DomainTools
DomainTools is a Seattle-based DNS threat intelligence platform serving Fortune 500 enterprises and government/defense organizations. It provides Iris Investigate, the DNSDB passive DNS database, ML-based risk scoring, and an MCP Server for AI agent integration, embedded in 25+ security product integrations.
- Company typePrivate
- Founded2004
- HeadquartersSeattle, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What DomainTools does
DomainTools is a Seattle-based DNS threat intelligence platform, founded in 2004 and operating as DomainTools LLC with a workforce in the 11-50 range. Its core platform, Iris Investigate, enables security analysts to pivot on domain, IP, and DNS infrastructure data; DNSDB provides a passive DNS database containing over 20 years of historical DNS intelligence and processing more than 2 TB of daily passive DNS observations. The portfolio also includes the Predictive Risk Score (a machine-learning risk scoring product), a Real-Time Threat Feeds API, the DNSDB Scout tool, and the recently launched MCP Server, which exposes threat intelligence to AI agents.
The company serves enterprise and government customers, including Fortune 500 organizations and public sector/defense entities, with primary users being SOC analysts, threat intelligence teams, and incident responders. The platform integrates with more than 25 security products across SIEM, SOAR, and TIP categories. Revenue is generated via a subscription-based SaaS model with quote-based enterprise pricing, sold primarily through direct enterprise sales and technology partner channels.
DomainTools acquired Farsight Security in November 2021, bringing the DNSDB passive DNS assets into its portfolio. The company has continued to invest in product expansion, including the MCP Server (2026-03), Real-Time Threat Feeds (2025), and ongoing DNSDB Scout updates, while adding channel partners such as Intruder (2025-12). Limited disclosed funding or headcount growth data restricts visibility into the company's current scaling pace.
DomainTools firmographics
Firmographics- Name
- DomainTools
- Legal name
- DomainTools LLC
- Website
- https://domaintools.com
- Company type
- Private
- Founded year
- 2004
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- DomainTools is a Seattle-based DNS threat intelligence platform serving Fortune 500 enterprises and government/defense organizations. It provides Iris Investigate, the DNSDB passive DNS database, ML-based risk scoring, and an MCP Server for AI agent integration, embedded in 25+ security product integrations.
- Ownership category
- akta.pro rank
DomainTools industry classification
Industry- Product category
- Threat Intelligence and Domain Security Software
- NAICS
- Software Publishers (5132), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518), Web Search Portals, Libraries, Archives, and Other Information Services (5192)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- DNS Security & Protective DNS (HDADABAF)
- akta.pro secondary industries
- IP Address Management (IPAM) & DNS/DHCP Management (DDI) (HDAFAGAF), Resilient DNS, Traffic Management & Global Load Balancing (HDABAIAI)
Keywords
Where DomainTools is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
DomainTools business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- Subscription-based SaaS: DomainTools operates primarily as a subscription-based SaaS platform with paid memberships. Memberships include automatic renewal and various membership types with different features and pricing tiers. The company offers both monthly and annual billing cycles.
- Enterprise Subscriptions: Enterprise Subscription Agreements (ESA) for larger organizations providing enhanced rights to access services with custom terms. Enterprise customers receive dedicated support and customized solutions.
- API/Developer Access: API access providing programmatic access to domain intelligence data with various endpoint configurations including real-time feeds API with configurable polling and session management.
- Threat Intelligence Feeds: Real-time threat intelligence feeds for domains and IPs delivered as streaming data products including NOD, NAD, Domain Hotlist, and Real-Time IP Risk Feed.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise plan with full platform access |
| Subscription | Monthly | Individual/Professional subscription |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
DomainTools product offering
Product offeringCore offering
DomainTools sells a subscription-based Internet intelligence platform that combines the world's largest passive DNS database (DNSDB), machine-learning-based domain risk scoring, and an investigation workbench (Iris Investigate) for security teams to detect, profile, and respond to malicious domains and attacker infrastructure. Its offering is delivered as SaaS subscriptions, APIs, real-time threat intelligence feeds, and an MCP Server for AI agent integration, with pre-built connectors to SIEM, SOAR, TIP, and XDR platforms.
