Docs / API reference
Domain Lookup
Checks a domain name for age, mail-authentication records and known danger.
Overview#
lookup/domain takes a domain such as example.com and returns its name, whether it is considered dangerous (is_dangerous), when it was created (created_at), whether it is recent (is_new), and the presence of the DNS records that make email trustworthy: is_mx, is_spf, is_dkim, is_dmarc and is_bimi.
The same domain block is embedded in the Email Scoring response; use this method when you need to evaluate a website or domain on its own.
When to use it#
- Vet the website a merchant or partner gives you during onboarding.
- Screen the domain of a link submitted by users.
- Check a company domain before trusting a "business" signup.
Reading the result#
is_new: truemeans the domain was registered recently. Fraud campaigns rely on throwaway domains, so recent registration deserves extra scrutiny.is_dangerous: trueis the strongest signal; refuse or review manually.is_mxshows whether the domain can receive mail at all. Without it, an address on that domain is unlikely to be real.is_spf,is_dkimandis_dmarcshow whether the owner has set up sender authentication. A legitimate business domain usually has them, while a freshly created or abusive one often does not.is_bimiindicates a brand-verified sender and is a mild positive.- None of these flags is proof by itself; look at them together with
created_at.
Notes#
- Counts as one request. Test mode returns fake data, is free and does not query DNS.
- Included in every plan, including Standard.
- It raises no events. Domain data is evaluated by custom rules only through the email group, via the
domain.namefield. - A missing or malformed domain returns error 128 (
invalid_domain) with HTTP 200.
Request#
https://gurdx.cretip.com/api/lookup/domain
- Authenticate with the key parameter or an Authorization: Bearer header.
- Counts as 1 request.
- Available on: Free trial Standard Premium Pay-as-you-go
Parameters#
| Name | Type | Description |
|---|---|---|
domain
required
query |
string |
The fully qualified domain name (FQDN) to look up. Learn more Sample value: example.com
|
Every method also accepts format, lang, mode, userID, callback. See Options.
Code samples#
curl -G "https://gurdx.cretip.com/api/lookup/domain" \
--data-urlencode "key=YOUR_API_KEY" \
--data-urlencode "domain=example.com"
<?php
$response = file_get_contents('https://gurdx.cretip.com/api/lookup/domain?'.http_build_query(['key' => 'YOUR_API_KEY', 'domain' => 'example.com']));
$result = json_decode($response, true);
if ($result['status'] === 'success') {
print_r($result['data']);
} else {
echo $result['code'].': '.$result['description'];
}
const params = new URLSearchParams({"key":"YOUR_API_KEY","domain":"example.com"});
const res = await fetch(`https://gurdx.cretip.com/api/lookup/domain?${params}`);
const result = await res.json();
if (result.status === 'success') {
console.log(result.data);
} else {
console.error(result.code, result.description);
}
import requests
res = requests.get("https://gurdx.cretip.com/api/lookup/domain", params={"key": "YOUR_API_KEY", "domain": "example.com"})
result = res.json()
if result["status"] == "success":
print(result["data"])
else:
print(result["code"], result["description"])
Response#
Success#
{
"data": {
"name": "dangerous-domain.com",
"is_dangerous": true,
"is_disposable": false,
"is_forwarding": false,
"is_spf": false,
"is_dmarc": false,
"is_dkim": false,
"is_mx": false,
"is_bimi": false,
"created_at": "2025-02-05",
"is_new": true
},
"status": "success",
"executionTime": 0
}Error#
Errors are delivered with HTTP 200 — always check the status field.
{
"status": "error",
"code": 101,
"type": "invalid_key",
"description": "The API Key is missing or invalid."
}Response fields#
| Name | Type | Description |
|---|---|---|
data.name |
string |
The full domain name associated with the email address (for example, gmail.com).
|
data.is_dangerous |
boolean|null |
Indicates whether the domain is flagged as dangerous or suspicious, which may suggest a higher risk of fraud or abuse. If this property is set to true, the domain is considered high-risk or potentially malicious. As a result, the isValid property will also be false, indicating that the email address should not be trusted for critical communications or user registrations. It is strongly recommended to block or flag such email addresses in your application workflow.
|
data.is_spf |
boolean|null |
Indicates whether the domain has a valid SPF (Sender Policy Framework) record, which helps prevent email spoofing. |
data.is_dmarc |
boolean|null |
Indicates whether the domain has a valid DMARC (Domain-based Message Authentication, Reporting, and Conformance) record, which helps protect against email phishing and spoofing. |
data.is_dkim |
boolean|null |
Indicates whether the domain has a valid DKIM (DomainKeys Identified Mail) record, which verifies the authenticity of the sender's domain. |
data.is_mx |
boolean|null |
Indicates whether the domain has valid MX (Mail Exchange) records, confirming that it is capable of receiving emails. |
data.is_bimi |
boolean|null |
Indicates whether the domain has a valid BIMI (Brand Indicators for Message Identification) record, which allows brand logos to be displayed in supported email clients. |
data.created_at |
string|null |
The date when the domain was first registered or created, if available. |
data.is_new |
boolean|null |
Indicates whether the domain is new or recently registered (registered within 1 year), which may affect its reputation and trustworthiness. |
data.status |
string |
The response status. Expected values: success, or error.
|
data.executionTime |
integer |
Time spent in milliseconds to process the data. |
data |
object |
— |
Found a mistake? Tell us on the contact page. Contact