WhoisXML API Blog

WhoisXML API Launches an MCP Server to Enable LLM Access to Internet Infrastructure Intelligence

WhoisXML API announces the launch of its MCP server that allows large language models (LLMs) to query 17 of its APIs, enabling users to access unique internet infrastructure intelligence data, run bulk queries and conduct complex internet infrastructure research projects directly from the chatbot interface using natural language.

The MCP server is software that enables the use of the Model Context Protocol, an open standard that enables LLMs and other AI systems to securely connect to external data sources. The protocol uses a client-server architecture, where the client is the AI application that connects to the MCP server.

July 2025: Domain Activity Highlights

WhoisXML API analyzed 8.3+ million domains registered between 1 and 31 July 2025 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by 49.3+ billion domains from our DNS database’s A record full file dated 3 July 2025.

Next, we studied the top TLDs of 1.1+ million domains detected as indicators of compromise (IoCs) this July.

Finally, we summed up our findings and provided links to the threat reports produced using DNS and domain intelligence sources during the period.

RDAP Readiness Enhanced with New Protocol Selector for WHOIS Lookup and DRS

We are excited to announce that a protocol selector has been added to WHOIS Lookup and WHOIS Search (on Domain Research Suite), giving users more flexibility to choose how to retrieve domain registration data. 

With this new feature, users can select from three protocols—RDAP, WHOIS, and Auto.

What Is DNS Tunneling and How to Detect It

You may have heard of notorious malware variants like Zloader using DNS tunneling for command and control (C2). Instead of making regular web requests, this malware uses the Domain Name System (DNS) to communicate with its C2 servers, and this allows malicious traffic to bypass network security, such as firewalls and intrusion detection systems (IDS).

But wait, DNS doesn’t support arbitrary data transfer like HTTP, does it? Well, it doesn’t, but DNS tunneling is a workaround for that. In this post, we break down DNS tunneling for you, including how it works and how to detect it – both from within an organization’s network and from outside it. 

17 Best Free OSINT Tools for Cyber Investigations

There are plenty of free or almost-free OSINT tools you can find online — ChatGPT can provide you with quite a list. But, as often happens with ChatGPT, some of those tools simply don’t exist, some don’t work anymore, and some provide low-quality data. 

In this post, we have collected several OSINT tools that actually work quite well for different cyber research purposes, grouped according to their primary use cases. All of these tools could be very handy for different tasks such as cybercrime investigation, threat hunting, offensive cybersecurity exercises, and more.

June 2025: Domain Activity Highlights

WhoisXML API analyzed 9.8+ million domains registered between 1 and 30 June 2025 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by 51.7+ billion domains from our DNS database’s A record full file dated 5 June 2025.

Next, we studied the top TLDs of 1.0+ million domains detected as indicators of compromise (IoCs) this June.

Finally, we summed up our findings and provided links to the threat reports produced using DNS, IP, and domain intelligence sources during the period.

Handling CSV Files with CR/LF Line Endings

Ed Gibbs, VP of Research, whoisxmlapi.com

Issue Overview

CSV files containing CR/LF (carriage return/line feed) line endings can cause parsing errors with certain CSV-to-JSON conversion tools. This commonly occurs when CSV files are created on Windows systems, which use CR/LF (\r\n) line endings, while many Unix-based tools expect only LF (\n) line endings.  This applies to various datafeeds WHOISXMLAPI provides such as WHOIS, Netblocks, and IP Geolocation.

Ingesting IP Netblocks with DynamoDB

Introduction

Overview

DynamoDB is Amazon's fully managed NoSQL database service that's designed for high-performance applications at scale. DynamoDB is known for its single-digit millisecond response times, automatic scaling, and built-in security features.

Try our WhoisXML API for free
Get started