Standard WHOIS lookup tells you who owns a domain. The WhoisFreaks Reverse WHOIS API flips that question: give it an email address, registrant name, company, or keyword and it returns every domain in our 4.1B+ record database connected to that identifier. Results are paginated in JSON or XML, and 500 free credits are included on signup.
Our Products
A forward WHOIS lookup starts with a domain and returns the owner. A reverse WHOIS lookup starts with an owner attribute - an email address, registrant name, company name, or domain keyword and returns all domains associated with it.
Features
Four search parameters: email, company, registrant name, and domain keyword.
Reverse WHOIS any registrant email, including wildcard patterns such as *@company.com, and list all of its domains.
Reverse WHOIS an organization name to map a company's entire domain portfolio, including brands it never announced.
Reverse WHOIS a registrant name to return every domain that a named individual has registered since 1986.
Reverse WHOIS a domain keyword between 3 and 63 characters to surface an entire brand or campaign footprint.
Use Cases
Where teams reach for reverse WHOIS instead of a single-domain lookup.
A reverse WHOIS search on a lead's email or company name returns the full domain portfolio for your CRM record.
Reverse WHOIS your own registrant email to surface forgotten domains before they lapse.
Reverse WHOIS one malicious domain's registrant email to map the rest of that actor's infrastructure in one query.
Reverse WHOIS your trademark as a keyword and catch cybersquatted domains before a phishing campaign starts.
Reverse WHOIS a competitor's organization name to reveal domains they registered before an unannounced launch.
Check a counterparty's claims with a reverse WHOIS search on their registrant email, using our pre-GDPR era records.
Start with 500 free credits. Search by email, registrant, company, or keyword across 4.1B+ WHOIS records, and page through results in JSON or XML.
Integrations
The WhoisFreaks Reverse WHOIS API ships with official Python and Go SDKs, so investigators and brand protection teams can retrieve every domain tied to an email, name, or company across 4.1B+ WHOIS records.
Zapier, Make, and n8n let non-technical teams automate reverse lookups, triggering watchlist pivots whenever a known threat actor email or brand keyword appears in new registrations and routing results to Slack.
Enterprise security operations integrate it into SIEM and SOAR platforms to expand domain indicators during incident response and surface the full registrant infrastructure behind a single malicious domain in real time.
To search for email addresses using regex in reverse WHOIS, use the 'email' parameter with regex patterns. The 'email' parameter supports:
Note: Regex matching is only available for email addresses. For keywords, owner/registrant names, or company names, use the optional parameter exact set to 'false', or omit it as it defaults to 'false'.