DataPulse Quick Reference
Tool Selection
| Task | Tool | Notes |
|---|---|---|
| Domain research | datapulse_domain_overview | START HERE. One call: web scrape + DNS + RDAP. Accepts domain name, submits all jobs, waits, returns combined result. |
| DNS lookup | datapulse_live_dns | Always synchronous — returns all record types directly, no polling |
| Domain/IP registration (RDAP) | datapulse_live_rdap | Domains and IPs (v4/v6). Always synchronous — returns registration data directly, no polling |
| Domain health check (DNS, DNSSEC, delegation, nameservers, TLS certificate, HTTP/HSTS, mail posture, CAA/TLSA) | datapulse_live_domain_health | One live probe, always synchronous. status is completed even for a broken domain — read raw_output.ok, errors, warnings. See datapulse_help(topic="domain_health") |
| DNSSEC inspection | datapulse_live_dns | dnssec_signed (AD flag) in the summary; use full=true for RRSIG and when querying DNSKEY/DS for the full chain (the summary strips DNSSEC record types) |
| Infrastructure history | datapulse_dns_dphistory | Hosting / nameserver timeline (a/c/d versions, oldest first); ASN numbers, no operator names |
| Similar tech domains | datapulse_dns_dptechsim | Find related infrastructure |
| Domain label search | datapulse_dns_searchlabels | Fuzzy/typosquatting label search with TLD spread. Matches domain-name labels only — not WHOIS/RDAP contents |
| Domain search (deprecated) | datapulse_dns_dpsearch | Use searchlabels instead |
| Find domains by owner/registrant email or name | — not supported | Reverse WHOIS is not possible; registrant data is GDPR-redacted. See datapulse_help(topic="registrant_lookup") |
| Bulk registration clusters | datapulse_dns_regclusters | Summary by date; set registrar_id to drill in |
| UDRP legal research | datapulse_disputedb_search | Semantic search over ~117K WIPO + Forum decisions, WIPO Overview 3.0, WIPO Guide, ICANN Policy/Rules. domain_names = disputed domains only, never the complainant’s own. Scores: 0.72+ strong, 0.65-0.72 relevant, <0.55 filtered |
| Web scraping (single URL) | datapulse_scrape_submit | Single URL — use wait=true. For root domains prefer datapulse_domain_overview instead. |
| Bulk scraping | datapulse_scrape_bulk | Up to 1000 URLs, always async — returns batch_id for tracking. Lower priority: can take hours or pause, so not for interactive use. |
| Scrape result | datapulse_scrape_result | Poll async results by url_hash, or get DOM with include_dom |
| Bulk scrape results | datapulse_scrape_bulk_results | Retrieve multiple results by url_hashes in one call |
| List/batch results | datapulse_scrape_list | Paginated list; use batch_id to filter to a bulk submission. |
DNS Response Patterns
Resolver: All DNS tools use a DNSSEC-validating recursive resolver with no content filtering, except that answers in private, link-local or unique-local ranges are dropped (DNS-rebinding protection). The specific resolver is not exposed or configurable.
Default (summary) — record found:
{"status": "ok", "dnssec_signed": true, "records": {"A": [{"name": "example.com.", "ttl": 3600, "data": {"address": "1.2.3.4"}}]}, "query_time_ms": 42}
NXDOMAIN:
{"status": "nxdomain", "records": {"SOA": [...]}, "query_time_ms": 15}
CNAME chains: Automatically resolved — both CNAME and final A/AAAA appear in records.
Full output: Set full=true for raw per-query flags, authorities, additionals, and RRSIG/NSEC records.
DNSSEC Validation
datapulse_live_dns returns DNSSEC status automatically (DO flag is set):
- Summary:
dnssec_signed: true= Authenticated Data (DNSSEC valid) - Full (
full=true):flags.ad: trueper query, RRSIG records in answers status: "servfail"often indicates DNSSEC validation failure- Query DNSKEY/DS record types with
full=trueto trace the trust chain (the summary strips DNSSEC record types, so a summary-mode DNSKEY/DS query returns no records)
Common Record Types
| Type | Purpose |
|---|---|
| A / AAAA | IPv4 / IPv6 addresses |
| MX | Mail servers (check preference values) |
| TXT | SPF, DKIM, domain verification tokens |
| NS | Authoritative nameservers |
| CAA | Certificate authority restrictions |
| SOA | Zone authority, serial numbers |
| SRV | Service discovery (e.g., SIP, XMPP) |
| PTR | Reverse DNS (query x.x.x.x.in-addr.arpa) |
| DNSKEY / DS | DNSSEC public keys and delegation signers |
SRV, PTR, TLSA, NAPTR, and SSHFP require specifying record_type in datapulse_live_dns.
The default (omitted) queries A, AAAA, MX, NS, TXT, SOA, CNAME, CAA, DNSKEY, DS plus a _dmarc.<domain> TXT lookup (returned in the dmarc field).
