Analyze
Analyze
Section titled “Analyze”Analyze one fully qualified domain name (FQDN) for infrastructure and threat signals.
Scope: analyze
Endpoint: GET /v2/analyze/{domain}
Encode domain as one URL path segment.
export API_TOKEN="YOUR_API_TOKEN"domain="example.com"
curl -N "https://api.haveibeensquatted.com/v2/analyze/$domain" \ -H "Authorization: Bearer $API_TOKEN" \ -H "Accept: application/x-ndjson"Response contract
Section titled “Response contract”Analyze supports two response representations:
Accept: application/x-ndjsonstreams newline-delimited JSON (NDJSON). Each non-empty line is one event with anopfield and operation-specificdata.Accept: application/jsonbuffers the result and returns one merged JSON object keyed by domain.
If neither representation is requested, the endpoint defaults to NDJSON. For complete client examples, see handling streaming responses.
Responses can include X-Hibs-Request-Id and, when a result is retained, X-Hibs-Result-Id.
Stream completion
Section titled “Stream completion”Metadata events use op: "Meta" with a nested data.kind value.
| Kind | Meaning | Client action |
|---|---|---|
Progress |
Current and total work | Optional progress reporting |
Heartbeat |
The request is still active | Ignore or use for liveness |
StoredResult |
Retained-result identifier | Store it if later retrieval is required |
Error |
The request failed | Fail the operation |
Timeout |
The response may be incomplete | Fail or explicitly mark the result incomplete |
Done |
Processing ended | Accept success only if no Error or Timeout was observed |
An HTTP 200 does not prove that a stream completed. Treat end-of-stream before Done as incomplete.
Signals
Section titled “Signals”Analyze can emit the following domain operations. A field is only emitted when its data is available.
NDJSON op |
Merged JSON field | Signal |
|---|---|---|
Levenshtein |
levenshtein |
Edit distance from the source domain |
IpEnumeration |
ipEnumeration |
Resolved Internet Protocol (IP) addresses |
Dns |
dns |
Domain Name System (DNS) records |
MxCheck |
mxCheck |
Mail exchange and Simple Mail Transfer Protocol (SMTP) response |
HttpBanner |
httpBanner |
HTTP server response banner |
Classification |
classification |
Legitimate, parked, and phishing scores |
GeoIp |
geoIp |
IP geolocation and network metadata |
RegistrationMetadata |
registrationMetadata |
Normalized registration details |
Rdap |
rdap |
Registration Data Access Protocol (RDAP) response |
WhoIs |
whoIs |
WHOIS response |
Screenshot |
screenshot |
Captured page image location |
DomainStatus |
domainStatus |
Registration and marketplace status |
PageRank |
pageRank |
Page-rank enrichment |
Technologies |
technologies |
Detected web technologies |
Identifiers |
identifiers |
Public identifiers found in page content |
RedirectChain |
redirectChain |
Observed HTTP redirects |
OriginX509 |
originX509 |
Origin X.509 certificate |
TlsChain |
tlsChain |
Transport Layer Security (TLS) certificate chain and validation data |
PassiveDns |
passiveDns |
Historical passive DNS observations |
PassiveTls |
passiveTls |
Historical passive TLS observations |
CertificateTransparency |
certificateTransparency |
Certificate Transparency names and certificates |
Subdomains |
subdomains |
Discovered subdomains |
Sitemap |
sitemap |
Crawled pages, link relationships, and page artifacts |
CrawlMeta |
crawlMeta |
Crawl summary and provenance |
BusinessIntel |
businessIntel |
Company names, phone numbers, addresses, and source URLs |
Ports |
ports |
Observed address and port pairs |
Security |
security |
Structured security findings and supporting evidence |
Signal order is not stable. Clients must tolerate unknown operations so that added signals do not break existing integrations. The absence of a signal means no value was returned for that operation; it does not prove a negative finding.
For nested application and retained-result fields, see the JSON export reference. For rule-facing field names, see the signals reference.
Errors and retries
Section titled “Errors and retries”| Status | Meaning | Client action |
|---|---|---|
400 |
Invalid domain or request parameters | Correct the request |
401 |
Missing or invalid authentication | Replace or restore the token |
403 |
Missing scope or authorization | Correct access before retrying |
429 |
Rate limit reached | Use bounded backoff and honor Retry-After |
503 |
The service is unavailable or at capacity | Use bounded backoff and honor Retry-After |
Do not automatically repeat a request after its response stream has started. A second invocation creates a new analysis request and can duplicate work.