# Domain Search Examples

One worked Domain Search example for each filter field, plus combinations of operators, boolean logic, sorting and pagination.

Source: https://docs.deepinfo.com/reference/discovery/domain-search/examples/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/domain-search` · endpoint: [Domain Search](/reference/discovery/domain-search/)

Worked examples for Domain Search: one for every filter field, then combinations of operators, `must` / `should` / `must_not`, sorting and pagination.

Every example is a real request with the response the API returned. The body is `{"filters": {"must": [...], "should": [...], "must_not": [...]}, "sort": [...]}`; a filter is `{"name": <field>, "type": <operator>, "value": <value>}` (see [Search & Filters](/getting-started/search-and-filters/)). The field examples use the operator that fits the field best; not every field takes every operator, and the table below lists what each one accepts.

Responses are trimmed for display: `results` shows the first 3 records, long lists inside a record the first 10 items and very long texts the first 4,000 characters, while `result_count` stays the full total; each page says what was shortened. Personal data (WHOIS contact names, addresses, phone numbers and personal e-mail addresses) is redacted, and cookie values are masked (`<value>`). `whois` and `whois_normalized` are redacted separately, so a contact's organization can be redacted in one and shown in the other: when in doubt, it is redacted.

## Supported Operators by Field

Not every field takes every operator: a filter with an operator its field does not support is answered with HTTP 400 ("Field '…' does not support '…' query"). Verified against the live API on 2026-09-23.

Legend: `wc` wildcard · `fz` fuzzy · `sw` startswith · `ew` endswith · `any` contains_any · `all` contains_all · `ex` exists; `eq`, `in`, `lte` and `gte` are the operators' own names.

