Skip to content

Domain signals

Domain signals describe a lookup result, including Domain Name System (DNS) records, registration data, web content, page-level semantic observations, certificates, and classification.

domain.classification.phishing:>0.8 AND
domain.registration_metadata.registration_date.days_since:<=30

The equivalent unqualified fields remain valid in existing Domain rules. The compatibility-only created_on field must remain unqualified and records when the lookup result was created. It is not the domain registration time. A classification value such as 0.8 uses the 0–1 scale. Rule scoring in the builder is separate.

Selector-backed fields such as domain.sitemap.title and domain.page_semantics.page_state match values extracted from nested data. Separate selectors can match different nested entries within the same result. Use the exact kind=value pair for domain.identifiers to match one identifier object.

The domain.page_semantics.* fields expose normalized observations from captured pages. They describe page state, site purpose, identity and support presentation, provider warnings, authentication and payment flows, and requests for sensitive data or actions.

domain.page_semantics.requests_account_password:true AND
domain.classification.phishing:>0.8

Use the exact catalog value for keyword fields. For requests_* Boolean fields, missing means unknown, not false.

173 signals

Web content 67
domain.page_semantics object
Per-page observations available for this Domain result; an empty array is present
domain.page_semantics.url string
Sanitized URL of a captured page, including pages on other hosts (matches any page independently)
domain.page_semantics.page_state keyword
Observed page state on a captured page (matches any page independently); values: substantive, for_sale, advertising_parking, placeholder, maintenance, error_or_access_denied, provider_warning, mixed
domain.page_semantics.open_directory boolean
Whether a captured page displays an open directory (matches any page independently); missing means unknown, not false
domain.page_semantics.site_purpose keyword
Observed site purpose on a captured page (matches any page independently); values: informational_community, commerce, account_or_software_service, financial_service, government_public_service, entertainment_social, domain_sale_or_parking, mixed, no_substantive_purpose
domain.page_semantics.provider_warning_type keyword
Observed provider warning type on a captured page (matches any page independently); values: phishing, malware, other_security, access_verification_only, none_observed, mixed
domain.page_semantics.identity_presentation keyword
Observed identity presentation on a captured page (matches any page independently); values: single_named_operator, multiple_named_operators, marketplace_or_directory, unnamed_service, conflicting_names
domain.page_semantics.operator_contact_role keyword
Observed operator contact role on a captured page (matches any page independently); values: operator_contact, third_party_contact, directory_or_reference, none_observed, mixed
domain.page_semantics.support_channel_mode keyword
Observed support channel mode on a captured page (matches any page independently); values: on_site_form_or_chat, email_or_phone, external_messaging, external_support_portal, none_observed, mixed
domain.page_semantics.authentication_flow_presentation keyword
Observed authentication flow presentation on a captured page (matches any page independently); values: login, registration, recovery_or_reset, reauthentication_or_verification, device_or_session_authorization, none_observed, mixed
domain.page_semantics.payment_purpose keyword
Observed payment purpose on a captured page (matches any page independently); values: purchase_or_booking, subscription, donation, investment_or_deposit, delivery_tax_or_fee, account_or_funds_release, recovery_or_support, none_observed, mixed
domain.page_semantics.requests_account_password boolean
Whether a captured page requests account password (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_one_time_code boolean
Whether a captured page requests one time code (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_account_recovery_code boolean
Whether a captured page requests account recovery code (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_wallet_recovery_secret boolean
Whether a captured page requests a wallet seed phrase, recovery phrase, or private key (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_wallet_connection boolean
Whether a captured page requests wallet connection (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_signature_or_transaction_approval boolean
