API & Tools

Lookup API

Real-time threat intelligence queries

Query our threat intelligence database in real-time. Get instant risk scores, threat categories, and enrichment data for any domain, IP, or URL.

Try It NowFree
Try:|

Get instant threat analysis with risk scores, threat categories, and detailed reports.

<0ms

Avg Response

Indexed

Observables

Configured

Data Sources

99.9%

Uptime

Capabilities

Key Features

Everything you need to protect your infrastructure and users

Domain Lookup

Check domain reputation with WHOIS and DNS enrichment.

IP Lookup

Get IP reputation with geolocation and ASN data.

URL Lookup

Scan URLs with redirect chain analysis.

Low-latency results

Sub-100ms response times for cached entities.

Risk Scoring

Normalized 0-100 risk score with confidence levels.

Rich Data

Threat categories, sources, and contextual data.

Applications

Use Cases

How security teams use this tool

Web Applications

Check user inputs and external links in real-time.

Email Filtering

Verify sender domains and embedded URLs.

Security Tools

Enrich alerts with threat intelligence.

Fraud Prevention

Assess risk during transactions and signups.

Real-Time Threat Intelligence API

The Lookup API provides instant access to our comprehensive threat intelligence database. With sub-100ms response times for cached entities, you can integrate real-time security checks into your applications without adding noticeable latency. Whether you're validating user inputs, filtering email content, or enriching security alerts, the Lookup API delivers specific threat data when you need it most.

Response Format and Data Fields

Every API response includes a normalized risk score from 0-100, threat categories describing the specific type of malicious activity detected, source attributions showing which intelligence feeds flagged the entity, and optional enrichment data including WHOIS records, geolocation, and ASN information. Confidence levels help you calibrate your security policies based on the strength of evidence behind each detection.

Integration Patterns for Security Teams

The Lookup API integrates directly with existing security infrastructure. Embed checks in web application workflows to validate user-submitted URLs, integrate with email gateways to scan sender domains and embedded links, enrich SIEM alerts with threat context to accelerate triage, and add reputation checks to fraud prevention pipelines. Our SDKs handle authentication, retries, and rate limiting automatically, letting you focus on security logic.

Getting Started with the Lookup API

Start using the Lookup API in minutes: sign up for a free account to receive your API key, install your preferred SDK or use direct REST calls, and begin querying domains, IPs, and URLs. The free tier includes 30 requests per month, enough to prototype your integration and evaluate the quality of our threat intelligence before committing to a paid plan.

Support

Frequently Asked Questions

What can I look up with this API?

You can look up domains, IP addresses, URLs, and file hashes. Each query returns threat scores, categories, and enrichment data.

What is the response time?

Average response time is under 100ms. Results are returned from our cached intelligence, with real-time enrichment available on request.

How many requests can I make?

Free tier allows 30 requests/month. Pro includes 10,000 requests/month and 60 requests/minute burst capacity.

What data is included in the response?

Responses include risk score (0-100), threat categories, source detections, enrichment data (WHOIS, geo, ASN), and confidence levels.
Get Started

Ready to Get Started?

Rejoignez des milliers d'équipes de sécurité qui utilisent isMalicious pour protéger leur infrastructure.