| Family | Field | Operators |
|---|---|---|
| Name & Extension | `domain.name` | eq in wc fz sw ew any all ex |
|  | `name.latinized` | eq in wc fz sw any all ex |
|  | `fqdn` | eq in wc fz sw ex |
|  | `domain` | eq in wc fz sw ex |
|  | `domain.name.language` | eq in wc fz sw ex |
|  | `domain.name.keywords` | eq in wc fz sw ex |
|  | `domain.extension` | eq in wc fz sw ex |
|  | `domain.extension_root` | eq in wc fz sw ex |
|  | `domain.extension_sub` | eq in wc fz sw ex |
|  | `type` | eq in lte gte ex |
|  | `domain.name.length` | eq in lte gte ex |
|  | `domain.name.keyword_count` | eq in lte gte ex |
|  | `domain.extension_type` | eq in lte gte ex |
|  | `is_idn` | eq in ex |
|  | `name.contains_confusable` | eq in ex |
|  | `domain.is_idn` | eq in ex |
|  | `domain.name.contains_letter` | eq in ex |
|  | `domain.name.contains_number` | eq in ex |
|  | `domain.name.contains_hyphen` | eq in ex |
|  | `domain.extension.is_idn` | eq in ex |
| Subdomain | `subdomain` | eq in wc fz sw ew any all ex |
|  | `subdomain_last` | eq in wc fz sw ex |
|  | `subdomain_root` | eq in wc fz sw ex |
|  | `subdomain.length` | eq in lte gte ex |
|  | `subdomain_level_count` | eq in lte gte ex |
|  | `subdomain.is_idn` | eq in ex |
|  | `subdomain.contains_letter` | eq in ex |
|  | `subdomain.contains_number` | eq in ex |
|  | `subdomain.contains_hyphen` | eq in ex |
| WHOIS | `domain.whois.registrar` | eq in wc fz sw ex |
|  | `domain.whois.registrant.name` | eq in wc fz sw ex |
|  | `domain.whois.registrant.organization` | eq in wc fz sw ex |
|  | `domain.whois.registrant.street` | eq in wc fz sw ex |
|  | `domain.whois.registrant.city` | eq in wc fz sw ex |
|  | `domain.whois.registrant.state` | eq in wc fz sw ex |
|  | `domain.whois.registrant.postal_code` | eq in wc fz sw ex |
|  | `domain.whois.registrant.country` | eq in wc fz sw ex |
|  | `domain.whois.registrant.phone` | eq in wc fz sw ex |
|  | `domain.whois.registrant.email` | eq in wc fz sw ex |
|  | `domain.whois.name_servers` | eq in wc fz sw ex |
|  | `domain.whois.domain_status` | eq in wc fz sw ex |
|  | `domain.whois_normalized.registrant.organization` | eq in wc fz sw ex |
|  | `domain.whois_normalized.registrant.phone` | eq in wc fz sw ex |
|  | `domain.whois_normalized.registrant.email` | eq in wc fz sw ex |
|  | `domain.whois_normalized.registrant.email_fqdn_apex` | eq in wc fz sw ex |
|  | `domain.whois_normalized.registrant.email_domain_apex` | eq in wc fz sw ex |
|  | `domain.whois_registrant_email_historical` | eq in wc fz sw ex |
|  | `domain.whois.create_date` | eq in lte gte ex |
|  | `domain.whois.update_date` | eq in lte gte ex |
|  | `domain.whois.expiry_date` | eq in lte gte ex |
|  | `domain.whois_create_date_historical` | eq in lte gte ex |
|  | `domain.whois_last_change_date` | eq in lte gte ex |
|  | `domain.whois_privacy_enabled` | eq in ex |
| DNS | `domain.dns.a.ip_addresses` | eq in wc fz sw ex |
|  | `dns.a.ip_addresses` | eq in wc fz sw ex |
|  | `dns.aaaa.ip_addresses` | eq in wc fz sw ex |
|  | `dns.ns.name_servers` | eq in wc fz sw ex |
|  | `dns.mx.mail_servers` | eq in wc fz sw ex |
|  | `dns.soa.mnames` | eq in wc fz sw ex |
|  | `dns.soa.rnames` | eq in wc fz sw ex |
|  | `dns.soa.rname_emails` | eq in wc fz sw ex |
|  | `dns.txt.values` | eq in wc fz sw ex |
|  | `dns.cname.values` | eq in wc fz sw ex |
|  | `dns.others.type` | eq in wc fz sw ex |
|  | `dns.others.values` | eq in wc fz sw ex |
|  | `domain.dns.a.update_date` | eq in lte gte ex |
|  | `domain.dns_update_date` | eq in lte gte ex |
|  | `domain.dns_last_change_date` | eq in lte gte ex |
|  | `dns.a.update_date` | eq in lte gte ex |
|  | `dns.aaaa.update_date` | eq in lte gte ex |
|  | `dns.ns.update_date` | eq in lte gte ex |
|  | `dns.mx.update_date` | eq in lte gte ex |
|  | `dns.soa.update_date` | eq in lte gte ex |
|  | `dns.txt.update_date` | eq in lte gte ex |
|  | `dns.cname.update_date` | eq in lte gte ex |
|  | `dns.others.update_date` | eq in lte gte ex |
|  | `dns_update_date` | eq in lte gte ex |
|  | `dns_last_change_date` | eq in lte gte ex |
| IP History | `domain.ip_history` | eq in wc fz sw ex |
