Domain Tech Similarity (datapulse_dns_dptechsim)
Find domains with similar DNS infrastructure using vector similarity search.
Overview
The datapulse_dns_dptechsim tool discovers domains that share similar technical infrastructure by comparing vector embeddings derived from DNS fingerprints. This enables:
- Infrastructure clustering: Find domains hosted on the same or similar infrastructure
- Operator discovery: Identify domains likely operated by the same entity
- IOC expansion: Pivot from suspicious domains to related infrastructure
- Brand protection: Find domains mimicking legitimate infrastructure patterns
Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
domain | string | Yes | — | Seed domain to find similar domains for (IDN/UTF-8 supported) |
similarity | number | No | 0.95 | Cosine similarity threshold (0.75 to 1.00) |
Parameter Details
domain
- Accepts ASCII domains or internationalized domain names (IDN/UTF-8)
- Unicode domains are automatically converted to Punycode (A-label) format
- The spelling is canonicalized (case, whitespace, trailing dots) and no labels are removed:
www.example.comis looked up aswww.example.com - A single label (
localhost,com) is rejected before any lookup - When canonicalizing changed more than letter case, the output carries a hint line
submitted_domain: <your input> (sent as <name>). Seedatapulse_help(topic="normalization") - Maximum length: 253 characters
- Examples:
example.com,münchen.de,xn--mnchen-3ya.de
similarity
- Higher values = stricter matching (fewer, more similar results)
- Lower values = broader matching (more results, less similar)
- Recommended ranges:
0.98-1.00: Near-identical infrastructure (the same hosting stack; evidence for, not proof of, a common operator)0.92-0.97: Very similar (shared major infrastructure components)0.85-0.91: Similar (shared hosting/registrar patterns)0.75-0.84: Loosely similar (common provider overlap)
Example Usage
Basic search (high similarity)
{
"domain": "example.com"
}
Broader search (lower threshold)
{
"domain": "suspicious-domain.com",
"similarity": 0.85
}
IDN domain search
{
"domain": "münchen.de",
"similarity": 0.90
}
Response Format
Returns CSV with a header row and one row per matching domain. Cosine similarity is rounded to 4 decimal places. Multi-value fields use * as a delimiter (e.g., 21342*44273).
Success Response
name,registrar_iana_id,registration_date,fpons,fpons_asn,fprns,fprns_asn,fpmx,fpmx_asn,fpaw_asn,cosine_similarity
example.com,1234,2023-01-15T00:00:00,a.ns.example*b.ns.ex,13335*15169,a.ns.example*b.ns.ex,13335*15169,mx1.example.com*mx2.,13335,13335*15169,1.0000
related-domain.com,1234,2023-03-20T00:00:00,a.ns.example*b.ns.ex,13335*15169,a.ns.example*b.ns.ex,13335*15169,mx1.example.com*mx2.,13335,13335,0.9730
CSV Columns
| Column | Description |
|---|---|
name | Domain name (A-label format for IDNs) |
registrar_iana_id | IANA ID of the registrar |
registration_date | Domain registration date |
fpons | Operational nameserver fingerprint (*-delimited) |
fpons_asn | ASNs hosting operational nameservers (*-delimited) |
fprns | Reported nameserver fingerprint (*-delimited) |
fprns_asn | ASNs hosting reported nameservers (*-delimited) |
fpmx | MX record fingerprint (*-delimited) |
fpmx_asn | ASNs hosting mail servers (*-delimited) |
fpaw_asn | ASNs hosting A/AAAA records (*-delimited) |
cosine_similarity | Similarity score (0.0000 to 1.0000) |
Error Responses
{"error": "missing required parameter 'domain'"}
{"error": "similarity must be between 0.75 and 1.00"}
{"error": "simserver: <the daemon's own error message, verbatim>"}
No similar domains is not an error: the CSV header row comes back alone with a hint as a second content item. A daemon that cannot be reached fails with the socket error itself.
Similarity Signals (Feature Space)
The similarity score is computed from a 1000-dimensional unified embedding composed of these DNS infrastructure signals:
Signal Categories
| Signal | Dimensions | Description |
|---|---|---|
| Operational NS | 100D | Active nameservers responding to queries |
| Operational NS ASN | 100D | ASNs hosting the nameservers |
| Reported NS | 100D | NS records as configured in DNS |
| Reported NS ASN | 100D | ASNs of reported nameservers |
| MX Records | 100D | Mail exchanger hostnames |
| MX ASN | 100D | ASNs hosting mail infrastructure |
| A/AAAA ASN | 100D | ASNs hosting web servers |
| TLD | 100D | Top-level domain categorization |
| Registrar | 100D | IANA registrar ID embedding |
| Registration Date | 100D | Temporal embedding (registration age) |
How Similarity Works
- Each signal is tokenized and embedded into a 100D vector
- Vectors are concatenated into a 1000D unified embedding
- PCA reduces dimensionality for efficient similarity search
- Cosine similarity compares embeddings using pgvector
Signal Weighting Implications
Strong indicators (rare overlaps = high signal):
- Matching custom nameservers (not Cloudflare/AWS/etc.)
