{"api":"domain-intel","summary":"Domain registration truth (RDAP) + DNS posture (DNS-over-HTTPS), pay-per-check. Part of the Trust & Verification suite.","sources":[{"name":"RDAP","how":"Registry base resolved from the IANA RDAP bootstrap (data.iana.org/rdap/dns.json), then GET <base>/domain/<domain>.","provides":"registration/expiry/last-changed dates, registrar (+IANA id), statuses, nameservers, DNSSEC.","freshness":"cached ≤ 86400s (24h); the /live sibling always fetches fresh."},{"name":"DNS-over-HTTPS","how":"Cloudflare (cloudflare-dns.com/dns-query) with Google (dns.google) fallback; A, AAAA, CNAME, MX, NS, TXT, SOA, CAA + derived SPF/DMARC.","provides":"live DNS records, each with its own lookup status and fault. A record type the name does not publish is an empty array; a type nobody answered is null (never an empty array — our outage must not read as their missing SPF/DMARC/MX), with fault 'zone' when both resolvers were told SERVFAIL and 'resolver' when we could not ask; a name that does not exist is found:false + why.","freshness":"ALWAYS live."}],"tools":[{"path":"/domain-intel/domain/:domain","live_sibling":{"path":"/domain-intel/domain/:domain/live"},"returns":"RDAP registration card (dates, registrar+IANA id, statuses, nameservers, DNSSEC) + derived flags (young_domain, expiring_soon, privacy_proxy, status_locked) with evidence, plus the inline DNS summary. An unregistered domain is a complete paid answer in the same shape: found:false, registered:false, why:{code:'DOMAIN_NOT_REGISTERED', detail}, and the registration fields present but null."},{"path":"/domain-intel/dns/:domain","returns":"ALWAYS-LIVE multi-record DNS summary: A, AAAA, CNAME, MX, NS, TXT, SOA, CAA + SPF and DMARC, each with a per-type lookup status (ok / nxdomain / servfail / lookup_failed), the RCODE, the resolver that served it and the fault when it produced nothing. A name that does not exist answers found:false + why:{code:'NXDOMAIN'}; a zone that SERVFAILs to both resolvers answers found:false + why:{code:'ZONE_SERVFAIL'}, which is their broken delegation, not our outage."}],"limitations":["RDAP field coverage varies by registry; some ccTLDs publish little or no RDAP.","A 404 from a registry means 'no record' (likely available) — availability is registry-dependent, not a guarantee.","Not a WHOIS proxy: only fields the registry exposes over RDAP are returned; registrant PII is usually redacted.","DNS is a live snapshot from a public resolver, subject to caching/propagation at the resolver.","A DNS record set of null means nobody answered, NOT that the record is absent — check `lookups[type].fault` and `complete` before reading an empty SPF/DMARC/MX as a security conclusion.","A zone that SERVFAILs resolves for nobody, so we report found:false — but it is not NXDOMAIN and the name may well be registered; the RDAP card is the authority on that."],"suite":{"positioning":"Trust & Verification — verify emails, domains, URLs, phones, wallets, and counterparties, pay-per-check.","siblings":["/email-check","/url-screen","/phone-check","/token-safety","/address-screen","/sanctions-screen"]},"pricing":"Quoted in each paid endpoint's own 402 challenge; GET /.well-known/x402 prices this whole origin in one free call.","disclaimer":"Registration and DNS facts are read live from public RDAP registries and DNS; record availability and field coverage vary by registry. All information is provided \"AS IS\" without warranty of any kind, for informational purposes only. We accept no responsibility or liability for any decision, loss, or action taken in reliance on it. Always verify independently before acting."}