|  | `ip_history` | eq in wc fz sw ex |
| SSL | `ssl.fqdns` | eq in wc fz sw ex |
|  | `ssl.fingerprint.sha256` | eq in wc fz sw ex |
|  | `ssl.fingerprint.sha1` | eq in wc fz sw ex |
|  | `ssl.fingerprint.md5` | eq in wc fz sw ex |
|  | `ssl.signature.value` | eq in wc fz sw ex |
|  | `ssl.issuer_dn` | eq in wc fz sw ex |
|  | `ssl.issuer.common_name` | eq in wc fz sw ex |
|  | `ssl.issuer.country` | eq in wc fz sw ex |
|  | `ssl.issuer.state` | eq in wc fz sw ex |
|  | `ssl.issuer.locality` | eq in wc fz sw ex |
|  | `ssl.issuer.organization` | eq in wc fz sw ex |
|  | `ssl.issuer.organizational_unit` | eq in wc fz sw ex |
|  | `ssl.subject_dn` | eq in wc fz sw ex |
|  | `ssl.subject.common_name` | eq in wc fz sw ex |
|  | `ssl.subject.country` | eq in wc fz sw ex |
|  | `ssl.subject.state` | eq in wc fz sw ex |
|  | `ssl.subject.locality` | eq in wc fz sw ex |
|  | `ssl.subject.organization` | eq in wc fz sw ex |
|  | `ssl.subject.organizational_unit` | eq in wc fz sw ex |
|  | `ssl.extensions.subject_alt_name.dns_names` | eq in wc fz sw ex |
|  | `domain.ssl.validity.start_date` | eq in lte gte ex |
|  | `domain.ssl.validity.end_date` | eq in lte gte ex |
|  | `domain.ssl_last_change_date` | eq in lte gte ex |
|  | `ssl.validity.start_date` | eq in lte gte ex |
|  | `ssl.validity.end_date` | eq in lte gte ex |
|  | `ssl.validity.length` | eq in lte gte ex |
|  | `ssl_last_change_date` | eq in lte gte ex |
|  | `ssl.signature.is_self_signed` | eq in ex |
|  | `ssl.signature.is_valid` | eq in ex |
| Webdata & HTTP | `webdata.url` | eq in wc fz sw ex |
|  | `webdata.connection_status` | eq in wc fz sw ex |
|  | `webdata.html.source_code_hash` | eq in wc fz sw ex |
|  | `webdata.http.redirection_history.url` | eq in wc fz sw ex |
|  | `webdata.http.final_url` | eq in wc fz sw ex |
|  | `webdata.http.final_fqdn` | eq in wc fz sw ex |
|  | `webdata.http.final_domain` | eq in wc fz sw ex |
|  | `webdata.http.headers.others.name` | eq in wc fz sw ex |
|  | `webdata.http.headers.others.value` | eq in wc fz sw ex |
|  | `webdata.http.headers.access_control_allow_headers` | eq in wc fz sw ex |
|  | `webdata.http.headers.access_control_allow_methods` | eq in wc fz sw ex |
|  | `webdata.http.headers.access_control_allow_origin` | eq in wc fz sw ex |
|  | `webdata.http.headers.cache_control` | eq in wc fz sw ex |
|  | `webdata.http.headers.clear_site_data` | eq in wc fz sw ex |
|  | `webdata.http.headers.content_encoding` | eq in wc fz sw ex |
|  | `webdata.http.headers.content_security_policy` | eq in wc fz sw ex |
|  | `webdata.http.headers.content_type` | eq in wc fz sw ex |
|  | `webdata.http.headers.cross_origin_embedder_policy` | eq in wc fz sw ex |
|  | `webdata.http.headers.cross_origin_opener_policy` | eq in wc fz sw ex |
|  | `webdata.http.headers.cross_origin_resource_policy` | eq in wc fz sw ex |
|  | `webdata.http.headers.expect_ct` | eq in wc fz sw ex |
|  | `webdata.http.headers.feature_policy` | eq in wc fz sw ex |
|  | `webdata.http.headers.last_modified` | eq in wc fz sw ex |
|  | `webdata.http.headers.permission_policy` | eq in wc fz sw ex |
|  | `webdata.http.headers.referrer_policy` | eq in wc fz sw ex |
|  | `webdata.http.headers.server` | eq in wc fz sw ex |
|  | `webdata.http.headers.set_cookie` | eq in wc fz sw ex |
|  | `webdata.http.headers.strict_transport_security` | eq in wc fz sw ex |
|  | `webdata.http.headers.x_content_type_options` | eq in wc fz sw ex |
|  | `webdata.http.headers.x_download_options` | eq in wc fz sw ex |
|  | `webdata.http.headers.x_frame_options` | eq in wc fz sw ex |
|  | `webdata.http.headers.x_permitted_cross_domain_policies` | eq in wc fz sw ex |
|  | `webdata.http.headers.x_powered_by` | eq in wc fz sw ex |
|  | `webdata.http.headers.x_xss_protection` | eq in wc fz sw ex |
|  | `webdata.http.cookies.name` | eq in wc fz sw ex |
|  | `webdata.http.cookies.value` | eq in wc fz sw ex |
|  | `webdata.http.status_code_first` | eq in lte gte ex |
|  | `webdata.http.status_code_last` | eq in lte gte ex |
|  | `webdata.http.redirection_history.status_code` | eq in lte gte ex |
|  | `webdata.http.external_redirection` | eq in ex |