- Same boutique hosting ASN
- Matching MX configuration
- Same registrar + similar registration date
Weak indicators (common = low signal):
- Cloudflare (ASN 13335) - millions of domains
- Google Cloud (ASN 15169) - very common
- AWS (various ASNs) - extremely common
- Major registrars (GoDaddy, Namecheap, etc.)
Interpretation Guide
Score Interpretation
| Score Range | Interpretation | Confidence |
|---|---|---|
0.99-1.00 | Nearly identical infrastructure | Very High |
0.95-0.98 | Near-identical hosting setup (common operator possible, not established) | High |
0.90-0.94 | Shared major components | Medium-High |
0.85-0.89 | Similar infrastructure patterns | Medium |
0.80-0.84 | Some infrastructure overlap | Low-Medium |
0.75-0.79 | Loose similarity | Low |
What High Similarity Means
A score of 0.95+ typically indicates:
- Same nameserver configuration
- Same hosting provider/ASN
- Same mail infrastructure
- Often the same registrar
- Similar registration timeframe
What High Similarity Does NOT Mean
- Domains are definitively owned by same entity
- Domains are related by content
- Domains share the same website
- Domains have similar names (use
searchlabelsfor that)
Use Cases
A) Security Investigation - IOC Expansion
Start with a known malicious domain, find related infrastructure:
{"domain": "phishing-site.example", "similarity": 0.90}
Workflow:
dptechsim→ find infrastructure siblingsdphistoryon top hits → check historical changesdatapulse_live_rdap→ verify registration patternsdatapulse_live_dns→ current DNS verification
B) Brand Protection
Find domains mimicking legitimate infrastructure:
{"domain": "your-brand.com", "similarity": 0.85}
Look for:
- Similar infrastructure but different registrar
- Recent registration dates
- Matching hosting but different content
C) Operator Discovery
Find all domains by a suspected operator:
{"domain": "known-operator-domain.com", "similarity": 0.95}
Indicators that point toward a common operator (none of them proves it):
- Identical nameserver configuration
- Same registrar IANA ID
- Clustered registration dates
D) Infrastructure Mapping
Map hosting relationships for a domain portfolio:
{"domain": "company-domain.com", "similarity": 0.92}
Common Pitfalls
1. Major CDN/Hosting Noise
Domains on Cloudflare, AWS, or Google Cloud will show many false positives.
Mitigation:
- Use higher similarity thresholds (0.95+)
- Look for matching registrar + registration date patterns
- Filter results by ASN fingerprints in response
2. Shared Hosting Platforms
Many unrelated domains share hosting infrastructure (Shopify, WordPress.com, etc.).
Mitigation:
- Cross-reference with
searchlabelsfor name patterns - Check registration dates for clustering
- Use
dphistoryto see infrastructure changes over time
3. Score vs. Significance
A 0.85 score between two Cloudflare domains is less meaningful than 0.85 between two domains on a boutique host.
Mitigation:
- Examine the fingerprint fields in the response
- Look for rare ASNs or custom nameservers
- Weight rare overlaps higher in your analysis
Limits and Constraints
| Constraint | Value |
|---|---|
| Maximum results | 200 domains |
| Minimum similarity | 0.75 |
| Maximum similarity | 1.00 |
| Query timeout | 55 seconds (database) |
| Request timeout | 60 seconds (tool) |
Performance Notes
- First query after cold start: 30-60 seconds (index warming)
- Subsequent queries: typically < 5 seconds
- Major domains (banks, tech): may take 40-50 seconds due to many matches
Relationship to Other Tools
Complementary Tools
| Tool | Use With dptechsim For |
|---|---|
searchlabels | Name similarity → then infra similarity |
dphistory | Historical context on dptechsim results |
datapulse_live_rdap | Registration details for top matches |
datapulse_live_dns | Current DNS for verification |
datapulse_scrape_submit | Content analysis of similar domains |
Suggested Workflows
Typosquatting Investigation:
searchlabels("brand") → dptechsim(top_hit) → dphistory(matches) → live_rdap(suspicious)
Infrastructure Pivot:
dptechsim(seed, 0.90) → filter by rare ASN → dphistory(filtered) → live_rdap(filtered)
Operator Attribution:
dptechsim(known_domain, 0.95) → group by registrar_iana_id → dphistory(clusters)
Availability
This tool requires the simserver daemon to be running. If unavailable:
- Tool will not appear in
tools/listresponse - Health check will report
unhealthystatus - Calls fail with the socket connection error, verbatim
Check availability via datapulse_health().
Data Freshness
- DNS fingerprints are updated periodically (typically daily)
- Vector embeddings are regenerated on major updates
- Historical data available via
dphistoryfor change tracking
Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="techsim").