MCP documentation menu

Bulk Registration Clusters (datapulse_dns_regclusters)

Detect bulk domain registration campaigns by finding registrars with unusually high registration volumes on a given date.

Overview

The datapulse_dns_regclusters tool operates in two modes:

  1. Summary mode (default): Returns one row per registrar with domain count and sample domains, sorted by volume descending.
  2. Detail mode (set registrar_id): Returns ALL domains registered at a specific registrar on a given date.

Large clusters often indicate:

  • Bulk registration campaigns — automated domain purchasing (parking, speculation, abuse)
  • Domain parking operations — registrars or resellers provisioning inventory
  • Coordinated malicious activity — phishing kits, malware C2 infrastructure, spam networks
  • Registrar volume anomalies — sudden spikes worth investigating

Parameters

ParameterTypeRequiredDefaultDescription
datestringNotoday (UTC)Target UTC day in YYYY-MM-DD format
min_cluster_sizeintegerNo8Minimum domains per registrar to appear (summary mode only)
limitintegerNo25/200Summary mode: max clusters (max 100). Detail mode: max domains per page (max 500)
offsetintegerNo0Pagination offset for detail mode — skip this many domains (alphabetically)
registrar_idintegerNo—Registrar identifier to drill into, as a summary row’s registrar_id reports it (activates detail mode)

Parameter Details

date

  • Format: YYYY-MM-DD (e.g., 2025-02-09)
  • A UTC day: registrations from 00:00 to 24:00 UTC (since 2026-09-25; before that, US/Central days)
  • Defaults to today’s UTC date if omitted
  • Data availability depends on ingestion pipeline; recent dates may have no data yet

min_cluster_size (summary mode only)

  • Controls the noise floor — higher values surface only large campaigns
  • Minimum value: 2
  • Recommended ranges:
    • 2-10: Broad view, includes small registrars (noisy)
    • 10-50: Moderate filtering, good for general monitoring
    • 50-200: Focus on significant bulk operations
    • 200+: Only major campaigns and large registrars

limit

  • Summary mode: results sorted by domain count descending, so the largest clusters appear first. Range: 1–100. Default: 25.
  • Detail mode: max domains per page. Range: 1–500. Default: 200.

offset (detail mode only)

  • Skip this many domains (ordered alphabetically) for pagination
  • Use total_count from the response to know how many domains exist
  • Example: first page offset=0, second page offset=200, etc.

registrar_id

  • The registrar identifier from a summary row’s registrar_id, whatever its registrar_id_scheme (get it from a summary call first)
  • When set, returns domains registered at that registrar on the given date (paginated)
  • min_cluster_size is ignored in detail mode

Example Usage

Summary: Default query (today, top 25 clusters with 8+ domains)

{}

Summary: Specific date

{
  "date": "2025-02-09"
}

Summary: Focus on large bulk campaigns

{
  "date": "2025-02-09",
  "min_cluster_size": 100,
  "limit": 10
}

Summary: Broad scan for smaller clusters

{
  "date": "2025-02-09",
  "min_cluster_size": 3,
  "limit": 50
}

Detail: All domains for a specific registrar

{
  "date": "2025-02-09",
  "registrar_id": 3222
}

Detail: Page 2 of a large result set

{
  "date": "2025-09-27",
  "registrar_id": 1068,
  "limit": 200,
  "offset": 200
}

Response Format

Summary Mode Response

Returns a JSON array of cluster objects, one per registrar:

[
  {
    "registrar_id": 146,
    "registrar_id_scheme": "iana",
    "registrar_name": "GoDaddy.com, LLC",
    "domain_count": 22341,
    "sample_domains": ["example1.com", "example2.net", "example3.org"]
  },
  {
    "registrar_id": 930834408,
    "registrar_id_scheme": "registry",
    "domain_count": 373,
    "sample_domains": ["a2gprofilering.no", "aasemulen.no", "acacia.no"]
  }
]

Summary Fields

FieldDescription
registrar_idThe registrar identifier the registry published for these registrations; the value to pass as registrar_id for drill-in.
registrar_id_schemeWhat kind of number registrar_id is. iana: an IANA-assigned registrar ID, resolvable with datapulse_dns_registrar(iana_id=...). registry: the registry’s own registrar identifier (Norid’s organisation numbers for .no, for example); it is NOT an IANA ID and datapulse_dns_registrar will not find it. unresolved: the IANA list could not be consulted for this call.
registrar_nameThe IANA-listed registrar name; present only when the scheme is iana.
domain_countTotal domains registered at this registrar on this date
sample_domainsUp to 10 example domain names from the cluster

The database column behind registrar_id holds whatever identifier each registry’s RDAP published. gTLD registries and most ccTLDs publish IANA IDs; some ccTLDs publish their own registrar numbers. Before 2026-09-17 the field was named registrar_iana_id for both, which invited a lookup that could not succeed.