Each example links to its own page with the request and the response.

## Filters › Name & Extension

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Look Up an Exact FQDN](/reference/discovery/domain-search/examples/fqdn/) | `fqdn` | `eq` |  |
| [Subdomains Only](/reference/discovery/domain-search/examples/type/) | `type` | `eq` |  |
| [Internationalized FQDNs Only](/reference/discovery/domain-search/examples/is-idn/) | `is_idn` | `eq` |  |
| [Latinized Form of an IDN Name](/reference/discovery/domain-search/examples/name-latinized/) | `name.latinized` | `contains_any` |  |
| [Names With Confusable Characters](/reference/discovery/domain-search/examples/name-contains-confusable/) | `name.contains_confusable` | `eq` |  |
| [All FQDNs Under One Domain](/reference/discovery/domain-search/examples/domain/) | `domain` | `eq` |  |
| [Internationalized Domains Only](/reference/discovery/domain-search/examples/domain-is-idn/) | `domain.is_idn` | `eq` |  |
| [Same Name Across All Extensions](/reference/discovery/domain-search/examples/domain-name/) | `domain.name` | `eq` |  |
| [Domain Names Containing Letters](/reference/discovery/domain-search/examples/domain-name-contains-letter/) | `domain.name.contains_letter` | `eq` |  |
| [Domain Names Containing Digits](/reference/discovery/domain-search/examples/domain-name-contains-number/) | `domain.name.contains_number` | `eq` |  |
| [Domain Names Containing a Hyphen](/reference/discovery/domain-search/examples/domain-name-contains-hyphen/) | `domain.name.contains_hyphen` | `eq` |  |
| [Short Domain Names (Up to 5 Characters)](/reference/discovery/domain-search/examples/domain-name-length/) | `domain.name.length` | `lte` |  |
| [Domain Names in German](/reference/discovery/domain-search/examples/domain-name-language/) | `domain.name.language` | `eq` |  |
| [Names Built From Two Keywords](/reference/discovery/domain-search/examples/domain-name-keywords/) | `domain.name.keywords` | `eq` |  |
| [Names With Three or More Keywords](/reference/discovery/domain-search/examples/domain-name-keyword-count/) | `domain.name.keyword_count` | `gte` |  |
| [Domains Under One Extension](/reference/discovery/domain-search/examples/domain-extension/) | `domain.extension` | `eq` |  |
| [Internationalized Extensions Only](/reference/discovery/domain-search/examples/domain-extension-is-idn/) | `domain.extension.is_idn` | `eq` |  |
| [Every Extension Under .uk](/reference/discovery/domain-search/examples/domain-extension-root/) | `domain.extension_root` | `eq` |  |
| [Second-Level Extensions Like co.uk](/reference/discovery/domain-search/examples/domain-extension-sub/) | `domain.extension_sub` | `eq` |  |
| [Country-Code Extensions Only](/reference/discovery/domain-search/examples/domain-extension-type/) | `domain.extension_type` | `eq` |  |

## Filters › Subdomain

| Example | Field | Operator | Sort |
|---|---|---|---|
| [One Subdomain Across Domains](/reference/discovery/domain-search/examples/subdomain/) | `subdomain` | `eq` |  |
| [Internationalized Subdomains](/reference/discovery/domain-search/examples/subdomain-is-idn/) | `subdomain.is_idn` | `eq` |  |
| [Subdomains Containing Letters](/reference/discovery/domain-search/examples/subdomain-contains-letter/) | `subdomain.contains_letter` | `eq` |  |
| [Subdomains Containing Digits](/reference/discovery/domain-search/examples/subdomain-contains-number/) | `subdomain.contains_number` | `eq` |  |
| [Subdomains Containing a Hyphen](/reference/discovery/domain-search/examples/subdomain-contains-hyphen/) | `subdomain.contains_hyphen` | `eq` |  |
| [Short Subdomains (Up to 3 Characters)](/reference/discovery/domain-search/examples/subdomain-length/) | `subdomain.length` | `lte` |  |
| [Last Subdomain Label](/reference/discovery/domain-search/examples/subdomain-last/) | `subdomain_last` | `eq` |  |
| [Root Subdomain Label](/reference/discovery/domain-search/examples/subdomain-root/) | `subdomain_root` | `eq` |  |
| [Deeply Nested Subdomains](/reference/discovery/domain-search/examples/subdomain-level-count/) | `subdomain_level_count` | `gte` |  |

