Domain Label Search (searchlabels)
Overview
The datapulse_dns_searchlabels tool is the primary tool for finding typosquatting, brand impersonation, and lookalike domains. It searches the DataPulse database for domain labels matching a search term, and returns each label along with the TLDs where it has been registered.
The label searched is the PSL+1 label — the registrable label sitting one level below a public suffix (google in google.com, example in example.co.uk). Hostnames and subdomains are not indexed and cannot be searched: DataPulse’s unit of analysis is the registrable domain, so a name like a.b.c.foo.com is represented in the corpus only as foo.com. See datapulse_help(topic="methodology").
This gives a complete picture of a string’s presence across the domain namespace — one label match may span dozens of TLDs.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
search_term | string | Yes | Search term to query (minimum length enforced by DP_MIN_SEARCH_CHARS, default 3; max 255 UTF-8 characters) |
filter | array | No | Restrict to listed match types: exact, substring, fuzzy. Omit for all types |
Response Format
The response is CSV with a header row followed by data rows, ordered by increasing score (nearest matches first):
label,type,score,tlds
g00gle,fuzzy,2,com|net|org|info
googl3,fuzzy,3,com|net
google-login,substring,6,com|net|org|info|co.uk
The tlds column is a pipe-delimited list of every TLD where the label is registered — the complete set, with no cap or truncation.
Do not fabricate beyond what is returned. The tlds list is authoritative and complete; treat it as the full set. Do not add TLDs, domains, or ownership/market/“defensive” annotations that are not present in the tool output. Registration of a label in a TLD does not establish who owns that domain — registrant identity is GDPR-redacted and this tool does not return it (see datapulse_help(topic="registrant_lookup")). If asked which of these a specific company owns, say that ownership cannot be confirmed from label data.
Match Types
| Type | Description |
|---|---|
exact | Exact match of the search term |
substring | Search term appears within the label |
fuzzy | Lookalike characters or typo variations |
Score
The score field is an edit distance — lower values mean a closer match. A score of 0 is an exact match; a score of 1 means one character substitution from the query. Typical fuzzy results range from 1-8.
Fuzzy Matching
The search algorithm detects:
- Homoglyphs: Visually similar characters (
0/O,1/l/I,rn/m) - IDN abuse: Unicode characters that look like ASCII (
аCyrillic vsaLatin) - Keyboard proximity: Adjacent key typos (
googkeforgoogle) - Character transposition: Swapped letters (
googelforgoogle) - Omission/duplication: Missing or repeated characters
Use Cases
1. Typosquatting Detection
Find labels targeting a brand:
datapulse_dns_searchlabels(search_term="microsoft")
Then investigate low-score fuzzy matches (closest to the brand) with:
datapulse_live_rdap— Check registration detailsdatapulse_dns_dptechsim— Find related infrastructuredatapulse_dns_dphistory— Check historical patterns
2. Brand Monitoring
Find all labels containing a brand name:
datapulse_dns_searchlabels(search_term="acme")
The TLDs column immediately shows how widespread each variant is — a fuzzy match registered in 15+ TLDs is more concerning than one in a single TLD.
3. IDN Abuse Detection
Search for a brand to find IDN homograph attacks:
datapulse_dns_searchlabels(search_term="paypal")
4. Defensive Registration Audit
Check whether your brand’s defensive registrations cover common typo variants:
datapulse_dns_searchlabels(search_term="yourbrand")
Compare the TLD spread of fuzzy matches against your known defensive portfolio.
Workflow Examples
Typosquatting Investigation
searchlabels("brand") → filter fuzzy matches → dptechsim(top_hit.tld) → dphistory(matches) → live_rdap(suspicious)
- Search for brand name
- Filter results to fuzzy matches with low scores (closest matches)
- Note TLD spread — high TLD count on a fuzzy match is a red flag
- Check infrastructure similarity for top hits
- RDAP on suspicious domains
Brand Protection Audit
searchlabels("company") → group by match_type → live_rdap(label+tld combos) → identify unowned
- Search for company name
- Categorize by exact/substring/fuzzy
- Check registration details (registrar, dates, status) via
datapulse_live_rdapfor concerning label+TLD combinations — registrant identity is GDPR-redacted - Flag domains whose registrar/infrastructure doesn’t match the company’s known portfolio
Domain Dispute Analysis
searchlabels("brandname") → find lookalike labels + TLD spread
→ live_rdap(suspect_domain) → registration details
→ disputedb_search("confusing similarity <trademark> <domain>") → case precedents
Relationship to Other Tools
| Tool | Use Together For |
|---|---|
dptechsim | Find if matching domains share infrastructure |
dphistory | Check when domains appeared, infrastructure changes |
datapulse_live_rdap | Registration details (registrar, dates, status — registrant is GDPR-redacted) |
datapulse_live_dns | Current DNS resolution for matches |
datapulse_scrape_submit | Content analysis of suspicious domains |
disputedb_search | UDRP case law for domain disputes |
If you are investigating hostnames that place a trusted brand in the leftmost label while hiding attacker control in the registered domain, see datapulse_help(topic="subdomain_cloaking").
Comparison with dpsearch
searchlabels is the recommended tool for domain similarity searches. The older dpsearch tool (deprecated) returns full domain names, while searchlabels returns labels with their TLD spread — showing at a glance how widely a variant has been registered.
Error Handling
| Error | Cause | Resolution |
|---|---|---|
| “search_term cannot be empty” | Empty or whitespace-only input | Provide valid search term |
| “search_term too short” | Below minimum length (DP_MIN_SEARCH_CHARS, default 3) | Use a longer, more specific term |
| “search_term too long” | Exceeds 255 character limit | Shorten the search term |
| “invalid search_term” | Invalid UTF-8 encoding | Use valid UTF-8 characters |
| “API request timed out” | Result set too large for the configured timeout | Use filter to narrow match types, or try a more specific term. Very common short strings (e.g. “pay”, “app”) match millions of labels and will exceed the timeout |
Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="searchlabels").