For security teams

Fast domain risk triage, with the evidence attached.

Inspect the DNS, subdomain, registration, and technology surface around a domain when trust, abuse, or brand exposure needs a fast read.

  • Inspect nameservers, DNS records, subdomains seen in certificate-transparency logs, registration timelines, and the detected technology stack with the date it was last crawled, from one domain profile.
  • Compare the domains around a brand and the TLD family behind a name to see where customer confusion or impersonation could appear.
  • Add look-alike and suspect domains to a watchlist and get alerted when their rank, traffic, DNS, or registration changes. Automatic newly registered and new-certificate feeds are rolling out.
  • Keep the exact endpoint, field path, displayed value, cache state, and source label in each card's API view.

Questions

Where do subdomains come from, and how fresh is DNS?

Subdomains are hostnames seen in certificate transparency logs, so a listed name may not resolve today. A cached DNS answer is refreshed once it is 6 hours old, subdomains at 2; each response reports its cache state, and freshness=live skips the cache.

Which security signals does Domain Atlas show?

Domain profiles show DNS records, nameservers, subdomains seen in certificate transparency, registration timelines, technology signals, and the source label behind each value.

Can teams automate recurring risk checks?

Yes. Customer API keys let teams call the same Domain Atlas endpoints used by the console for recurring domain checks and reports.

Is Domain Atlas a full investigation platform?

No. Domain Atlas is designed for fast domain risk triage and repeatable checks before deeper investigation is needed.