## Filters › WHOIS

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Domains Registered Since 2025](/reference/discovery/domain-search/examples/domain-whois-create-date/) | `domain.whois.create_date` | `gte` |  |
| [WHOIS Records Updated Since 2026](/reference/discovery/domain-search/examples/domain-whois-update-date/) | `domain.whois.update_date` | `gte` |  |
| [Domains Expiring by the End of 2026](/reference/discovery/domain-search/examples/domain-whois-expiry-date/) | `domain.whois.expiry_date` | `lte` |  |
| [Registered Through GoDaddy](/reference/discovery/domain-search/examples/domain-whois-registrar/) | `domain.whois.registrar` | `eq` |  |
| [Registrant Name Present](/reference/discovery/domain-search/examples/domain-whois-registrant-name/) | `domain.whois.registrant.name` | `exists` |  |
| [Registrant Organization Is Cloudflare](/reference/discovery/domain-search/examples/domain-whois-registrant-organization/) | `domain.whois.registrant.organization` | `eq` |  |
| [Registrant Street Present](/reference/discovery/domain-search/examples/domain-whois-registrant-street/) | `domain.whois.registrant.street` | `exists` |  |
| [Registrants in One City](/reference/discovery/domain-search/examples/domain-whois-registrant-city/) | `domain.whois.registrant.city` | `eq` |  |
| [Registrants in One State](/reference/discovery/domain-search/examples/domain-whois-registrant-state/) | `domain.whois.registrant.state` | `eq` |  |
| [Registrant Postal Code Present](/reference/discovery/domain-search/examples/domain-whois-registrant-postal-code/) | `domain.whois.registrant.postal_code` | `exists` |  |
| [Registrants in Germany](/reference/discovery/domain-search/examples/domain-whois-registrant-country/) | `domain.whois.registrant.country` | `eq` |  |
| [Registrant Phone Present](/reference/discovery/domain-search/examples/domain-whois-registrant-phone/) | `domain.whois.registrant.phone` | `exists` |  |
| [Registrant E-mail at a Privacy Service](/reference/discovery/domain-search/examples/domain-whois-registrant-email/) | `domain.whois.registrant.email` | `wildcard` |  |
| [Name Servers at Cloudflare](/reference/discovery/domain-search/examples/domain-whois-name-servers/) | `domain.whois.name_servers` | `wildcard` |  |
| [Domains on Client Hold](/reference/discovery/domain-search/examples/domain-whois-domain-status/) | `domain.whois.domain_status` | `eq` |  |
| [Normalized Registrant Organization](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-organization/) | `domain.whois_normalized.registrant.organization` | `wildcard` |  |
| [Normalized Registrant Phone Present](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-phone/) | `domain.whois_normalized.registrant.phone` | `exists` |  |
| [Normalized Registrant E-mail Present](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-email/) | `domain.whois_normalized.registrant.email` | `exists` |  |
| [Registrant E-mail Host](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-email-fqdn-apex/) | `domain.whois_normalized.registrant.email_fqdn_apex` | `eq` |  |
| [Registrant E-mail Domain](/reference/discovery/domain-search/examples/domain-whois-normalized-registrant-email-domain-apex/) | `domain.whois_normalized.registrant.email_domain_apex` | `eq` |  |
| [First Registered Before 2001](/reference/discovery/domain-search/examples/domain-whois-create-date-historical/) | `domain.whois_create_date_historical` | `lte` |  |
| [WHOIS Changed Since the Start of 2026](/reference/discovery/domain-search/examples/domain-whois-last-change-date/) | `domain.whois_last_change_date` | `gte` |  |
| [Past Registrant E-mails at a Privacy Service](/reference/discovery/domain-search/examples/domain-whois-registrant-email-historical/) | `domain.whois_registrant_email_historical` | `wildcard` |  |
| [WHOIS Privacy Enabled](/reference/discovery/domain-search/examples/domain-whois-privacy-enabled/) | `domain.whois_privacy_enabled` | `eq` |  |

