WhoisFreaks
DATA · DATA & ANALYTICS
WHOIS, DNS, SSL, subdomain, and reputation lookups for domains and IPs on their own key.
Acts as the person, not as itself
Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.
Credentials never touch the agent
Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.
Every call on the record
Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.
What an agent can do
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
whoisfreaks_get_v1_0_api_key_rotateWRITERegenerate the WhoisFreaks account's API key, via GET /v1.0/api-key/rotate. CALLING THIS THROUGH THIS CONNECTION DESTROYS THIS CONNECTION'S OWN CREDENTIAL. WhoisFreaks issues ONE key per account; rotating it invalidates the previous value instantly and everywhere, including the copy Agentic Fabriq holds. Every subsequent tool call on this connection answers 401 until someone signs in at billing.whoisfreaks.com, copies the NEW key and edits the connection. Every other integration, script and product using the same account key breaks at the same moment, because there is no second key to migrate to. THE REPLY IS PLAIN TEXT, NOT JSON, AND A 200 DOES NOT MEAN IT WORKED: measured 2026-09-25, a bogus key gets HTTP 200 with `Content-Type: text/plain` and the body `API Key does not exist`. So `raise_for_status` sees nothing wrong and this connector hands the sentence back under `raw` -- READ IT. The only safe use is a deliberate rotation you are ready to finish by re-pasting the new key; it is marked destructive so the confirm gate stands in front of it.
whoisfreaks_get_v1_0_geolocationREADResolve one IP address to a location, via GET /v1.0/geolocation. Returns the country, region, city, postal code, coordinates, timezone, currency and the connection's ISP, organisation and ASN. IP GEOLOCATION IS AN ESTIMATE: city-level accuracy is good for fixed broadband and poor for mobile, satellite, VPN and corporate egress, so this is evidence rather than a fact about where a person is. The coordinates locate a network, never a household. Use the POST form of the same path for up to 100 addresses in one call, and 'Read an IP address's reputation' for whether the address is flagged.
whoisfreaks_get_v1_0_ip_whoisREADRead the registry allocation record for one IP address, via GET /v1.0/ip-whois. The REGISTRY view of an address: which block it falls in, who the block is allocated to, the abuse contact and the regional registry. Distinct from 'Geolocate an IP address', which estimates a physical location -- this one is authoritative about ownership and says nothing about where the address is used. The abuse contact here is the address to report to. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v1_0_securityREADLook up one IP address's threat reputation, via GET /v1.0/security. Reports whether the address is associated with malware, phishing, spam, scanning, a proxy, a VPN or a Tor exit, along with a reputation score. A SIGNAL, NOT A VERDICT: shared hosting, carrier NAT and cloud egress mean a flagged address is routinely also carrying legitimate traffic, so this belongs in a decision alongside other evidence rather than as an automatic block. Note the path: `/v1.0/security` is the IP tool, while `/v1/domain/security` -- one version segment shorter -- is the DOMAIN one, and they are different endpoints. Use the POST form of this path for up to 100 addresses.
whoisfreaks_get_v1_0_ssl_liveREADFetch the certificate a domain is serving right now, via GET /v1.0/ssl/live. Connects to the host at call time and reports the issuer, the subject, the validity window, the signature algorithm and the subject alternative names -- which is how an expiry sweep or a wildcard audit is driven. `chain` true also returns the intermediate and root certificates, which is what you need to diagnose a trust-path failure rather than an expiry. `sslRaw` true adds the raw PEM, which is large: leave it false unless something downstream parses certificates itself. A host that refuses TLS or presents nothing answers an error rather than an empty certificate. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v1_0_subdomainsREADList the subdomains WhoisFreaks has observed under one domain, via GET /v1.0/subdomains. An attack-surface inventory: what exists under a registrable domain, as observed from certificate transparency, DNS and crawling. OBSERVED IS NOT EXHAUSTIVE -- an internal-only or wildcard-served name that never appeared in a certificate or a zone will be missing, so a short answer is not evidence of a small footprint. `after` and `before` narrow to a first-seen window (YYYY-MM-DD), which is how you find what appeared since the last audit; `status` narrows to `active` or `inactive`. PAGED through `page`. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v1_0_whoisapi_usageREADRead the connected WhoisFreaks account's subscription status, credit balance and rate limits, via GET /v1.0/whoisapi/usage. The Credit Usage API, and the cheapest thing to call before a bulk run: WhoisFreaks serves every API from ONE credit pool, and once it is empty requests stop being served rather than degrading, so the balance here is what says whether a batch will complete. Also this connection's health check -- it is the endpoint this provider declares as its probe, because a bogus key, an absent key and an Authorization header alone all answer 401 here (measured 2026-09-24 and again 2026-09-25). It reports the key's entitlements; it cannot create or change a credential. Reading a balance costs nothing.