Product overview
DomainTools is a threat intelligence and domain security platform offering a comprehensive suite of products built around DNS-focused data. The core platform (DomainTools Platform) provides investigation and defense automation capabilities, supplemented by Iris Investigate for domain queries and visualization, IrisQL for structured searches, and DNSDB as the underlying passive DNS database. Real-time threat intelligence is delivered through feeds including Newly Observed Domains (NOD), Newly Active Domains (NAD), and Domain Hotlist. The Predictive Risk Score uses machine learning to identify malicious domains. The MCP Server enables AI agent integration with natural language access to all domain intelligence. The product portfolio was expanded through the 2021 acquisition of Farsight Security, which brought additional passive DNS technology and the Security Information Exchange platform.
Differentiator
Problem solved
Functional benefit
Brands
- DomainTools Investigations (DTI): A program with researchers and analysts focused on investigating, mitigating, and preventing Domain- and DNS-based attacks
- Iris Investigate
- DNSDB
- Farsight DNSDB
Products and services
- DomainTools Platform Core threat intelligence and domain security platform that lets security teams investigate threats, track malicious infrastructure, and automate defenses using integrated DNS and domain data.
- Iris Investigate Investigation platform that enables security teams to query, pivot, and visualize domain relationships, historical DNS data, registrant information, and threat infrastructure connections.
- DNSDB (Farsight) Passive DNS database providing historical DNS records and infrastructure tracking with over 20 years of domain intelligence, offering unmatched visibility and historical infrastructure tracking for security investigations.
- Real-Time Threat Feeds Streaming threat intelligence feeds delivering current domain and IP risk data, including Newly Observed Domains, Newly Active Domains, and Domain Hotlist, for immediate blocking, alerting, and enrichment in security stacks.
- Newly Observed Domains (NOD) Real-time feed that captures domains never previously observed by the DomainTools passive DNS sensor network, enabling detection of malicious domains within minutes of creation rather than the typical 17-hour discovery lag from zone file or WHOIS sources.
- Newly Active Domains (NAD) Real-time feed of domains that have become active after a period of inactivity, leveraging the passive DNS sensor array and cross-referenced with the historical DNS database to detect reactivated malicious infrastructure.
- Domain Hotlist Curated feed pinpointing domains with the highest likelihood of malicious intent based on infrastructure patterns, threat actor behavior, and machine learning, requiring a proximity score of 70+ or threat profile score of 90+ and recent passive DNS observation.
- MCP Server Hosted Model Context Protocol server that connects AI agents and LLMs directly to DomainTools' DNS datasets, enabling natural-language retrieval of Risk Scores, hosting history, passive DNS records, and infrastructure connections for enterprise SOC environments.
- DNSDB Scout Desktop application for querying DNSDB with improved interoperability to Iris Investigate and enhanced copy-paste functionality for security investigations.
Quantifiable outcome
- Detects 68% to 96% more malicious domains per month than other solutions
- +3 more outcomes
Companies that use DomainTools
Customer profileNamed customers2 records
Segments6 records
Ideal customer profiles3 records
DomainTools technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration26 records
AI capability5 records
Feature10 records
DomainTools partnerships and signals
Strategic signalPartnerships
30 partnerships are on record, tiered core.
- IntrudercoreIntruder integrated DomainTools DNSDB passive DNS database into its Attack Surface Management platform. The partnership enables Enterprise customers to automatically discover and secure unknown subdomains across extended networks. Pilot program with 60 customers showed 100% saw increase in detected subdomains, with 44% identifying 10+ additional subdomains and 23% uncovering 50+ additional subdomains.
- AnomalicoreIntegration partnership providing TIP (Threat Intelligence Platform) integration enabling Anomali users to access DomainTools domain intelligence within their threat intelligence workflows.
- Palo Alto NetworkscoreBest-in-class DNS intelligence integration with Palo Alto Networks platforms for enhanced threat detection and prevention capabilities.
- Microsoft Security CopilotcoreIntegration into Microsoft Security Copilot Partner Ecosystem enabling enhanced domain intelligence within Microsoft's AI-powered security operations platform.
