MCP documentation menu

datapulse_dns_regclusters

DataPulse IntelligenceScope: datapulse:dnsOutput: JSONRead-only

Bulk registration clusters: summary or drill-in by registrar

Description

Find clusters of domains registered at the same registrar on a given date.

Two modes:

  1. Summary (default): Returns one row per registrar with domain count and a few SAMPLE domain names, sorted by count descending. The samples are illustrative, NOT the full cluster — do not present them as the complete list; use Detail mode (registrar_id) to enumerate all domains. Use min_cluster_size and limit to control results.
  2. Detail (set registrar_id): Returns domains registered at that registrar on the given date, paginated (default 200 per page). Each row includes total_count. Use limit and offset to page through large result sets.

Registrar identifiers: every row carries registrar_id and registrar_id_scheme. Scheme “iana” means the number is an IANA-assigned registrar ID (gTLDs and ccTLDs that use them) and the row also carries registrar_name; pass it to datapulse_dns_registrar(iana_id=…) for status and portfolio size. Scheme “registry” means the number is the registry’s own registrar identifier (Norid .no, for example) that no IANA lookup can resolve — do not pivot it into datapulse_dns_registrar. “unresolved” means the IANA registry could not be consulted for this call, or the identifier is not a number. registrar_id is what to pass back as the registrar_id parameter in either case. An empty answer is [] with a hint.

Use Cases:

  • Detect bulk registration campaigns (set min_cluster_size=100+)
  • Identify domain parking operations
  • Spot coordinated malicious registration activity
  • Drill into a specific registrar’s domains by setting registrar_id

Tip: On busy days, registrars like GoDaddy register 20K+ domains. Use min_cluster_size=100 or higher to filter noise.

For detailed documentation: datapulse_help(topic="regclusters")

Parameters

ParameterTypeDescription
datestring
Date to search for registrar clusters (YYYY-MM-DD format), a UTC day: registrations from 00:00 to 24:00 UTC. Defaults to today (UTC) if not specified.
Pattern: ^\d{4}-\d{2}-\d{2}$
limitinteger
Maximum number of results to return. Summary mode: max registrar clusters (default 25, max 100). Detail mode: max domains per page (default 200, max 500).
Default: 25Min: 1Max: 500
min_cluster_sizeinteger
Minimum number of domains a registrar must have registered on that date to be included. Default: 8. Use higher values (50, 100, 500) to focus on large bulk campaigns. Ignored when registrar_id is set.
Default: 8Min: 2
offsetinteger
Pagination offset for detail mode. Skip this many domains (alphabetically). Default: 0. Use total_count in the response to know how many exist. Ignored in summary mode.
Default: 0Min: 0
registrar_idinteger
Registrar identifier to drill into, exactly as a summary row’s registrar_id reports it (IANA ID or registry-specific ID alike). When set, returns domains registered at this registrar on the given date (paginated).
Min: 1
Input schema (JSON)
{
  "additionalProperties": false,
  "properties": {
    "date": {
      "description": "Date to search for registrar clusters (YYYY-MM-DD format), a UTC day: registrations from 00:00 to 24:00 UTC. Defaults to today (UTC) if not specified.",
      "pattern": "^\\d{4}-\\d{2}-\\d{2}$",
      "type": "string"
    },
    "limit": {
      "default": 25,
      "description": "Maximum number of results to return. Summary mode: max registrar clusters (default 25, max 100). Detail mode: max domains per page (default 200, max 500).",
      "maximum": 500,
      "minimum": 1,
      "type": "integer"
    },
    "min_cluster_size": {
      "default": 8,
      "description": "Minimum number of domains a registrar must have registered on that date to be included. Default: 8. Use higher values (50, 100, 500) to focus on large bulk campaigns. Ignored when registrar_id is set.",
      "minimum": 2,
      "type": "integer"
    },
    "offset": {
      "default": 0,
      "description": "Pagination offset for detail mode. Skip this many domains (alphabetically). Default: 0. Use total_count in the response to know how many exist. Ignored in summary mode.",
      "minimum": 0,
      "type": "integer"
    },
    "registrar_id": {
      "description": "Registrar identifier to drill into, exactly as a summary row's registrar_id reports it (IANA ID or registry-specific ID alike). When set, returns domains registered at this registrar on the given date (paginated).",
      "minimum": 1,
      "type": "integer"
    }
  },
  "required": [],
  "type": "object"
}

Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026.