Lookup API Real-time threat intelligence queries
Query our threat intelligence database in real-time. Get instant risk scores, threat categories, and enrichment data for any domain, IP, or URL.
No credit card required · Free API key
risk score · threat categories · sources · age · confidence — in one request
<0ms
Cached Lookup
Indexed
Observables
Configured
Data Sources
Live
Health Endpoint
Key features. Everything you need to protect your infrastructure and users.
Domain Lookup
Check domain reputation with WHOIS and DNS enrichment.
IP Lookup
Get IP reputation with geolocation and ASN data.
URL Lookup
Scan URLs with redirect chain analysis.
Low-latency results
Sub-100ms response times for cached entities.
Risk Scoring
Normalized 0-100 risk score with confidence levels.
Rich Data
Threat categories, sources, and contextual data.
Use cases. How security teams use this tool.
Web Applications
Check user inputs and external links in real-time.
Email Filtering
Verify sender domains and embedded URLs.
Security Tools
Enrich alerts with threat intelligence.
Fraud Prevention
Assess risk during transactions and signups.
Real-Time Threat Intelligence API
The Lookup API provides instant access to our comprehensive threat intelligence database. With sub-100ms response times for cached entities, you can integrate real-time security checks into your applications without adding noticeable latency. Whether you're validating user inputs, filtering email content, or enriching security alerts, the Lookup API delivers specific threat data when you need it most.
Response Format and Data Fields
Every API response includes a normalized risk score from 0-100, threat categories describing the specific type of malicious activity detected, source attributions showing which intelligence feeds flagged the entity, and optional enrichment data including WHOIS records, geolocation, and ASN information. Confidence levels help you calibrate your security policies based on the strength of evidence behind each detection.
Integration Patterns for Security Teams
The Lookup API integrates directly with existing security infrastructure. Embed checks in web application workflows to validate user-submitted URLs, integrate with email gateways to scan sender domains and embedded links, enrich SIEM alerts with threat context to accelerate triage, and add reputation checks to fraud prevention pipelines. Our SDKs handle authentication, retries, and rate limiting automatically, letting you focus on security logic.
Getting Started with the Lookup API
Start using the Lookup API in minutes: sign up for a free account to receive your API key, install your preferred SDK or use direct REST calls, and begin querying domains, IPs, and URLs. The free tier includes 30 requests per month, enough to prototype your integration and evaluate the quality of our threat intelligence before committing to a paid plan.
Frequently asked questions.
What can I look up with this API?
What is the response time?
How many requests can I make?
What data is included in the response?
Related articles. Learn more from our security research blog.
Ready to get started?
Rejoignez des milliers d'équipes de sécurité qui utilisent isMalicious pour protéger leur infrastructure.
No credit card required · Free API key