MCP documentation menu

datapulse_dns_dptechsim

DataPulse IntelligenceScope: datapulse:dnsOutput: CSVRead-only

Infrastructure similarity (NS, MX, ASN embeddings)

Description

Find domains with similar DNS infrastructure using vector similarity search.

Similarity Signals (1000D embedding from):

  • Nameservers (operational + reported) and their ASNs
  • MX records and mail server ASNs
  • A/AAAA record ASNs (web hosting)
  • TLD, registrar IANA ID, registration date

Use Cases:

  • IOC expansion: pivot from suspicious domain to related infrastructure
  • Operator discovery: find domains by same entity
  • Brand protection: detect infrastructure mimicry
  • Infrastructure clustering: map hosting relationships

Response: CSV with up to 200 domains, every value as the similarity service reports it (hostnames case-folded). No match is the header row alone. Columns: name, registrar_iana_id, registration_date, fpons, fpons_asn, fprns, fprns_asn, fpmx, fpmx_asn, fpaw_asn, cosine_similarity

Score Interpretation:

  • 0.98+: Near-identical infrastructure (shared hosting stack; not proof of a common operator)
  • 0.95+: Same hosting setup (high confidence)
  • 0.90+: Shared major components (medium-high)
  • 0.85+: Similar patterns (medium, may include CDN noise)

Caveat: Domains on major CDNs (Cloudflare, AWS) will have many matches; look for rare ASN overlaps.

For detailed documentation: datapulse_help(topic="techsim")

Parameters

ParameterTypeDescription
domain
required
string
Seed domain to find similar domains for. Accepts ASCII or IDN (UTF-8) format. Its spelling is canonicalized and no labels are removed (www. kept); a single label (localhost) is rejected. When canonicalizing changed more than letter case, a hint line reads submitted_domain: (sent as ).
Min length: 1Max length: 253
similaritynumber
Cosine similarity threshold (0.75 to 1.00). Higher = stricter matching. Default: 0.95. Use 0.98+ for near-identical infra, 0.90+ for strong similarity, 0.85+ for broader discovery.
Default: 0.95Min: 0.75Max: 1
Input schema (JSON)
{
  "additionalProperties": false,
  "properties": {
    "domain": {
      "description": "Seed domain to find similar domains for. Accepts ASCII or IDN (UTF-8) format. Its spelling is canonicalized and no labels are removed (www. kept); a single label (localhost) is rejected. When canonicalizing changed more than letter case, a hint line reads submitted_domain: \u003cyour input\u003e (sent as \u003cname\u003e).",
      "maxLength": 253,
      "minLength": 1,
      "type": "string"
    },
    "similarity": {
      "default": 0.95,
      "description": "Cosine similarity threshold (0.75 to 1.00). Higher = stricter matching. Default: 0.95. Use 0.98+ for near-identical infra, 0.90+ for strong similarity, 0.85+ for broader discovery.",
      "maximum": 1,
      "minimum": 0.75,
      "type": "number"
    }
  },
  "required": [
    "domain"
  ],
  "type": "object"
}

Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026.