Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
Look into all current and historical DNS / IP connections between domains and A, MX, NS, and other records. Monitor suspicious changes to DNS records.
Get detailed context on an IP address, including its user’s geolocation, time zone, connected domains, connection type, IP range, ASN, and other network ownership details.
Access our web-based solution to dig into and monitor all domain events of interest.
Get access to a web-based enterprise-grade solution to search and monitor domain registrations and ownership details for branded terms, fuzzy matches, registrants of interest, and more.
Detect and block access to and from dangerous domain names before malicious actors can weaponize them. Contact us today for more information.
Unlock integrated intelligence on Internet properties and their ownership, infrastructure, and other attributes.
Our complete set of domain, IP, and DNS intelligence available via API calls as an annual subscription with predictable pricing.
Offers complete access to WHOIS, IP, DNS, and subdomain data for product enrichment, threat hunting and more.
Multi-Level API User Administration Now Available - Manage individual API keys for team members in your organization.
Learn MoreDNS Chronicle Lookup lets you perform a forward search for any FQDN to find its historically connected IP addresses or a reverse search for an IP address’s past connected FQDNs—all within seconds. Test it now.
Access historical DNS data points based on the data you already have, whether it’s an IP address or a domain name.
Tap into our market-leading passive DNS database with billions of recorded events collected and aggregated for years.
Generate lookup reports within seconds. Copy or download the results in JSON format for deeper analysis.
Quickly review the historical connections of suspicious domains and IP addresses interacting with your network.
Obtain a full list of domains and subdomains historically linked to known IP addresses and could represent forgotten or shadow assets.
Analyze the DNS activity timeline of known malicious domains and IP addresses to uncover their connections over a specific period.
Audit your domain’s IP connections over time, and look for unusual or unauthorized changes that may indicate misconfigurations or compromise.
“WhoisXML API’s passive DNS database, even the lite version for academic purposes, has much better subdomain data coverage compared with other commercial and free databases.”
“WhoisXML was the game changer for us. It has revolutionized our ability to disrupt cybercrime in process and at scale by quickly identifying all of the vendors providing material support for scammers using sophisticated website templates that look legitimate. By quickly identifying the vendors unknowingly supporting the criminals, we can provide them with public interest justification to burn down the criminal infrastructure.”
“After thorough testing, we were thrilled to find that Premium DNS 365 consistently identified 10 times more 'active' subdomains compared to other options in the market.”
We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.