- CrowdStrikecoreTIP integration partnership enabling CrowdStrike users to leverage DomainTools domain intelligence for threat detection and investigation.
- SplunkcoreSIEM integration enabling Splunk users to incorporate DomainTools threat intelligence feeds and domain data into their security monitoring and analytics workflows.
- Recorded FuturecoreTIP integration partnership providing Recorded Future users access to DomainTools domain intelligence capabilities.
- IBM QRadarcoreSIEM integration enabling IBM QRadar users to leverage DomainTools domain and DNS threat intelligence.
- Cortex XSOARcoreSOAR integration enabling Cortex XSOAR users to automate domain threat intelligence workflows and response playbooks.
- Microsoft SentinelcoreSIEM integration providing Microsoft Sentinel users access to DomainTools domain intelligence for security operations.
- Elastic (ELK) StackcoreSIEM integration enabling Elastic Stack users to incorporate DomainTools domain intelligence into their security analytics.
- MaltegocoreTIP integration enabling Maltego users to pivot on DomainTools domain intelligence for investigative workflows.
- EclecticIQcoreTIP integration providing EclecticIQ users access to DomainTools threat intelligence.
- ExabeamcoreSOAR integration enabling Exabeam users to leverage DomainTools domain intelligence in security operations.
- Filigran OpenCTIcoreTIP integration providing OpenCTI users access to DomainTools domain intelligence capabilities.
- ServiceNowcoreSOAR integration enabling ServiceNow users to incorporate DomainTools threat intelligence into their security workflows.
- MISPcoreTIP integration enabling MISP users to access DomainTools domain intelligence within their threat intelligence platform.
- ThreatConnectcoreSOAR/TIP integration partnership providing ThreatConnect users access to DomainTools domain intelligence.
- TinescoreSOAR integration enabling Tines users to automate workflows incorporating DomainTools domain intelligence.
- TorqcoreSOAR integration partnership providing Torq users access to DomainTools domain intelligence for security automation.
- Rapid7coreSOAR integration enabling Rapid7 users to leverage DomainTools threat intelligence in their security operations.
- The Hive and CortexcoreSOAR integration enabling The Hive and Cortex users to incorporate DomainTools domain intelligence into investigations.
- Cortex XSIAMcoreSIEM integration providing Cortex XSIAM users access to DomainTools domain intelligence capabilities.
- PolaritycoreTIP integration enabling Polarity users to access DomainTools domain intelligence within their security workflows.
- ThreatQcoreSOAR/TIP integration partnership providing ThreatQ users access to DomainTools domain intelligence.
- IBM ResilientcoreSOAR integration enabling IBM Resilient users to incorporate DomainTools domain intelligence into incident response.
- Google SOARcoreSOAR integration enabling Google Security Operations users to leverage DomainTools threat intelligence.
- Splunk SOARcoreSOAR integration specifically for Splunk SOAR users to automate DomainTools domain intelligence workflows.
- CriblcoreIntegration for continuous enrichment enabling Cribl users to incorporate DomainTools intelligence into their data pipelines.
- Farsight SecuritycoreAcquisition completed November 2021, bringing Farsight Security's passive DNS database (DNSDB) and security intelligence capabilities into the DomainTools portfolio. The acquisition expanded DomainTools' security capabilities and data assets.
Scale indicators7 records
Recent moves5 records
Expansion highlights4 records
DomainTools competitors and assessment
Company assessmentDirect peers
- Recorded Future: One of the largest commercial threat intelligence platforms, offering broad indicator-of-compromise and adversary intelligence. Directly comparable to DomainTools as an enterprise-paid threat intelligence subscription with strong SIEM/SOAR integration footprint.
- Mandiant (Google Cloud): Leading adversary and infrastructure intelligence provider, now part of Google Cloud. Overlaps directly with DomainTools' APT/infrastructure mapping use cases for SOC, IR, and government customers, and competes for similar threat intel budget.
- Anomali: Threat intelligence platform (TIP) that aggregates and correlates feeds for enterprise SOCs. Both a DomainTools integration partner (consuming DNS intel) and a competitor in the threat intel management layer.