whoisfreaks_get_v1_domain_securityREADLook up one domain's threat reputation, via GET /v1/domain/security. The domain counterpart to the IP reputation tool: malware, phishing, spam and abuse associations plus a reputation score, for a name rather than an address. NOTE THE PATH -- `/v1/domain/security`, with `v1` and not `v1.0`. It is the only `/v1/` path on this provider and `/v1.0/domain/security` reaches nothing. Five API credits per call at the documented rate, five times a live WHOIS lookup, so it is not the tool to run speculatively over a large list. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v2_0_asn_whoisREADRead the registry record for one autonomous system number, via GET /v2.0/asn-whois. Who operates a network, from the regional internet registry: the organisation, its country, the registry that allocated the number, the allocation date and the announced prefixes. This is the network-operator layer above the per-address lookups -- use 'Look up an IP address's WHOIS record' for one address and this for the AS it belongs to. `asn` takes the number with or without the `AS` prefix. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v2_0_dns_historicalREADRead the archived DNS records WhoisFreaks holds for one domain, via GET /v2.0/dns/historical. How a hosting move, a mail-provider change or a CDN migration is dated: each entry is a snapshot with the interval it was observed over. `domainName` and `type` are both required -- unlike the live lookup there is no IP form. PAGED through `page`. This is an archive query rather than a resolution, so it answers for domains that no longer resolve at all, which is exactly what makes it useful after a takedown. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v2_0_dns_liveREADResolve one domain's (or one IP's) current DNS records, via GET /v2.0/dns/live. SUPPLY EXACTLY ONE OF `domainName` OR `ipAddress`. Both are declared optional and neither is enough on its own -- a call with neither is a 400 that names no field, which reads as a server problem. `type` IS required and chooses which record family comes back; `all` returns every type in one reply and is the usual choice. Resolved at call time against live nameservers, so it reflects the zone as it stands rather than a cached snapshot -- use 'List a domain's historical DNS records' for what it used to be. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v2_0_domain_availabilityREADCheck one domain's registration availability and optionally suggest alternatives, via GET /v2.0/domain/availability. Answers whether the exact name is registrable right now. Set `sug` true to get alternative names as well, and `count` to say how many (1-100, default 5) -- `count` does nothing while `sug` is false. AVAILABILITY IS NOT OWNERSHIP: a name can be unregistered and still be reserved, premium-priced or blocked by the registry, so treat a positive answer as 'worth trying at a registrar' rather than as a purchase guarantee. Use the POST form of the same path to check many names or many TLDs in one call. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v2_0_whois_historyREADRead every archived WHOIS record WhoisFreaks holds for one domain, via GET /v2.0/whois/history. The archive rather than the live lookup: each entry is a snapshot WhoisFreaks captured, so this is how an ownership change, a registrar transfer or a nameserver move is dated. Contact details in older snapshots may be visible where the CURRENT record is redacted, which is the whole reason this endpoint is used in investigations -- and a reason to treat its output as personal data. PAGED: pass `page` and walk it; a caller that reads only the first page sees the newest snapshots and no error saying there are more. Costs more credits per call than a live lookup. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v2_0_whois_liveREADQuery the registry and registrar for one domain's current WHOIS record, via GET /v2.0/whois/live. The live lookup, not the archive: WhoisFreaks queries the authoritative servers at call time, so this is what to use for 'who owns this now'. The reply carries the registrar, the create/update/expiry dates, the nameservers, the domain status codes and the registrant, administrative, technical and billing contact blocks -- most of which are redacted to a privacy-service placeholder for GDPR-covered registrants, which is the provider telling you the truth rather than a failure. Use 'List a domain's historical WHOIS records' for what the record USED to say and 'Find domains matching a WHOIS keyword' to search by registrant. Costs one API credit per lookup from the account's single credit pool. