datapulse_dns_dptechsim
datapulse:dnsOutput: CSVRead-onlyInfrastructure similarity (NS, MX, ASN embeddings)
Description
Find domains with similar DNS infrastructure using vector similarity search.
Similarity Signals (1000D embedding from):
- Nameservers (operational + reported) and their ASNs
- MX records and mail server ASNs
- A/AAAA record ASNs (web hosting)
- TLD, registrar IANA ID, registration date
Use Cases:
- IOC expansion: pivot from suspicious domain to related infrastructure
- Operator discovery: find domains by same entity
- Brand protection: detect infrastructure mimicry
- Infrastructure clustering: map hosting relationships
Response: CSV with up to 200 domains, every value as the similarity service reports it (hostnames case-folded). No match is the header row alone. Columns: name, registrar_iana_id, registration_date, fpons, fpons_asn, fprns, fprns_asn, fpmx, fpmx_asn, fpaw_asn, cosine_similarity
Score Interpretation:
- 0.98+: Near-identical infrastructure (shared hosting stack; not proof of a common operator)
- 0.95+: Same hosting setup (high confidence)
- 0.90+: Shared major components (medium-high)
- 0.85+: Similar patterns (medium, may include CDN noise)
Caveat: Domains on major CDNs (Cloudflare, AWS) will have many matches; look for rare ASN overlaps.
For detailed documentation: datapulse_help(topic="techsim")
Parameters
| Parameter | Type | Description |
|---|---|---|
domainrequired | string | Seed domain to find similar domains for. Accepts ASCII or IDN (UTF-8) format. Its spelling is canonicalized and no labels are removed (www. kept); a single label (localhost) is rejected. When canonicalizing changed more than letter case, a hint line reads submitted_domain: Min length: 1Max length: 253 |
similarity | number | Cosine similarity threshold (0.75 to 1.00). Higher = stricter matching. Default: 0.95. Use 0.98+ for near-identical infra, 0.90+ for strong similarity, 0.85+ for broader discovery. Default: 0.95Min: 0.75Max: 1 |
Input schema (JSON)
{
"additionalProperties": false,
"properties": {
"domain": {
"description": "Seed domain to find similar domains for. Accepts ASCII or IDN (UTF-8) format. Its spelling is canonicalized and no labels are removed (www. kept); a single label (localhost) is rejected. When canonicalizing changed more than letter case, a hint line reads submitted_domain: \u003cyour input\u003e (sent as \u003cname\u003e).",
"maxLength": 253,
"minLength": 1,
"type": "string"
},
"similarity": {
"default": 0.95,
"description": "Cosine similarity threshold (0.75 to 1.00). Higher = stricter matching. Default: 0.95. Use 0.98+ for near-identical infra, 0.90+ for strong similarity, 0.85+ for broader discovery.",
"maximum": 1,
"minimum": 0.75,
"type": "number"
}
},
"required": [
"domain"
],
"type": "object"
}Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026.