Cisco Umbrella WHOIS Information for a Domain API

The WHOIS Information for a Domain API from Cisco Umbrella — 6 operation(s) for whois information for a domain.

Business capability
Threat Detection & Response Management BC-620.30

Operations 6

GET /whois/{domain} Get WHOIS Information for Domain #
GET /whois/{domain}/history Get WHOIS History for Domain #
GET /whois/nameservers/{nameserver} Get WHOIS Information for Nameserver #
GET /whois/nameservers Get WHOIS Information for Nameservers #
GET /whois/emails/{email} Get WHOIS Email Information #
GET /whois/search/{searchField}/{regexExpression} Get WHOIS Information Search #

Documentation

📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/

Specifications

Other Resources

🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/key-admin.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/managed-providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/s3-key-rotation.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/service-providers-console.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/users-roles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/auth/token.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/cloudlock/cloudlock.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-domains.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-tunnels.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/policies.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/roaming-computers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/sites.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/swg-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/tagging.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/virtual-appliances.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/investigate/investigate.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/application-lists-internet-umb.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/destination-lists.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/api-usage.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/app-discovery.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/provider-consoles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/reporting.yaml

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cisco-umbrella-whois-information-for-a-domain-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cisco-umbrella-whois-information-for-a-domain-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cisco Umbrella Investigate WHOIS Information for a Domain API
  description: 'The Umbrella Investigate API provides a complete view of domains in relation to IP and autonomous system number (ASN) information.

    You can get the following domain information:


    * Domain status, risk score, and geolocation

    * Number of domain searches

    * Co-occurring domains

    * Subdomains of a domain

    * Tagged timeline of a domain, IP, or URL

    * Security reputation of a domain

    * Top accessed domains

    * WHOIS information for the domain

    * Threat intelligence data for domains, IPs, and URLs

    * Threat intelligence samples by file hash'
  version: 2.0.0
  contact:
    name: Cloud Security Developer Community
  x-provenance:
    method: harvested
    authored_by: Cisco Umbrella
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: pubhub.devnetcloud.com
    note: 26 first-party OpenAPI 3.0 documents (256 operations) listed by Cisco's own docs-nav config and fetched anonymously. Byte-identity reconfirmed 2026-08-19 by SHA-256 against the live source.
  x-evidence:
  - type: source
    url: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/umbrella-config.json
  - type: source
    url: https://developer.cisco.com/docs/cloud-security/
servers:
- url: https://api.umbrella.com/{basePath}
  variables:
    basePath:
      default: investigate/v2
security:
- oauthFlow: []
tags:
- name: WHOIS Information for a Domain
paths:
  /whois/{domain}:
    get:
      summary: Get WHOIS Information for Domain
      operationId: getWhois
      tags:
      - WHOIS Information for a Domain
      description: 'Get the WHOIS information for the specified email addresses,

        nameservers, and domains. You can search by multiple email addresses or multiple nameservers.

        This documentation outlines the following API endpoints:

        email (single and multiple), domain record (current and historical), and nameserver (single and multiple).

        In some instances, WHOIS information can be irregular as there are no standards

        between domain registrars and large volumes of information can be returned from a query.

        As such, both the email and nameserver WHOIS endpoints have a limit of 500 results,

        which you can reduce to a smaller set of results.

        There is an `offset` parameter that can be leveraged to retrieve the entire set

        of domain entries for a given email without any limitation. Only the email parameter

        supports this.

        You can sort the email parameter by filtering the entries based on the timestamp field.

        If a domain, email, or nameserver has no known WHOIS information, Investigate returns `HTTP 404`.

        If a domain, email or nameserver does not exist, Investigate returns `HTTP 404`.