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v2_0_whois_reverseREADSearch WhoisFreaks' WHOIS index for every domain whose record contains a keyword, via GET /v2.0/whois/reverse. THE INVERSE OF A LOOKUP: given a registrant name, an e-mail address, a company or a nameserver, this returns the domains whose WHOIS records mention it. That makes it the tool for mapping a portfolio or an infrastructure cluster, and also the one most likely to return personal data about a private registrant, so choose deliberately when granting it. PAGED -- a single keyword can match tens of thousands of domains, so `page` is how you get past the first slice. Five API credits per call at the documented rate, against one for a live lookup, so a loop over pages is five times more expensive than it looks. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v2_1_dns_reverseREADSearch for every domain whose DNS records contain a given value, via GET /v2.1/dns/reverse. Given an IP, a mail host, a nameserver or a CNAME target, this returns the domains that point at it -- the tool for finding every site on one server or every domain using one mail provider. NOTE THE VERSION: this is the only `/v2.1` path on the provider, and a call to `/v2.0/dns/reverse` reaches nothing. `type` is required and is a CLOSED set here (`a`, `mx`, `cname`, `ns`, `aaaa`, `txt`, `soa`) rather than the open string the live lookup takes -- there is no `all`, because a reverse search is over one record family. `exact` defaults to true; set it false for a substring match, which is much broader and much slower. PAGED. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_get_v3_0_domain_typosREADGenerate the look-alike domain names an attacker would register against a brand, via GET /v3.0/domain/typos. SUPPLY `keyword` OR `pattern`. Both are declared optional and a call with neither returns nothing useful. `keyword` takes a brand or domain and WhoisFreaks generates the usual confusions -- character swaps, omissions, doubled letters, homoglyphs, neighbouring TLDs; `pattern` lets you specify the shape yourself. This is a GENERATOR, not a lookup: it tells you which names exist as strings, so feed the output to 'Check whether a domain is available to register' or to a WHOIS lookup to find which are actually registered. Paged by OPAQUE TOKEN rather than by number -- pass the `pageToken` from the previous reply; a numeric `page` is not accepted here. Despite the `/v3.0` prefix this is on the LIVE API host, not the database host; the split begins at /v3.1.
whoisfreaks_get_v3_1_domains_droppedREADList the domains that were deleted and returned to the available pool on a given day, as JSON, via GET /v3.1/domains/dropped. DROPPED means the registration lapsed through its expiry and redemption windows and the name is registrable again -- which is why this feed is used both by domain investors and by anyone watching for an abandoned name that still has traffic or backlinks pointed at it. The bulk `/v3.1/download/domainer/dropped` file and the backlink-annotated `/v3.3/download/domainer/dropped/backlinks` file are NOT shipped -- unbounded binary with no artifact transport. `date` picks the drop day; `tlds` narrows. SERVED FROM files.whoisfreaks.com; the same path on api.whoisfreaks.com answers 404 (measured 2026-09-25).
whoisfreaks_get_v3_1_domains_newly_cctldREADList the country-code-TLD domains registered on a given day, as JSON, via GET /v3.1/domains/newly/cctld. The country-code counterpart to the gTLD listing, and a separate dataset rather than a filter over it: ccTLD registries publish on their own schedules and some do not publish at all, so a ccTLD absent from this feed is not evidence it was not registered. The bulk `/v3.1/download/domainer/cctld` file is NOT shipped -- unbounded binary with no artifact transport. `date` and `tlds` work as on the gTLD listing. SERVED FROM files.whoisfreaks.com; the same path on api.whoisfreaks.com answers 404 (measured 2026-09-25). Sold as a database product, not deducted from API credits.
