history.urlThe URL of one step of Deepinfo's web visit; redirection_history lists every URL requested, from the first one to the final page.Redirect Chain Through Plain HTTP
webdata.http.final_urlThe URL Deepinfo's web visit ended on after all redirects, exactly as recorded, with or without a trailing /.Final URL
webdata.http.final_fqdnThe host name of the URL Deepinfo's web visit ended on after all redirects; an internationalized name is stored and compared in its readable (Unicode) form, not as punycode.Final FQDN
webdata.http.final_domainThe registrable domain of the host Deepinfo's web visit ended on after all redirects, such as cloudflare.com; an internationalized name is stored and compared in its readable (Unicode) form, not as punycode.Final Domain
webdata.http.headers.others.nameThe name of a response header that has no field of its own (headers.others), in lower case with dashes written as underscores: cf-ray becomes cf_ray.Other Header Name
webdata.http.headers.others.valueThe value of a response header listed in headers.others, as text.Other Header Value
webdata.http.headers.access_control_allow_headersThe value of the Access-Control-Allow-Headers response header on Deepinfo's web visit to the FQDN: the request headers the site accepts in cross-origin (CORS) requests.Access-Control-Allow-Headers Present
webdata.http.headers.access_control_allow_methodsThe value of the Access-Control-Allow-Methods response header on Deepinfo's web visit to the FQDN: the HTTP methods the site allows in cross-origin (CORS) requests, such as GET, POST, OPTIONS.Access-Control-Allow-Methods Present
webdata.http.headers.access_control_allow_originThe value of the Access-Control-Allow-Origin response header on Deepinfo's web visit to the FQDN: the origins allowed to read the response in cross-origin (CORS) requests; * means any origin.CORS Open to Any Origin
webdata.http.headers.cache_controlThe value of the Cache-Control response header on Deepinfo's web visit to the FQDN: the caching rules, such as no-store or max-age=0.Cache-Control With a Max Age
webdata.http.headers.clear_site_dataThe value of the Clear-Site-Data response header on Deepinfo's web visit to the FQDN: the browser data the site asks to clear, such as cache.Clear-Site-Data Present
webdata.http.headers.content_encodingThe value of the Content-Encoding response header on Deepinfo's web visit to the FQDN: the compression used, such as gzip.Compressed With Gzip
webdata.http.headers.content_security_policyThe value of the Content-Security-Policy response header on Deepinfo's web visit to the FQDN: the sources the page may load scripts and other content from.
webdata.http.headers.content_typeThe value of the Content-Type response header on Deepinfo's web visit to the FQDN: the media type and character set, such as text/html; charset=UTF-8.HTML Content Type
webdata.http.headers.cross_origin_embedder_policyThe value of the Cross-Origin-Embedder-Policy response header on Deepinfo's web visit to the FQDN, such as require-corp or credentialless.Cross-Origin-Embedder-Policy
webdata.http.headers.cross_origin_opener_policyThe value of the Cross-Origin-Opener-Policy response header on Deepinfo's web visit to the FQDN, such as same-origin or unsafe-none.Cross-Origin-Opener-Policy