## Filters › DNS

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Domain IPv4 (A) Record Pointing to an IP](/reference/discovery/domain-search/examples/domain-dns-a-ip-addresses/) | `domain.dns.a.ip_addresses` | `eq` |  |
| [Domain IPv4 (A) Record Updated Since 2026](/reference/discovery/domain-search/examples/domain-dns-a-update-date/) | `domain.dns.a.update_date` | `gte` |  |
| [Domain DNS Updated Since 2026](/reference/discovery/domain-search/examples/domain-dns-update-date/) | `domain.dns_update_date` | `gte` |  |
| [Domain DNS Changed Since 2026](/reference/discovery/domain-search/examples/domain-dns-last-change-date/) | `domain.dns_last_change_date` | `gte` |  |
| [FQDN IPv4 (A) Record Pointing to an IP](/reference/discovery/domain-search/examples/dns-a-ip-addresses/) | `dns.a.ip_addresses` | `eq` |  |
| [A Record Updated Since 2026](/reference/discovery/domain-search/examples/dns-a-update-date/) | `dns.a.update_date` | `gte` |  |
| [AAAA Record Pointing to an IPv6 Address](/reference/discovery/domain-search/examples/dns-aaaa-ip-addresses/) | `dns.aaaa.ip_addresses` | `eq` |  |
| [AAAA Record Updated Since 2026](/reference/discovery/domain-search/examples/dns-aaaa-update-date/) | `dns.aaaa.update_date` | `gte` |  |
| [Delegated to a Name Server](/reference/discovery/domain-search/examples/dns-ns-name-servers/) | `dns.ns.name_servers` | `eq` |  |
| [NS Record Updated Since 2026](/reference/discovery/domain-search/examples/dns-ns-update-date/) | `dns.ns.update_date` | `gte` |  |
| [Mail Handled by Google Workspace](/reference/discovery/domain-search/examples/dns-mx-mail-servers/) | `dns.mx.mail_servers` | `eq` |  |
| [MX Record Updated Since 2026](/reference/discovery/domain-search/examples/dns-mx-update-date/) | `dns.mx.update_date` | `gte` |  |
| [SOA Primary Name Server](/reference/discovery/domain-search/examples/dns-soa-mnames/) | `dns.soa.mnames` | `eq` |  |
| [SOA Responsible Mailbox](/reference/discovery/domain-search/examples/dns-soa-rnames/) | `dns.soa.rnames` | `eq` |  |
| [SOA Contact E-mail Domain](/reference/discovery/domain-search/examples/dns-soa-rname-emails/) | `dns.soa.rname_emails` | `wildcard` |  |
| [SOA Record Updated Since 2026](/reference/discovery/domain-search/examples/dns-soa-update-date/) | `dns.soa.update_date` | `gte` |  |
| [TXT Record Starting With a Verification Token](/reference/discovery/domain-search/examples/dns-txt-values/) | `dns.txt.values` | `startswith` |  |
| [TXT Record Updated Since 2026](/reference/discovery/domain-search/examples/dns-txt-update-date/) | `dns.txt.update_date` | `gte` |  |
| [CNAME Pointing to GitHub Pages](/reference/discovery/domain-search/examples/dns-cname-values/) | `dns.cname.values` | `wildcard` |  |
| [CNAME Record Updated Since 2026](/reference/discovery/domain-search/examples/dns-cname-update-date/) | `dns.cname.update_date` | `gte` |  |
| [Other Record Type: DNSKEY](/reference/discovery/domain-search/examples/dns-others-type/) | `dns.others.type` | `eq` |  |
| [Other Record Values Present](/reference/discovery/domain-search/examples/dns-others-values/) | `dns.others.values` | `exists` |  |
| [Other Records Updated Since 2026](/reference/discovery/domain-search/examples/dns-others-update-date/) | `dns.others.update_date` | `gte` |  |
| [DNS Updated Since 2026](/reference/discovery/domain-search/examples/dns-update-date/) | `dns_update_date` | `gte` |  |
| [DNS Changed Since 2026](/reference/discovery/domain-search/examples/dns-last-change-date/) | `dns_last_change_date` | `gte` |  |

## Filters › IP History

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Domain Once Resolved to an IP](/reference/discovery/domain-search/examples/domain-ip-history/) | `domain.ip_history` | `eq` |  |
| [FQDN Once Resolved to Any of Several IPs](/reference/discovery/domain-search/examples/ip-history/) | `ip_history` | `in` |  |

## Filters › SSL

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Domain Certificate Issued Since 2026](/reference/discovery/domain-search/examples/domain-ssl-validity-start-date/) | `domain.ssl.validity.start_date` | `gte` |  |
| [Domain Certificate Expiring by October 2026](/reference/discovery/domain-search/examples/domain-ssl-validity-end-date/) | `domain.ssl.validity.end_date` | `lte` |  |
| [Domain Certificate Changed Since 2026](/reference/discovery/domain-search/examples/domain-ssl-last-change-date/) | `domain.ssl_last_change_date` | `gte` |  |
| [Certificates Covering a Name](/reference/discovery/domain-search/examples/ssl-fqdns/) | `ssl.fqdns` | `eq` |  |
| [Certificate by SHA-256 Fingerprint](/reference/discovery/domain-search/examples/ssl-fingerprint-sha256/) | `ssl.fingerprint.sha256` | `eq` |  |
| [Certificate by SHA-1 Fingerprint](/reference/discovery/domain-search/examples/ssl-fingerprint-sha1/) | `ssl.fingerprint.sha1` | `eq` |  |
| [Certificate by MD5 Fingerprint](/reference/discovery/domain-search/examples/ssl-fingerprint-md5/) | `ssl.fingerprint.md5` | `eq` |  |
| [Certificate Issued Since 2026](/reference/discovery/domain-search/examples/ssl-validity-start-date/) | `ssl.validity.start_date` | `gte` |  |
| [Certificate Expiring by October 2026](/reference/discovery/domain-search/examples/ssl-validity-end-date/) | `ssl.validity.end_date` | `lte` |  |
| [Certificates Valid for 90 Days or Less](/reference/discovery/domain-search/examples/ssl-validity-length/) | `ssl.validity.length` | `lte` |  |
| [Self-Signed Certificates](/reference/discovery/domain-search/examples/ssl-signature-is-self-signed/) | `ssl.signature.is_self_signed` | `eq` |  |
| [Certificates With a Valid Signature](/reference/discovery/domain-search/examples/ssl-signature-is-valid/) | `ssl.signature.is_valid` | `eq` |  |
| [Certificate Signature Present](/reference/discovery/domain-search/examples/ssl-signature-value/) | `ssl.signature.value` | `exists` |  |
| [Issuer Distinguished Name](/reference/discovery/domain-search/examples/ssl-issuer-dn/) | `ssl.issuer_dn` | `eq` |  |
| [Issuer Common Name](/reference/discovery/domain-search/examples/ssl-issuer-common-name/) | `ssl.issuer.common_name` | `eq` |  |
| [Issuer Country](/reference/discovery/domain-search/examples/ssl-issuer-country/) | `ssl.issuer.country` | `eq` |  |
| [Issuer State](/reference/discovery/domain-search/examples/ssl-issuer-state/) | `ssl.issuer.state` | `eq` |  |
| [Issuer Locality](/reference/discovery/domain-search/examples/ssl-issuer-locality/) | `ssl.issuer.locality` | `eq` |  |
| [Issued by Let's Encrypt](/reference/discovery/domain-search/examples/ssl-issuer-organization/) | `ssl.issuer.organization` | `eq` |  |
| [Issuer Organizational Unit Present](/reference/discovery/domain-search/examples/ssl-issuer-organizational-unit/) | `ssl.issuer.organizational_unit` | `exists` |  |
| [Wildcard Certificates by Subject DN](/reference/discovery/domain-search/examples/ssl-subject-dn/) | `ssl.subject_dn` | `startswith` |  |
| [Subject Common Name](/reference/discovery/domain-search/examples/ssl-subject-common-name/) | `ssl.subject.common_name` | `eq` |  |
| [Subject Country](/reference/discovery/domain-search/examples/ssl-subject-country/) | `ssl.subject.country` | `eq` |  |
| [Subject State](/reference/discovery/domain-search/examples/ssl-subject-state/) | `ssl.subject.state` | `eq` |  |
| [Subject Locality](/reference/discovery/domain-search/examples/ssl-subject-locality/) | `ssl.subject.locality` | `eq` |  |
| [Subject Organization](/reference/discovery/domain-search/examples/ssl-subject-organization/) | `ssl.subject.organization` | `eq` |  |
| [Subject Organizational Unit Present](/reference/discovery/domain-search/examples/ssl-subject-organizational-unit/) | `ssl.subject.organizational_unit` | `exists` |  |
| [Subject Alternative Names](/reference/discovery/domain-search/examples/ssl-extensions-subject-alt-name-dns-names/) | `ssl.extensions.subject_alt_name.dns_names` | `in` |  |
| [Certificate Changed Since 2026](/reference/discovery/domain-search/examples/ssl-last-change-date/) | `ssl_last_change_date` | `gte` |  |