Detail Mode Response

Returns a JSON array of individual domain records (paginated, default 200 per page):

[
  {
    "name": "byts-cy.com",
    "registrar_id": 3222,
    "registrar_id_scheme": "iana",
    "registrar_name": "Alibaba Cloud Computing Ltd.",
    "registration_date": "2025-02-09T11:45:42Z",
    "total_count": 964
  },
  {
    "name": "fm664.com",
    "registrar_id": 3222,
    "registrar_id_scheme": "iana",
    "registrar_name": "Alibaba Cloud Computing Ltd.",
    "registration_date": "2025-02-09T19:10:41Z",
    "total_count": 964
  }
]

Detail Fields

FieldDescription
nameDomain name
registrar_id, registrar_id_scheme, registrar_nameAs in summary mode: the identifier, whether it is an IANA ID (iana, with the name) or the registry’s own (registry), or unresolved.
registration_dateExact registration timestamp, in UTC (Z)
total_countTotal domains at this registrar on this date (use for pagination)

Pagination

If total_count exceeds limit, page through results:

Page 1: offset=0   → domains 1–200   (total_count: 14442)
Page 2: offset=200  → domains 201–400
Page 3: offset=400  → domains 401–600
...

For analysis, the first 200 domains (default) are usually sufficient to identify naming patterns, TLD distribution, and registration timing.

Empty Results

If no results match, a text message is returned instead of JSON.

Interpretation Guide

Scale Context

On a typical day, the database contains 100,000–200,000+ domain registrations across ~200 registrars. Major registrars like GoDaddy, Namecheap, and Tucows routinely register 10,000–25,000+ domains per day. These are normal volumes.

Identifying Suspicious Activity

Look for:

  • Unfamiliar registrars with high volumes — smaller or niche registrars suddenly appearing with thousands of registrations
  • Known abuse-friendly registrars appearing in the top clusters
  • Sample domains with algorithmically generated names (DGA patterns), keyword stuffing, or brand impersonation
  • Volume spikes — compare a registrar’s count across multiple dates to spot anomalies

False Positives

Large volumes at well-known registrars (GoDaddy, Namecheap, Tucows, Google Domains) are typically legitimate. Use min_cluster_size=100 or higher to filter past normal retail registrar traffic and focus on true bulk campaigns.

Workflow Patterns

Daily Monitoring

regclusters(date="2025-02-09", min_cluster_size=50)
→ Review unfamiliar registrars
→ regclusters(date="2025-02-09", registrar_id=3222)  ← drill into suspicious one
→ dptechsim(sample_domains) to check infrastructure overlap

Campaign Deep Dive

regclusters(date="2025-02-09", min_cluster_size=3, limit=100)
→ Spot an interesting registrar_id (check registrar_id_scheme before any IANA pivot)
→ regclusters(date="2025-02-09", registrar_id=XXXX)  ← get full domain list
→ Examine domains for DGA patterns
→ dphistory(suspicious_domain) for infrastructure timeline

Cross-Date Comparison

regclusters(date="2025-02-08", min_cluster_size=100)
regclusters(date="2025-02-09", min_cluster_size=100)
→ Compare registrar volumes between dates
→ New registrars or major volume changes flag anomalies
dptechsim(suspicious.com, 0.90)
→ Note registrar_iana_id from results (the same registry-published number; pass it as registrar_id)
→ regclusters(date=registration_date, registrar_id=XXXX)
→ See all domains from that registrar on that date

Data Source

This tool queries two PostgreSQL stored procedures via the dbserver daemon:

  • registrar_clusters_summary — aggregated summary (summary mode)
  • registrar_cluster_domains — full domain list (detail mode)

The underlying data comes from zone file analysis correlated with WHOIS/RDAP registration records.

Limitations

  • Data depends on zone file and registration data ingestion; there may be a 1–2 day lag
  • Summary mode shows at most 10 sample domains per cluster; use detail mode for the full list
  • Detail mode returns up to 200 domains per page by default (max 500); use offset to paginate
  • Very recent dates (today) may return no data if ingestion hasn’t completed
  • Summary queries complete in ~250ms; detail queries in ~30–130ms

Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="regclusters").