Searches across all lookalike categories (unclassified, low-risk, high-risk) and returns matching domains with their risk classification. Returns a lightweight response with only domain name and type - useful for typeahead search or quick lookups.
⚠️ At least one filter parameter is required.
Filter Pattern
Filters follow the pattern: {field}[{operator}]={value}
Available Fields
String/Keyword Fields
Operators: contains, equals, is, startsWith, endsWith, isEmpty, isNotEmpty, isAnyOf, not_equal, is_not, not, not_contain, isNotAnyOf
Fields: id, domain, unicodeDomain, looks_like, similarity, dmarc_status, ns_records, apexDomain, matchBasedOn, industry, source, origin, dns_providers, agenticTag, classification, tags, keywords, annotations, face_annotations, ns_records_list, dns_providers_list
Boolean Fields
Values: true, false, any
Fields: email_ready, reputation, web_presence, riskBump, read, is_subdomain, has_screenshot, has_annotations, has_face_annotations, has_detected_keywords, reportedAsFalsePositive, in_takedown, flagged_by_google_safe_browsing, hasSubdomailer, manuallyAdded, hasNotes, detected_emails
Numeric Fields
Operators: equals, equalOrLargerThan, largerThan, lessThan, lessThanOrEqual, between
Fields: traffic_rank, risk_rating, new_risk_rating, numThreatEmails
Date Fields (YYYY-MM-DD format)
Operators: is, not, after, onOrAfter, before, onOrBefore, isEmpty, isNotEmpty
Fields: observed_date, updated_at, lastScanCrux, deletionCountdownSince
Common Use Cases
- Search by domain:
unicodeDomain[contains]=example - Find by apex domain:
apexDomain[equals]=example.com - Check specific domain:
domain[equals]=suspicious-site.com - Multiple conditions:
unicodeDomain[startsWith]=phish&new_risk_rating[equalOrLargerThan]=5
Examples
- String:
unicodeDomain[contains]=test - Boolean:
email_ready[eq]=true - Numeric:
new_risk_rating[equalOrLargerThan]=5 - Date:
observed_date[after]=2024-01-01
Combining Filters
Use linkOperator=and (all must match) or linkOperator=or (any must match)
