datapulse_dns_regclusters
datapulse:dnsOutput: JSONRead-onlyBulk registration clusters: summary or drill-in by registrar
Description
Find clusters of domains registered at the same registrar on a given date.
Two modes:
- Summary (default): Returns one row per registrar with domain count and a few SAMPLE domain names, sorted by count descending. The samples are illustrative, NOT the full cluster — do not present them as the complete list; use Detail mode (registrar_id) to enumerate all domains. Use min_cluster_size and limit to control results.
- Detail (set registrar_id): Returns domains registered at that registrar on the given date, paginated (default 200 per page). Each row includes total_count. Use limit and offset to page through large result sets.
Registrar identifiers: every row carries registrar_id and registrar_id_scheme. Scheme “iana” means the number is an IANA-assigned registrar ID (gTLDs and ccTLDs that use them) and the row also carries registrar_name; pass it to datapulse_dns_registrar(iana_id=…) for status and portfolio size. Scheme “registry” means the number is the registry’s own registrar identifier (Norid .no, for example) that no IANA lookup can resolve — do not pivot it into datapulse_dns_registrar. “unresolved” means the IANA registry could not be consulted for this call, or the identifier is not a number. registrar_id is what to pass back as the registrar_id parameter in either case. An empty answer is [] with a hint.
Use Cases:
- Detect bulk registration campaigns (set min_cluster_size=100+)
- Identify domain parking operations
- Spot coordinated malicious registration activity
- Drill into a specific registrar’s domains by setting registrar_id
Tip: On busy days, registrars like GoDaddy register 20K+ domains. Use min_cluster_size=100 or higher to filter noise.
For detailed documentation: datapulse_help(topic="regclusters")
Parameters
| Parameter | Type | Description |
|---|---|---|
date | string | Date to search for registrar clusters (YYYY-MM-DD format), a UTC day: registrations from 00:00 to 24:00 UTC. Defaults to today (UTC) if not specified. Pattern: ^\d{4}-\d{2}-\d{2}$ |
limit | integer | Maximum number of results to return. Summary mode: max registrar clusters (default 25, max 100). Detail mode: max domains per page (default 200, max 500). Default: 25Min: 1Max: 500 |
min_cluster_size | integer | Minimum number of domains a registrar must have registered on that date to be included. Default: 8. Use higher values (50, 100, 500) to focus on large bulk campaigns. Ignored when registrar_id is set. Default: 8Min: 2 |
offset | integer | Pagination offset for detail mode. Skip this many domains (alphabetically). Default: 0. Use total_count in the response to know how many exist. Ignored in summary mode. Default: 0Min: 0 |
registrar_id | integer | Registrar identifier to drill into, exactly as a summary row’s registrar_id reports it (IANA ID or registry-specific ID alike). When set, returns domains registered at this registrar on the given date (paginated). Min: 1 |
Input schema (JSON)
{
"additionalProperties": false,
"properties": {
"date": {
"description": "Date to search for registrar clusters (YYYY-MM-DD format), a UTC day: registrations from 00:00 to 24:00 UTC. Defaults to today (UTC) if not specified.",
"pattern": "^\\d{4}-\\d{2}-\\d{2}$",
"type": "string"
},
"limit": {
"default": 25,
"description": "Maximum number of results to return. Summary mode: max registrar clusters (default 25, max 100). Detail mode: max domains per page (default 200, max 500).",
"maximum": 500,
"minimum": 1,
"type": "integer"
},
"min_cluster_size": {
"default": 8,
"description": "Minimum number of domains a registrar must have registered on that date to be included. Default: 8. Use higher values (50, 100, 500) to focus on large bulk campaigns. Ignored when registrar_id is set.",
"minimum": 2,
"type": "integer"
},
"offset": {
"default": 0,
"description": "Pagination offset for detail mode. Skip this many domains (alphabetically). Default: 0. Use total_count in the response to know how many exist. Ignored in summary mode.",
"minimum": 0,
"type": "integer"
},
"registrar_id": {
"description": "Registrar identifier to drill into, exactly as a summary row's registrar_id reports it (IANA ID or registry-specific ID alike). When set, returns domains registered at this registrar on the given date (paginated).",
"minimum": 1,
"type": "integer"
}
},
"required": [],
"type": "object"
}Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026.