datapulse_dns_neighborhood
DataPulse IntelligenceScope:
datapulse:dnsOutput: JSONRead-onlyDNS cluster membership, metadata, and exemplar domains
Description
Look up DNS infrastructure cluster membership for a domain or cluster ID.
Two modes:
- Domain lookup (set
domain): Returns the domain’s cluster, metadata, and exemplar. - Cluster ID lookup (set
cluster_id): Returns cluster metadata and exemplar.
If both domain and cluster_id are provided, domain takes precedence.
At least one of domain or cluster_id must be provided.
Cluster Types:
- Normal clusters (351): Domains grouped by similar DNS infrastructure (HDBSCAN).
- Anomaly clusters (25): Domains with unusual infrastructure patterns. Use
is_anomaly=truewithcluster_id.
Exemplar: The domain closest to the cluster centroid (lowest anomaly_score).
Key fields:
cluster_name: Label from dominant nameserver patterns across the cluster (not a description of any individual domain’s DNS).nearest_normal_dist: Always populated. Equalsanomaly_scorefor normal cluster members; for anomaly members, distance to closest normal cluster.
Use Cases:
- Identify which infrastructure cluster a domain belongs to
- Find the representative (exemplar) domain for a cluster
- Get cluster size and density metrics
- Combine with dptechsim for “who’s in my neighborhood” analysis
For detailed documentation: datapulse_help(topic="neighborhood")
Parameters
| Parameter | Type | Description |
|---|---|---|
cluster_id | integer | Direct cluster ID lookup. Returns cluster metadata and exemplar domain. |
domain | string | Domain name to look up (e.g., “google.com”). Returns cluster membership, metadata, and exemplar domain. Its spelling is canonicalized and no labels are removed (www. kept); a single label (localhost) is rejected. When canonicalizing changed more than letter case, a hint line reads submitted_domain: Min length: 1Max length: 253 |
is_anomaly | boolean | Set true when looking up an anomaly cluster by ID (default false). Default: false |
Input schema (JSON)
{
"additionalProperties": false,
"properties": {
"cluster_id": {
"description": "Direct cluster ID lookup. Returns cluster metadata and exemplar domain.",
"type": "integer"
},
"domain": {
"description": "Domain name to look up (e.g., \"google.com\"). Returns cluster membership, metadata, and exemplar domain. Its spelling is canonicalized and no labels are removed (www. kept); a single label (localhost) is rejected. When canonicalizing changed more than letter case, a hint line reads submitted_domain: \u003cyour input\u003e (sent as \u003cname\u003e).",
"maxLength": 253,
"minLength": 1,
"type": "string"
},
"is_anomaly": {
"default": false,
"description": "Set true when looking up an anomaly cluster by ID (default false).",
"type": "boolean"
}
},
"type": "object"
}Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026.