DOMAIN RECON
Full passive recon on any domain: RDAP registration data (registrar, dates, status), live DNS records, and certificate-transparency subdomain discovery. Free, no keys.
API: GET /api/domain?d=example.com → JSON: rdap, events, entities, dns, subdomains.
HOW IT WORKS
- Type the bare domain — no scheme, no path.
- RDAP answers who runs it, when it was registered and when it expires.
- DNS shows A/AAAA/MX/NS/TXT/CNAME — where it lives and what mail it accepts.
- Certificate logs expose hostnames even when DNS tries to hide them — great for finding staging/hidden subdomains.
- All sources are public registries — passive, no packets touch the target.
JARGON — hover any chip:
RDAP CT log TXT
FOR AGENTS ?
GET /api/domain?d=example.comcurl "https://dark0rbits.thetempleofdoom.com/api/domain?d=example.com"RDAP registration, DNS records, CT-log subdomains. Passive OSINT, free. · spec: /openapi.json · catalog: /llms.txt