Skip to content
Gurdx

Docs / API reference

Domain Lookup

Checks a domain name for age, mail-authentication records and known danger.

Overview#

lookup/domain takes a domain such as example.com and returns its name, whether it is considered dangerous (is_dangerous), when it was created (created_at), whether it is recent (is_new), and the presence of the DNS records that make email trustworthy: is_mx, is_spf, is_dkim, is_dmarc and is_bimi.

The same domain block is embedded in the Email Scoring response; use this method when you need to evaluate a website or domain on its own.

When to use it#

  • Vet the website a merchant or partner gives you during onboarding.
  • Screen the domain of a link submitted by users.
  • Check a company domain before trusting a "business" signup.

Reading the result#

  • is_new: true means the domain was registered recently. Fraud campaigns rely on throwaway domains, so recent registration deserves extra scrutiny.
  • is_dangerous: true is the strongest signal; refuse or review manually.
  • is_mx shows whether the domain can receive mail at all. Without it, an address on that domain is unlikely to be real.
  • is_spf, is_dkim and is_dmarc show whether the owner has set up sender authentication. A legitimate business domain usually has them, while a freshly created or abusive one often does not. is_bimi indicates a brand-verified sender and is a mild positive.
  • None of these flags is proof by itself; look at them together with created_at.

Notes#

  • Counts as one request. Test mode returns fake data, is free and does not query DNS.
  • Included in every plan, including Standard.
  • It raises no events. Domain data is evaluated by custom rules only through the email group, via the domain.name field.
  • A missing or malformed domain returns error 128 (invalid_domain) with HTTP 200.

Request#

GET https://gurdx.cretip.com/api/lookup/domain
  • Authenticate with the key parameter or an Authorization: Bearer header.
  • Counts as 1 request.
  • Available on: Free trial Standard Premium Pay-as-you-go

Parameters#

NameTypeDescription
domain
required query
string The fully qualified domain name (FQDN) to look up. Learn more Sample value: example.com

Every method also accepts format, lang, mode, userID, callback. See Options.

Code samples#

curl -G "https://gurdx.cretip.com/api/lookup/domain" \
  --data-urlencode "key=YOUR_API_KEY" \
  --data-urlencode "domain=example.com"

Response#

Success#

{
    "data": {
        "name": "dangerous-domain.com",
        "is_dangerous": true,
        "is_disposable": false,
        "is_forwarding": false,
        "is_spf": false,
        "is_dmarc": false,
        "is_dkim": false,
        "is_mx": false,
        "is_bimi": false,
        "created_at": "2025-02-05",
        "is_new": true
    },
    "status": "success",
    "executionTime": 0
}

Error#

Errors are delivered with HTTP 200 — always check the status field.

{
    "status": "error",
    "code": 101,
    "type": "invalid_key",
    "description": "The API Key is missing or invalid."
}

Response fields#

NameTypeDescription
data.name string The full domain name associated with the email address (for example, gmail.com).
data.is_dangerous boolean|null Indicates whether the domain is flagged as dangerous or suspicious, which may suggest a higher risk of fraud or abuse. If this property is set to true, the domain is considered high-risk or potentially malicious. As a result, the isValid property will also be false, indicating that the email address should not be trusted for critical communications or user registrations. It is strongly recommended to block or flag such email addresses in your application workflow.
data.is_spf boolean|null Indicates whether the domain has a valid SPF (Sender Policy Framework) record, which helps prevent email spoofing.
data.is_dmarc boolean|null Indicates whether the domain has a valid DMARC (Domain-based Message Authentication, Reporting, and Conformance) record, which helps protect against email phishing and spoofing.
data.is_dkim boolean|null Indicates whether the domain has a valid DKIM (DomainKeys Identified Mail) record, which verifies the authenticity of the sender's domain.
data.is_mx boolean|null Indicates whether the domain has valid MX (Mail Exchange) records, confirming that it is capable of receiving emails.
data.is_bimi boolean|null Indicates whether the domain has a valid BIMI (Brand Indicators for Message Identification) record, which allows brand logos to be displayed in supported email clients.
data.created_at string|null The date when the domain was first registered or created, if available.
data.is_new boolean|null Indicates whether the domain is new or recently registered (registered within 1 year), which may affect its reputation and trustworthiness.
data.status string The response status. Expected values: success, or error.
data.executionTime integer Time spent in milliseconds to process the data.
data object —

Found a mistake? Tell us on the contact page. Contact