Real-time threat intelligence queries
Query our threat intelligence database in real-time. Get instant risk scores, threat categories, and enrichment data for any domain, IP, or URL.
Get instant threat analysis with risk scores, threat categories, and detailed reports.
<0ms
Avg Response
Indexed
Observables
Configured
Data Sources
99.9%
Uptime
Everything you need to protect your infrastructure and users
Check domain reputation with WHOIS and DNS enrichment.
Get IP reputation with geolocation and ASN data.
Scan URLs with redirect chain analysis.
Sub-100ms response times for cached entities.
Normalized 0-100 risk score with confidence levels.
Threat categories, sources, and contextual data.
How security teams use this tool
Check user inputs and external links in real-time.
Verify sender domains and embedded URLs.
Enrich alerts with threat intelligence.
Assess risk during transactions and signups.
The Lookup API provides instant access to our comprehensive threat intelligence database. With sub-100ms response times for cached entities, you can integrate real-time security checks into your applications without adding noticeable latency. Whether you're validating user inputs, filtering email content, or enriching security alerts, the Lookup API delivers specific threat data when you need it most.
Every API response includes a normalized risk score from 0-100, threat categories describing the specific type of malicious activity detected, source attributions showing which intelligence feeds flagged the entity, and optional enrichment data including WHOIS records, geolocation, and ASN information. Confidence levels help you calibrate your security policies based on the strength of evidence behind each detection.
The Lookup API integrates directly with existing security infrastructure. Embed checks in web application workflows to validate user-submitted URLs, integrate with email gateways to scan sender domains and embedded links, enrich SIEM alerts with threat context to accelerate triage, and add reputation checks to fraud prevention pipelines. Our SDKs handle authentication, retries, and rate limiting automatically, letting you focus on security logic.
Start using the Lookup API in minutes: sign up for a free account to receive your API key, install your preferred SDK or use direct REST calls, and begin querying domains, IPs, and URLs. The free tier includes 30 requests per month, enough to prototype your integration and evaluate the quality of our threat intelligence before committing to a paid plan.
Learn more from our security research blog
Rejoignez des milliers d'équipes de sécurité qui utilisent isMalicious pour protéger leur infrastructure.