## Filters › Webdata & HTTP

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Web URL Starting With https://](/reference/discovery/domain-search/examples/webdata-url/) | `webdata.url` | `startswith` |  |
| [Web Connection Failed With an SSL Error](/reference/discovery/domain-search/examples/webdata-connection-status/) | `webdata.connection_status` | `eq` |  |
| [Pages With an Empty HTML Body](/reference/discovery/domain-search/examples/webdata-html-source-code-hash/) | `webdata.html.source_code_hash` | `eq` |  |
| [First Response Is a Permanent Redirect](/reference/discovery/domain-search/examples/webdata-http-status-code-first/) | `webdata.http.status_code_first` | `eq` |  |
| [Final Response Is a Server Error](/reference/discovery/domain-search/examples/webdata-http-status-code-last/) | `webdata.http.status_code_last` | `gte` |  |
| [Redirect Chain Through Plain HTTP](/reference/discovery/domain-search/examples/webdata-http-redirection-history-url/) | `webdata.http.redirection_history.url` | `startswith` |  |
| [Redirect Chain With a 302](/reference/discovery/domain-search/examples/webdata-http-redirection-history-status-code/) | `webdata.http.redirection_history.status_code` | `eq` |  |
| [Redirects to Another Site](/reference/discovery/domain-search/examples/webdata-http-external-redirection/) | `webdata.http.external_redirection` | `eq` |  |
| [Final URL](/reference/discovery/domain-search/examples/webdata-http-final-url/) | `webdata.http.final_url` | `eq` |  |
| [Final FQDN](/reference/discovery/domain-search/examples/webdata-http-final-fqdn/) | `webdata.http.final_fqdn` | `eq` |  |
| [Final Domain](/reference/discovery/domain-search/examples/webdata-http-final-domain/) | `webdata.http.final_domain` | `eq` |  |
| [Other Header Name](/reference/discovery/domain-search/examples/webdata-http-headers-others-name/) | `webdata.http.headers.others.name` | `eq` |  |
| [Other Header Value](/reference/discovery/domain-search/examples/webdata-http-headers-others-value/) | `webdata.http.headers.others.value` | `wildcard` |  |
| [Access-Control-Allow-Headers Present](/reference/discovery/domain-search/examples/webdata-http-headers-access-control-allow-headers/) | `webdata.http.headers.access_control_allow_headers` | `exists` |  |
| [Access-Control-Allow-Methods Present](/reference/discovery/domain-search/examples/webdata-http-headers-access-control-allow-methods/) | `webdata.http.headers.access_control_allow_methods` | `exists` |  |
| [CORS Open to Any Origin](/reference/discovery/domain-search/examples/webdata-http-headers-access-control-allow-origin/) | `webdata.http.headers.access_control_allow_origin` | `eq` |  |
| [Cache-Control With a Max Age](/reference/discovery/domain-search/examples/webdata-http-headers-cache-control/) | `webdata.http.headers.cache_control` | `startswith` |  |
| [Clear-Site-Data Present](/reference/discovery/domain-search/examples/webdata-http-headers-clear-site-data/) | `webdata.http.headers.clear_site_data` | `exists` |  |
| [Compressed With Gzip](/reference/discovery/domain-search/examples/webdata-http-headers-content-encoding/) | `webdata.http.headers.content_encoding` | `eq` |  |
| [CSP Allowing Unsafe Inline Code](/reference/discovery/domain-search/examples/webdata-http-headers-content-security-policy/) | `webdata.http.headers.content_security_policy` | `wildcard` |  |
| [HTML Content Type](/reference/discovery/domain-search/examples/webdata-http-headers-content-type/) | `webdata.http.headers.content_type` | `startswith` |  |
| [Cross-Origin-Embedder-Policy](/reference/discovery/domain-search/examples/webdata-http-headers-cross-origin-embedder-policy/) | `webdata.http.headers.cross_origin_embedder_policy` | `eq` |  |
| [Cross-Origin-Opener-Policy](/reference/discovery/domain-search/examples/webdata-http-headers-cross-origin-opener-policy/) | `webdata.http.headers.cross_origin_opener_policy` | `eq` |  |
| [Cross-Origin-Resource-Policy](/reference/discovery/domain-search/examples/webdata-http-headers-cross-origin-resource-policy/) | `webdata.http.headers.cross_origin_resource_policy` | `eq` |  |
| [Expect-CT Present](/reference/discovery/domain-search/examples/webdata-http-headers-expect-ct/) | `webdata.http.headers.expect_ct` | `exists` |  |
| [Feature-Policy Present](/reference/discovery/domain-search/examples/webdata-http-headers-feature-policy/) | `webdata.http.headers.feature_policy` | `exists` |  |
| [Last-Modified Present](/reference/discovery/domain-search/examples/webdata-http-headers-last-modified/) | `webdata.http.headers.last_modified` | `exists` |  |
| [Permission Policy Present](/reference/discovery/domain-search/examples/webdata-http-headers-permission-policy/) | `webdata.http.headers.permission_policy` | `exists` |  |
| [Referrer-Policy](/reference/discovery/domain-search/examples/webdata-http-headers-referrer-policy/) | `webdata.http.headers.referrer_policy` | `eq` |  |
| [Server Header](/reference/discovery/domain-search/examples/webdata-http-headers-server/) | `webdata.http.headers.server` | `eq` |  |
| [Sets a PHP Session Cookie](/reference/discovery/domain-search/examples/webdata-http-headers-set-cookie/) | `webdata.http.headers.set_cookie` | `startswith` |  |
| [HSTS With Preload](/reference/discovery/domain-search/examples/webdata-http-headers-strict-transport-security/) | `webdata.http.headers.strict_transport_security` | `wildcard` |  |
| [X-Content-Type-Options](/reference/discovery/domain-search/examples/webdata-http-headers-x-content-type-options/) | `webdata.http.headers.x_content_type_options` | `eq` |  |
| [X-Download-Options](/reference/discovery/domain-search/examples/webdata-http-headers-x-download-options/) | `webdata.http.headers.x_download_options` | `eq` |  |
| [X-Frame-Options](/reference/discovery/domain-search/examples/webdata-http-headers-x-frame-options/) | `webdata.http.headers.x_frame_options` | `in` |  |
| [X-Permitted-Cross-Domain-Policies](/reference/discovery/domain-search/examples/webdata-http-headers-x-permitted-cross-domain-policies/) | `webdata.http.headers.x_permitted_cross_domain_policies` | `eq` |  |
| [Powered by PHP](/reference/discovery/domain-search/examples/webdata-http-headers-x-powered-by/) | `webdata.http.headers.x_powered_by` | `startswith` |  |
| [X-XSS-Protection](/reference/discovery/domain-search/examples/webdata-http-headers-x-xss-protection/) | `webdata.http.headers.x_xss_protection` | `eq` |  |
| [Cookie Name](/reference/discovery/domain-search/examples/webdata-http-cookies-name/) | `webdata.http.cookies.name` | `eq` |  |
| [Cookie Value Present](/reference/discovery/domain-search/examples/webdata-http-cookies-value/) | `webdata.http.cookies.value` | `exists` |  |

## Combinations › Operators

One example for each operator, on a field where it is the natural choice.

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Wildcard: Names Containing a Word](/reference/discovery/domain-search/examples/wildcard-names-containing-a-word/) | `domain.name` | `wildcard` |  |
| [Fuzzy: Names Close to a Brand](/reference/discovery/domain-search/examples/fuzzy-names-close-to-a-brand/) | `domain.name` | `fuzzy` |  |
| [Starts With: Login Hosts](/reference/discovery/domain-search/examples/startswith-login-hosts/) | `fqdn` | `startswith` |  |
| [Ends With: Names Ending in a Word](/reference/discovery/domain-search/examples/endswith-names-ending-in-a-word/) | `domain.name` | `endswith` |  |
| [In: One of Several Extensions](/reference/discovery/domain-search/examples/in-one-of-several-extensions/) | `domain.extension`<br>`domain.name` | `in`<br>`eq` |  |
| [Contains Any: Phishing-Style Keywords](/reference/discovery/domain-search/examples/contains-any-phishing-style-keywords/) | `domain.name` | `contains_any` |  |
| [Contains All: Every Keyword Present](/reference/discovery/domain-search/examples/contains-all-every-keyword-present/) | `domain.name` | `contains_all` |  |
| [Range: Name Length Between 3 and 4](/reference/discovery/domain-search/examples/range-name-length-between-3-and-4/) | `domain.name.length`<br>`domain.extension` | `gte`<br>`lte`<br>`eq` |  |
| [Exists False: Domains Without a Registrar](/reference/discovery/domain-search/examples/exists-false-domains-without-a-registrar/) | `domain.whois.registrar`<br>`type` | `exists`<br>`eq` |  |

## Combinations › Must, Should and Must Not

`must` filters all have to match (AND), at least one `should` filter has to match (OR), and no `must_not` filter may match (NOT).

