MCP documentation menu

DataPulse Quick Reference

Tool Selection

TaskToolNotes
Domain researchdatapulse_domain_overviewSTART HERE. One call: web scrape + DNS + RDAP. Accepts domain name, submits all jobs, waits, returns combined result.
DNS lookupdatapulse_live_dnsAlways synchronous — returns all record types directly, no polling
Domain/IP registration (RDAP)datapulse_live_rdapDomains and IPs (v4/v6). Always synchronous — returns registration data directly, no polling
Domain health check (DNS, DNSSEC, delegation, nameservers, TLS certificate, HTTP/HSTS, mail posture, CAA/TLSA)datapulse_live_domain_healthOne live probe, always synchronous. status is completed even for a broken domain — read raw_output.ok, errors, warnings. See datapulse_help(topic="domain_health")
DNSSEC inspectiondatapulse_live_dnsdnssec_signed (AD flag) in the summary; use full=true for RRSIG and when querying DNSKEY/DS for the full chain (the summary strips DNSSEC record types)
Infrastructure historydatapulse_dns_dphistoryHosting / nameserver timeline (a/c/d versions, oldest first); ASN numbers, no operator names
Similar tech domainsdatapulse_dns_dptechsimFind related infrastructure
Domain label searchdatapulse_dns_searchlabelsFuzzy/typosquatting label search with TLD spread. Matches domain-name labels only — not WHOIS/RDAP contents
Domain search (deprecated)datapulse_dns_dpsearchUse searchlabels instead
Find domains by owner/registrant email or name— not supportedReverse WHOIS is not possible; registrant data is GDPR-redacted. See datapulse_help(topic="registrant_lookup")
Bulk registration clustersdatapulse_dns_regclustersSummary by date; set registrar_id to drill in
UDRP legal researchdatapulse_disputedb_searchSemantic search over ~117K WIPO + Forum decisions, WIPO Overview 3.0, WIPO Guide, ICANN Policy/Rules. domain_names = disputed domains only, never the complainant’s own. Scores: 0.72+ strong, 0.65-0.72 relevant, <0.55 filtered
Web scraping (single URL)datapulse_scrape_submitSingle URL — use wait=true. For root domains prefer datapulse_domain_overview instead.
Bulk scrapingdatapulse_scrape_bulkUp to 1000 URLs, always async — returns batch_id for tracking. Lower priority: can take hours or pause, so not for interactive use.
Scrape resultdatapulse_scrape_resultPoll async results by url_hash, or get DOM with include_dom
Bulk scrape resultsdatapulse_scrape_bulk_resultsRetrieve multiple results by url_hashes in one call
List/batch resultsdatapulse_scrape_listPaginated list; use batch_id to filter to a bulk submission.

DNS Response Patterns

Resolver: All DNS tools use a DNSSEC-validating recursive resolver with no content filtering, except that answers in private, link-local or unique-local ranges are dropped (DNS-rebinding protection). The specific resolver is not exposed or configurable.

Default (summary) — record found:

{"status": "ok", "dnssec_signed": true, "records": {"A": [{"name": "example.com.", "ttl": 3600, "data": {"address": "1.2.3.4"}}]}, "query_time_ms": 42}

NXDOMAIN:

{"status": "nxdomain", "records": {"SOA": [...]}, "query_time_ms": 15}

CNAME chains: Automatically resolved — both CNAME and final A/AAAA appear in records.

Full output: Set full=true for raw per-query flags, authorities, additionals, and RRSIG/NSEC records.

DNSSEC Validation

datapulse_live_dns returns DNSSEC status automatically (DO flag is set):

  • Summary: dnssec_signed: true = Authenticated Data (DNSSEC valid)
  • Full (full=true): flags.ad: true per query, RRSIG records in answers
  • status: "servfail" often indicates DNSSEC validation failure
  • Query DNSKEY/DS record types with full=true to trace the trust chain (the summary strips DNSSEC record types, so a summary-mode DNSKEY/DS query returns no records)

Common Record Types

TypePurpose
A / AAAAIPv4 / IPv6 addresses
MXMail servers (check preference values)
TXTSPF, DKIM, domain verification tokens
NSAuthoritative nameservers
CAACertificate authority restrictions
SOAZone authority, serial numbers
SRVService discovery (e.g., SIP, XMPP)
PTRReverse DNS (query x.x.x.x.in-addr.arpa)
DNSKEY / DSDNSSEC public keys and delegation signers

SRV, PTR, TLSA, NAPTR, and SSHFP require specifying record_type in datapulse_live_dns. The default (omitted) queries A, AAAA, MX, NS, TXT, SOA, CNAME, CAA, DNSKEY, DS plus a _dmarc.<domain> TXT lookup (returned in the dmarc field).