webdata.http.headers.cross_origin_resource_policyThe value of the Cross-Origin-Resource-Policy response header on Deepinfo's web visit to the FQDN, such as same-origin or cross-origin.Cross-Origin-Resource-Policy
webdata.http.headers.expect_ctThe value of the Expect-CT response header on Deepinfo's web visit to the FQDN (Certificate Transparency enforcement), such as max-age=86400, enforce.Expect-CT Present
webdata.http.headers.feature_policyThe value of the Feature-Policy response header on Deepinfo's web visit to the FQDN: the older form of the policy that limits browser features such as camera or geolocation.Feature-Policy Present
webdata.http.headers.last_modifiedThe value of the Last-Modified response header on Deepinfo's web visit to the FQDN, stored as the header text (an HTTP date such as Tue, 20 Jan 2026 04:02:54 GMT), so it takes text operators, not date ranges.Last-Modified Present
webdata.http.headers.permission_policyThe value of the Permission-Policy response header on Deepinfo's web visit to the FQDN (singular spelling). The standard Permissions-Policy header is listed in webdata.http.headers.others as permissions_policy.Permission Policy Present
webdata.http.headers.referrer_policyThe value of the Referrer-Policy response header on Deepinfo's web visit to the FQDN, such as strict-origin-when-cross-origin or no-referrer.Referrer-Policy
webdata.http.headers.serverThe value of the Server response header on Deepinfo's web visit to the FQDN: the web server software the site reports, such as nginx, Apache, LiteSpeed or cloudflare.Server Header
webdata.http.headers.set_cookieThe value of the Set-Cookie response header on Deepinfo's web visit to the FQDN, as text starting with the cookie name, such as PHPSESSID=.Sets a PHP Session Cookie
webdata.http.headers.strict_transport_securityThe value of the Strict-Transport-Security response header on Deepinfo's web visit to the FQDN (HSTS), such as max-age=31536000; includeSubDomains; preload.
webdata.http.headers.x_content_type_optionsThe value of the X-Content-Type-Options response header on Deepinfo's web visit to the FQDN, usually nosniff.X-Content-Type-Options
webdata.http.headers.x_download_optionsThe value of the X-Download-Options response header on Deepinfo's web visit to the FQDN, usually noopen.X-Download-Options
webdata.http.headers.x_frame_optionsThe value of the X-Frame-Options response header on Deepinfo's web visit to the FQDN: whether other sites may show the page in a frame, such as SAMEORIGIN or DENY, in the case the site sent.
webdata.http.headers.x_permitted_cross_domain_policiesThe value of the X-Permitted-Cross-Domain-Policies response header on Deepinfo's web visit to the FQDN, such as none.X-Permitted-Cross-Domain-Policies
webdata.http.headers.x_powered_byThe value of the X-Powered-By response header on Deepinfo's web visit to the FQDN: the technology the site reports, such as PHP/8.2.32, ASP.NET or Next.js.Powered by PHP
webdata.http.headers.x_xss_protectionThe value of the X-XSS-Protection response header on Deepinfo's web visit to the FQDN, such as 1; mode=block or 0.X-XSS-Protection
webdata.http.cookies.nameThe name of a cookie the site set on Deepinfo's web visit, such as PHPSESSID or __cf_bm.Cookie Name
webdata.http.cookies.valueThe value of a cookie the site set on Deepinfo's web visit, as text.Cookie Value Present