Whether a captured page requests signature or transaction approval (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_payment_card_data boolean
Whether a captured page requests payment card data (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_bank_access_credentials boolean
Whether a captured page requests bank login credentials (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_identity_document boolean
Whether a captured page requests identity document (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_financial_account_identifier boolean
Whether a captured page requests an account number or payment identifier (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_contact_or_delivery_data boolean
Whether a captured page requests contact or delivery data (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_software_download boolean
Whether a captured page requests software download (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_remote_access boolean
Whether a captured page requests remote access (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_security_setting_change boolean
Whether a captured page requests security setting change (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_session_transfer_or_qr_login boolean
Whether a captured page requests session transfer or qr login (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_secrecy boolean
Whether a captured page requests secrecy (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_code_execution boolean
Whether a captured page asks the visitor to execute code (matches any page independently); missing means unknown, not false
domain.page_semantics.requests_command_paste boolean
Whether a captured page asks the visitor to paste a command (matches any page independently); missing means unknown, not false
domain.page_semantics.code_execution_purpose keyword
Observed code execution purpose on a captured page (matches any page independently); values: human_verification, technical_repair, content_access, installation_or_development, other, mixed
domain.identifiers identifier
Exact public web identifier pairs in kind=value form
domain.favicon.url string
Source URL of the favicon used for fingerprinting
domain.favicon.content_type string
Content type reported for the favicon asset
domain.favicon.sha256 string
SHA-256 hash of the favicon asset
domain.favicon.dhash string
Perceptual dHash of the favicon asset
domain.sitemap.url string
URL observed in the crawl sitemap (matches any entry)
domain.sitemap.title string
Page title observed in the crawl sitemap (matches any entry)
domain.sitemap.status_code number
HTTP status code observed in the crawl sitemap (matches any entry)
domain.sitemap.depth number
Discovery depth of a crawled page (matches any entry)
domain.sitemap.parent_url string
Parent URL that linked to a crawled page (matches any entry)
domain.sitemap.entry_count number
Number of entries discovered during crawl
domain.sitemap.broken_link.kind string
Broken link classification observed during crawl (matches any link)
domain.sitemap.broken_link.page_url string
Page URL where a broken link was observed (matches any link)
domain.sitemap.broken_link.target_url string
Target URL of a broken link, when available (matches any link)
domain.sitemap.broken_link.status_code number
HTTP status code returned for a broken link, when available (matches any link)
domain.sitemap.external_link.target_host string
External navigation target host observed during crawl (matches any link)
domain.sitemap.external_link.target_url string
External navigation target URL observed during crawl (matches any link)
domain.sitemap.external_link.source_host string
Source host for an external navigation link (matches any link)
domain.business_intel.company_names string
Company name extracted from crawled pages (matches any value)
domain.business_intel.phone_numbers string
Phone number extracted from crawled pages (matches any value)
domain.business_intel.addresses string
Address extracted from crawled pages (matches any value)
domain.business_intel.source_urls string
Source URL used for business information extraction (matches any value)
domain.business_intel.company_name_count number
Number of extracted company names
domain.business_intel.phone_number_count number
Number of extracted phone numbers
domain.business_intel.address_count number
Number of extracted addresses
domain.business_intel.source_url_count number
Number of source URLs used for business information extraction
domain.page_rank.domain string
Domain name returned by page rank enrichment
domain.page_rank.status_code number
HTTP-like status code returned by the page rank API
domain.page_rank.error string