whoisfreaks_get_v3_1_domains_newly_gtldREADList the generic-TLD domains registered on a given day, as JSON, via GET /v3.1/domains/newly/gtld. The JSON counterpart to WhoisFreaks' newly-registered gTLD file drop -- the bulk `.csv`/`.zip` download at `/v3.1/download/domainer/gtld` is NOT shipped here, because it answers unbounded binary and no bounded artifact transport exists for it yet. Brand-protection and abuse teams use this to see what was registered against their marks yesterday. `date` picks the day (YYYY-MM-DD) and defaults to the most recent drop; `tlds` narrows to a comma-separated list such as `com,net`. Call 'Check every database file's freshness' first to learn which dates exist -- an unavailable date is an error, not an empty list. SERVED FROM files.whoisfreaks.com, not the live API host; the same path on api.whoisfreaks.com answers 404 (measured 2026-09-25). Database products are sold separately and are NOT deducted from API credits.
whoisfreaks_get_v3_3_status_snapshot_asn_whoisREADReport the current ASN-WHOIS snapshot's name, build date and deletion time, via GET /v3.3/status/snapshot/asn/whois. The bulk form of 'Look up an autonomous system's WHOIS record' -- every AS registry record in one `.json.gz`. This tool reports readiness; the download (`/v3.3/download/snapshot/asn/whois`) is NOT shipped, being unbounded binary with no artifact transport. The AS dataset is small and slow-moving compared with the IP ones, so for a handful of numbers the live lookup is almost always the better answer. SERVED FROM files.whoisfreaks.com. MEASURED 2026-09-25: answers 200 to an invalid key.
whoisfreaks_get_v3_3_status_snapshot_ip_cityREADReport the current IP-to-city snapshot's name, build date and deletion time, via GET /v3.3/status/snapshot/ip/city. The city-resolution counterpart to the country snapshot, and a bigger file on a schedule of its own -- check this one rather than assuming the two move together. The download (`/v3.3/download/snapshot/ip/city`) is NOT shipped: unbounded binary with no artifact transport. SERVED FROM files.whoisfreaks.com. MEASURED 2026-09-25: answers 200 to an invalid key, so it cannot be used to test the connection.
whoisfreaks_get_v3_3_status_snapshot_ip_countryREADReport the current IP-to-country snapshot's name, build date and deletion time, via GET /v3.3/status/snapshot/ip/country. Says WHICH snapshot exists and until WHEN -- `snapshot_name`, `snapshot_creation_date` and `snapshot_deletion_time`. The download itself (`/v3.3/download/snapshot/ip/country`) is NOT shipped: it answers a multi-gigabyte `.zip` and no bounded artifact transport exists for it, so this status tool is how an agent learns the file is ready and hands the name to whoever fetches it out of band. SERVED FROM files.whoisfreaks.com. MEASURED 2026-09-25: this endpoint answers 200 with real data to an INVALID key, so a success here says nothing about whether the connection's credential is good -- use 'Read this account's credit balance' for that.
whoisfreaks_get_v3_3_status_snapshot_ip_securityREADReport the current IP-security snapshot's name, build date and deletion time, via GET /v3.3/status/snapshot/ip/security. The bulk form of 'Read an IP address's reputation' -- the whole reputation dataset as a `.csv.gz` rather than one address per call. This tool reports readiness only; the download (`/v3.3/download/snapshot/ip/security`) is NOT shipped, being unbounded binary with no artifact transport. Freshness matters more here than on the other snapshots: a reputation file is a claim about a moving target, so `snapshot_creation_date` is the number to read before trusting it. SERVED FROM files.whoisfreaks.com. MEASURED 2026-09-25: answers 200 to an invalid key.
whoisfreaks_get_v3_3_status_snapshot_ip_whoisREADReport the current IP-WHOIS snapshot's name, build date and deletion time, via GET /v3.3/status/snapshot/ip/whois. The bulk form of 'Look up an IP address's WHOIS record' -- every allocation record in one file rather than one address per call. This tool reports the snapshot's readiness; the download (`/v3.3/download/snapshot/ip/whois`) is NOT shipped, being a multi-gigabyte `.json.gz` with no bounded artifact transport. For a handful of addresses the live lookup is the right tool and costs credits rather than a database licence. SERVED FROM files.whoisfreaks.com. MEASURED 2026-09-25: answers 200 to an invalid key.
whoisfreaks_get_v3_4_statusREADReport the available-from and last-update dates for every WhoisFreaks database product, via GET /v3.4/status. THE INDEX FOR EVERYTHING THIS INTEGRATION CANNOT DOWNLOAD. One reply covers the newly-registered feeds (gTLD, ccTLD, their cleaned variants, DNS), expired, dropped and dropped-with-backlinks, the daily/weekly/monthly WHOIS, DNS and subdomain deltas, and the phishing, malware and spam threat feeds -- each with `available_from` and `last_update`. Call it first to learn which `date` values the JSON listings will accept, and to find out whether a feed has stalled. The 29 `/download/` endpoints those dates describe are NOT shipped as tools: every one answers unbounded `application/octet-stream` and no bounded AF artifact transport exists for it, so they are fetched out of band with the same account key. SERVED FROM files.whoisfreaks.com -- the same path on api.whoisfreaks.com answers 404 (measured 2026-09-25). MEASURED 2026-09-25: answers 200 with real data to an INVALID key, so a success here proves nothing about the credential.
whoisfreaks_post_v1_0_geolocationREADResolve up to 100 IP addresses to locations in one call, via POST /v1.0/geolocation. The batch form of the single lookup, on the same path with a different verb. A POST and a READ: nothing is created. `ips` is a JSON array capped at 100 and a longer list is refused rather than truncated. The same estimate caveat applies to every entry -- see 'Geolocate an IP address'. Charged per address, so the saving over 100 single calls is in rate limit and latency.
whoisfreaks_post_v1_0_securityREADLook up threat reputation for up to 100 IP addresses in one call, via POST /v1.0/security. The batch form of the single reputation lookup, on the same path with a different verb. A POST and a READ. `ips` is capped at 100. The same 'signal, not verdict' caveat applies to every entry -- see 'Read an IP address's reputation and threat signals'. This is the right tool for scoring a log slice; it is the wrong tool for enriching one address, where the GET costs less to call.
whoisfreaks_post_v2_0_bulkwhois_liveREADQuery current WHOIS records for up to 100 domains in one call, via POST /v2.0/bulkwhois/live. A POST because the domain list is a body, but a READ: nothing is created or changed. Prefer it over 100 single lookups -- it is one request against the bulk rate limit rather than 100 against the live one -- but note that it still spends one credit per domain, so the saving is in rate limit and latency, not in credits. The list is capped at 100 and a longer one is refused rather than truncated. The reply is keyed by domain, and a domain that could not be resolved appears with its own error rather than failing the whole call. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_post_v2_0_dns_bulk_liveREADResolve current DNS records for a list of domains or IP addresses in one call, via POST /v2.0/dns/bulk/live. A POST because the list is a body, but a READ. The body takes `domainNames`, `ipAddresses`, or both -- unlike the single lookup, which accepts exactly one form. `type` is a QUERY parameter here and applies to the whole batch, so one call cannot ask for MX on some names and A on others. Charged per name resolved, not per call. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
whoisfreaks_post_v2_0_domain_availabilityREADCheck registration availability for a list of names, or for one name across a list of TLDs, via POST /v2.0/domain/availability. TWO MODES, AND THEY ARE EXCLUSIVE. Body `domainNames` is a list of up to 100 FULL names and ignores the `domain` query parameter. Body `tld` is a list of up to 100 TLDs checked against the `domain` QUERY parameter -- so `domain=example` with `tld=["com","io"]` asks about example.com and example.io. Sending both body keys is a 400. The same path serves GET for a single name; this POST is a read despite the verb. WhoisFreaks can answer this call as XML; this tool always asks for JSON and does not offer the switch.
Often connected alongside
Put WhoisFreaks behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.