        '
      parameters:
      - $ref: '#/components/parameters/domain'
      security:
      - oauthFlow:
        - investigate.investigate:read
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                type: array
                description: The list of WHOIS information.
                items:
                  $ref: '#/components/schemas/WhoisDomain'
              example:
              - administrativeContactFax: ''
                whoisServers: ''
                addresses:
                - 1600 amphitheatre parkway
                - please contact contact-admin@google.com, 1600 amphitheatre parkway
                - 2400 e. bayshore pkwy
                administrativeContactName: DNS Admin
                zoneContactEmail: ''
                billingContactFax: ''
                administrativeContactTelephoneExt: ''
                administrativeContactEmail: dns-admin@google.com
                technicalContactEmail: dns-admin@google.com
                technicalContactFax: '16506181499'
                nameServers:
                - ns1.google.com
                - ns2.google.com
                - ns3.google.com
                - ns4.google.com
                zoneContactName: ''
                billingContactPostalCode: ''
                zoneContactFax: ''
                registrantTelephoneExt: ''
                zoneContactFaxExt: ''
                technicalContactTelephoneExt: ''
                billingContactCity: ''
                zoneContactStreet: []
                created: ''
                administrativeContactCity: Mountain View
                registrantName: Dns Admin
                zoneContactCity: ''
                domainName: google.com
                zoneContactPostalCode: ''
                administrativeContactFaxExt: ''
                technicalContactCountry: UNITED STATES
                registrarIANAID: '292'
                updated: 2011-07-20 00:00:00 UTC
                administrativeContactStreet:
                - 1600 amphitheatre parkway
                billingContactEmail: ''
                status:
                - clientDeleteProhibited
                - clientTransferProhibited
                - clientUpdateProhibited
                - serverDeleteProhibited
                - serverTransferProhibited
                - serverUpdateProhibited
                registrantCity: Mountain View
                billingContactCountry: ''
                expires: 2020-09-14 00:00:00 UTC
                technicalContactStreet:
                - 2400 e. bayshore pkwy
                registrantOrganization: Google Inc.
                billingContactStreet: []
                registrarName: MARKMONITOR INC.
                registrantPostalCode: '94043'
                zoneContactTelephone: ''
                registrantEmail: dns-admin@google.com
                technicalContactFaxExt: ''
                technicalContactOrganization: Google Inc.
                emails:
                - dns-admin@google.com
                registrantStreet:
                - please contact contact-admin@google.com
                - 1600 amphitheatre parkway
                technicalContactTelephone: '16503300100'
                technicalContactState: CA
                technicalContactCity: Mountain View
                registrantFax: '16506188571'
                registrantCountry: UNITED STATES
                billingContactFaxExt: ''
                timestamp: 0
                zoneContactOrganization: ''
                administrativeContactCountry: UNITED STATES
                billingContactName: ''
                registrantState: CA
                registrantTelephone: '16502530000'
                administrativeContactState: CA
                registrantFaxExt: ''
                technicalContactPostalCode: '94043'
                rawBase64: ''
                zoneContctTelephoneExt: ''
                administrativeContactOrganization: Google Inc.
                billingContactTelephone: ''
                billingContactTelephoneExt: ''
                zoneContactState: ''
                administrativeContactTelephone: '16506234000'
                billingContactOrganization: ''
                technicalContactName: DNS Admin
                administrativeContactPostalCode: '94043'
                zoneContactCountry: ''
                billingContactState: ''
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /whois/{domain}/history:
    get:
      summary: Get WHOIS History for Domain
      operationId: getWhoisHistory
      tags:
      - WHOIS Information for a Domain
      description: 'Get a standard WHOIS response record for a single domain with available historical

        WHOIS data returned in an object. The information displayed varies by registrant.

        The default limit for history is 10. You can set another value with the `limit` query parameter.

