The Edgewatch Domain Intelligence API provides advanced access to a rich dataset of historical and contextual DNS information, going beyond traditional passive DNS to deliver full-spectrum domain observability. Designed for security analysts, threat hunters, and automated systems, this API enables the investigation of domain resolutions, infrastructure reuse, registrar metadata, and global name server behavior.
By combining passive DNS records, RDAP registration data, name server intelligence, and TLD-level analytics, the API empowers users to detect malicious infrastructure, analyze domain lifecycles, correlate threat actor behavior, and support digital supply chain investigations. Whether you're tracing phishing campaigns, mapping botnet infrastructure, or enriching SIEM alerts, this API provides the depth and precision required for modern cybersecurity operations.
To access all API documentation, navigate to API Docs. For more information please visit our Knowledge base.
New, updated, and deleted domain registrations observed across the dataset.
Records added since the start of the window — the slope shows the per-day pace.
Click a TLD to toggle it. Hide the largest to compare smaller TLDs.