canonical: https://jentic.com/apis/domaintools.com/domaintools

# DomainTools Iris API

Jentic publishes the only available OpenAPI specification for the DomainTools Iris API, keeping it validated and agent-ready. The DomainTools Iris API delivers domain intelligence for threat investigation and brand protection. Its Iris Investigate and Iris Enrich operations return a domain's risk score, registration, and infrastructure data, while Iris Detect monitors track lookalike domains and surface newly discovered, watched, and ignored domains. Analysts can escalate suspicious domains and manage watchlists from the same API.

## For AI agents

Investigate and enrich domains with risk and infrastructure data, and monitor lookalike domains: create monitors, review newly discovered domains, escalate threats, and manage watchlists.

## Scope

Does not handle endpoint protection, email filtering, or SIEM alerting. Use for domain intelligence, lookalike-domain monitoring, and investigation only.

## Capabilities

- Investigate a domain and pull its full Iris risk and infrastructure profile
- Enrich a set of domains with DomainTools Iris data
- Create and configure monitors that track lookalike domains for a brand
- Retrieve newly discovered, watched, and ignored domains for active monitors
- Add or remove domains from Watchlist or Ignored lists
- Escalate suspicious domains internally and externally

## Use cases

### Agent Domain Threat Investigation

A security AI agent can send a suspicious domain to the DomainTools Iris API's investigate operation and receive its risk score, registration, and infrastructure data in one call. The agent can then enrich related domains to map an attacker's footprint.

Example prompt: Investigate a domain and return its risk score and associated infrastructure

### Lookalike Domain Monitoring

Brand-protection workflows can create monitors for lookalike domains and poll newly discovered and watched domains with the DomainTools Iris API. When a confusingly similar domain appears, the agent can escalate it or add it to a watchlist.

Example prompt: Create a monitor for a brand term, then list the newly discovered domains it has found

### Bulk Domain Enrichment

Analysts can enrich a batch of domains with DomainTools Iris data to add registration, hosting, and risk attributes to their records. The enrich operation accepts a set of domains and returns their attributes in one response.

Example prompt: Enrich a set of domains and record their risk scores and hosting attributes

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | `/v1/iris-detect/monitors/` | Retrieve monitors and monitor IDs |
| POST | `/v1/iris-detect/monitors/` | Create a monitor to track lookalike domains |
| GET | `/v1/iris-detect/domains/new/` | List newly discovered domains for active monitors |
| GET | `/v1/iris-detect/domains/watched/` | List recently changed or escalated domains |
| POST | `/v1/iris-detect/escalations/` | Escalate domains internally and externally |
| GET | `/v1/iris-investigate/` | Investigate domains |
| POST | `/v1/iris-enrich/` | Enrich domains with Iris data |
| GET | `/v1/account/` | Account information |

## Key resources

- **Iris Investigate** — Return a domain's risk score, registration, and infrastructure profile
- **Iris Enrich** — Add registration, hosting, and risk attributes to a set of domains
- **Iris Detect monitors** — Create, update, delete, and list monitors that track lookalike domains
- **Detected domains** — Retrieve newly discovered, watched, and ignored domains and manage lists
- **Account** — Retrieve account information and limits

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 54 / 100
- **Maturity:** Foundational
- **Dimensions:**
  - Foundational Compliance: 58 / 100
  - Developer Experience & Jentic Compatibility: 64 / 100
  - AI-Readiness & Agent Experience: 54 / 100
  - Agent Usability: 94 / 100
  - Security: 25 / 100
  - AI Discoverability: 60 / 100
- **View full report:** https://jentic.com/apis/domaintools.com/domaintools/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Wiring the DomainTools Iris API by hand means choosing among three authentication schemes, an X-Api-Key header, HTTP basic, or an HMAC signature, and building the signature yourself for HMAC. Through Jentic you install once, import the DomainTools Iris API from the API Directory, store the credentials once, and your agent calls it.
- **Permission scoping:** The DomainTools Iris API identifies domains and monitors by parameters in the query or body rather than the URL path, so rules bound which operations your agent may call. Limit it to the investigate and enrich read operations, and leave monitor creation, updates, and deletion out unless you add them.
- **Credential handling:** Your DomainTools credentials are stored once, encrypted, by your own Jentic One instance and injected at execution time. They never enter the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'investigate a suspicious domain' or 'monitor lookalike domains', and Jentic returns the matching DomainTools operation with its input schema so the agent calls the right endpoint without reading the reference docs.

## Related APIs

- **Censys** — Censys provides internet host and certificate intelligence, an alternative lens to the DomainTools Iris API's domain data.
- **Shodan** — Shodan indexes internet-connected devices and services, overlapping with the DomainTools Iris API's infrastructure data.
- **AbuseIPDB** — AbuseIPDB supplies IP reputation data that complements the DomainTools Iris API's domain risk scoring.

## FAQ

### Why is there no official OpenAPI spec for the DomainTools Iris API?

DomainTools does not publish an OpenAPI specification for its Iris API. Jentic generates and maintains this spec so that AI agents and developers can call the DomainTools Iris API via structured tooling. It is validated against the live API and kept up to date. To run it on your own infrastructure, install Jentic One from its GitHub repo.

### What authentication does the DomainTools Iris API use?

The DomainTools Iris API supports three schemes per its OpenAPI spec: an API key in the `X-Api-Key` header, HTTP basic authentication with your API username and key, and an HMAC `signature` passed as a query parameter. DomainTools recommends the header or HMAC method. Through Jentic the credentials are stored encrypted by your own Jentic One instance and injected at call time, so they never enter the agent's prompt or logs.

### Can I investigate a domain with the DomainTools Iris API?

Yes. The Iris Investigate operation returns a domain's risk and infrastructure profile, and the Iris Enrich operation adds attributes to a set of domains. For monitoring, you can create monitors that track lookalike domains and review the newly discovered ones.

### What are the rate limits for the DomainTools Iris API?

The OpenAPI spec does not specify rate limits for the DomainTools Iris API. Check the provider's documentation at https://docs.domaintools.com for the limits that apply to your plan.

### Can I limit what my agent is allowed to do with the DomainTools Iris API?

Yes. Domains and monitors are identified by parameters in the query or body rather than the URL path, so a rule bounds which operations your agent may call. Write a rule that allows only the investigate and enrich read operations, and leave monitor creation, updates, and deletion out unless the agent needs them, and every call it makes is logged.

### How do I investigate a domain with the DomainTools Iris API through Jentic?

Search Jentic for 'investigate a suspicious domain' and it returns the Iris Investigate operation with its input schema. Import the DomainTools Iris API from the Jentic API Directory, store your credentials once, and your agent can investigate and enrich domains without hand-wiring the authentication on each request.

### Is there a DomainTools Iris API MCP server?

You don't need an MCP server to give your agent the DomainTools Iris API. Jentic connects it directly from the API Directory: import it, store your credentials once, and your agent calls the investigate, enrich, and monitor operations. Nothing extra loads into the agent's context until an operation is actually used.
