Worked examples for Reverse IP: the domains whose DNS A record points to an IP address, or to any address of its network. One example per parameter value (mask, include_subdomains), then paging and ordering. The address is 104.26.10.21, a Cloudflare address that deepinfo.com has used (see its ip_history in Domain Detail); sites behind Cloudflare share such addresses, so the results are unrelated sites.

Every example is a real request with the response the API returned on September 24, 2026 (Deepinfo DEMO account); totals such as result_count change as the dataset is updated.

Responses are trimmed for display: results shows the first 3 records, long lists inside a record the first 10 items and very long texts the first 4,000 characters, while result_count stays the full total; each page says what was shortened. Personal data (WHOIS contact names, addresses, phone numbers and personal e-mail addresses) is redacted, and cookie values are masked (<value>).

Unless an example shows paging, it asks for page_size=25. page is 1 to 400 and page_size 25 to 100 (the API default is 100).

Each result is a full domain record, the same shape as a Domain Detail response: WHOIS, DNS, SSL certificate and web data.

After the examples: Ordering Values · Parameters Without an Example

Endpoint
Reverse IP

Lookups

ExampleParamValue
Domains on One IP Addressip104.26.10.21

Network Mask

ExampleParamValue
Domains in the Same /24 Networkmask
ip
24
104.26.10.21
Domains in the Same /16 Networkmask
ip
16
104.26.10.21
Domains in the Same /8 Networkmask
ip
8
104.26.10.21

Options

ExampleParamValue
Including Subdomainsinclude_subdomains
ip
true
104.26.10.21

Paging

ExampleParamValue
Second Page of Resultspage
ip
2
104.26.10.21
Larger Pages (100 Results)page_size
ip
100
104.26.10.21

Ordering

ExampleParamValue
Most Recent DNS Change Firstordering
ip
-dns_last_change_date
104.26.10.21

Ordering Values

ordering sorts the results by one field, ascending; a leading - sorts descending (-domain.whois.create_date puts the newest registration first). Each value below was tried on the live API on September 24, 2026, on one of the Discovery endpoints, and sorted the results as described. Without ordering, the order is not fixed: the same request can return its records in a different order.

Value Sorts By
punycode The domain name, in its ASCII (punycode) form
domain.extension.punycode The extension (TLD)
dns_last_change_date The last change seen in the DNS records
ssl_last_change_date The last change seen in the SSL certificate
domain.whois_last_change_date The last change seen in the WHOIS record
domain.whois.create_date The registration date
domain.whois.expiry_date The expiry date
domain.whois.update_date The date the registry last updated the WHOIS record

Parameters Without an Example

As of September 24, 2026, these parameters have no worked example.

Parameter Why
export export=true returns the whole result set as a file download (JSON or CSV) instead of a page of results; these examples show paged JSON only.
export_format Used only with export=true: json (the default) or csv.
export_scope Used only with export=true: basic, default or extended (how many fields each exported record carries).

Reference updated