Blog & How To Guides | WhoisXML API

WhoisXML API Blog

October 2024: Domain Activity Highlights

The WhoisXML API research team analyzed more than 8.2 million domains registered between 1 and 31 October 2024 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by the more than 57.4 billion domains from our DNS database’s A record full file released in the same month.

Next, we studied the top TLDs of more than 1.0 million domains detected as indicators of compromise (IoCs) in October.

Finally, we summed up our findings and provided links to the threat reports produced using DNS, IP, and domain intelligence sources during the period.

DNS Database Download Is Now Reinforced with Wildcard and Active Fields

We are excited to announce that the Standard and Premium DNS Database files from DNS Database Download are now enriched with two new columns, namely, wildcard and active. These additions allow you to determine if a DNS record is part of a wildcard entry and check if a domain name or subdomain is active based on its most recent resolution status.

Quarterly WHOIS Database Download Files Are Now Available on Snowflake

We are excited to announce that Snowflake users can now request access to WHOIS Database Download’s quarterly gTLD and ccTLD files on the platform, available in three formats:

  • Simple: The simple CSV file contains the domain name, registrar name and email address, WHOIS and name servers, creation and expiration dates, and registrant and administrative contact details.
  • Regular: The regular CSV file contains all the fields in the Simple file, along with information about the billing, technical, and zone contacts.
  • Full: This file format contains all fields in the Simple file, in addition to the raw text from the WHOIS registry and registrar.

Importing and Indexing First Watch Malicious Domains Data Feed into MySQL

Abstract

This white paper provides a comprehensive guide for importing First Watch Malicious Domain data from a CSV file into a MySQL database and indexing it on the `domainName` column. The steps outlined here cover the creation of a database, the table structure design, and data import using MySQL. By following this approach, users can efficiently handle domain-related datasets for querying and analysis purposes.

WhoisXML API Launches New Passive DNS Product DNS Chronicle API

We are excited to introduce DNS Chronicle API, the latest addition to our passive DNS offerings. This API release enables use cases such as proactive threat detection and attack surface discovery by providing visibility into the complete DNS history of a domain or an IP address.

With DNS Chronicle API, users can perform two types of passive DNS queries, namely:

  • Forward search: Using any FQDN as a search string, users can retrieve its historical A and AAAA records.
  • Reverse search: Users can obtain a list of all the FQDNs associated with a given IP address.

September 2024: Domain Activity Highlights

The WhoisXML API research team analyzed more than 7.1 million domains registered between 1 and 30 September 2024 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by the more than 60.1 billion domains from our DNS database’s A record full file released in the same month.

Next, we studied the top TLDs and associated threat types of more than 1.0 million domains detected as indicators of compromise (IoCs) in September.

Finally, we summed up our findings and provided links to the threat reports produced using DNS, IP, and domain intelligence sources during the period.

The SPF Onion: Enter the World of SPF Chaos

The SPF Onion: Enter the World of SPF Chaos

Authors:
Ed Gibbs, Field CTO, WHOIS API Inc.
Jeff Vogelpohl

Introduction

It was late in the evening on September 25, 2024, when I received a suspicious email in my personal inbox. It was cleverly disguised as a message from an insurance company I currently do business with, but something felt off—the usual company icon didn’t look quite right. Normally, I verify the sender by clicking on the icon to check the email address, but this time it wouldn’t pop up. Sensing something was amiss, I decided to dig deeper.

APTLD86 Recap: ccTLD Trends and Takeaways

APTLD86 Recap: ccTLD Trends and Takeaways

WhoisXML API is honored to have been represented at the recent APTLD86 conference, the 86th members meeting of the Asia Pacific Top Level Domain (APTLD) Association. Held on 17–20 September 2024 in Da Nang, Vietnam, the event took on a hybrid format, with 110 participants on-site and 50 others online.

Our Head of APAC and Global Partnership, Ching Chao, participated in the conference and shared in-depth insights into DNS abuse, contributing to the discussions and knowledge exchange among the APTLD members.

In this post, we’ll share some of the most notable takeaways from the APTLD86 conference.

Try our WhoisXML API for free
Get started