MCP documentation menu

Domain Search (dpsearch)

DEPRECATED: This tool is deprecated. Use datapulse_dns_searchlabels instead. See datapulse_help(topic="searchlabels") for the recommended tool. searchlabels returns labels with their TLD spread, which is more useful for typosquatting, brand variant, and impersonation analysis.

Overview

The datapulse_dns_dpsearch tool searches the DataPulse database for domains matching a search term using fuzzy matching algorithms that detect lookalike characters and common typosquatting patterns.

Parameters

ParameterTypeRequiredDescription
search_termstringYesSearch term to query (minimum length enforced by DP_MIN_SEARCH_CHARS, default 3; max 100 UTF-8 characters)
datestringNoDate to query in YYYY-MM-DD format. Defaults to most recent data.

Response Format

The response is CSV with a metadata header:

count: 3 (complete)
query: /dpdb/v1/search/google

match,type,score
g00gle.com,fuzzy,2
googl3.com,fuzzy,3
google-login.com,substring,6

When more matches exist beyond the returned set:

count: 50 of 5000+ (incomplete, showing top matches)
query: /dpdb/v1/search/test

match,type,score
test.com,exact,0
...

Match Types

TypeDescription
exactExact match of the search term
substringSearch term appears within the domain
fuzzyLookalike characters or typo variations

Score

The score field is an edit distance — lower values mean a closer match. A score of 1 means one character substitution away from the query; a score of 8 means eight edits. Typical fuzzy results range from 1-8. Exact matches have a score of 0. Substring matches reflect the edit distance between the query and the matching portion.

Result Completeness

Results are limited server-side via the topn parameter (configured by the server operator). The header line indicates completeness:

  • count: N (complete) — all matches in the database were returned
  • count: N of M+ (incomplete, showing top matches) — more matches exist; only the top N by score were returned. M is the total count in the database.

When incomplete, the returned results are the closest matches by score. A score of 0 is an exact match; lower scores indicate fewer character edits from the query.

Limits and Constraints

ConstraintValue
Maximum resultsServer-side limit via topn (1-1000, default 500)
Search term lengthDP_MIN_SEARCH_CHARS (default 3) to 100 UTF-8 characters
Request timeout30 seconds
Result orderingBy score (top N closest matches)

Fuzzy Matching

The search algorithm detects:

  • Homoglyphs: Visually similar characters (0/O, 1/l/I, rn/m)
  • IDN abuse: Unicode characters that look like ASCII (а Cyrillic vs a Latin)
  • Keyboard proximity: Adjacent key typos (googke for google)
  • Character transposition: Swapped letters (googel for google)
  • Omission/duplication: Missing or repeated characters

Use Cases

1. Typosquatting Detection

Find domains targeting a brand:

datapulse_dns_dpsearch(search_term="microsoft")

Then investigate low-score fuzzy matches (closest to the brand) with:

2. Brand Monitoring

Find all domains containing a brand name:

datapulse_dns_dpsearch(search_term="acme")

Look for:

  • Defensive registrations (same registrar/infrastructure)
  • Potentially infringing domains (different registrar/infrastructure)
  • Phishing domains (fuzzy matches with different infrastructure)

Note: search matches domain-name strings only — it cannot find domains by registrant email/name (no reverse-WHOIS; registrant data is GDPR-redacted).

3. IDN Abuse Detection

Search for a brand to find IDN homograph attacks:

datapulse_dns_dpsearch(search_term="paypal")

IDN domains will appear with their ASCII-compatible encoding (xn-- prefix in WHOIS/RDAP).

Workflow Examples

Typosquatting Investigation

dpsearch("brand") → filter fuzzy matches → dptechsim(top_hit) → dphistory(matches) → live_rdap(suspicious)
  1. Search for brand name
  2. Filter results to fuzzy matches with low scores (closest matches)
  3. Check if similar infrastructure (defensive registration?)
  4. Review historical DNS for patterns
  5. RDAP on suspicious domains

Brand Protection Audit

dpsearch("company") → group by match_type → live_rdap(each) → identify unowned
  1. Search for company name
  2. Categorize by exact/substring/fuzzy
  3. Check registration details (registrar, dates, status) of each via datapulse_live_rdap — registrant identity is GDPR-redacted
  4. Flag domains whose registrar/infrastructure doesn’t match the company’s known portfolio

Relationship to Other Tools

ToolUse Together For
dptechsimFind if matching domains share infrastructure
dphistoryCheck when domains appeared, infrastructure changes
datapulse_live_rdapRegistration details (registrar, dates, status — registrant is GDPR-redacted)
datapulse_live_dnsCurrent DNS resolution for matches
datapulse_scrape_submitContent analysis of suspicious domains

Common Patterns

Defensive Registration Check

If dpsearch finds a typo domain, check if it’s defensive:

dpsearch("brand") → get matches → live_dns(match) vs live_dns("brand.com")

Same IP/infrastructure = likely defensive registration.

Phishing Detection

High-risk indicators from dpsearch results:

  • Fuzzy match with low score (1-3 edits — very close to original)
  • Different registrar than legitimate domain (check with datapulse_live_rdap)
  • Recent registration date
  • MX records configured (email interception risk)

Error Handling

ErrorCauseResolution
“search_term cannot be empty”Empty or whitespace-only inputProvide valid search term
“search_term too short”Below minimum length (DP_MIN_SEARCH_CHARS, default 3)Use a longer, more specific term
“search_term too long”Exceeds 100 character limitShorten the search term
“invalid search_term”Invalid UTF-8 encodingUse valid UTF-8 characters
“API request timed out”Database query took too longRetry with simpler term

Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="dpsearch").