Error string returned by the page rank API when present
domain.page_rank.page_rank_integer number
Integer page rank score returned by page rank enrichment
domain.page_rank.page_rank_decimal number
Decimal page rank score returned by page rank enrichment
domain.page_rank.rank string
Absolute rank returned by page rank enrichment
domain.page_rank.last_updated string
Last update string returned by the page rank API
Core fields 7
domain.permutation string
The domain permutation being analyzed
domain.kind string
Type of domain permutation (e.g., typosquatting, combosquatting)
domain.levenshtein_distance number
Edit distance from original domain
domain.tags array<string>
Tags associated with the lookup result
domain.metadata.origin string
Origin label attached to the lookup result metadata
domain.metadata.sources.kind string
External source kind attached to the lookup result metadata (matches any source)
domain.metadata.sources.provider string
External source provider attached to the lookup result metadata (matches any source)
DNS records 13
domain.dns_a array<inet>
IPv4 addresses from DNS A records
domain.dns_aaaa array<inet>
IPv6 addresses from DNS AAAA records
domain.dns_cname array<string>
Canonical names from DNS CNAME records
domain.dns_txt array<string>
Text records from DNS TXT records
domain.dns_ns array<string>
Name servers from DNS NS records
domain.dns_mx array<string>
Mail exchange servers from DNS MX records
domain.dns_caa array<string>
Certificate Authority Authorization records
domain.dns_tlsa array<string>
TLSA records used for DANE/TLS authentication
domain.dns_srv array<string>
Service locator records for host/port discovery
domain.dns_naptr array<string>
Naming Authority Pointer records
domain.dns_ptr array<string>
Reverse DNS pointer records
domain.dns_dnskey array<string>
DNSSEC public key records
domain.dns_ds array<string>
DNSSEC delegation signer records
Servers and services 19
domain.smtp string
SMTP server banner
domain.http_banner string
HTTP server banner
domain.technologies array<string>
Detected web technologies
domain.ports.port number
Open port observed during network scan (matches any finding)
domain.ports.address string
IP address associated with an open port finding (matches any finding)
domain.ports.finding_count number
Number of open port findings observed during scan
domain.ports.unique_port_count number
Number of distinct open ports observed during scan
domain.ports.unique_address_count number
Number of distinct IP addresses with open port findings
domain.security.slug string
Canonical slug of a security finding
domain.security.severity string
Severity assigned by the security finding registry
domain.security.cvss31.score number
CVSS 3.1 base score derived from the registry vector
domain.security.cve string
CVE identifier associated with a security finding
domain.security.cwe string
CWE identifier associated with a security finding
domain.security.mitre.framework string
MITRE framework associated with a security finding
domain.security.mitre.id string
MITRE ATT&CK, CAPEC, or D3FEND identifier associated with a finding
domain.redirect_chain.url string
URL observed in the redirect chain (matches any hop)
domain.redirect_chain.status number
HTTP status code observed in the redirect chain (matches any hop)
domain.redirect_chain.kind string
Redirect kind (initial_request/http/javascript/client) observed in the redirect chain
domain.screenshot_url string
URL to website screenshot
Classification 3
domain.classification.phishing number
ML model confidence for phishing classification (0.0-1.0)
domain.classification.malware number
ML model confidence for malware classification (0.0-1.0)
domain.classification.impersonation number
ML model confidence for impersonation classification (0.0-1.0)
Network and location 4
domain.geolocation.asn.number number
Autonomous System Number
domain.geolocation.asn.name string
Autonomous System organization name
domain.geolocation.country string
Country ISO code (e.g., US)
domain.geolocation.continent string
Continent code (e.g., NA)
Registration 21
domain.registration_metadata.registration_date date
Domain registration date
domain.registration_metadata.expiration_date date
Domain expiration date
domain.registration_metadata.updated_on date
Last updated timestamp from registration metadata
domain.registration_metadata.registrar string
Domain registrar name
domain.registration_metadata.registrar_iana_id string
Domain registrar IANA identifier
domain.registration_metadata.registrar_abuse_contact string
Registrar abuse contact email or URL
domain.registration_metadata.status_codes string
Domain status codes (JSON array)
domain.registration_metadata.url string
RDAP or WHOIS server URL
domain.registration_metadata.server string