Operators eq in gte lte exists

FieldDescriptionExample
typeWhether the record is a registrable domain or a subdomain: 1 = domain (such as example.com), 2 = subdomain (such as www.example.com).
subdomain.lengthThe number of characters in the subdomain part (0 to 255), counted in its ASCII (punycode) form without the dots between labels: 6 for api.dev.example.com.Short Subdomains (Up to 3 Characters)
subdomain_level_countThe number of labels in front of the registrable domain: 0 for the domain itself, 1 for www.example.com, 2 for a.b.example.com.Deeply Nested Subdomains
domain.name.lengthThe number of characters in the domain name without its extension, counted in its ASCII (punycode) form (0 to 63).
domain.name.keyword_countThe number of words detected in the domain name (the length of domain.name.keywords).Names With Three or More Keywords
domain.extension_typeThe kind of extension: 1 = generic (gTLD, such as .com), 2 = country code (ccTLD, such as .de or .co.uk).Country-Code Extensions Only
domain.whois.create_dateThe date the registrable domain was created (registered), from its WHOIS record (UTC, ISO 8601).
domain.whois.update_dateThe last-updated date that the domain's WHOIS record itself reports (UTC, ISO 8601); domain.whois_last_change_date is when Deepinfo saw the record change.WHOIS Records Updated Since 2026
domain.whois.expiry_dateThe date the domain's registration expires, from its WHOIS record (UTC, ISO 8601).
domain.whois_create_date_historicalEvery creation date seen in the domain's WHOIS records over time (UTC, ISO 8601), so a domain that was registered again still matches on its earlier dates.First Registered Before 2001
domain.whois_last_change_dateThe last time Deepinfo saw the domain's WHOIS record change (UTC, ISO 8601).WHOIS Changed Since the Start of 2026
domain.dns.a.update_dateThe update date Deepinfo recorded for the registrable domain's A records (UTC, ISO 8601); it is set even when the domain has no A record.Domain IPv4 (A) Record Updated Since 2026
domain.dns_update_dateA DNS update date of the registrable domain (UTC, ISO 8601) that takes date filters; search results do not return this field.Domain DNS Updated Since 2026
domain.dns_last_change_dateThe last time Deepinfo saw the DNS records of the registrable domain change (UTC, ISO 8601).Domain DNS Changed Since 2026
domain.ssl.validity.start_dateThe date the registrable domain's TLS certificate became valid, its not-before date (UTC, ISO 8601). ssl.validity.start_date holds the same for the FQDN's own certificate.Domain Certificate Issued Since 2026
domain.ssl.validity.end_dateThe date the registrable domain's TLS certificate expires, its not-after date (UTC, ISO 8601). ssl.validity.end_date holds the same for the FQDN's own certificate.Domain Certificate Expiring by October 2026
domain.ssl_last_change_dateThe last time Deepinfo saw the registrable domain's TLS certificate change (UTC, ISO 8601).Domain Certificate Changed Since 2026
dns.a.update_dateThe update date Deepinfo recorded for the FQDN's A records (UTC, ISO 8601); it is set even when the FQDN has no A record.A Record Updated Since 2026
dns.aaaa.update_dateThe update date Deepinfo recorded for the FQDN's AAAA records (UTC, ISO 8601); it is set even when the FQDN has no AAAA record.AAAA Record Updated Since 2026
dns.ns.update_dateThe update date Deepinfo recorded for the FQDN's NS records (UTC, ISO 8601); it is set even when the FQDN has no NS record.NS Record Updated Since 2026
dns.mx.update_dateThe update date Deepinfo recorded for the FQDN's MX records (UTC, ISO 8601); it is set even when the FQDN has no MX record.MX Record Updated Since 2026
dns.soa.update_dateThe update date Deepinfo recorded for the FQDN's SOA records (UTC, ISO 8601); it is set even when the FQDN has no SOA record.SOA Record Updated Since 2026
dns.txt.update_dateThe update date Deepinfo recorded for the FQDN's TXT records (UTC, ISO 8601); it is set even when the FQDN has no TXT record.TXT Record Updated Since 2026
dns.cname.update_dateThe update date Deepinfo recorded for the FQDN's CNAME records (UTC, ISO 8601); it is set even when the FQDN has no CNAME record.CNAME Record Updated Since 2026
dns.others.update_dateThe update date Deepinfo recorded for a record in dns.others (UTC, ISO 8601).Other Records Updated Since 2026
dns_update_dateA DNS update date of the FQDN (UTC, ISO 8601) that takes date filters; search results do not return this field.DNS Updated Since 2026
dns_last_change_dateThe last time Deepinfo saw the DNS records of the FQDN change (UTC, ISO 8601).DNS Changed Since 2026
ssl.validity.start_dateThe date the FQDN's TLS certificate became valid, its not-before date (UTC, ISO 8601).Certificate Issued Since 2026
ssl.validity.end_dateThe date the FQDN's TLS certificate expires, its not-after date (UTC, ISO 8601).Certificate Expiring by October 2026
ssl.validity.lengthThe validity period of the FQDN's TLS certificate in seconds, from start date to end date: 7,776,000 seconds are 90 days.Certificates Valid for 90 Days or Less
ssl_last_change_dateThe last time Deepinfo saw the FQDN's TLS certificate change (UTC, ISO 8601).Certificate Changed Since 2026
webdata.http.status_code_firstThe HTTP status code of the first response on Deepinfo's web visit to the FQDN, such as 200, or 301 for a permanent redirect.
webdata.http.status_code_lastThe HTTP status code of the final response on Deepinfo's web visit, after all redirects, such as 200, 403 or 404.Final Response Is a Server Error
webdata.http.redirection_history.status_codeThe HTTP status code returned at one step of Deepinfo's web visit, such as 301 or 302 for a redirect and 200 for the final page.Redirect Chain With a 302