RDAP / WHOIS Status Codes

StatusMeaning
ok (alone)Unlocked - potential security risk
clientTransferProhibitedStandard registrar lock
clientDeleteProhibitedProtected from deletion
serverHold / clientHoldDomain suspended
redemptionPeriodExpired, in grace period

Corpus Basics

FactConsequence
Unit is PSL+1 (= eTLD+1 = registrable domain)Hostnames/subdomains are not corpus entries and cannot be searched; a hostname given to a hostname-keeping tool is looked up as that hostname, not reduced
All PSL registries covered (ICANN, non-ICANN, cc)No TLD tier is out of scope; ccTLD gaps are an RDAP protocol limit only
Only active, functioning names are listedAbsence means it failed the liveness gate — not that it is undiscovered
Discovery source is never reportedNever attribute a record to CT, zone files, or any source

Full detail: datapulse_help(topic="methodology").

History Service Types (dphistory)

ServiceMeaning
AWWeb hosting: ASN of the address www resolves to (or the apex if no www)
MXMail exchangers
OperationalNSNameservers actually answering for the name
ReportedNSNameservers delegated by the parent zone (registry NS set)

Version types a (listed) / c (changed) / d (de-listed) are listing events (passed / stopped passing the quality gate), not registry events. The timeline is a change log from 2023-04-07, mostly month-dated; services is [] for a d. Input is canonicalized (case, whitespace, IDN, trailing dots) but the hostname level is kept: www.github.com and github.com are different lookups (only the RDAP tools reduce hostnames; see datapulse_help(topic="normalization")). A never-listed name answers found: false with a hint. Same-hostname, different-ASN c versions are usually anycast churn, not moves. See datapulse_help(topic="history").

Tech Similarity (dptechsim)

Similarity Signals (what the embedding captures):

  • Nameservers (operational + reported) and their ASNs
  • MX records and mail server ASNs
  • A/AAAA record ASNs (web hosting)
  • TLD, registrar IANA ID, registration date

Score Interpretation:

ScoreMeaning
0.98+Near-identical infrastructure (shared hosting stack; not proof of a common operator)
0.95+Same hosting setup (high confidence)
0.90+Shared major components
0.85+Similar patterns (may include CDN noise)
0.75-0.84Loose similarity

Caveat: Major CDNs (Cloudflare ASN 13335, AWS, Google) cause many false positives. Look for rare ASN overlaps in the response fingerprint fields.

Response Fields:

  • name, cosine_similarity - domain and score
  • fpons, fpons_asn - operational nameserver fingerprint
  • fprns, fprns_asn - reported nameserver fingerprint
  • fpmx, fpmx_asn - mail exchanger fingerprint
  • fpaw_asn - web hosting ASN fingerprint
  • registrar_iana_id, registration_date

Workflow Patterns

Domain Research (start here)

datapulse_domain_overview(domain="suspicious.com")
→ Scrape + DNS + RDAP in one call. Then pivot with the specialized tools below.

Investigation Pivot

dptechsim(suspicious.com, 0.90) → filter rare ASNs → dphistory(matches) → live_rdap(top hits)

Typosquatting Analysis

searchlabels("brand") → dptechsim(top_hits, 0.95) → group by registrar → live_rdap(clusters)

Operator Attribution

dptechsim(known_domain, 0.95) → filter by registrar_iana_id → dphistory for timeline

Bulk Registration Monitoring

regclusters(date, min_cluster_size=50) → identify unfamiliar registrars
→ regclusters(date, registrar_id=XXXX) → get full domain list for that registrar
→ dptechsim(sample_domains) → live_rdap(suspicious)

Malicious Bulk Registration Triage

regclusters(date, min_cluster_size=50) → flag unknown/abuse-friendly registrars
→ Check sample_domains for DGA, brand abuse, high-abuse TLDs (.top, .icu, .sbs)
→ regclusters(date, registrar_id=XXXX) → examine full list + timestamps
→ dptechsim(2-3 samples, 0.90) → shared infrastructure = coordinated campaign
→ scrape_submit(sample) → parked/phishing/redirect = confirmed malicious
See: datapulse_help(topic="malicious_bulk_regs")

Domain Dispute Analysis

searchlabels("brandname") → find lookalike/typosquatting labels + TLD spread
→ live_rdap(suspect_domain) → registration details, registrar, dates
→ disputedb_search("confusing similarity <trademark> <domain>") → case precedents
→ disputedb_search("bad faith <specific circumstances>") → bad faith factors
→ disputedb_search("legitimate interests <respondent argument>") → defenses
See: datapulse_help(topic="disputedb")

Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="quick_reference").