Jonathan Zhang, CEO of WhoisXML API, one of the world's leading WHOIS and DNS data aggregators and providers, briefly describes what the WhoisXML API does.
SecNews, in collaboration with the WHOisXML API, identified domain names that have been used to infect Greek citizens with the Predator malware.
Learn more: Predator surveillance - This is how they targeted politicians, citizens and companies!

WhoisXML API stands out from other data aggregators because it provides some of the most comprehensive and accurate sources of domain, IP , and DNS data in the industry, thanks to over ten years of data monitoring.
The data it provides enables a variety of use cases. The service’s comprehensive repositories built using unique data collection help streamline cybersecurity processes and operations, such as attack surface management (ASM), digital risk protection, and managed detection and response (MDR). In fact, since it uses a data-as-a-service business model, the data also feeds into many types of security platforms.
Furthermore, data applications go beyond the realm of cybersecurity. They augment critical business processes, such as know-your-customer (KYC) processes, market forecasting, service discovery, competitive research and monitoring, and business-to-business (B2B) target market profiling.
They also recognize that customers receive information from many sources, so they ensure that data is delivered in readable and well-analyzed formats and offer flexible delivery models that best meet user needs.

How did the WhoisXML API success story begin and what was the need of the founders that led to its creation?
The idea first took shape in 2010 when I was a software engineer working on a network security project. To make it work, I needed access to consolidated and structured raw WHOIS data, but it was very difficult to find.
WHOIS records from multiple registries and registrars came in different formats, so the data was difficult to integrate. Proper data integration would take thousands of hours of work. While there were a few integrated data providers back then, they were also quite expensive.
So, the WhoisXML API was born out of the need for WHOIS data, which led to the idea of creating a company that would help businesses and organizations achieve security and, ultimately, make the Internet safer.
Your products are based on machine learning. How do you manage to avoid poor data and unreliable results?
While machine learning and data mining are the leading technical methods for aggregating and unifying our data, what happens behind the scenes is equally important in ensuring structured, reliable, and high-quality data.
For example, we have long-standing legal partnerships with Internet Service Providers (ISPs), registries, and registrars around the world. We also work with organizations in the cybersecurity community to identify abusive domains using passive DNS (pDNS) data. In addition, we clean our data to reduce “noise” for our customers to avoid propagating errors. These relationships and processes allow us to update our data daily, contributing to its accuracy and reliability.
How can a business benefit from using the WhoisXML API? Can you introduce us to the WhoisXML API products?
We provide WHOIS, IP and DNS information that organizations need to power their business processes. We have a variety of solutions for different security and business capabilities, including:
- Attack Surface Intelligence
- Cyber Threat Intelligence
- Digital Risk Protection Intelligence
- Know Who You're Talking To (KWYTT) Intelligence
- Law Enforcement Intelligence
- Market and Competitive Intelligence
- Security Operations and Platform Intelligence
In addition to these solutions, our domain search and monitoring products are also available as standalone APIs, data feeds, real-time feeds, and web-based search tools.
How do you contribute to the world of cybersecurity?
Our information helps the security community gain broader and deeper visibility into the Internet, allowing it to respond quickly and effectively to cyber threats and trends.
Our customers use WhoisXML API data to combat fraud, particularly by enabling real-time DNS-based threat customization for security teams and companies. We also work with threat hunters, cybercrime investigators, and security researchers to help them add context to indicators of compromise (IoC), map malicious infrastructure, and find hidden connections and clues in DNS.
The WhoisXML API contributes to the work of law enforcement agencies against counterfeiting, child exploitation , and other crimes.
What keeps your company on the move and your customers happy?
The goal of WhoisXML API has always been to work towards transparency and security on the Internet. We continue the journey by providing high-quality, reliable and comprehensive IP, DNS and WHOIS data to our customers. We also ensure that our data is delivered in readable formats so that it can be easily integrated with other information sources.
As one of our customers says, “Through the WhoisXML API, we can access DNS, WHOIS, and IP information with real-time coverage. The data works seamlessly with our other intelligence sources, allowing us to derive the most complete cyber threat intelligence so we can analyze and predict threat behaviors and provide timely information to our users.”
What can we expect from the WhoisXML API in the future?
We will continue to work on our mission to create a safer and more transparent Internet, especially as access to WHOIS records becomes more difficult, making security investigations more challenging.
We will continue to expand our data coverage. Currently, we have 4.2+ billion domains and subdomains, 4+ billion DNS records, and 15.6+ billion WHOIS records, and we track 99.5% of assigned IP addresses. Our goal is to grow this data for optimal accuracy and reliability.
We will also strive to provide real-time data and reduce the windows of opportunity that exist between domain registration and abuse for faster threat remediation.
For more information about our offerings and how they can help the cybersecurity world, contact WhoisXML API.
