Domain Search Examples
Worked examples for Domain Search: one for every filter field, then combinations of operators, must / should / must_not, sorting and pagination.
Every example is a real request with the response the API returned. The body is {"filters": {"must": [...], "should": [...], "must_not": [...]}, "sort": [...]}; a filter is {"name": <field>, "type": <operator>, "value": <value>} (see Search & Filters). The field examples use the operator that fits the field best; not every field takes every operator, and the table below lists what each one accepts.
Responses are trimmed for display: results shows the first 3 records, long lists inside a record the first 10 items and very long texts the first 4,000 characters, while result_count stays the full total; each page says what was shortened. Personal data (WHOIS contact names, addresses, phone numbers and personal e-mail addresses) is redacted, and cookie values are masked (<value>). whois and whois_normalized are redacted separately, so a contact's organization can be redacted in one and shown in the other: when in doubt, it is redacted.
After the examples: Supported Operators by Field
- Endpoint
- Domain Search
183 examples
No examples match these filters.
Filters › Name & Extension
| Example | Field | Operator | Sort |
|---|---|---|---|
| Look Up an Exact FQDN | fqdn | eq | |
| Subdomains Only | type | eq | |
| Internationalized FQDNs Only | is_ | eq | |
| Latinized Form of an IDN Name | name. | contains_ | |
| Names With Confusable Characters | name. | eq | |
| All FQDNs Under One Domain | domain | eq | |
| Internationalized Domains Only | domain. | eq | |
| Same Name Across All Extensions | domain. | eq | |
| Domain Names Containing Letters | domain. | eq | |
| Domain Names Containing Digits | domain. | eq | |
| Domain Names Containing a Hyphen | domain. | eq | |
| Short Domain Names (Up to 5 Characters) | domain. | lte | |
| Domain Names in German | domain. | eq | |
| Names Built From Two Keywords | domain. | eq | |
| Names With Three or More Keywords | domain. | gte | |
| Domains Under One Extension | domain. | eq | |
| Internationalized Extensions Only | domain. | eq | |
| Every Extension Under .uk | domain. | eq | |
| Second-Level Extensions Like co.uk | domain. | eq | |
| Country-Code Extensions Only | domain. | eq |
Filters › Subdomain
| Example | Field | Operator | Sort |
|---|---|---|---|
| One Subdomain Across Domains | subdomain | eq | |
| Internationalized Subdomains | subdomain. | eq | |
| Subdomains Containing Letters | subdomain. | eq | |
| Subdomains Containing Digits | subdomain. | eq | |
| Subdomains Containing a Hyphen | subdomain. | eq | |
| Short Subdomains (Up to 3 Characters) | subdomain. | lte | |
| Last Subdomain Label | subdomain_ | eq | |
| Root Subdomain Label | subdomain_ | eq | |
| Deeply Nested Subdomains | subdomain_ | gte |
Filters › WHOIS
| Example | Field | Operator | Sort |
|---|---|---|---|
| Domains Registered Since 2025 | domain. | gte | |
| WHOIS Records Updated Since 2026 | domain. | gte | |
| Domains Expiring by the End of 2026 | domain. | lte | |
| Registered Through GoDaddy | domain. | eq | |
| Registrant Name Present | domain. | exists | |
| Registrant Organization Is Cloudflare | domain. | eq | |
| Registrant Street Present | domain. | exists | |
| Registrants in One City | domain. | eq | |
| Registrants in One State | domain. | eq | |
| Registrant Postal Code Present | domain. | exists | |
| Registrants in Germany | domain. | eq | |
| Registrant Phone Present | domain. | exists | |
| Registrant E-mail at a Privacy Service | domain. | wildcard | |
| Name Servers at Cloudflare | domain. | wildcard | |
| Domains on Client Hold | domain. | eq | |
| Normalized Registrant Organization | domain. | wildcard | |
| Normalized Registrant Phone Present | domain. | exists | |
| Normalized Registrant E-mail Present | domain. | exists | |
