WHOIS API - Domain, DNS, IP, Subdomain, SSL Lookup
Pricing
from $8.00 / 1,000 record returneds
WHOIS API - Domain, DNS, IP, Subdomain, SSL Lookup
Look up WHOIS registration and its history, live DNS records, IP geolocation and netblocks, subdomains, reverse IP, MX, NS and WHOIS, domain availability and reputation, website contacts and category, email verification and SSL certificates. Bring your own key.
Pricing
from $8.00 / 1,000 record returneds
Rating
0.0
(0)
Developer
Nabeel Hassan
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
4 days ago
Last modified
Categories
Share
Sixteen domain and IP intelligence services behind one input: who registered a domain and when, how that registration has changed, what its DNS says today, which domains sit on an address, what a website is and who to contact there.
This actor calls a domain and IP intelligence API on your behalf and stores one row per record. Bring your own key: paste your account key into the input and the run uses your own plan and your own contract.
What you get
- WHOIS, now and over time. The registrar, creation, update and expiry dates, status codes, name servers and registrant details. WHOIS history returns one row per recorded change, so you can see when a domain changed hands.
- Reverse WHOIS. Every domain whose registration details mention up to four terms you give, with up to four more terms excluded, over current records or over historical ones as well.
- DNS as rows. One row per live record with its type, name, TTL, address or target, SOA serial and admin, TXT strings and the raw text it was parsed from.
- Reverse IP, MX and NS. Every domain pointing at an address, using a mail server, or using a name server, each with the dates it was first and last seen and optionally whether it still resolves.
- Subdomain enumeration. Every subdomain the provider has observed, paged past the ten thousand record limit.
- IP geolocation and netblocks. Country, region, city, postcode, coordinates, timezone, ISP and connection type; and the registered range around it with its owner, description, admin and abuse contacts and autonomous system.
- Domain availability and reputation. Registered or not, checked against DNS or against the registry; and a reputation score with the specific checks that raised warnings.
- Website contacts and category. Company names, emails, phone numbers, postal addresses, social links, page title and description; and what the site is about with a confidence score.
- Email verification. Format, mail domain, mailbox over SMTP, accept-all, free provider and disposable checks, reduced to one honest deliverability verdict.
- SSL certificates. Subject, issuer, validity window, serial, signature algorithm, public key type and size, and every subject alternative name, optionally up the whole chain.
Pay per result
You are charged per record, never per request, and only for rows that carry real data. A domain the provider has no record for is stored with the reason and costs nothing.
| Event | Price | What it covers |
|---|---|---|
| Record returned | $0.008 | One WHOIS record, historical change, DNS record, geolocation, netblock, availability or reputation result, contact set, category, verified email or certificate |
| Discovered domain returned | $0.003 | One name from a reverse IP, MX, NS, WHOIS or subdomain lookup, with first and last seen dates |
Quick start
- Get an API key from the products page of your provider account.
- Paste it into API key.
- Leave What this run does on WHOIS and put one domain in What to look up.
- Set Maximum rows to the most you want to pay for.
- Run it.
FAQ
What is a WHOIS API?
A WHOIS API returns the registration record behind a domain name: which registrar it is with, when it was created, last updated and when it expires, the status codes the registry has applied to it, its name servers, and whatever registrant contact details are public. This actor reads that record and fifteen related services from the same account, including the historical versions of the record and the reverse searches over it.
Can I find every domain a company owns?
Yes, two ways. Reverse WHOIS finds every domain whose registration details contain terms you give, such as a company name plus a country, with up to four terms included and four excluded, and it can search past registrations as well as current ones. Reverse NS and reverse MX find every domain using the same name servers or mail servers, which catches domains registered under privacy protection that a WHOIS search would miss.
How do I enumerate a domain's subdomains?
Subdomains mode returns every subdomain the provider has observed, with the dates each was first and last seen. A response is capped at ten thousand records, and this actor pages past that using the provider's own cursor, up to whatever row limit you set.
What is the difference between reverse IP and IP netblocks?
Reverse IP answers which domains point at one address. IP netblocks answers who owns the range that address sits in: the registered range, the network name, the organisation, the admin and abuse contacts and the autonomous system. One is about the sites, the other is about the network.
How reliable is the email verification?
It runs five checks and this actor turns them into one verdict rather than leaving you to combine them. The important subtlety is the accept-all check: on a domain that accepts mail to every address, a passing mailbox check proves nothing, so the verdict reads accept-all domain, mailbox unconfirmed instead of deliverable. A check the provider could not run comes back as null rather than as a false, so an unknown is never reported as a failure.
Why does a preview mode return a count and no rows?
WHOIS history and reverse WHOIS both default to a preview that reports how many records match without listing them. Preview costs one credit or none; buying the list costs considerably more. This actor keeps preview as the default so an exploratory run cannot spend fifty credits per domain by accident, stores the count as the reason on the row, and tells you which option to turn on.
My key works elsewhere but this run says it is refused. Why?
The provider gives three reasons for a refusal and any of them fits: the key is wrong, the credit balance is empty, or the address the request came from is not on the account's IP allowlist. The last one is the one that catches people running on a cloud platform, because the key is fine and only the address is wrong. The run passes the provider's own wording through rather than guessing which of the three it was.
Do all the services report an error the same way?
No, and this is worth knowing if you have written against this API yourself. The DNS service returns HTTP 200 with an error object in the body when the key is bad, while the WHOIS service returns 401 and the rest return 403; and the three families use three different error envelopes. A client that trusted the status line would report an empty result set for a dead key. This actor inspects every response body before treating it as data, so a refused key ends the run with an explanation rather than looking like a domain with no DNS.
What happens if my key is missing or rejected?
The run ends cleanly with the reason as its status message rather than failing with a stack trace. A missing key, an empty input, a key the provider will not accept and an exhausted balance are all treated as answers, not faults.
Is my API key stored anywhere?
No. It is read from the run input or from the DATA_API_KEY environment secret, used for that run's requests, and never written to the dataset or the log.
Example output
{"recordType": "whois","requested": "google.com","found": true,"domainName": "google.com","registrarName": "MarkMonitor, Inc.","registrarIanaId": 292,"whoisServer": "whois.markmonitor.com","createdDate": "1997-09-15T07:00:00Z","updatedDate": "2019-09-09T15:39:04Z","expiresDate": "2028-09-13T07:00:00Z","estimatedDomainAgeDays": 10582,"status": ["clientUpdateProhibited","clientTransferProhibited","clientDeleteProhibited"],"nameServers": ["NS1.GOOGLE.COM", "NS2.GOOGLE.COM", "NS3.GOOGLE.COM", "NS4.GOOGLE.COM"],"registrantOrganization": "Google LLC","registrantState": "CA","registrantCountry": "US"}
Keyword map
WHOIS API, WHOIS lookup API, domain lookup API, WHOIS history API, reverse WHOIS API, DNS lookup API, DNS records API, subdomain finder API, subdomain enumeration, reverse IP lookup API, reverse MX lookup, reverse NS lookup, IP geolocation API, IP to location API, IP netblocks API, ASN lookup API, abuse contact lookup, domain availability API, domain reputation API, website contacts API, website categorization API, email verification API, email validation API, disposable email check, catch-all detection, SSL certificate lookup API, certificate transparency data, attack surface discovery, domain monitoring, threat intelligence enrichment