- RiskIQ (Microsoft Defender Threat Intelligence): External attack surface and internet intelligence platform originally built on passive DNS and WHOIS data, now integrated into Microsoft's security stack. Closest direct functional competitor to DomainTools' DNS/internet intelligence core.
- Censys: Internet intelligence and attack surface management platform built on continuous scanning and certificate/passive data. Comparable to DomainTools for external threat and infrastructure visibility, particularly for enterprise ASM buyers.
- EclecticIQ: Threat intelligence platform targeting enterprise SOCs, governments, and MSSPs with CTI feeds and TIP tooling. Overlaps with DomainTools' intelligence platform use cases and is both an integration partner and competitor.
Emerging players
- Shodan: Internet-connected device search and intelligence platform used heavily by researchers and security teams. Comparable as an alternative source of internet intelligence feeding into threat hunting and exposure workflows.
Broad incumbents
- CrowdStrike Falcon Intelligence: Endpoint and XDR incumbent that also offers adversary/threat intelligence and integrates third-party DNS data. Comparable as both a buyer of DNS intelligence (existing DomainTools integration partner) and a potential vertical integrator competitor.
- Palo Alto Networks Unit 42: Threat intelligence arm of a major network/security platform incumbent. Comparable buyer of DNS intelligence via DomainTools integration and a competitor for the same enterprise threat intel budget.
- Infoblox: DNS, DDI and protective DNS incumbent that publishes the DNS Threat Landscape Report cited by DomainTools. Comparable as a security-via-DNS incumbent and potential competitor in protective DNS and DNS-layer threat intelligence.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
DomainTools social profiles
Digital presenceDomainTools financial estimates
Financial estimateRevenue estimate
Valuation estimate
DomainTools leadership team
Management profileNumber of profiles
Profiles5 records
DomainTools subsidiaries and ownership
Company hierarchySubsidiaries1 record
DomainTools funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
DomainTools M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about DomainTools
What does DomainTools do?
DomainTools sells a subscription-based Internet intelligence platform that combines the world's largest passive DNS database (DNSDB), machine-learning-based domain risk scoring, and an investigation workbench (Iris Investigate) for security teams to detect, profile, and respond to malicious domains and attacker infrastructure. Its offering is delivered as SaaS subscriptions, APIs, real-time threat intelligence feeds, and an MCP Server for AI agent integration, with pre-built connectors to SIEM, SOAR, TIP, and XDR platforms.
Is DomainTools a public or private company?
DomainTools is a private company. It is classified as unknown and is currently operating.
When was DomainTools founded?
DomainTools was founded in 2004. It employs 11 to 50 people.
Where is DomainTools based?
DomainTools is headquartered in Seattle, United States, in the North America region.
How does DomainTools make money?
Four revenue lines are on record. Subscription-based SaaS are the primary driver. The others are enterprise Subscriptions, API/Developer Access and threat Intelligence Feeds.
Who are DomainTools's main competitors?
Direct peers on record are Recorded Future, Mandiant (Google Cloud), Anomali, RiskIQ (Microsoft Defender Threat Intelligence), Censys and EclecticIQ. Shodan is listed as an emerging player. Broad incumbents are CrowdStrike Falcon Intelligence, Palo Alto Networks Unit 42 and Infoblox.
Does DomainTools have an API?
Yes. DomainTools offers a public API enabling developers to access domain intelligence data including Risk Scores, hosting history, passive DNS records, and infrastructure connections. The API supports feed-based access including Newly Observed Domains (NOD) feed and Domain Hotlist feed with features such as session management, configurable polling frequency (down to every 60 seconds), 5-day data retention, and server-side pattern filtering. API endpoints include https://api.domaintools.com/v1/feed/ for real-time threat intelligence feeds. Developer documentation is at docs.domaintools.com/api.
What industry is DomainTools in?
DomainTools's product category is Threat Intelligence and Domain Security Software. Its primary akta.pro industry code is HDADABAF, DNS Security & Protective DNS, with a secondary code of HDAFAGAF, IP Address Management (IPAM) & DNS/DHCP Management (DDI). Its NAICS code is 5132 and its SIC code is 7370.