Domain Search (dpsearch)
DEPRECATED: This tool is deprecated. Use
datapulse_dns_searchlabelsinstead. Seedatapulse_help(topic="searchlabels")for the recommended tool.searchlabelsreturns labels with their TLD spread, which is more useful for typosquatting, brand variant, and impersonation analysis.
Overview
The datapulse_dns_dpsearch tool searches the DataPulse database for domains matching a search term using fuzzy matching algorithms that detect lookalike characters and common typosquatting patterns.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
search_term | string | Yes | Search term to query (minimum length enforced by DP_MIN_SEARCH_CHARS, default 3; max 100 UTF-8 characters) |
date | string | No | Date to query in YYYY-MM-DD format. Defaults to most recent data. |
Response Format
The response is CSV with a metadata header:
count: 3 (complete)
query: /dpdb/v1/search/google
match,type,score
g00gle.com,fuzzy,2
googl3.com,fuzzy,3
google-login.com,substring,6
When more matches exist beyond the returned set:
count: 50 of 5000+ (incomplete, showing top matches)
query: /dpdb/v1/search/test
match,type,score
test.com,exact,0
...
Match Types
| Type | Description |
|---|---|
exact | Exact match of the search term |
substring | Search term appears within the domain |
fuzzy | Lookalike characters or typo variations |
Score
The score field is an edit distance — lower values mean a closer match. A score of 1 means one character substitution away from the query; a score of 8 means eight edits. Typical fuzzy results range from 1-8. Exact matches have a score of 0. Substring matches reflect the edit distance between the query and the matching portion.
Result Completeness
Results are limited server-side via the topn parameter (configured by the server operator). The header line indicates completeness:
count: N (complete)— all matches in the database were returnedcount: N of M+ (incomplete, showing top matches)— more matches exist; only the top N by score were returned. M is the total count in the database.
When incomplete, the returned results are the closest matches by score. A score of 0 is an exact match; lower scores indicate fewer character edits from the query.
Limits and Constraints
| Constraint | Value |
|---|---|
| Maximum results | Server-side limit via topn (1-1000, default 500) |
| Search term length | DP_MIN_SEARCH_CHARS (default 3) to 100 UTF-8 characters |
| Request timeout | 30 seconds |
| Result ordering | By score (top N closest matches) |
Fuzzy Matching
The search algorithm detects:
- Homoglyphs: Visually similar characters (
0/O,1/l/I,rn/m) - IDN abuse: Unicode characters that look like ASCII (
аCyrillic vsaLatin) - Keyboard proximity: Adjacent key typos (
googkeforgoogle) - Character transposition: Swapped letters (
googelforgoogle) - Omission/duplication: Missing or repeated characters
Use Cases
1. Typosquatting Detection
Find domains targeting a brand:
datapulse_dns_dpsearch(search_term="microsoft")
Then investigate low-score fuzzy matches (closest to the brand) with:
datapulse_live_rdap- Check registration detailsdatapulse_dns_dptechsim- Find related infrastructuredatapulse_dns_dphistory- Check historical patterns
2. Brand Monitoring
Find all domains containing a brand name:
datapulse_dns_dpsearch(search_term="acme")
Look for:
- Defensive registrations (same registrar/infrastructure)
- Potentially infringing domains (different registrar/infrastructure)
- Phishing domains (fuzzy matches with different infrastructure)
Note: search matches domain-name strings only — it cannot find domains by registrant email/name (no reverse-WHOIS; registrant data is GDPR-redacted).
3. IDN Abuse Detection
Search for a brand to find IDN homograph attacks:
datapulse_dns_dpsearch(search_term="paypal")
IDN domains will appear with their ASCII-compatible encoding (xn-- prefix in WHOIS/RDAP).
Workflow Examples
Typosquatting Investigation
dpsearch("brand") → filter fuzzy matches → dptechsim(top_hit) → dphistory(matches) → live_rdap(suspicious)
- Search for brand name
- Filter results to fuzzy matches with low scores (closest matches)
- Check if similar infrastructure (defensive registration?)
- Review historical DNS for patterns
- RDAP on suspicious domains
Brand Protection Audit
dpsearch("company") → group by match_type → live_rdap(each) → identify unowned
- Search for company name
- Categorize by exact/substring/fuzzy
- Check registration details (registrar, dates, status) of each via
datapulse_live_rdap— registrant identity is GDPR-redacted - Flag domains whose registrar/infrastructure doesn’t match the company’s known portfolio
Relationship to Other Tools
| Tool | Use Together For |
|---|---|
dptechsim | Find if matching domains share infrastructure |
dphistory | Check when domains appeared, infrastructure changes |
datapulse_live_rdap | Registration details (registrar, dates, status — registrant is GDPR-redacted) |
datapulse_live_dns | Current DNS resolution for matches |
datapulse_scrape_submit | Content analysis of suspicious domains |
Common Patterns
Defensive Registration Check
If dpsearch finds a typo domain, check if it’s defensive:
dpsearch("brand") → get matches → live_dns(match) vs live_dns("brand.com")
Same IP/infrastructure = likely defensive registration.
Phishing Detection
High-risk indicators from dpsearch results:
- Fuzzy match with low score (1-3 edits — very close to original)
- Different registrar than legitimate domain (check with
datapulse_live_rdap) - Recent registration date
- MX records configured (email interception risk)
Error Handling
| Error | Cause | Resolution |
|---|---|---|
| “search_term cannot be empty” | Empty or whitespace-only input | Provide valid search term |
| “search_term too short” | Below minimum length (DP_MIN_SEARCH_CHARS, default 3) | Use a longer, more specific term |
| “search_term too long” | Exceeds 100 character limit | Shorten the search term |
| “invalid search_term” | Invalid UTF-8 encoding | Use valid UTF-8 characters |
| “API request timed out” | Database query took too long | Retry with simpler term |
Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="dpsearch").