Operators eq in exists

FieldDescriptionExample
is_idntrue when the FQDN is an internationalized domain name (IDN) with non-ASCII characters; punycode then holds its ASCII form and unicode the readable one.
subdomain.is_idntrue when the subdomain part contains non-ASCII (internationalized) characters.Internationalized Subdomains
subdomain.contains_lettertrue when the subdomain part contains at least one letter, checked on its readable (Unicode) form.Subdomains Containing Letters
subdomain.contains_numbertrue when the subdomain part contains at least one digit, checked on its readable (Unicode) form, so the digits of an xn-- punycode form do not count.Subdomains Containing Digits
subdomain.contains_hyphentrue when the subdomain part contains at least one hyphen, checked on its readable (Unicode) form, so the xn-- prefix of an IDN does not count.Subdomains Containing a Hyphen
name.contains_confusabletrue when the FQDN's name (without its extension) contains confusable characters: letters that look like others, such as Cyrillic а and Latin a, a common trick in look-alike domains.
domain.is_idntrue when the registrable domain contains non-ASCII (internationalized) characters.Internationalized Domains Only
domain.name.contains_lettertrue when the domain name (without its extension) contains at least one letter, checked on its readable (Unicode) form.Domain Names Containing Letters
domain.name.contains_numbertrue when the domain name (without its extension) contains at least one digit, checked on its readable (Unicode) form, so the digits of an xn-- punycode form do not count.Domain Names Containing Digits
domain.name.contains_hyphentrue when the domain name (without its extension) contains at least one hyphen, checked on its readable (Unicode) form, so the xn-- prefix of an IDN does not count.Domain Names Containing a Hyphen
domain.extension.is_idntrue when the extension contains non-ASCII (internationalized) characters, such as .рф (xn--p1ai).Internationalized Extensions Only
domain.whois_privacy_enabledtrue when the domain's WHOIS record hides the registrant's details, through a privacy service or redaction, false when it does not.
ssl.signature.is_self_signedtrue when the FQDN's TLS certificate is self-signed, signed with its own key instead of by a certificate authority.
ssl.signature.is_validtrue when the signature of the FQDN's TLS certificate validates, false when it does not.
webdata.http.external_redirectiontrue when Deepinfo's web visit was redirected to a different registrable domain, false when it ended on the FQDN's own domain, for example on its www. host.

Operators eq in startswith endswith wildcard fuzzy contains_any contains_all exists

FieldDescriptionExample
subdomainThe subdomain part of the FQDN, everything in front of the registrable domain (mail in mail.example.com), compared in its ASCII (punycode) form. It is null for a registrable domain.One Subdomain Across Domains
domain.nameThe name of the registrable domain without its extension, compared in its ASCII (punycode) form: example in example.com, and the same when the extension has two parts, such as co.uk.

Operators eq in startswith wildcard fuzzy contains_any contains_all exists

FieldDescriptionExample
name.latinizedLatin look-alike forms of the FQDN's name (the FQDN without its extension) when it has non-Latin or accented letters: each character becomes the Latin letter it resembles (Cyrillic р becomes p), so istanbul also finds names written with İ.Latinized Form of an IDN Name

Sortable Fields

Example: a worked example that sorts by the field, with the request and the response it returns.

FieldDescriptionExample
punycodeThe FQDN in its ASCII (punycode) form, such as www.example.com; sorting on it lists results alphabetically. Filters use the same value under the name fqdn.Sort by Name (A to Z)
domain.extension.punycodeThe extension of the registrable domain in its ASCII (punycode) form, such as com or co.uk; sorting on it lists results by extension.
domain.whois.create_dateThe date the registrable domain was created (registered), from its WHOIS record (UTC, ISO 8601).
domain.whois.expiry_dateThe date the domain's registration expires, from its WHOIS record (UTC, ISO 8601).Soonest to Expire First
domain.whois.update_dateThe last-updated date that the domain's WHOIS record itself reports (UTC, ISO 8601); domain.whois_last_change_date is when Deepinfo saw the record change.Most Recently Updated WHOIS First
domain.whois_last_change_dateThe last time Deepinfo saw the domain's WHOIS record change (UTC, ISO 8601).Latest WHOIS Changes First
dns_last_change_dateThe last time Deepinfo saw the DNS records of the FQDN change (UTC, ISO 8601).Latest DNS Changes First
ssl_last_change_dateThe last time Deepinfo saw the FQDN's TLS certificate change (UTC, ISO 8601).Latest Certificate Changes First

Response Fields

FieldTypeDescription
pageinteger
page_sizeinteger
result_countinteger
resultsarray of object
results[].punycodestring
results[].unicodestring
results[].is_idnboolean
results[].subdomainobject
results[].subdomain_lastobject
results[].subdomain_rootobject
results[].nameobject
results[].domainobject
results[].typeinteger
results[].subdomain_level_countinteger
results[].dnsobject
results[].dns_last_change_datestring
date-time
results[].ip_historyarray of string
results[].sslobject
results[].ssl_last_change_datestring
date-time
results[].webdataobject

Paginated. See Getting Started → Pagination.