        '
      parameters:
      - $ref: '#/components/parameters/domain'
      - $ref: '#/components/parameters/limitParam'
      security:
      - oauthFlow:
        - investigate.investigate:read
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                type: array
                description: The list of WHOIS information.
                items:
                  $ref: '#/components/schemas/WhoisDomain'
              example:
              - administrativeContactFax: ''
                whoisServers: ''
                addresses:
                - 1600 amphitheatre parkway
                - please contact contact-admin@google.com, 1600 amphitheatre parkway
                - 2400 e. bayshore pkwy
                administrativeContactName: DNS Admin
                zoneContactEmail: ''
                billingContactFax: ''
                administrativeContactTelephoneExt: ''
                administrativeContactEmail: dns-admin@google.com
                technicalContactEmail: dns-admin@google.com
                technicalContactFax: '16506181499'
                nameServers:
                - ns1.google.com
                - ns2.google.com
                - ns3.google.com
                - ns4.google.com
                zoneContactName: ''
                billingContactPostalCode: ''
                zoneContactFax: ''
                registrantTelephoneExt: ''
                zoneContactFaxExt: ''
                technicalContactTelephoneExt: ''
                billingContactCity: ''
                zoneContactStreet: []
                created: ''
                administrativeContactCity: Mountain View
                registrantName: Dns Admin
                zoneContactCity: ''
                domainName: google.com
                zoneContactPostalCode: ''
                administrativeContactFaxExt: ''
                technicalContactCountry: UNITED STATES
                registrarIANAID: '292'
                updated: 2011-07-20 00:00:00 UTC
                administrativeContactStreet:
                - 1600 amphitheatre parkway
                billingContactEmail: ''
                status:
                - clientDeleteProhibited
                - clientTransferProhibited
                - clientUpdateProhibited
                - serverDeleteProhibited
                - serverTransferProhibited
                - serverUpdateProhibited
                registrantCity: Mountain View
                billingContactCountry: ''
                expires: 2020-09-14 00:00:00 UTC
                technicalContactStreet:
                - 2400 e. bayshore pkwy
                registrantOrganization: Google Inc.
                billingContactStreet: []
                registrarName: MARKMONITOR INC.
                registrantPostalCode: '94043'
                zoneContactTelephone: ''
                registrantEmail: dns-admin@google.com
                technicalContactFaxExt: ''
                technicalContactOrganization: Google Inc.
                emails:
                - dns-admin@google.com
                registrantStreet:
                - please contact contact-admin@google.com
                - 1600 amphitheatre parkway
                technicalContactTelephone: '16503300100'
                technicalContactState: CA
                technicalContactCity: Mountain View
                registrantFax: '16506188571'
                registrantCountry: UNITED STATES
                billingContactFaxExt: ''
                timestamp: 0
                zoneContactOrganization: ''
                administrativeContactCountry: UNITED STATES
                billingContactName: ''
                registrantState: CA
                registrantTelephone: '16502530000'
                administrativeContactState: CA
                registrantFaxExt: ''
                technicalContactPostalCode: '94043'
                rawBase64: ''
                zoneContctTelephoneExt: ''
                administrativeContactOrganization: Google Inc.
                billingContactTelephone: ''
                billingContactTelephoneExt: ''
                zoneContactState: ''
                administrativeContactTelephone: '16506234000'
                billingContactOrganization: ''
                technicalContactName: DNS Admin
                administrativeContactPostalCode: '94043'
                zoneContactCountry: ''
                billingContactState: ''
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /whois/nameservers/{nameserver}:
    get:
      summary: Get WHOIS Information for Nameserver
      operationId: getWhoisNameserver
      tags:
      - WHOIS Information for a Domain
      description: 'Get WHOIS information for the nameserver.

        As a nameserver can potentially register hundreds or thousands of domains,

        the server limits the number of results to 500.'
      parameters:
      - name: nameserver
        in: path
        required: true
        description: The nameserver's domain name.
        schema:
          type: string
        example: nameserver1.com
      - name: limit
        in: query
        required: false
        description: 'Specify the number of records to return from the collection.

