Honeypots only catch those that are weaponized. The rest stay invisible to threat intelligence.
With Bulk Registration Risk API, you can take just one domain to get the entire cluster.
From online-advertising-4450886[.]bond
To a cluster of 10,331 online-advertising-*[.]bond domains
The Bulk Registration Risk API allows you to detect the entire cluster based on that one domain.
Take a group of known IoC domains — and expand it with more domain artifacts registered by the same actor for the purposes of this campaign.
WhoisXML API's researchers have identified and added 100,000+ domains to the list of domains belonging to scam infrastructure provider Funnull that were identified by the FBI — read the full report.
It doesn't matter if cybercriminals used the same or different TLDs, registrars, or nameservers for their campaign — the Bulk Registration Risk API would see through it and detect the entire cluster nonetheless.
From one lordfilm* domain
To a cluster of 4,801 domains across multiple TLDs.
Get WHOIS and DNS data for all domains in the cluster to have the context you need to act.
The Bulk Registration Risk API helped identify more than 1,661 additional domains belonging to the LabHost threat actor infrastructure — read the full report.
The API operates in a 3-stage intelligence cycle.
You can query the API in two ways, depending on what data you already have.
The API cross-references your input against a database of bulk-registered domains built from 400,000+ newly registered domains ingested each day. Each daily batch is analyzed for second-level domain name patterns, including look-alike and pattern-based names, to identify bulk registered domains with a very high confidence level.
The API returns a list of domains within the same cluster, along with 15+ WHOIS and DNS fields per domain, including:
Query a suspicious or confirmed malicious domain you encounter during an investigation against the Bulk Domain Registration Risk API to reveal the broader cluster it belongs to and obtain a much richer picture of the threat actor's infrastructure.
When you discover a lookalike or typosquatted domain, query the API to confirm whether it belongs to a larger cluster of bulk-registered domains. The API also returns a list of domains in the same group, helping teams track related malicious domains in the same campaign before they target customers.
Automatically enrich alerts within your SIEM or SOAR platform when an external domain triggers a security event. The API verifies whether the domain is part of an aggressive bulk deployment, allowing your team to accelerate triage and escalate alerts based on group-level risk metrics.
Integrate bulk registration data to upgrade raw indicators into high-fidelity feeds. Grouping isolated domains into malicious clusters helps providers deliver the predictive intelligence subscribers need to block entire campaign infrastructures.
















Yes, organizations use bulk registration for legitimate purposes, such as defensive brand protection, acquiring regional top-level domains (TLDs), or launching multi-brand marketing campaigns.
The API provides data in JSON or XML format. The specific output depends on which of the four endpoints you use:
The API returns a cluster when it finds at least three domains that appeared on the same day and share similar second-level domain naming patterns. These signals help identify likely bulk-registration activity rather than isolated look-alike domains.
Recognized industry practices often combine several measures, including:
Easily identify malicious resources and retrieve their threat information.
Learn more
Get data feeds of new registered domains along with their WHOIS data generated in real time.
Learn more
Get well-parsed and normalized WHOIS information for any domain name, IP address or email.
Learn more
Enhance your domain research toolkit by our enterprise-grade web-based solution that helps you in searching...
Learn more
Get insights for the new business registered on the web.
Learn more
Get the most relevant data to be ahead of emerging security threats.
Learn more
Find out which domains were added or dropped by registrants, with given search criteria.
Learn more
Give the list of domain names tied to the specified DNS records via API calls with outputs in JSON and XML.
Learn more
Get the most comprehensive database of SSL (Secure Sockets Layer) Certificates.
Learn more
Find out the exact physical location of any IP address, email or domain name.
Learn more
Find domains and subdomains related by specific terms in their hostnames.
Learn more
Assess the domain's or IP addresses reputation and risk profile with a simple score based on a comprehensive...
Learn more
Easily detect all typosquatting domain names as soon as they are registered each day.
Learn more
We provide complete and relevant domain WHOIS data which can be customized and easily integrated as per your business needs.
Learn more
Monitor exact matches, variations and common misspellings of your brand name & trademarks.
Learn more
Get data feeds of SSL certificates along with their well parsed fields in real time. Accurate. Up-to-date.
Learn more