Single-target queries that return in seconds.

Analyst and IR workflows hit lookup queries constantly: what's the current DNS for this domain, who's the registrar, what's the SSL certificate's full chain, what ports are open right now. Instant Lookups is the fast-query layer for these single-target questions, with full historical state available for the cases where current isn't enough.

WHAT THIS DOES

Real-time and historical lookups against any target.

Real-time lookup categories: DNS records (full record types), Whois (registration metadata), IP-Whois (network ownership), SSL certificate (full chain, issuer, validity, hostnames), port scan (current open-ports state). Each query returns in seconds against the target's live state, not a cached snapshot.

Historical lookups expose the time-series state preserved in Deepinfo's dataset: DNS history (every record change observed), Whois history (every registration update). Useful for incident investigation ("what did this domain's DNS look like three months ago"), due diligence ("what's the registration history of this acquisition target's domains"), and forensic timelines.

HOW IT WORKS

Three lookup categories, all with structured output.

Real-time queries against the target's live state. Historical state for forensic and due-diligence work. API or UI access for the consumption pattern that fits the workflow.

Real-time queries.

DNS, Whois, IP-Whois, SSL certificate, port scan. Each runs against the target's current live state. Sub-second to few-second response times depending on lookup type.

Historical state.

DNS history (every record change preserved), Whois history (every registration update preserved). Time-series queries against the historical record. Foundational for incident investigation and due diligence.

API or UI access.

Same lookups available through API for programmatic consumption (SOAR integration, automation tooling, custom workflows) and through the platform UI for analyst-driven investigation. Same data, different consumption patterns.

WHAT IT SURFACES

Lookup types currently available.

DNS

Live DNS record query (A, AAAA, MX, NS, SOA, TXT, full type list).

Whois

Domain registration metadata: registrar, dates, registrant if public.

IP-Whois

Network-level ownership: ASN, country, organization, network range.

SSL certificate

Current certificate state: issuer, validity, cipher suites, full chain, hostnames.

Port scan

Current TCP/UDP port scan results against the target.

DNS history

Time-series view of DNS record changes across the target's history.

Whois history

Time-series view of registration changes across the target's history.

PART OF DSI

Instant Lookups handle the fast-query workflow.

Domain Intelligence and Vulnerability Intelligence handle structural research questions. Domain Search and Vulnerability Search handle filter-based queries against the corpus. Instant Lookups handle single-target queries with low latency, the IR-and-analyst workflow that hits lookup queries dozens of times per investigation. The five sub-features cover the full search, research, and investigate surface for DSI.

← Back to DSI

“Single-target queries during incident response need to be sub-second; analysts can't afford waiting on a multi-step API call. Instant Lookups returns DNS, WHOIS, certificate, and port data in one shot.”

— SOC Lead, National Bank
RUN A LOOKUP

Try a real-time lookup against any target you bring.

Book a demo. We'll run live lookups against domains, IPs, and certificates of your choice.

Request a demo