RDAP / WHOIS Status Codes
| Status | Meaning |
|---|---|
ok (alone) | Unlocked - potential security risk |
clientTransferProhibited | Standard registrar lock |
clientDeleteProhibited | Protected from deletion |
serverHold / clientHold | Domain suspended |
redemptionPeriod | Expired, in grace period |
Corpus Basics
| Fact | Consequence |
|---|---|
| Unit is PSL+1 (= eTLD+1 = registrable domain) | Hostnames/subdomains are not corpus entries and cannot be searched; a hostname given to a hostname-keeping tool is looked up as that hostname, not reduced |
| All PSL registries covered (ICANN, non-ICANN, cc) | No TLD tier is out of scope; ccTLD gaps are an RDAP protocol limit only |
| Only active, functioning names are listed | Absence means it failed the liveness gate — not that it is undiscovered |
| Discovery source is never reported | Never attribute a record to CT, zone files, or any source |
Full detail: datapulse_help(topic="methodology").
History Service Types (dphistory)
| Service | Meaning |
|---|---|
| AW | Web hosting: ASN of the address www resolves to (or the apex if no www) |
| MX | Mail exchangers |
| OperationalNS | Nameservers actually answering for the name |
| ReportedNS | Nameservers delegated by the parent zone (registry NS set) |
Version types a (listed) / c (changed) / d (de-listed) are listing events
(passed / stopped passing the quality gate), not registry events. The timeline is a
change log from 2023-04-07, mostly month-dated; services is [] for a d. Input is
canonicalized (case, whitespace, IDN, trailing dots) but the hostname level is kept:
www.github.com and github.com are different lookups (only the RDAP tools reduce
hostnames; see datapulse_help(topic="normalization")). A never-listed name answers found: false with a hint. Same-hostname,
different-ASN c versions are usually anycast churn, not moves. See
datapulse_help(topic="history").
Tech Similarity (dptechsim)
Similarity Signals (what the embedding captures):
- Nameservers (operational + reported) and their ASNs
- MX records and mail server ASNs
- A/AAAA record ASNs (web hosting)
- TLD, registrar IANA ID, registration date
Score Interpretation:
| Score | Meaning |
|---|---|
| 0.98+ | Near-identical infrastructure (shared hosting stack; not proof of a common operator) |
| 0.95+ | Same hosting setup (high confidence) |
| 0.90+ | Shared major components |
| 0.85+ | Similar patterns (may include CDN noise) |
| 0.75-0.84 | Loose similarity |
Caveat: Major CDNs (Cloudflare ASN 13335, AWS, Google) cause many false positives. Look for rare ASN overlaps in the response fingerprint fields.
Response Fields:
name,cosine_similarity- domain and scorefpons,fpons_asn- operational nameserver fingerprintfprns,fprns_asn- reported nameserver fingerprintfpmx,fpmx_asn- mail exchanger fingerprintfpaw_asn- web hosting ASN fingerprintregistrar_iana_id,registration_date
Workflow Patterns
Domain Research (start here)
datapulse_domain_overview(domain="suspicious.com")
→ Scrape + DNS + RDAP in one call. Then pivot with the specialized tools below.
Investigation Pivot
dptechsim(suspicious.com, 0.90) → filter rare ASNs → dphistory(matches) → live_rdap(top hits)
Typosquatting Analysis
searchlabels("brand") → dptechsim(top_hits, 0.95) → group by registrar → live_rdap(clusters)
Operator Attribution
dptechsim(known_domain, 0.95) → filter by registrar_iana_id → dphistory for timeline
Bulk Registration Monitoring
regclusters(date, min_cluster_size=50) → identify unfamiliar registrars
→ regclusters(date, registrar_id=XXXX) → get full domain list for that registrar
→ dptechsim(sample_domains) → live_rdap(suspicious)
Malicious Bulk Registration Triage
regclusters(date, min_cluster_size=50) → flag unknown/abuse-friendly registrars
→ Check sample_domains for DGA, brand abuse, high-abuse TLDs (.top, .icu, .sbs)
→ regclusters(date, registrar_id=XXXX) → examine full list + timestamps
→ dptechsim(2-3 samples, 0.90) → shared infrastructure = coordinated campaign
→ scrape_submit(sample) → parked/phishing/redirect = confirmed malicious
See: datapulse_help(topic="malicious_bulk_regs")
Domain Dispute Analysis
searchlabels("brandname") → find lookalike/typosquatting labels + TLD spread
→ live_rdap(suspect_domain) → registration details, registrar, dates
→ disputedb_search("confusing similarity <trademark> <domain>") → case precedents
→ disputedb_search("bad faith <specific circumstances>") → bad faith factors
→ disputedb_search("legitimate interests <respondent argument>") → defenses
See: datapulse_help(topic="disputedb")
Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="quick_reference").