| Registrant E-mail Host | domain. | eq | |
| Registrant E-mail Domain | domain. | eq | |
| First Registered Before 2001 | domain. | lte | |
| WHOIS Changed Since the Start of 2026 | domain. | gte | |
| Past Registrant E-mails at a Privacy Service | domain. | wildcard | |
| WHOIS Privacy Enabled | domain. | eq |
Filters › DNS
Filters › IP History
| Example | Field | Operator | Sort |
|---|---|---|---|
| Domain Once Resolved to an IP | domain. | eq | |
| FQDN Once Resolved to Any of Several IPs | ip_ | in |
Filters › SSL
Filters › Webdata & HTTP
| Example | Field | Operator | Sort |
|---|---|---|---|
| Web URL Starting With https:// | webdata. | startswith | |
| Web Connection Failed With an SSL Error | webdata. | eq | |
| Pages With an Empty HTML Body | webdata. | eq | |
| First Response Is a Permanent Redirect | webdata. | eq | |
| Final Response Is a Server Error | webdata. | gte | |
| Redirect Chain Through Plain HTTP | webdata. | startswith | |
| Redirect Chain With a 302 | webdata. | eq | |
| Redirects to Another Site | webdata. | eq | |
| Final URL | webdata. | eq | |
| Final FQDN | webdata. | eq | |
| Final Domain | webdata. | eq | |
| Other Header Name | webdata. | eq | |
| Other Header Value | webdata. | wildcard | |
| Access-Control-Allow-Headers Present | webdata. | exists | |
| Access-Control-Allow-Methods Present | webdata. | exists | |
| CORS Open to Any Origin | webdata. | eq | |
| Cache-Control With a Max Age | webdata. | startswith | |
| Clear-Site-Data Present | webdata. | exists | |
| Compressed With Gzip | webdata. | eq | |
| CSP Allowing Unsafe Inline Code | webdata. | wildcard | |
| HTML Content Type | webdata. | startswith | |
| Cross-Origin-Embedder-Policy | webdata. | eq | |
| Cross-Origin-Opener-Policy | webdata. | eq | |
| Cross-Origin-Resource-Policy | webdata. | eq | |
| Expect-CT Present | webdata. | exists | |
| Feature-Policy Present | webdata. | exists | |
| Last-Modified Present | webdata. | exists | |
| Permission Policy Present | webdata. | exists | |
| Referrer-Policy | webdata. | eq | |
| Server Header | webdata. | eq | |
| Sets a PHP Session Cookie | webdata. | startswith | |
| HSTS With Preload | webdata. | wildcard | |
| X-Content-Type-Options | webdata. | eq | |
| X-Download-Options | webdata. | eq | |
| X-Frame-Options | webdata. | in | |
| X-Permitted-Cross-Domain-Policies | webdata. | eq | |
| Powered by PHP | webdata. | startswith | |
| X-XSS-Protection | webdata. | eq | |
| Cookie Name | webdata. | eq | |
| Cookie Value Present | webdata. | exists |
Combinations › Operators
One example for each operator, on a field where it is the natural choice.
| Example | Field | Operator | Sort |
|---|---|---|---|
| Wildcard: Names Containing a Word | domain. | wildcard | |
| Fuzzy: Names Close to a Brand | domain. | fuzzy | |
| Starts With: Login Hosts | fqdn | startswith | |
| Ends With: Names Ending in a Word | domain. | endswith | |
| In: One of Several Extensions | domain. domain. | in eq | |
| Contains Any: Phishing-Style Keywords | domain. | contains_ | |
| Contains All: Every Keyword Present | domain. | contains_ | |
| Range: Name Length Between 3 and 4 | domain. domain. | gte lte eq | |
| Exists False: Domains Without a Registrar | domain. type | exists eq |
Combinations › Must, Should and Must Not
must filters all have to match (AND), at least one should filter has to match (OR), and no must_not filter may match (NOT).
| Example | Field | Operator | Sort |
|---|---|---|---|
| Look-Alikes Excluding the Real Domain | domain. domain | fuzzy eq | |
| Should: Either of Two Registrars | domain. | eq | |
| Must and Should Together | domain. dns. | eq wildcard | |
| Must Not: Registrable Domains Outside .com | type domain. domain. | eq | |
| All Three: New Shops Without WHOIS Privacy | domain. domain. domain. | gte eq |
Combinations › Sorting
sort is a list of {field, order}; order is asc or desc. One example for each sortable field.
