EmailLive

Domain Threat Report

Domain threat report API for a security investigation on any domain: is this a phishing domain, a lookalike squat, or a legitimate registration? Covers WHOIS/RDAP registration…

$0.092USDC per call · settled on Base · no subscription, no API key

Overview

Domain threat report API for a security investigation on any domain: is this a phishing domain, a lookalike squat, or a legitimate registration? Covers WHOIS/RDAP registration age, DNS records, TLS certificate posture, DMARC/SPF/DKIM email authentication, certificate-transparency subdomain enumeration, IP/ASN hosting attribution, and homoglyph lookalike detection on the domain string. Composite: one call runs whois-lookup + dns-lookup + ssl-cert-info + dmarc-check + subdomain-enum + homoglyph-check + ip-asn in parallel (ip-asn needs a resolved A record and is skipped otherwise) into {registration, dns, tls, email_auth, subdomains, ip_intelligence, lookalike_check}. Use it as a phishing check API, domain security audit, or brand-impersonation detector.

Endpoint

MethodEndpointPriceDescription
POST/v1/marketplace/api/domain-threat-report$0.092Invoke Domain Threat Report (Email) and return the upstream response.

How to call it

Requests are paid per call over the x402 protocol. Call the endpoint, receive a 402 Payment Required quote, then repeat the request with the signed payment header. The SDKs do both steps for you.

# 1. Ask for a quote
curl -i -X POST https://api.jarvisclaw.ai/v1/marketplace/api/domain-threat-report \
  -H 'Content-Type: application/json' \
  -d '{}'

# 2. Pay it (the SDK signs and retries for you)
curl -X POST https://api.jarvisclaw.ai/v1/marketplace/api/domain-threat-report \
  -H 'Content-Type: application/json' \
  -H 'X-PAYMENT: <signed-payload>' \
  -d '{}'
Open in the marketplace

Docs: Getting started · x402 payments · x402 discovery · All APIs