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
pagenumber1
page_sizenumber25
result_countnumber1932808835
resultsarray<object>
results[].punycodestring"jjcyyl.com"
results[].unicodestring"jjcyyl.com"
results[].is_idnbooleanfalse
results[].subdomainnull
results[].subdomain_lastnull
results[].subdomain_rootnull
results[].nameobject
results[].name.punycodestring"jjcyyl"
results[].name.unicodestring"jjcyyl"
results[].name.is_idnbooleanfalse
results[].name.contains_letterbooleantrue
results[].name.contains_numberbooleanfalse
results[].name.contains_hyphenbooleanfalse
results[].name.lengthnumber6
results[].name.langstring"en"
results[].name.keywordsarray<string>"jjc"
results[].name.keyword_countnumber2
results[].name.latinizedarray
results[].name.contains_confusablebooleanfalse
results[].domainobject
results[].domain.punycodestring"jjcyyl.com"
results[].domain.unicodestring"jjcyyl.com"
results[].domain.is_idnbooleanfalse
results[].domain.nameobject
results[].domain.name.punycodestring"jjcyyl"
results[].domain.name.unicodestring"jjcyyl"
results[].domain.name.is_idnbooleanfalse
results[].domain.name.contains_letterbooleantrue
results[].domain.name.contains_numberbooleanfalse
results[].domain.name.contains_hyphenbooleanfalse
results[].domain.name.lengthnumber6
results[].domain.name.langstring"en"
results[].domain.name.keywordsarray<string>"jjc"
results[].domain.name.keyword_countnumber2
results[].domain.extensionobject
results[].domain.extension.punycodestring"com"
results[].domain.extension.unicodestring"com"
results[].domain.extension.is_idnbooleanfalse
results[].domain.extension_rootobject
results[].domain.extension_root.punycodestring"com"
results[].domain.extension_root.unicodestring"com"
results[].domain.extension_root.is_idnbooleanfalse
results[].domain.extension_subnull
results[].domain.extension_typenumber1
results[].domain.reservednull
results[].domain.premiumnull
results[].domain.registeredbooleantrue
results[].domain.whoisobject
results[].domain.whois.create_datestring | null"2018-07-23T06:35:52Z"
results[].domain.whois.update_datestring"2026-07-03T00:55:38Z"
results[].domain.whois.expiry_datestring | null"2027-07-23T06:35:52Z"
results[].domain.whois.registrarstring | null"spaceship, inc."
results[].domain.whois.registrantobject
results[].domain.whois.registrant.namenull
results[].domain.whois.registrant.organizationnull
results[].domain.whois.registrant.streetnull
results[].domain.whois.registrant.citynull
results[].domain.whois.registrant.statenull
results[].domain.whois.registrant.postal_codenull
results[].domain.whois.registrant.countrynull
results[].domain.whois.registrant.phonenull
results[].domain.whois.registrant.emailnull
results[].domain.whois.name_serversarray<string>"launch1.spaceship.net"
results[].domain.whois.domain_statusarray<string>"clienttransferprohibited"
results[].domain.whois.whois_serverstring | null"whois.spaceship.com"
results[].domain.whois.check_datestring"2026-07-20T03:16:08Z"
results[].domain.whois_normalizedobject
results[].domain.whois_normalized.registrantnull
results[].domain.whois_last_check_datestring"2026-07-20T03:16:08Z"
results[].domain.whois_create_date_historicalarray<string>"2018-07-23T06:35:52Z"
results[].domain.whois_last_change_datestring | null"2026-07-20T03:16:15Z"
results[].domain.whois_registrant_email_historicalarray<string>
results[].domain.whois_privacy_enablednull
results[].domain.dnsobject
results[].domain.dns.aobject
results[].domain.dns.a.update_datestring"2026-08-25T16:43:01Z"
results[].domain.dns.a.ip_addressesarray<string>"192.238.152.241"
results[].domain.dns_last_change_datestring"2026-07-07T22:28:35Z"
results[].domain.ip_historyarray<string>"154.23.207.42"
results[].domain.sslobject
results[].domain.ssl.validityobject
