Search Combolists
Get the dedicated combolist exposure report for a domain
Aggregate Combolist exposure for a root email domain: total pairs, distinct email addresses, password strength breakdown, and the first and last dates a pair for that domain entered the index.
Access
- Authentication is optional. An anonymous caller gets the same aggregate figures; the report exposes counts only, never a credential.
- A domain matching one of your blacklist rules returns a zeroed report rather than an error.
Caching Cached for one hour per domain and shared across callers. Send x-no-cache: 1 to force a recompute.
Response CombolistDomainReportResponse. dataset is always combolist, which is what distinguishes it from the stealer-log report at GET /search/domain/{domain}.
get/search/combolist/domain/{domain}/report
Path parameters
domainstring required
Root email domain to report on, for example example.com.
Root email domain to report on, for example example.com.
Response
Report returned successfully.
Example response
{
"dataset": "combolist",
"domain": "example.com",
"first_seen": "2024-03-02T08:11:00Z",
"last_seen": "2026-01-15T10:30:00Z",
"password_strength": {
"medium": 298,
"strong": 73,
"too_weak": 402,
"weak": 511
},
"total_credentials": 1284,
"unique_emails": 973
}Changes
Changed in 1 of the 8 revisions of this API.1
- ○
endpoint added
endpoint-added
- ○