search

Search Keywords

Domains the corpus lists that look like a brand or domain: typosquats, homoglyphs, the name on other TLDs or wrapped in phishing words (paypal-login). A bare keyword is read as its .com; the searched name itself comes first when listed. Most dangerous first, capped at 500 hits (total_hits counts every lookalike found).

post/search

Path parameters

keywordsstring required

Search keywords (e.g., 'paypal', 'microsoft')

Response

Search results response (capped at 500 hits)

hitsstring[] required

Listed lookalike domains, most dangerous first, capped at 500

keywordsstring required

Search keywords used

total_hitsinteger required

Every lookalike found; hits stops at 500

truncatedboolean required

True when hits stops short of total_hits

Example response

{
  "keywords": "paypal",
  "matches": [
    {
      "domain": "paypa1.com",
      "fuzzer": "homoglyph",
      "threatLevel": "critical"
    }
  ]
}

Changes

Changed in 2 of the 15 revisions of this API.73

    • ○

      added the non-success response with the status

      response-non-success-status-added

    • ○

      added the required property to the response with the status

      response-required-property-added

    • ○

      added the required property to the response with the status

      response-required-property-added

    • ▲

      the response property became nullable for the status

      response-property-became-nullable

    • ▲

      the response property became nullable for the status

      response-property-became-nullable

    • ▲

      the response property became nullable for the status

      response-property-became-nullable

    • ▲

      the response property became optional for the status

      response-property-became-optional

    • ▲

      the response property became optional for the status

      response-property-became-optional

    • ▲

      the response property became optional for the status

      response-property-became-optional

    • ▲

      the response's property format changed from int32 to int64 for status

      response-property-type-changed

    This revision also has 17 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog