WhoisFreaks
Identity & SecurityWhoisFreaks is a WHOIS, DNS, and domain intelligence API. Agents run live and historical WHOIS and DNS lookups, check domain availability, find typosquats and subdomains, inspect SSL certificates, and score IP reputation.
What This Integration Enables
Most domain lookups answer what a name looks like today. WhoisFreaks is built around the fact that today is rarely the interesting part. Whois History returns every record the platform holds for a domain, so comparing consecutive entries shows when it changed hands, changed registrar or changed name servers. DNS History does the same for infrastructure, showing when a domain moved hosting or swapped mail providers. Reverse Whois Search turns one known email address, registrant name or organization into every domain registered behind it, and Reverse DNS Lookup pointed at a name server or a mail host maps a whole hosting estate. That is the shape of the tool: it is a corpus, not a resolver.
FlowRunner agents use it to keep the reads running continuously and to assemble evidence rather than fragments. This connector writes nothing, so the risk it carries is not in the API. It is in what a workflow does with an answer, which is exactly the boundary FlowRunner's human-in-the-loop design is drawn around: the agent gathers, correlates and ranks, and the decisions that reach a third party belong to a person.
Without FlowRunner
With FlowRunner
Use Case Scenarios
-
Watching the portfolio for the things that quietly break it
A domain that stops resolving takes a website, an email flow and every sign-in redirect with it. On a schedule the agent runs Bulk Whois Lookup across the whole portfolio in one call rather than one request per name, and watches two fields: the expiry date, and the domain status codes that signal a registry hold or a pending deletion. SSL Certificate Lookup is checked at the same time, both for the expiry date and for growth in the certificate's alternative names, since a certificate that has quietly acquired hosts nobody recognizes is worth a look. Anything inside the alert window raises an incident in PagerDuty and a row in Google Sheets for the renewal owner.
-
Building the attack surface inventory that live DNS cannot
Find Subdomains returns the subdomains the platform knows about, with the dates each was first and last seen, and its status filter is the part that matters: the inactive entries are the forgotten staging and legacy hosts that an inventory built from live DNS never sees. The agent pulls the inactive set, checks each against IP Reputation Lookup and Domain Security Lookup, and cross-references anything still pointed at company infrastructure through Cloudflare. The output is a list of hosts the security team did not know existed, which is usually the useful half of an attack surface.
-
Due diligence on a domain somebody wants to buy
Before a domain purchase, the agent runs Check Domain Availability, then reads Whois History and DNS History to see what the name was used for previously. A name that has changed hands repeatedly, hosted a mail server for a period, and appears in Domain Security Lookup with an abuse association is not the same purchase as a name that has sat parked since registration. The agent presents both records side by side. It does not score the domain, because the judgment about whether a name's history is acceptable is a business one.
Human-in-Loop Highlight
The costly act on this connector is not a call to WhoisFreaks. It is the abuse complaint that follows one. Find Typosquat Domains generates the homoglyph and lookalike variations of a brand name and reports which are registered, and that list is genuinely the set an attacker registers before impersonating a company. It is also, reliably, a mixed bag: some entries are defensive registrations the company itself made years ago, some belong to unrelated businesses with a legitimate claim to a similar name, some are parked, and some are live phishing. IP Whois Lookup gives the netblock's abuse contact, which makes filing a complaint a single step. Filing one against a legitimate business is not something an apology takes back.
There is a second reason to keep a person here, and it is specific to this data. A registry that redacts under privacy rules returns the registrar and the dates and no registrant details at all, and that is not an error and not evidence of hiding. A workflow that treats an empty registrant field as a hostile signal will manufacture suspects. So the agent assembles the case and stops: "Eleven registered lookalikes. Four resolve to live hosts, three of those serve a certificate naming our brand, and one changed hands last month per the WHOIS history. Registrant is redacted on six, which the registry does under privacy rules rather than at the holder's request. Here is the abuse contact for each. Which do we file on?" Counsel decides. The agent's contribution is that the evidence was already assembled when the question was asked.
Agent Capabilities
18 actionsWHOIS
4- Whois Lookup Returns a domain's live WHOIS record: registrar, registrant, name servers, status codes and the create, update and expiry dates. The expiry date and the status codes are the two fields worth alerting on.
- Whois History Returns every historical WHOIS record the platform holds for a domain. Comparing consecutive records shows when a domain changed hands, registrar or name servers, which a live lookup cannot tell you.
- Reverse Whois Search Finds every domain registered to an email address, registrant name, organization or keyword across the current and historical corpus. The highest-value operation here for security and brand work, and the most tightly rate limited.
- Bulk Whois Lookup Looks up WHOIS for a list of domains in one call, which is the right shape for auditing a portfolio without spending one request per name.
IP and ASN
2- IP Whois Lookup Returns the WHOIS registration behind an IP address: the netblock, its allocated organization, abuse contacts and the regional registry. The abuse contact is the actionable field.
- ASN Whois Lookup Returns the registration for an autonomous system number: its organization, country, registry and announced prefixes.
DNS
4- DNS Lookup Returns a domain's live DNS records. Requesting all types in one call costs one lookup rather than one per record type, and a type the domain does not publish comes back absent rather than as an error.
- DNS History Returns a domain's historical DNS records, which is an infrastructure timeline: when a domain moved hosting, changed mail providers or pointed somewhere else. Live DNS destroys exactly this.
- Reverse DNS Lookup Finds every domain whose DNS points at a given value, whether an address for an A record, a host for a mail or name server record, or a string in a text record. Pointed at a name server it maps a whole hosting estate.
- Bulk DNS Lookup Queries DNS for a list of domains in one call, the same batching shape as the bulk WHOIS operation.
Domain Intelligence
5- Check Domain Availability Reports whether a domain can be registered, optionally with alternative suggestions. Available is not the same as registrable, because a name can be unregistered and still be blocked as premium, reserved or held in a redemption period.
- Find Taken Domains Returns registered domains whose name contains a keyword, across the covered top level domains. It surfaces the lookalikes somebody has already registered, which an availability check never will.
- Find Typosquat Domains Generates the typo, homoglyph and lookalike variations of a keyword and reports which are registered. These are the domains an attacker registers before impersonating a brand, and they are invisible to an exact-name check.
- Find Subdomains Returns the subdomains known for a domain, with the dates each was first and last seen. The inactive filter is the interesting part, because forgotten staging and legacy hosts make up most of an attack surface.
- SSL Certificate Lookup Returns a domain's live certificate: issuer, subject, validity dates, alternative names and optionally the chain. The expiry is the field to alert on, and a growing list of alternative names is the second.
Security Intelligence
3- IP Geolocation Lookup Returns the geographic and network detail behind an address. Geolocation is an estimate rather than a fact, so it belongs in a picture and not in an access decision on its own.
- IP Reputation Lookup Returns security intelligence for an address: whether it is a proxy, a VPN, an exit node, a hosting range, a known bot or a listed threat. The hosting and datacenter flags are the most useful signal, and legitimate users behind a corporate VPN look exactly like the thing being flagged.
- Domain Security Lookup Returns security intelligence about a domain rather than an address, including association with malware, phishing or other abuse.
Frequently Asked Questions
What can FlowRunner do with WhoisFreaks?
FlowRunner agents can run Whois Lookup, Whois History, and Reverse Whois Search in WhoisFreaks, plus 15 more actions.
Does connecting WhoisFreaks to FlowRunner require OAuth?
No. WhoisFreaks connects to FlowRunner with an API key, no OAuth flow required.
Can WhoisFreaks trigger a FlowRunner workflow automatically?
WhoisFreaks doesn't currently expose triggers in FlowRunner. It connects as an action step inside workflows started by another trigger.
Start building with WhoisFreaks
Free plan, no card required. Connect in minutes.