results[].domain.ssl.validity.start_datestring"2026-08-09T01:02:19Z"
results[].domain.ssl.validity.end_datestring"2026-11-07T01:02:18Z"
results[].domain.ssl.serial_numberstring"49080258881301126573104250239199093…"
results[].domain.ssl.check_datestring"2026-09-03T16:34:41Z"
results[].domain.ssl_last_change_datestring"2026-09-03T16:35:23Z"
results[].typenumber1
results[].subdomain_level_countnumber0
results[].dnsobject
results[].dns.aobject
results[].dns.a.update_datestring"2026-08-25T16:43:01Z"
results[].dns.a.ip_addressesarray<string>"192.238.152.241"
results[].dns.aaaaobject
results[].dns.aaaa.update_datestring"2026-08-25T16:43:01Z"
results[].dns.aaaa.ip_addressesarray
results[].dns.nsobject
results[].dns.ns.update_datestring"2026-08-25T16:43:01Z"
results[].dns.ns.name_serversarray<string>"launch1.spaceship.net"
results[].dns.mxobject
results[].dns.mx.update_datestring"2026-08-25T16:43:01Z"
results[].dns.mx.mail_serversarray<string>"w0176a57.kasserver.com"
results[].dns.soaobject
results[].dns.soa.update_datestring"2026-08-25T16:43:01Z"
results[].dns.soa.mnamesarray<string>"launch1.spaceship.net"
results[].dns.soa.rnamesarray<string>"support.spaceship.com"
results[].dns.soa.rname_emailsarray<string>
results[].dns.txtobject
results[].dns.txt.update_datestring"2026-08-25T16:43:01Z"
results[].dns.txt.valuesarray<string>"\"v=spf1 a mx include:spf.kasserver.…"
results[].dns.cnameobject
results[].dns.cname.update_datestring"2026-08-25T16:43:01Z"
results[].dns.cname.valuesarray
results[].dns.othersarray
results[].dns_last_change_datestring"2026-07-07T22:28:33Z"
results[].ip_historyarray<string>"154.23.207.42"
results[].sslobject
results[].ssl.tagsarray<string>"dla"
results[].ssl.fqdnsarray<string>"50eg.com"
results[].ssl.versionnumber3
results[].ssl.serial_numberstring"49080258881301126573104250239199093…"
results[].ssl.fingerprintobject
results[].ssl.fingerprint.sha256string"e16b523f54d2d0cb217eec73a8e1f0cc649…"
results[].ssl.fingerprint.sha1string"268e336c2a11d649c5e61844a518cf0763f…"
results[].ssl.fingerprint.md5string"a5e51f43b7b8a264e84222a37850485d"
results[].ssl.validityobject
results[].ssl.validity.start_datestring"2026-08-09T01:02:19Z"
results[].ssl.validity.end_datestring"2026-11-07T01:02:18Z"
results[].ssl.validity.lengthnumber7775999
results[].ssl.signatureobject
results[].ssl.signature.is_self_signedbooleanfalse
results[].ssl.signature.is_validbooleantrue
results[].ssl.signature.valuestring"Xd+e75rjvwgjbY/rRYB4FnTY9g3N3k0bWkD…"
results[].ssl.signature.algorithmobject
results[].ssl.signature.algorithm.oidstring"1.2.840.113549.1.1.11"
results[].ssl.signature.algorithm.namestring"sha256"
results[].ssl.issuer_dnstring"CN=YR2,O=Let's Encrypt,C=US"
results[].ssl.issuerobject
results[].ssl.issuer.common_namestring"YR2"
results[].ssl.issuer.countrystring"US"
results[].ssl.issuer.statenull
results[].ssl.issuer.localitynull
results[].ssl.issuer.organizationstring"Let's Encrypt"
results[].ssl.issuer.organizational_unitnull
results[].ssl.subject_dnstring"CN=job0758.com.cn"
results[].ssl.subjectobject
results[].ssl.subject.common_namestring"job0758.com.cn"
results[].ssl.subject.countrynull
results[].ssl.subject.statenull
results[].ssl.subject.localitynull
results[].ssl.subject.organizationnull
results[].ssl.subject.organizational_unitnull
results[].ssl.extensionsobject
results[].ssl.extensions.authority_key_idstring"QBUtJnntMiCe35pyHdYyH4EMgQw="
results[].ssl.extensions.basic_constraintsobject
results[].ssl.extensions.basic_constraints.is_cabooleanfalse
results[].ssl.extensions.certificate_policiesarray<string>"2.23.140.1.2.1"
results[].ssl.extensions.extended_key_usageobject
results[].ssl.extensions.extended_key_usage.client_authnull
results[].ssl.extensions.extended_key_usage.server_authbooleantrue