| Example | Field | Operator | Sort |
|---|---|---|---|
| Sort by Name (A to Z) | domain. type | eq | punycode |
| Sort by Extension | domain. type | eq | domain. |
| Newest Registrations First | domain. type | gte eq | domain. |
| Soonest to Expire First | domain. domain. | gte eq | domain. |
| Most Recently Updated WHOIS First | domain. | eq | domain. |
| Latest WHOIS Changes First | domain. type | eq | domain. |
| Latest DNS Changes First | dns. | wildcard | dns_ |
| Latest Certificate Changes First | ssl. | eq | ssl_ |
| Sort by Two Fields | domain. | eq | domain. domain. |
Combinations › Pagination
page and page_size are query parameters. result_count is always the full total; results page up to 10,000.
| Example | Field | Operator | Sort |
|---|---|---|---|
| Second Page of Results | domain. type | eq | |
| Larger Pages (100 Results) | domain. type | eq | |
| Last Reachable Page (10,000 Results) | domain. type | eq |
Combinations › Investigations
Filters combined the way they are used in practice.
| Example | Field | Operator | Sort |
|---|---|---|---|
| Expiring Soon With WHOIS Privacy | domain. domain. | lte eq | |
| Self-Signed or Invalid Certificates | ssl. ssl. | eq | |
| Live Sites Without HSTS | webdata. webdata. | eq exists | |
| Missing Clickjacking Protection | webdata. webdata. webdata. | eq exists | |
| New Look-Alikes With Mail Servers | domain. domain. dns. domain | fuzzy gte exists eq | |
| Wildcard Certificates From Let's Encrypt | ssl. ssl. | startswith eq | |
| Confusable IDN Domains | is_ name. | eq | |
| Redirects Away to Another Site | webdata. webdata. | eq in |
Supported Operators by Field
Not every field takes every operator: a filter with an operator its field does not support is answered with HTTP 400 ("Field '…' does not support '…' query"). Verified against the live API on 2026-09-23.
Legend: wc wildcard · fz fuzzy · sw startswith · ew endswith · any contains_any · all contains_all · ex exists; eq, in, lte and gte are the operators' own names.
| Family | Field | Operators |
|---|---|---|
| Name & Extension | domain. |
eq in wc fz sw ew any all ex |
name. |
eq in wc fz sw any all ex | |
fqdn |
eq in wc fz sw ex | |
domain |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
type |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
is_ |
eq in ex | |
name. |
eq in ex | |
domain. |
eq in ex | |
domain. |
eq in ex | |
domain. |
eq in ex | |
domain. |
eq in ex | |
domain. |
eq in ex | |
| Subdomain | subdomain |
eq in wc fz sw ew any all ex |
subdomain_ |
eq in wc fz sw ex | |
subdomain_ |
eq in wc fz sw ex | |
subdomain. |
eq in lte gte ex | |
subdomain_ |
eq in lte gte ex | |
subdomain. |
eq in ex | |
subdomain. |
eq in ex | |
subdomain. |
eq in ex | |
subdomain. |
eq in ex | |
| WHOIS | domain. |
eq in wc fz sw ex |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in wc fz sw ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in ex | |
| DNS | domain. |
eq in wc fz sw ex |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
dns. |
eq in wc fz sw ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
dns. |
eq in lte gte ex | |
dns. |
eq in lte gte ex | |
dns. |
eq in lte gte ex | |
dns. |
eq in lte gte ex | |
dns. |
eq in lte gte ex | |
dns. |
eq in lte gte ex | |
dns. |
eq in lte gte ex | |
dns. |
eq in lte gte ex | |
dns_ |
eq in lte gte ex | |
dns_ |
eq in lte gte ex | |
| IP History | domain. |
eq in wc fz sw ex |
ip_ |
eq in wc fz sw ex | |
| SSL | ssl. |
eq in wc fz sw ex |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
ssl. |
eq in wc fz sw ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
domain. |
eq in lte gte ex | |
ssl. |
eq in lte gte ex | |
ssl. |
eq in lte gte ex | |
ssl. |
eq in lte gte ex | |
ssl_ |
eq in lte gte ex | |
ssl. |
eq in ex | |
ssl. |
eq in ex | |
| Webdata & HTTP | webdata. |
eq in wc fz sw ex |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in wc fz sw ex | |
webdata. |
eq in lte gte ex | |
webdata. |
eq in lte gte ex | |
webdata. |
eq in lte gte ex | |
webdata. |
eq in ex |