OWNERSHIP & ROUTING

Reverse WHOIS Search

Find domains associated with a WHOIS value. This feature requires a configured SecurityTrails API key and an appropriate subscription.

39DExternal testRuns from the toolbox server

RUN TEST

Reverse WHOIS Search

Public targets only

This optional feature needs a SecurityTrails API key and suitable subscription in config.php.

HOW IT WORKS

About the Reverse WHOIS Search

The toolbox sends a narrowly scoped search to the configured data provider. Because bulk WHOIS datasets are not available through ordinary port 43 WHOIS, an API subscription is required.

How to use this result

  1. Run the test from this server.Use a public hostname, address, prefix or ASN in the format requested above.
  2. Compare with another observation point.Run a local command or use a second provider to identify location-specific behaviour.
  3. Correlate related evidence.Use the related tools below to compare DNS, routes, ports, TLS and application responses.
  4. Keep the time and context.Routing, DNS caches and reputation data change, so record when the result was collected.

Common interpretation issues

  • Privacy redaction greatly reduces reverse-WHOIS coverage.
  • Historical and current associations can differ.
  • Use the feature only for legitimate security, brand-protection or asset-management work.

NEED HELP INTERPRETING THE RESULT?

39D supports business networks, cyber security and managed IT.

For ongoing support or a larger infrastructure project, speak to the 39D team.

Visit 39D

Frequently asked questions

Why is an API key required?

Reverse searches depend on an indexed historical WHOIS dataset rather than a single registry query.

Will it find every domain?

No. Redaction, data age, provider coverage and subscription limits affect results.