Search Combolists

Get the dedicated combolist exposure report for a domain

Aggregate Combolist exposure for a root email domain: total pairs, distinct email addresses, password strength breakdown, and the first and last dates a pair for that domain entered the index.

Access

  • Authentication is optional. An anonymous caller gets the same aggregate figures; the report exposes counts only, never a credential.
  • A domain matching one of your blacklist rules returns a zeroed report rather than an error.

Caching Cached for one hour per domain and shared across callers. Send x-no-cache: 1 to force a recompute.

Response CombolistDomainReportResponse. dataset is always combolist, which is what distinguishes it from the stealer-log report at GET /search/domain/{domain}.

get/search/combolist/domain/{domain}/report

Path parameters

domainstring required

Root email domain to report on, for example example.com.

Root email domain to report on, for example example.com.

Response

Report returned successfully.

domainstring required
total_credentialsinteger required
unique_emailsinteger required

Distinct email identifiers, approximate on large domains.

first_seenstring date-time nullable

Earliest date a pair for this domain entered the index.

last_seenstring date-time nullable

Most recent date a pair for this domain entered the index.

dataset'combolist'

Example response

{
  "dataset": "combolist",
  "domain": "example.com",
  "first_seen": "2024-03-02T08:11:00Z",
  "last_seen": "2026-01-15T10:30:00Z",
  "password_strength": {
    "medium": 298,
    "strong": 73,
    "too_weak": 402,
    "weak": 511
  },
  "total_credentials": 1284,
  "unique_emails": 973
}

Changes

Changed in 1 of the 8 revisions of this API.1