WhoisXML API Blog

New Account Controls: API IP Allowlist and Per-Member Usage Monitoring

TL;DR

  • You can now restrict API requests to a list of trusted IP addresses, so a leaked or shared key alone is no longer enough for unauthorized users to use your API key.
  • Enterprise account administrators using Parent-Child API keys can see API usage broken down by individual team member or combined for the whole account.
  • Both are available now in your account settings. The IP allowlist is off by default, and your account setup stays the same.
WhoisXML API Intelligence Is Now Available on Malfors

WhoisXML API Intelligence Is Now Available on Malfors

WhoisXML API is proud to announce its integration with Malfors, an investigation platform built for threat intelligence, OSINT, and security research teams, adding WhoisXML API as an enrichment source for entities across Malfors’ platform. The integration is live and widely used, and is one of the most popular among Malfors users.

What Is a Newly Observed Domain and Why Does It Matter for Cybersecurity?

A newly observed domain (NOD) is one that has just appeared in Domain Name System (DNS) traffic for the first time, indicating that it has started being queried, resolved, or otherwise seen in DNS activity. Tracking newly observed domains has become an important part of modern threat intelligence because threat actors often register domains in batches and well in advance — sometimes months ahead — then activate them only when a campaign is ready to launch or when the previous domain they used was taken down. 

We discuss NODs in more detail in this post, including how they differ from newly registered domains, the risks they pose, and how to track them.

11 Ways to Verify Website Authenticity in 2026

Scammers have always been good at making fake websites look real, even when there were some telltale signs — wrong grammar, typos, pixelated logos. 

But in 2026, legitimate and fake websites can look very similar. Generative AI can produce copy with perfect grammar and spelling as well as high-quality web pages and UI layouts.

So, how do you verify website authenticity today? The short answer is: no single method is enough, but there’s a combination of methods and tools you can try. This guide breaks down 11 methods into three categories — high-confidence tool-based checks; manual verification that still works; and old-school indicators that have mostly lost their value. 

June 2026: Domain Activity Highlights

WhoisXML API analyzed 9.2+ million domains registered between 1 and 30 June 2026 that appeared in Newly Registered Domains to identify the most popular registrars, TLD extensions, and other global domain registration trends. This number declined by 12.2% from 10.5+ million NRDs last month.

We also determined the top TLD extensions used by 2.0+ million domains likely registered with malicious intent from the First Watch Malicious Domains Data Feed in June 2026. This number decreased by 31.2% from the previous month.

Next, we studied the top TLD extensions of 1.07+ million confirmed malicious domains from the Threat Intelligence Data Feeds this month, which dropped by 1.1% from 1.08+ million in May.

Finally, we summed up our findings and provided links to the threat reports produced using DNS and domain intelligence sources during the period.

The dig Command Explained

In this post, we explain what the dig command does as well as how to install and use it. We also talk about how to work around its limitations. 

21 Best Free OSINT Tools for Cyber Investigations

There are plenty of free or almost-free OSINT tools you can find online — ChatGPT can provide you with quite a list. But, as often happens with ChatGPT, some of those tools simply don’t exist, some don’t work anymore, and some provide low-quality data. 

In this post, we have collected several OSINT tools that actually work quite well for different digital research and information gathering purposes, grouped according to their primary use cases. All of these tools could be very handy for different tasks such as cybercrime investigation, threat hunting, offensive cybersecurity exercises, and more.

Note that the tools on this list are mostly for investigating and mapping internet infrastructure and working with indicators of compromise (IoCs), such as network and host artifacts, domain names, IP addresses, and hash values. For tools that look into people, entities, and their internet presence, we suggest that you take a look at Bellingcat’s OSINT toolkit, even though some of the tools mentioned below can help with that as well.

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.

White Paper Download

Please complete the form below to download the required file: