Skip to content

Analyze

Analyze one fully qualified domain name (FQDN) for infrastructure and threat signals.

Scope: analyze

Endpoint: GET /v2/analyze/{domain}

Encode domain as one URL path segment.

Terminal window
export API_TOKEN="YOUR_API_TOKEN"
domain="example.com"
curl -N "https://api.haveibeensquatted.com/v2/analyze/$domain" \
-H "Authorization: Bearer $API_TOKEN" \
-H "Accept: application/x-ndjson"

Analyze supports two response representations:

  • Accept: application/x-ndjson streams newline-delimited JSON (NDJSON). Each non-empty line is one event with an op field and operation-specific data.
  • Accept: application/json buffers the result and returns one merged JSON object keyed by domain.

If neither representation is requested, the endpoint defaults to NDJSON. For complete client examples, see handling streaming responses.

Responses can include X-Hibs-Request-Id and, when a result is retained, X-Hibs-Result-Id.

Metadata events use op: "Meta" with a nested data.kind value.

Kind Meaning Client action
Progress Current and total work Optional progress reporting
Heartbeat The request is still active Ignore or use for liveness
StoredResult Retained-result identifier Store it if later retrieval is required
Error The request failed Fail the operation
Timeout The response may be incomplete Fail or explicitly mark the result incomplete
Done Processing ended Accept success only if no Error or Timeout was observed

An HTTP 200 does not prove that a stream completed. Treat end-of-stream before Done as incomplete.

Analyze can emit the following domain operations. A field is only emitted when its data is available.

NDJSON op Merged JSON field Signal
Levenshtein levenshtein Edit distance from the source domain
IpEnumeration ipEnumeration Resolved Internet Protocol (IP) addresses
Dns dns Domain Name System (DNS) records
MxCheck mxCheck Mail exchange and Simple Mail Transfer Protocol (SMTP) response
HttpBanner httpBanner HTTP server response banner
Classification classification Legitimate, parked, and phishing scores
GeoIp geoIp IP geolocation and network metadata
RegistrationMetadata registrationMetadata Normalized registration details
Rdap rdap Registration Data Access Protocol (RDAP) response
WhoIs whoIs WHOIS response
Screenshot screenshot Captured page image location
DomainStatus domainStatus Registration and marketplace status
PageRank pageRank Page-rank enrichment
Technologies technologies Detected web technologies
Identifiers identifiers Public identifiers found in page content
RedirectChain redirectChain Observed HTTP redirects
OriginX509 originX509 Origin X.509 certificate
TlsChain tlsChain Transport Layer Security (TLS) certificate chain and validation data
PassiveDns passiveDns Historical passive DNS observations
PassiveTls passiveTls Historical passive TLS observations
CertificateTransparency certificateTransparency Certificate Transparency names and certificates
Subdomains subdomains Discovered subdomains
Sitemap sitemap Crawled pages, link relationships, and page artifacts
CrawlMeta crawlMeta Crawl summary and provenance
BusinessIntel businessIntel Company names, phone numbers, addresses, and source URLs
Ports ports Observed address and port pairs
Security security Structured security findings and supporting evidence

Signal order is not stable. Clients must tolerate unknown operations so that added signals do not break existing integrations. The absence of a signal means no value was returned for that operation; it does not prove a negative finding.

For nested application and retained-result fields, see the JSON export reference. For rule-facing field names, see the signals reference.

Status Meaning Client action
400 Invalid domain or request parameters Correct the request
401 Missing or invalid authentication Replace or restore the token
403 Missing scope or authorization Correct access before retrying
429 Rate limit reached Use bounded backoff and honor Retry-After
503 The service is unavailable or at capacity Use bounded backoff and honor Retry-After

Do not automatically repeat a request after its response stream has started. A second invocation creates a new analysis request and can duplicate work.