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Look-Alikes Excluding the Real Domain](/reference/discovery/domain-search/examples/look-alikes-excluding-the-real-domain/) | `domain.name`<br>`domain` | `fuzzy`<br>`eq` |  |
| [Should: Either of Two Registrars](/reference/discovery/domain-search/examples/should-either-of-two-registrars/) | `domain.whois.registrar` | `eq` |  |
| [Must and Should Together](/reference/discovery/domain-search/examples/must-and-should-together/) | `domain.extension`<br>`dns.ns.name_servers` | `eq`<br>`wildcard` |  |
| [Must Not: Registrable Domains Outside .com](/reference/discovery/domain-search/examples/must-not-registrable-domains-outside-com/) | `type`<br>`domain.name`<br>`domain.extension` | `eq` |  |
| [All Three: New Shops Without WHOIS Privacy](/reference/discovery/domain-search/examples/all-three-new-shops-without-whois-privacy/) | `domain.whois.create_date`<br>`domain.name.keywords`<br>`domain.whois_privacy_enabled` | `gte`<br>`eq` |  |

## Combinations › Sorting

`sort` is a list of `{field, order}`; `order` is `asc` or `desc`. One example for each sortable field.

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Sort by Name (A to Z)](/reference/discovery/domain-search/examples/sort-by-name/) | `domain.extension`<br>`type` | `eq` | `punycode` |
| [Sort by Extension](/reference/discovery/domain-search/examples/sort-by-extension/) | `domain.name`<br>`type` | `eq` | `domain.extension.punycode` |
| [Newest Registrations First](/reference/discovery/domain-search/examples/newest-registrations-first/) | `domain.whois.create_date`<br>`type` | `gte`<br>`eq` | `domain.whois.create_date` |
| [Soonest to Expire First](/reference/discovery/domain-search/examples/soonest-to-expire-first/) | `domain.whois.expiry_date`<br>`domain.extension` | `gte`<br>`eq` | `domain.whois.expiry_date` |
| [Most Recently Updated WHOIS First](/reference/discovery/domain-search/examples/most-recently-updated-whois-first/) | `domain.whois.registrar` | `eq` | `domain.whois.update_date` |
| [Latest WHOIS Changes First](/reference/discovery/domain-search/examples/latest-whois-changes-first/) | `domain.extension`<br>`type` | `eq` | `domain.whois_last_change_date` |
| [Latest DNS Changes First](/reference/discovery/domain-search/examples/latest-dns-changes-first/) | `dns.ns.name_servers` | `wildcard` | `dns_last_change_date` |
| [Latest Certificate Changes First](/reference/discovery/domain-search/examples/latest-certificate-changes-first/) | `ssl.issuer.organization` | `eq` | `ssl_last_change_date` |
| [Sort by Two Fields](/reference/discovery/domain-search/examples/sort-by-two-fields/) | `domain.name` | `eq` | `domain.extension.punycode`<br>`domain.whois.create_date` |

## Combinations › Pagination

`page` and `page_size` are query parameters. `result_count` is always the full total; results page up to 10,000.

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Second Page of Results](/reference/discovery/domain-search/examples/second-page-of-results/) | `domain.extension`<br>`type` | `eq` |  |
| [Larger Pages (100 Results)](/reference/discovery/domain-search/examples/larger-pages/) | `domain.extension`<br>`type` | `eq` |  |
| [Last Reachable Page (10,000 Results)](/reference/discovery/domain-search/examples/last-reachable-page/) | `domain.extension`<br>`type` | `eq` |  |

## Combinations › Investigations

Filters combined the way they are used in practice.

| Example | Field | Operator | Sort |
|---|---|---|---|
| [Expiring Soon With WHOIS Privacy](/reference/discovery/domain-search/examples/expiring-soon-with-whois-privacy/) | `domain.whois.expiry_date`<br>`domain.whois_privacy_enabled` | `lte`<br>`eq` |  |
| [Self-Signed or Invalid Certificates](/reference/discovery/domain-search/examples/self-signed-or-invalid-certificates/) | `ssl.signature.is_self_signed`<br>`ssl.signature.is_valid` | `eq` |  |
| [Live Sites Without HSTS](/reference/discovery/domain-search/examples/live-sites-without-hsts/) | `webdata.connection_status`<br>`webdata.http.headers.strict_transport_security` | `eq`<br>`exists` |  |
| [Missing Clickjacking Protection](/reference/discovery/domain-search/examples/missing-clickjacking-protection/) | `webdata.connection_status`<br>`webdata.http.headers.x_frame_options`<br>`webdata.http.headers.content_security_policy` | `eq`<br>`exists` |  |
| [New Look-Alikes With Mail Servers](/reference/discovery/domain-search/examples/new-look-alikes-with-mail-servers/) | `domain.name`<br>`domain.whois.create_date`<br>`dns.mx.mail_servers`<br>`domain` | `fuzzy`<br>`gte`<br>`exists`<br>`eq` |  |
| [Wildcard Certificates From Let's Encrypt](/reference/discovery/domain-search/examples/wildcard-certificates-from-lets-encrypt/) | `ssl.subject_dn`<br>`ssl.issuer.organization` | `startswith`<br>`eq` |  |
| [Confusable IDN Domains](/reference/discovery/domain-search/examples/confusable-idn-domains/) | `is_idn`<br>`name.contains_confusable` | `eq` |  |
| [Redirects Away to Another Site](/reference/discovery/domain-search/examples/redirects-away-to-another-site/) | `webdata.http.external_redirection`<br>`webdata.http.status_code_first` | `eq`<br>`in` |  |
