Bulk Registration Clusters (datapulse_dns_regclusters)
Detect bulk domain registration campaigns by finding registrars with unusually high registration volumes on a given date.
Overview
The datapulse_dns_regclusters tool operates in two modes:
- Summary mode (default): Returns one row per registrar with domain count and sample domains, sorted by volume descending.
- Detail mode (set
registrar_id): Returns ALL domains registered at a specific registrar on a given date.
Large clusters often indicate:
- Bulk registration campaigns — automated domain purchasing (parking, speculation, abuse)
- Domain parking operations — registrars or resellers provisioning inventory
- Coordinated malicious activity — phishing kits, malware C2 infrastructure, spam networks
- Registrar volume anomalies — sudden spikes worth investigating
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
date | string | No | today (UTC) | Target UTC day in YYYY-MM-DD format |
min_cluster_size | integer | No | 8 | Minimum domains per registrar to appear (summary mode only) |
limit | integer | No | 25/200 | Summary mode: max clusters (max 100). Detail mode: max domains per page (max 500) |
offset | integer | No | 0 | Pagination offset for detail mode — skip this many domains (alphabetically) |
registrar_id | integer | No | — | Registrar identifier to drill into, as a summary row’s registrar_id reports it (activates detail mode) |
Parameter Details
date
- Format:
YYYY-MM-DD(e.g.,2025-02-09) - A UTC day: registrations from 00:00 to 24:00 UTC (since 2026-09-25; before that, US/Central days)
- Defaults to today’s UTC date if omitted
- Data availability depends on ingestion pipeline; recent dates may have no data yet
min_cluster_size (summary mode only)
- Controls the noise floor — higher values surface only large campaigns
- Minimum value: 2
- Recommended ranges:
2-10: Broad view, includes small registrars (noisy)10-50: Moderate filtering, good for general monitoring50-200: Focus on significant bulk operations200+: Only major campaigns and large registrars
limit
- Summary mode: results sorted by domain count descending, so the largest clusters appear first. Range: 1–100. Default: 25.
- Detail mode: max domains per page. Range: 1–500. Default: 200.
offset (detail mode only)
- Skip this many domains (ordered alphabetically) for pagination
- Use
total_countfrom the response to know how many domains exist - Example: first page
offset=0, second pageoffset=200, etc.
registrar_id
- The registrar identifier from a summary row’s
registrar_id, whatever itsregistrar_id_scheme(get it from a summary call first) - When set, returns domains registered at that registrar on the given date (paginated)
min_cluster_sizeis ignored in detail mode
Example Usage
Summary: Default query (today, top 25 clusters with 8+ domains)
{}
Summary: Specific date
{
"date": "2025-02-09"
}
Summary: Focus on large bulk campaigns
{
"date": "2025-02-09",
"min_cluster_size": 100,
"limit": 10
}
Summary: Broad scan for smaller clusters
{
"date": "2025-02-09",
"min_cluster_size": 3,
"limit": 50
}
Detail: All domains for a specific registrar
{
"date": "2025-02-09",
"registrar_id": 3222
}
Detail: Page 2 of a large result set
{
"date": "2025-09-27",
"registrar_id": 1068,
"limit": 200,
"offset": 200
}
Response Format
Summary Mode Response
Returns a JSON array of cluster objects, one per registrar:
[
{
"registrar_id": 146,
"registrar_id_scheme": "iana",
"registrar_name": "GoDaddy.com, LLC",
"domain_count": 22341,
"sample_domains": ["example1.com", "example2.net", "example3.org"]
},
{
"registrar_id": 930834408,
"registrar_id_scheme": "registry",
"domain_count": 373,
"sample_domains": ["a2gprofilering.no", "aasemulen.no", "acacia.no"]
}
]
Summary Fields
| Field | Description |
|---|---|
registrar_id | The registrar identifier the registry published for these registrations; the value to pass as registrar_id for drill-in. |
registrar_id_scheme | What kind of number registrar_id is. iana: an IANA-assigned registrar ID, resolvable with datapulse_dns_registrar(iana_id=...). registry: the registry’s own registrar identifier (Norid’s organisation numbers for .no, for example); it is NOT an IANA ID and datapulse_dns_registrar will not find it. unresolved: the IANA list could not be consulted for this call. |
registrar_name | The IANA-listed registrar name; present only when the scheme is iana. |
domain_count | Total domains registered at this registrar on this date |
sample_domains | Up to 10 example domain names from the cluster |
The database column behind registrar_id holds whatever identifier each registry’s RDAP published. gTLD registries and most ccTLDs publish IANA IDs; some ccTLDs publish their own registrar numbers. Before 2026-09-17 the field was named registrar_iana_id for both, which invited a lookup that could not succeed.