          The default limit is 500.'
        schema:
          type: integer
          default: 500
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/sortFieldParam'
      security:
      - oauthFlow:
        - investigate.investigate:read
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                type: object
                description: The WHOIS email and nameserver information.
                properties:
                  totalResults:
                    type: integer
                    description: The total number of WHOIS records found for this query.
                  moreDataAvailable:
                    $ref: '#/components/schemas/moreDataAvailable'
                  limit:
                    $ref: '#/components/schemas/limit'
                  sortField:
                    type: string
                    description: The field that is used to sort the collection.
                    example: updated
                  domains:
                    type: array
                    description: The list of information about the WHOIS emails and nameservers.
                    items:
                      $ref: '#/components/schemas/WhoisEmailsAndNameservers'
                    example:
                    - domain: 46645.biz
                      current: true
              example:
                totalResults: 500
                moreDataAvailable: true
                limit: 500
                sortField: updated
                domains:
                - domain: 46645.biz
                  current: true
                - domain: 800google411.net
                  current: true
                - domain: zagatnyc.com
                  current: true
                - domain: zavers.com
                  current: true
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /whois/nameservers:
    get:
      summary: Get WHOIS Information for Nameservers
      operationId: getWhoisNameservers
      tags:
      - WHOIS Information for a Domain
      description: 'Get WHOIS information for the nameservers. To search by multiple nameservers, provide

        a comma-delimited list of domain names for the `nameServerList` query parameter.

        For example: `ns1.google.com,ns2.google.com`.'
      parameters:
      - name: nameServerList
        in: query
        required: true
        description: The nameserver's domain names.
        schema:
          type: string
          description: The list of the nameserver's domain names.
        example: ns1.google.com,ns2.google.com
      - name: limit
        in: query
        required: false
        description: 'The number of records to return in the response from the collection.

          The default limit is 500.'
        schema:
          type: integer
          default: 500
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/sortFieldParam'
      security:
      - oauthFlow:
        - investigate.investigate:read
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                type: object
                description: The WHOIS information about the nameservers.
                properties:
                  totalResults:
                    $ref: '#/components/schemas/totalresults'
                  moreDataAvailable:
                    $ref: '#/components/schemas/moreDataAvailable'
                  limit:
                    $ref: '#/components/schemas/limit'
                  sortField:
                    type: string
                    description: The field that is used to sort the collection.
                    example: updated
                  domains:
                    type: array
                    description: The list of WHOIS nameserver domain information.
                    items:
                      $ref: '#/components/schemas/WhoisEmailsAndNameservers'
                    example:
                    - domain: 46645.biz
                      current: true
              example:
                totalResults: 500
                moreDataAvailable: true
                limit: 500
                sortField: updated
                domains:
                - domain: 46645.biz
                  current: true
                - domain: 800google411.net
                  current: true
                - domain: zagatnyc.com
                  current: true
                - domain: zavers.com
                  current: true
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /whois/emails/{email}:
    get:
      summary: Get WHOIS Email Information
      operationId: getWhoisEmail
      tags:
      - WHOIS Information for a Domain
      description: 'Get the email address or addresses of the registrar for the domain or domains. The results include

        the total number of results for domains registered by this email address and a list

        of the first 500 domains associated with this email.

        You can pivot on the email address to find other malicious domains registered by the same email.

        This endpoint is limited to a maximum of 500 results, which are the first 500 gathered from the database.

        Reduce the number of results by setting the `limit` query parameter.

        **Note:** Due to the sample length, Investigate may truncate a sample.'
      parameters:
      - name: email
        in: path
        required: true
        description: An email address that follows the RFC5322 conventions.
        schema:
          type: string
        example: hello@sample.com
      - name: limit
        in: query
        required: false
        description: 'Specify the number of results to return.

