Skip to main content
Piloterr
Back to library

Domain Malicious API

Check if a domain or IP address has been flagged as malicious across multiple threat intelligence feeds, with source attribution.

Active1 credit = 1 requestGET/v2/domain/malicious

Endpoint Overview

Detailed documentation, pricing, and usage examples.

OverviewLink to Overview

The Domain Malicious endpoint checks any domain or IP address against community-curated threat intelligence feeds to determine if it has been flagged for malicious activity. It returns a boolean verdict along with the specific sources that reported the threat.

QuickstartLink to Quickstart

GET https://api.piloterr.com/v2/domain/malicious?query=197.33.189.70

ParametersLink to Parameters

Parameter Type Required Description
query string yes Domain name or IP address to check

Response fieldsLink to Response fields

Field Type Description
malicious boolean Whether flagged as malicious
sources array Threat feeds that reported the address
sources[].url string URL to the threat list
sources[].name string Source name
sources[].type string Indicator type: ip or domain

NotesLink to Notes

  • Aggregates data from multiple open-source threat intelligence feeds.
  • Empty sources with malicious: false means no known threat reports.

Main use casesLink to Main use cases

  • Screen inbound traffic IPs for known malicious actors
  • Validate third-party vendor domains in supply chain security checks
  • Enrich SIEM workflows with threat classification data
  • Block malicious IPs at the firewall or API gateway level

Related APIs

Expand your data capabilities with these complementary tools.

Ready to get started?

Your web scraping API is one click away. Start with +500 credits, no infrastructure to set up, no proxies to manage, and no credit card required.

  • +500 credits
  • No credit card required
  • All endpoints included