results[].ssl.extensions.key_usageobject
results[].ssl.extensions.key_usage.digital_signaturebooleantrue
results[].ssl.extensions.key_usage.content_commitmentbooleanfalse
results[].ssl.extensions.key_usage.key_agreementbooleanfalse
results[].ssl.extensions.key_usage.data_enciphermentbooleanfalse
results[].ssl.extensions.key_usage.key_enciphermentbooleantrue
results[].ssl.extensions.key_usage.key_cert_signbooleanfalse
results[].ssl.extensions.key_usage.crl_signbooleanfalse
results[].ssl.extensions.signed_certificate_timestampsarray<string>"2026-08-09T02:00:49Z"
results[].ssl.extensions.subject_alt_nameobject
results[].ssl.extensions.subject_alt_name.dns_namesarray<string>"50eg.com"
results[].ssl.extensions.subject_key_idstring"+IodGf7ET61TYCE90DG1Gw5dXtA="
results[].ssl.check_datestring"2026-09-03T16:34:41Z"
results[].ssl_last_change_datestring"2026-09-03T16:35:22Z"
results[].webdataobject
results[].webdata.connection_statusstring"success"
results[].webdata.htmlobject
results[].webdata.html.source_code_hashstring"e3b0c44298fc1c149afbf4c8996fb92427a…"
results[].webdata.httpobject
results[].webdata.http.status_code_firstnumber444
results[].webdata.http.status_code_lastnumber444
results[].webdata.http.redirection_historyarray<object>
results[].webdata.http.redirection_history[].urlstring"http://jjcyyl.com/"
results[].webdata.http.redirection_history[].status_codenumber444
results[].webdata.http.external_redirectionnull
results[].webdata.http.final_urlstring"http://jjcyyl.com/"
results[].webdata.http.final_fqdnstring"jjcyyl.com"
results[].webdata.http.final_domainstring"jjcyyl.com"
results[].webdata.http.headersobject
results[].webdata.http.headers.othersarray<object>
results[].webdata.http.headers.others[].namestring"date"
results[].webdata.http.headers.others[].valuestring"Tue, 16 Jun 2026 13:57:19 GMT"
results[].webdata.http.headers.access_control_allow_headersnull
results[].webdata.http.headers.access_control_allow_methodsnull
results[].webdata.http.headers.access_control_allow_originnull
results[].webdata.http.headers.cache_controlnull
results[].webdata.http.headers.clear_site_datanull
results[].webdata.http.headers.content_encodingstring | null"gzip"
results[].webdata.http.headers.content_security_policynull
results[].webdata.http.headers.content_typestring | null"text/html"
results[].webdata.http.headers.cross_origin_embedder_policynull
results[].webdata.http.headers.cross_origin_opener_policynull
results[].webdata.http.headers.cross_origin_resource_policynull
results[].webdata.http.headers.expect_ctnull
results[].webdata.http.headers.feature_policynull
results[].webdata.http.headers.last_modifiedstring | null"Sat, 07 Oct 2017 00:18:24 GMT"
results[].webdata.http.headers.permission_policynull
results[].webdata.http.headers.referrer_policynull
results[].webdata.http.headers.serverstring"nginx"
results[].webdata.http.headers.set_cookiestring | null
results[].webdata.http.headers.strict_transport_securitynull
results[].webdata.http.headers.x_content_type_optionsnull
results[].webdata.http.headers.x_download_optionsnull
results[].webdata.http.headers.x_frame_optionsnull
results[].webdata.http.headers.x_permitted_cross_domain_policiesnull
results[].webdata.http.headers.x_powered_bynull
results[].webdata.http.headers.x_xss_protectionnull
results[].webdata.http.cookiesarray<object>
results[].webdata.http.cookies[].namestring"server_session_ced1ee40"
results[].webdata.http.cookies[].valuestring"69710d2dc1bd2c646038eaabd7dda5b9"

Examples

Saved examples from the Deepinfo API and a request template. Selecting one loads it into the request and response panels.

Worked Examples

Worked examples of this endpoint, each on its own page with the exact request and the response it returns.

See all examples

Reference updated