          The default limit is 500.'
        example: 400
        schema:
          type: integer
          default: 500
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/sortFieldParam'
      security:
      - oauthFlow:
        - investigate.investigate:read
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                type: object
                properties:
                  totalResults:
                    type: integer
                    description: The total number of results for this email address.
                    example: 400
                  offset:
                    $ref: '#/components/schemas/offset'
                  moreDataAvailable:
                    type: boolean
                    description: Specifies whether there is more than 500 results for this email.
                    example: true
                  limit:
                    type: integer
                    description: 'The number of results returned in the response. The default

                      limit is 500.'
                  sortField:
                    type: string
                    description: The field that is used to sort the collection.
                    example: updated
                  domains:
                    type: array
                    items:
                      $ref: '#/components/schemas/WhoisEmailsAndNameservers'
                    description: 'The list of domains registered by this email and if the domain is currently registered

                      by this email address.'
                    example:
                    - domain: 0emm.com
                      current: true
              example:
                totalResults: 500
                moreDataAvailable: true
                limit: 500
                sortField: updated
                domains:
                - domain: 0emm.com
                  current: true
                - domain: 10tothe100.net
                  current: true
                - domain: youtubube.com
                  current: true
                - domain: zagat.net
                  current: true
                - domain: zagatnyc.com
                  current: true
                - domain: zavers.com
                  current: true
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /whois/search/{searchField}/{regexExpression}:
    get:
      summary: Get WHOIS Information Search
      operationId: getWhoisSearch
      tags:
      - WHOIS Information for a Domain
      description: 'Performs a regular expression (RegEx) search on the WHOIS data (domain, nameserver, and email fields)

        that was updated or created in the specified time range.

        Returns a list of ten WHOIS records that match the specified RegEx expression.

        Use the `offset` query parameter to paginate the collection.

        By default, Investigate sorts by the `updated` field.

        '
      parameters:
      - name: searchField
        in: path
        required: true
        description: 'Specifies the field name to use in the RegEx search.

