{"uid":"cap_SlQ62J0i0GQG5AQHIZZ1N","slug":"domain-intel-by-halowerk-3f88d2df","name":"Domain Intel by Halowerk","description":"Resolves A, AAAA, MX, NS, TXT, CAA and SOA, reads the WHOIS record of the responsible registry, checks SPF, DMARC and known DKIM selectors, opens a TLS handshake for issuer, validity, chain and SAN list, and collects subdomains from Certificate Transparency. Fields that a registry refuses to answer are reported as unknown, never guessed.","url":"https://dns.halowerk.com/domain","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"Domain without scheme, for example example.com. A full URL or a mail address is accepted and reduced to its host."},"whois_raw":{"type":"boolean","default":false,"description":"Include the unparsed WHOIS text of the registry answer."},"cert_chain":{"type":"boolean","default":false,"description":"Return the full certificate chain the server presents, not only the leaf certificate."},"subdomains":{"type":"boolean","default":true,"description":"Collect subdomains from Certificate Transparency (crt.sh) and the certificate SAN list."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_KqY4xiN5cc5Cx3QJ_5w0i","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs comprehensive domain intelligence: DNS resolution (A/AAAA/MX/NS/TXT/CAA/SOA), WHOIS lookup, SPF/DMARC/DKIM email security checks, TLS certificate analysis, and Certificate Transparency subdomain enumeration for any given domain.","exampleAgentPrompt":"Can you run a full domain intel check on stripe.com — grab the DNS records, check their SPF and DMARC setup, inspect the TLS certificate, and enumerate any subdomains you can find via Certificate Transparency?","exampleUseCases":[{"title":"Email deliverability audit for sender domain","prompt":"Check the email security configuration for mailchimp.com — I need to see if they have valid SPF, DMARC, and any DKIM selectors set up before we try to deliver to them."},{"title":"TLS certificate expiry and chain inspection","prompt":"Inspect the TLS certificate for api.github.com — I want to know the issuer, expiry date, the full certificate chain, and what domains are in the SAN list."},{"title":"Subdomain discovery for security recon","prompt":"Find all subdomains you can for tesla.com using Certificate Transparency and the SAN list from their TLS certificate — I need a full picture of their exposed infrastructure."}],"resultDescription":"Returns structured DNS records (A, AAAA, MX, NS, TXT, CAA, SOA), parsed WHOIS data (and optionally raw WHOIS text), SPF/DMARC/DKIM email security records, TLS leaf certificate details (issuer, validity dates, SANs) and optionally the full chain, plus a list of subdomains from Certificate Transparency and the SAN list. Fields refused by registries are reported as unknown rather than omitted or guessed.","failureModes":["Domain does not exist — DNS NXDOMAIN returned, most fields will be empty or unknown","WHOIS registry rate-limited or refuses — WHOIS fields reported as unknown","TLS handshake fails — no certificate data returned if server does not support TLS","crt.sh unavailable — subdomain enumeration may be incomplete or empty","Invalid domain input — malformed domain string rejected","Network timeout reaching authoritative nameservers — partial DNS results"],"whenToPreferThis":"Choose this endpoint when you need a single-call, comprehensive domain profile combining DNS, WHOIS, email security (SPF/DMARC/DKIM), TLS certificate details, and subdomain enumeration. It is ideal for security audits, onboarding vendor checks, email deliverability investigations, or infrastructure reconnaissance where querying each data source separately would require multiple tools. Prefer it over raw DNS-only resolvers when TLS and email security context is also needed.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:34:59.204Z","isFirstParty":false}