RDAP or WHOIS server hostname
domain.registration_metadata.nameservers string
Nameserver value from registration metadata (matches any)
domain.registration_metadata.dnssec_status string
Whether DNSSEC is enabled (signed/unsigned)
domain.registration_metadata.delegation_signer string
DNSSEC delegation signer (DS) value (matches any)
domain.registration_metadata.privacy_proxy string
Heuristic indicator for a privacy proxy (if detected)
domain.registration_metadata.reseller string
Domain reseller information (if available)
domain.domain_status.domain string
Domain name returned by domain status enrichment
domain.domain_status.status string
Availability or registration status returned by domain status enrichment
domain.domain_status.tags string
Tags returned by domain status enrichment
domain.domain_status.zone string
Top-level zone returned by domain status enrichment
domain.domain_status.scope string
Scope returned by domain status enrichment
domain.whois string
Raw WHOIS response
TLS certificates 20
domain.origin_x509.subject_dn string
TLS certificate subject distinguished name
domain.origin_x509.issuer_dn string
TLS certificate issuer distinguished name
domain.origin_x509.fingerprint_sha256 string
TLS certificate fingerprint (SHA-256)
domain.origin_x509.serial string
TLS certificate serial number
domain.origin_x509.not_before number
TLS certificate validity start time (unix seconds)
domain.origin_x509.not_after number
TLS certificate validity end time (unix seconds)
domain.origin_x509.san_dns string
TLS certificate Subject Alternative Name DNS entry (matches any)
domain.origin_x509.san_dns_count number
Number of DNS entries in certificate Subject Alternative Names
domain.origin_x509.san_ip array<inet>
TLS certificate Subject Alternative Name IP entries (matches any)
domain.origin_x509.ttl_days number
TLS certificate time-to-live in days
domain.origin_x509.key_alg string
TLS certificate public key algorithm
domain.origin_x509.key_size_bits number
TLS certificate public key size (bits)
domain.origin_x509.sig_alg_oid string
TLS certificate signature algorithm OID
domain.origin_x509.is_ca boolean
Whether the certificate is a Certificate Authority
domain.origin_x509.path_len number
Certificate path length constraint (if present)
domain.origin_x509.policy_oids string
Certificate policy OID (matches any)
domain.origin_x509.ocsp_uris string
OCSP URI found in the certificate (matches any)
domain.origin_x509.crl_dp string
CRL distribution point URL found in the certificate (matches any)
domain.redirect_chain.certificate.issuer string
TLS certificate issuer observed during redirects (matches any hop)
domain.redirect_chain.certificate.subject_name string
TLS certificate subject observed during redirects (matches any hop)
Passive observations 19
domain.passive_dns.rrtype string
Passive DNS record type (matches any record)
domain.passive_dns.rrname string
Passive DNS rrname value (matches any record)
domain.passive_dns.rdata string
Passive DNS rdata value (matches any record)
domain.passive_dns.source string
Passive DNS provider source (matches any record)
domain.passive_dns.bailiwick string
Passive DNS bailiwick value (matches any record)
domain.passive_dns.time_first number
First-seen timestamp (unix seconds) for a passive DNS record (matches any record)
domain.passive_dns.time_last number
Last-seen timestamp (unix seconds) for a passive DNS record (matches any record)
domain.passive_dns.count number
Observation count for a passive DNS record (matches any record)
domain.certificate_transparency.name string
Domain name found in Certificate Transparency logs
domain.certificate_transparency.is_precert boolean
Whether the CT entry is a precertificate
domain.certificate_transparency.log_id number
Certificate Transparency log identifier (if available)
domain.certificate_transparency.index number
Certificate Transparency index within the log (if available)
domain.certificate_transparency.occurrences_count number
Number of occurrences in Certificate Transparency logs
domain.certificate_transparency.last_seen_ts number
Last seen timestamp in Certificate Transparency logs
domain.certificate_transparency.labels.tld string
Top-level domain label from Certificate Transparency match
domain.certificate_transparency.labels.etld1 string
Effective TLD+1 label from Certificate Transparency match
domain.certificate_transparency.labels.domain string
Domain label from Certificate Transparency match
domain.certificate_transparency.labels.registrable_domain string
Registrable domain from Certificate Transparency match (if available)
domain.certificate_transparency.labels.subdomain string
Subdomain label from Certificate Transparency match (if available)