Detail Mode Response
Returns a JSON array of individual domain records (paginated, default 200 per page):
[
{
"name": "byts-cy.com",
"registrar_id": 3222,
"registrar_id_scheme": "iana",
"registrar_name": "Alibaba Cloud Computing Ltd.",
"registration_date": "2025-02-09T11:45:42Z",
"total_count": 964
},
{
"name": "fm664.com",
"registrar_id": 3222,
"registrar_id_scheme": "iana",
"registrar_name": "Alibaba Cloud Computing Ltd.",
"registration_date": "2025-02-09T19:10:41Z",
"total_count": 964
}
]
Detail Fields
| Field | Description |
|---|---|
name | Domain name |
registrar_id, registrar_id_scheme, registrar_name | As in summary mode: the identifier, whether it is an IANA ID (iana, with the name) or the registry’s own (registry), or unresolved. |
registration_date | Exact registration timestamp, in UTC (Z) |
total_count | Total domains at this registrar on this date (use for pagination) |
Pagination
If total_count exceeds limit, page through results:
Page 1: offset=0 → domains 1–200 (total_count: 14442)
Page 2: offset=200 → domains 201–400
Page 3: offset=400 → domains 401–600
...
For analysis, the first 200 domains (default) are usually sufficient to identify naming patterns, TLD distribution, and registration timing.
Empty Results
If no results match, a text message is returned instead of JSON.
Interpretation Guide
Scale Context
On a typical day, the database contains 100,000–200,000+ domain registrations across ~200 registrars. Major registrars like GoDaddy, Namecheap, and Tucows routinely register 10,000–25,000+ domains per day. These are normal volumes.
Identifying Suspicious Activity
Look for:
- Unfamiliar registrars with high volumes — smaller or niche registrars suddenly appearing with thousands of registrations
- Known abuse-friendly registrars appearing in the top clusters
- Sample domains with algorithmically generated names (DGA patterns), keyword stuffing, or brand impersonation
- Volume spikes — compare a registrar’s count across multiple dates to spot anomalies
False Positives
Large volumes at well-known registrars (GoDaddy, Namecheap, Tucows, Google Domains) are typically legitimate. Use min_cluster_size=100 or higher to filter past normal retail registrar traffic and focus on true bulk campaigns.
Workflow Patterns
Daily Monitoring
regclusters(date="2025-02-09", min_cluster_size=50)
→ Review unfamiliar registrars
→ regclusters(date="2025-02-09", registrar_id=3222) ← drill into suspicious one
→ dptechsim(sample_domains) to check infrastructure overlap
Campaign Deep Dive
regclusters(date="2025-02-09", min_cluster_size=3, limit=100)
→ Spot an interesting registrar_id (check registrar_id_scheme before any IANA pivot)
→ regclusters(date="2025-02-09", registrar_id=XXXX) ← get full domain list
→ Examine domains for DGA patterns
→ dphistory(suspicious_domain) for infrastructure timeline
Cross-Date Comparison
regclusters(date="2025-02-08", min_cluster_size=100)
regclusters(date="2025-02-09", min_cluster_size=100)
→ Compare registrar volumes between dates
→ New registrars or major volume changes flag anomalies
Pivot from Similarity Search
dptechsim(suspicious.com, 0.90)
→ Note registrar_iana_id from results (the same registry-published number; pass it as registrar_id)
→ regclusters(date=registration_date, registrar_id=XXXX)
→ See all domains from that registrar on that date
Data Source
This tool queries two PostgreSQL stored procedures via the dbserver daemon:
registrar_clusters_summary— aggregated summary (summary mode)registrar_cluster_domains— full domain list (detail mode)
The underlying data comes from zone file analysis correlated with WHOIS/RDAP registration records.
Limitations
- Data depends on zone file and registration data ingestion; there may be a 1–2 day lag
- Summary mode shows at most 10 sample domains per cluster; use detail mode for the full list
- Detail mode returns up to 200 domains per page by default (max 500); use offset to paginate
- Very recent dates (today) may return no data if ingestion hasn’t completed
- Summary queries complete in ~250ms; detail queries in ~30–130ms
Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="regclusters").