          Valid field names are: `domain`, `nameserver`, and `email`.'
        schema:
          type: string
          enum:
          - domain
          - nameserver
          - email
        example: domain
      - name: regexExpression
        in: path
        required: true
        description: A standard regular expression pattern search.
        schema:
          type: string
        example: exa[a-z]ple.com
      - $ref: '#/components/parameters/start'
      - $ref: '#/components/parameters/stop'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/sortFieldParam'
      security:
      - oauthFlow:
        - investigate.investigate:read
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                type: object
                description: The WHOIS information for a domain.
                properties:
                  totalResults:
                    type: integer
                    description: The total number of results for this search.
                    example: 500
                  offset:
                    $ref: '#/components/schemas/offset'
                  moreDataAvailable:
                    type: boolean
                    description: Specifies whether there is more than 10 results for this search.
                    example: true
                  limit:
                    type: integer
                    description: The total number of results for this page. Default limit is 10.
                    example: 15
                  sortField:
                    type: string
                    description: The field that is used to sort the collection.
                    example: updated
                  records:
                    type: array
                    description: The list of WHOIS records.
                    items:
                      $ref: '#/components/schemas/WhoisDomain'
                    example:
                    - administrativeContactFax: ''
                      whoisServers: ''
                      addresses:
                      - 1600 amphitheatre parkway
                      - please contact contact-admin@google.com, 1600 amphitheatre parkway
                      - 2400 e. bayshore pkwy
                      administrativeContactName: DNS Admin
                      zoneContactEmail: ''
                      billingContactFax: ''
                      administrativeContactTelephoneExt: ''
                      administrativeContactEmail: dns-admin@google.com
                      technicalContactEmail: dns-admin@google.com
                      technicalContactFax: '16506181499'
                      nameServers:
                      - ns1.google.com
                      - ns2.google.com
                      - ns3.google.com
                      - ns4.google.com
                      zoneContactName: ''
                      billingContactPostalCode: ''
                      zoneContactFax: ''
                      registrantTelephoneExt: ''
                      zoneContactFaxExt: ''
                      technicalContactTelephoneExt: ''
                      billingContactCity: ''
                      zoneContactStreet: []
                      created: ''
                      administrativeContactCity: Mountain View
                      registrantName: Dns Admin
                      zoneContactCity: ''
                      domainName: google.com
                      zoneContactPostalCode: ''
                      administrativeContactFaxExt: ''
                      technicalContactCountry: UNITED STATES
                      registrarIANAID: '292'
                      updated: 2011-07-20 00:00:00 UTC
                      administrativeContactStreet:
                      - 1600 amphitheatre parkway
                      billingContactEmail: ''
                      status:
                      - clientDeleteProhibited
                      - clientTransferProhibited
                      - clientUpdateProhibited
                      - serverDeleteProhibited
                      - serverTransferProhibited
                      - serverUpdateProhibited
                      registrantCity: Mountain View
                      billingContactCountry: ''
                      expires: 2020-09-14 00:00:00 UTC
                      technicalContactStreet:
                      - 2400 e. bayshore pkwy
                      registrantOrganization: Google Inc.
                      billingContactStreet: []
                      registrarName: MARKMONITOR INC.
                      registrantPostalCode: '94043'
                      zoneContactTelephone: ''
                      registrantEmail: dns-admin@google.com
                      technicalContactFaxExt: ''
                      technicalContactOrganization: Google Inc.
                      emails:
                      - dns-admin@google.com
                      registrantStreet:
                      - please contact contact-admin@google.com
                      - 1600 amphitheatre parkway
                      technicalContactTelephone: '16503300100'
                      technicalContactState: CA
                      technicalContactCity: Mountain View
                      registrantFax: '16506188571'
                      registrantCountry: UNITED STATES
                      billingContactFaxExt: ''
                      timestamp: 0
                      zoneContactOrganization: ''
                      administrativeContactCountry: UNITED STATES
                      billingContactName: ''
                      registrantState: CA
                      registrantTelephone: '16502530000'
                      administrativeContactState: CA
                      registrantFaxExt: ''
                      technicalContactPostalCode: '94043'
                      rawBase64: ''
                      zoneContctTelephoneExt: ''
                      administrativeContactOrganization: Google Inc.
                      billingContactTelephone: ''
                      billingContactTelephoneExt: ''
                      zoneContactState: ''
                      administrativeContactTelephone: '16506234000'
                      billingContactOrganization: ''
                      technicalContactName: DNS Admin
                      administrativeContactPostalCode: '94043'
                      zoneContactCountry: ''
                      billingContactState: ''
              example:
                totalResults: 500
                offset: 0
                moreDataAvailable: true
                limit: 10
                sortField: updated
                records:
                - administrativeContactFax: ''
                  whoisServers: ''
                  addresses:
                  - 1600 amphitheatre parkway
                  - please contact contact-admin@google.com, 1600 amphitheatre parkway
                  - 2400 e. bayshore pkwy
                  administrativeContactName: DNS Admin
                  zoneContactEmail: ''
                  billingContactFax: ''
                  administrativeContactTelephoneExt: ''
                  administrativeContactEmail: dns-admin@google.com
                  technicalContactEmail: dns-admin@google.com
                  technicalContactFax: '16506181499'
                  nameServers:
                  - ns1.google.com
                  - ns2.google.com
                  - ns3.google.com
                  - ns4.google.com
                  zoneContactName: ''
                  billingContactPostalCode: ''
                  zoneContactFax: ''
                  registrantTelephoneExt: ''
                  zoneContactFaxExt: ''
                  technicalContactTelephoneExt: ''
                  billingContactCity: ''
                  zoneContactStreet: []
                  created: ''
                  administrativeContactCity: Mountain View
                  registrantName: Dns Admin
                  zoneConta

# --- truncated at 32 KB (48 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-umbrella/refs/heads/main/openapi/cisco-umbrella-whois-information-for-a-domain-api-openapi.yml