Domain APIs return indexed observations for a domain. They do not initiate a live scan.

Domain details

The response can include the queried domain, normalized host records, result metadata, and available WHOIS data. Host fields can include IP addresses, ports, services, products, web technologies, TLS observations, and first-seen or last-seen timestamps.

Subdomains

Use this route when you need the discovered hostname list without the larger host-detail payload.

Limits

  • Domain details: 200 requests per hour
  • Subdomains: 200 requests per hour
  • Result availability and credit behavior depend on the account

Interpretation

  • last_seen describes the dataset observation, not the request time.
  • A missing subdomain means it was not returned under the current dataset, filter, and account limits.
  • WHOIS, DNS, certificate, and hosting relationships require ownership review.
  • Use Attack-Surface Drift Detection to compare results over time.