MCP documentation menu

Domain Label Search (searchlabels)

Overview

The datapulse_dns_searchlabels tool is the primary tool for finding typosquatting, brand impersonation, and lookalike domains. It searches the DataPulse database for domain labels matching a search term, and returns each label along with the TLDs where it has been registered.

The label searched is the PSL+1 label — the registrable label sitting one level below a public suffix (google in google.com, example in example.co.uk). Hostnames and subdomains are not indexed and cannot be searched: DataPulse’s unit of analysis is the registrable domain, so a name like a.b.c.foo.com is represented in the corpus only as foo.com. See datapulse_help(topic="methodology").

This gives a complete picture of a string’s presence across the domain namespace — one label match may span dozens of TLDs.

Parameters

ParameterTypeRequiredDescription
search_termstringYesSearch term to query (minimum length enforced by DP_MIN_SEARCH_CHARS, default 3; max 255 UTF-8 characters)
filterarrayNoRestrict to listed match types: exact, substring, fuzzy. Omit for all types

Response Format

The response is CSV with a header row followed by data rows, ordered by increasing score (nearest matches first):

label,type,score,tlds
g00gle,fuzzy,2,com|net|org|info
googl3,fuzzy,3,com|net
google-login,substring,6,com|net|org|info|co.uk

The tlds column is a pipe-delimited list of every TLD where the label is registered — the complete set, with no cap or truncation.

Do not fabricate beyond what is returned. The tlds list is authoritative and complete; treat it as the full set. Do not add TLDs, domains, or ownership/market/“defensive” annotations that are not present in the tool output. Registration of a label in a TLD does not establish who owns that domain — registrant identity is GDPR-redacted and this tool does not return it (see datapulse_help(topic="registrant_lookup")). If asked which of these a specific company owns, say that ownership cannot be confirmed from label data.

Match Types

TypeDescription
exactExact match of the search term
substringSearch term appears within the label
fuzzyLookalike characters or typo variations

Score

The score field is an edit distance — lower values mean a closer match. A score of 0 is an exact match; a score of 1 means one character substitution from the query. Typical fuzzy results range from 1-8.

Fuzzy Matching

The search algorithm detects:

  • Homoglyphs: Visually similar characters (0/O, 1/l/I, rn/m)
  • IDN abuse: Unicode characters that look like ASCII (а Cyrillic vs a Latin)
  • Keyboard proximity: Adjacent key typos (googke for google)
  • Character transposition: Swapped letters (googel for google)
  • Omission/duplication: Missing or repeated characters

Use Cases

1. Typosquatting Detection

Find labels targeting a brand:

datapulse_dns_searchlabels(search_term="microsoft")

Then investigate low-score fuzzy matches (closest to the brand) with:

2. Brand Monitoring

Find all labels containing a brand name:

datapulse_dns_searchlabels(search_term="acme")

The TLDs column immediately shows how widespread each variant is — a fuzzy match registered in 15+ TLDs is more concerning than one in a single TLD.

3. IDN Abuse Detection

Search for a brand to find IDN homograph attacks:

datapulse_dns_searchlabels(search_term="paypal")

4. Defensive Registration Audit

Check whether your brand’s defensive registrations cover common typo variants:

datapulse_dns_searchlabels(search_term="yourbrand")

Compare the TLD spread of fuzzy matches against your known defensive portfolio.

Workflow Examples

Typosquatting Investigation

searchlabels("brand") → filter fuzzy matches → dptechsim(top_hit.tld) → dphistory(matches) → live_rdap(suspicious)
  1. Search for brand name
  2. Filter results to fuzzy matches with low scores (closest matches)
  3. Note TLD spread — high TLD count on a fuzzy match is a red flag
  4. Check infrastructure similarity for top hits
  5. RDAP on suspicious domains

Brand Protection Audit

searchlabels("company") → group by match_type → live_rdap(label+tld combos) → identify unowned
  1. Search for company name
  2. Categorize by exact/substring/fuzzy
  3. Check registration details (registrar, dates, status) via datapulse_live_rdap for concerning label+TLD combinations — registrant identity is GDPR-redacted
  4. Flag domains whose registrar/infrastructure doesn’t match the company’s known portfolio

Domain Dispute Analysis

searchlabels("brandname") → find lookalike labels + TLD spread
→ live_rdap(suspect_domain) → registration details
→ disputedb_search("confusing similarity <trademark> <domain>") → case precedents

Relationship to Other Tools

ToolUse Together For
dptechsimFind if matching domains share infrastructure
dphistoryCheck when domains appeared, infrastructure changes
datapulse_live_rdapRegistration details (registrar, dates, status — registrant is GDPR-redacted)
datapulse_live_dnsCurrent DNS resolution for matches
datapulse_scrape_submitContent analysis of suspicious domains
disputedb_searchUDRP case law for domain disputes

If you are investigating hostnames that place a trusted brand in the leftmost label while hiding attacker control in the registered domain, see datapulse_help(topic="subdomain_cloaking").

Comparison with dpsearch

searchlabels is the recommended tool for domain similarity searches. The older dpsearch tool (deprecated) returns full domain names, while searchlabels returns labels with their TLD spread — showing at a glance how widely a variant has been registered.

Error Handling

ErrorCauseResolution
“search_term cannot be empty”Empty or whitespace-only inputProvide valid search term
“search_term too short”Below minimum length (DP_MIN_SEARCH_CHARS, default 3)Use a longer, more specific term
“search_term too long”Exceeds 255 character limitShorten the search term
“invalid search_term”Invalid UTF-8 encodingUse valid UTF-8 characters
“API request timed out”Result set too large for the configured timeoutUse filter to narrow match types, or try a more specific term. Very common short strings (e.g. “pay”, “app”) match millions of labels and will exceed the timeout

Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="searchlabels").