WhoisXML API Blog

9 Best DNS Lookup Tools for Malware Analysis and Phishing Investigations

For cybersecurity researchers, the DNS hides a treasure trove of data. It offers insights to identify malicious domains, map attacker infrastructure, detect fast flux, and identify typosquatting domains. But it also requires knowing where to look and what to analyze. 

In this post, we cover different the best DNS lookup tools for different types of lookups and what types of investigations they can help with. 

May 2025: Domain Activity Highlights

The WhoisXML API research team analyzed 8.5+ million domains registered between 1 and 31 May 2025 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by 54.6+ billion domains from our DNS database’s A record full file dated 1 May 2025.

Next, we studied the top TLDs of 1.3+ million domains detected as indicators of compromise (IoCs) this May.

Finally, we summed up our findings and provided links to the threat reports produced using DNS, IP, and domain intelligence sources during the period.

WhoisXML API Is Now a Global Signal Exchange (GSE) Partner

WhoisXML API Is Now a Global Signal Exchange (GSE) Partner

WhoisXML API is proud to announce its new partnership with the Global Signal Exchange (GSE), a collaborative initiative that serves as a global clearinghouse for the real-time sharing of scam and fraud signals.

The company joins tech giants Google, Meta, Microsoft, and Netcraft, along with other leaders in the Internet infrastructure, financial services, and law enforcement sectors.

As a GSE Partner, WhoisXML API contributes its Early Warning Phishing Feed to the project’s open data layer. Early Warning Phishing Feed is a predictive threat intelligence source that identifies newly registered domains likely to figure in upcoming phishing campaigns, scams, and brand abuse.

DNS Security Best Practices from the NIST Secure Deployment Guide (SP 800-81r3 Initial Public Draft)

Often dubbed as the Internet’s phonebook, the DNS serves a critical function in modern Internet communications, translating human-readable domain names into IP addresses. We have a primer on the subject if you want to dig deeper into the DNS, how it works, and other related concepts.

Given its foundational role, it’s no surprise that threat actors often target the DNS. According to the Cybersecurity & Infrastructure Security Agency (CISA), “DNS infrastructures are common threat vectors for attacks.” It is within this context that the U.S. National Institute of Standards and Technology (NIST) published an initial public draft of the third Secure DNS Deployment Guide (NIST SP 800-81r3 ipd) in April 2025.

RSA Conference 2025: Emerging Trends and Key Insights

RSA Conference 2025: Emerging Trends and Key Insights

The RSA Conference held in San Francisco from 28 April to 1 May 2025 attracted a record-breaking 41,000 attendees, and we’re thrilled to say that WhoisXML API representatives were among them. The global cybersecurity gathering featured 413 sessions and 656 exhibitors, all offering valuable insights into emerging cybersecurity trends—evolving threats, cutting-edge solutions, and industry best practices.

In this post, we’ll recap the recurring themes and key trends from the event and highlight the most impactful insights that will continue to shape organizations’ cybersecurity strategies.

WhoisXML API Participates in Cybersec 2025

WhoisXML API Participates in Cybersec 2025

Ching Chiao, Head of APAC & Global Partnership at WhoisXML API, joined more than 20,000 security professionals from around the world in the recently concluded Cybersec 2025. He participated as a speaker at the three-day conference and expo that aims to take on digital threats as one cybersecurity community.

Held in Taiwan on 15–17 April 2025, Cybersec 2025 hosted more than 300 sessions and speakers and focused on 28 various themes, including artificial intelligence (AI), cloud, AI of Things (AIoT) and hardware, financial technology (fintech), and open-source security. Several of the topics resonated with us, and we’ll dive into some of them in this post.

Upgraded Web Interfaces for All Lookup Tools

We’re excited to introduce upgraded web tool interfaces with enhanced data access across all our lookup tools. The improved GUIs are designed to make your lookup reports richer and simpler to use for investigations and testing, improving how technical and nontechnical users access and utilize domain, DNS, IP, and other cyber data accessible through this complete list of our lookup tools.

Here are the new features available to all logged-in users with credits.

April 2025: Domain Activity Highlights

The WhoisXML API research team analyzed 7.6+ million domains registered between 1 and 30 April 2025 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by 55.8+ billion domains from our DNS database’s A record full file dated 3 April 2025.

Next, we studied the top TLDs of 1.5+ million domains detected as indicators of compromise (IoCs) this April.

Finally, we summed up our findings and provided links to the threat reports produced using DNS, IP, and domain intelligence sources during the period.

Try our WhoisXML API for free
Get started