FlowRunner
PricingContact
Theme
Start Free

Query live DNS records and trace domain ownership and hosting history with the ViewDNS research toolkit. Agents investigate a domain before trusting an inbound signup or a supplier.

22 actions API key available
ViewDNS website ↗ Platform Documentation ↗ Capability data verified 2026-07-31
A supplier emails updated bank details from a domain that resembles the one on file
Agent isolates the sending domain and the domain of record from the vendor master
Agent runs WHOIS Lookup on both domains for registrar, creation date and registrant
Agent runs Get IP History and Reverse IP Lookup to compare hosting lineage and neighbours
Agent runs Lookup DNS Records and Reverse DNS Lookup to confirm the mail path matches the domain of record
Agent assembles the two domains side by side with every field that differs highlighted
Finance approver decides whether to accept the payment instruction change or reject the request

What This Integration Enables

ViewDNS is not a monitoring product and reading it as one misses the point. It is a research toolkit for the question that sits underneath a lot of expensive mistakes: who is actually on the other end of this. A domain arrives in a payment instruction, a supplier form, an inbound signup, or a phishing report, and somebody has to decide whether to trust it. ViewDNS supplies the record trail. WHOIS Lookup returns parsed registration data including registrar, creation, update and expiry dates, registrant and administrative contacts, nameservers and status codes. Reverse WHOIS Lookup finds every other domain registered to the same name or email. Get IP History traces which addresses a domain has resolved to over time with the owning ISP for each. Reverse IP Lookup lists the other domains sharing the same server, and Discover Subdomains enumerates known subdomains with their resolved addresses.

Around that sit live DNS operations that bypass local caches, a global propagation check for confirming a cutover landed everywhere, blacklist screening against more than thirty spam databases including Spamhaus and SORBS, IP geolocation, abuse contact resolution, ping and traceroute from multiple continents, HTTP header inspection, and reachability tests from inside the Chinese and Iranian filtering regimes. Because FlowRunner connectors are built and verified against each vendor's official API, an agent can assemble that dossier the same way every time and present it in a consistent shape. What the agent does not do is convert the dossier into a verdict on its own, because the cost of a wrong verdict here falls on a real counterparty.

Without FlowRunner

Trust decided on appearance A domain that looks right is treated as the domain of record
Research done by hand Checking registration, hosting and mail routing means visiting several lookup sites
Findings not retained The evidence behind an approval lives in the approver's browser tabs

With FlowRunner

Trust decided on records Registration date, hosting history and mail path are gathered before anyone approves
One pass, many angles Registration, DNS, reverse lookups and blacklist checks run in a single flow
Findings attached Every field the agent gathered is stored with the decision it informed

Use Case Scenarios

Verifying a payment instruction change before finance acts on it

A supplier sends new bank details. The agent compares the sending domain against the vendor master, runs WHOIS Lookup on both, and pulls the creation date, registrar and registrant for each. It checks whether the mail path resolves through the same infrastructure with Lookup DNS Records and Reverse DNS Lookup, and whether the sending IP appears in any blacklist with Check Spam Databases. The findings go into the approval request in Slack alongside the two domains rendered side by side. A finance approver makes the call. The agent never releases the change on the strength of a lookup.

Supplier onboarding screening attached to the vendor record

A new supplier submits an onboarding form. The agent runs WHOIS Lookup for registration age and registrar, Get IP History for hosting lineage, Reverse WHOIS Lookup for the other domains the same registrant holds, and Check Free Email Domain on the contact address domain. For a deeper read on the contact address itself, the same flow can call UserCheck, which is purpose built for disposable and relay detection. Everything gathered is written into the vendor record in Airtable so the file shows what was known at the moment of approval, not what a lookup returns a year later.

Routing an abuse report to somewhere it will be read

A phishing page is reported that impersonates a company brand. The agent resolves the hosting provider with Reverse DNS Lookup and Get IP History, resolves the correct destination with Get Abuse Contact, and captures the served headers with Get HTTP Headers for the report body. It drafts the complaint with the evidence attached and opens the tracking ticket in Jira. Brand protection teams spend most of their time finding the right recipient, and that part is mechanical.

Human-in-Loop Highlight

Domain age is the single most seductive fraud signal in this toolkit and the one most likely to be wrong about a real business. WHOIS Lookup will tell an agent that a supplier's domain was registered eleven days ago. That is exactly the profile of an invoice fraud setup, and it is also exactly the profile of a company that rebranded last month, a regional subsidiary that just spun up, or a supplier who finally moved off a shared marketplace domain. An agent that auto rejects on registration age will block real counterparties, and the person on the other end will never know why their onboarding stalled.

So the agent assembles rather than adjudicates. It presents the whole picture to the approver in one message: registration date and registrar, the registrant's other domains from Reverse WHOIS Lookup, the hosting lineage from Get IP History, the shared hosting neighbours from Reverse IP Lookup, the mail path, and the blacklist result, followed by the question it cannot answer. "Domain registered 11 days ago, registrar and registrant differ from the domain on file, no blacklist hits, mail resolves to a different provider than the vendor master. Approve this supplier, request documentation, or reject?" A second rule follows from the same principle. Most operations here are passive lookups against public records, but Scan Ports and Discover Subdomains actively probe infrastructure that belongs to someone else, and Download Newly Registered Domains pulls a large feed into storage. An agent does not run those against a third party as part of routine screening. It asks for the instruction first, names the target, and records who authorised it.

Agent processes routinely
Detects exception requiring judgment
Clear match Continues automatically
Ambiguous Routes to human via preferred channel
Human decides
Agent resumes with decision

Agent Capabilities

22 actions

DNS Lookups

6
  • Lookup DNS Records Retrieves live DNS records for a hostname straight from the authoritative nameservers, bypassing local caches. Returns each record's name, TTL, class, type and data, plus priority for MX records. Query one record type or request every record at once.
  • Check DNS Propagation Resolves a hostname from DNS servers around the world to confirm a record change has propagated everywhere, returning the expected address alongside what each location actually resolved and a per location status. Used after a migration or cutover to find stale resolvers.
  • Reverse DNS Lookup Resolves the pointer record for an IP address in real time, returning the hostname the address maps back to. Used to validate mail server reverse DNS, attribute log entries to named hosts, and confirm that forward and reverse DNS agree.
  • Reverse IP Lookup Lists every other domain hosted on the same IP address or server as the supplied host, with the date each domain last resolved there. Returns up to 10,000 results per page. Used to map shared hosting neighbourhoods and uncover related web properties.
  • Reverse MX Lookup Finds all domains routing their email through a given mail server, returning the total count, pagination metadata and the matching domains. Used to size a mail platform's footprint and investigate shared mail infrastructure.
  • Reverse NS Lookup Lists every domain that delegates to a given nameserver with the total count and pagination metadata. Used to audit a DNS provider's customer base and identify domains sharing infrastructure.

Domain Intelligence

7
  • WHOIS Lookup Returns parsed WHOIS registration data for a domain or IP address, including registrar name and IANA ID, creation, update and expiry dates, registrant, administrative and technical contacts, nameservers, status codes and the raw WHOIS text. This is the anchor record for ownership research and expiry monitoring.
  • Reverse WHOIS Lookup Searches WHOIS records for every domain registered by a given registrant name or email address, returning each match with its creation date and registrar. Used for brand protection, portfolio discovery and mapping networks of related registrations.
  • Get IP History Returns the historical record of IP addresses a domain has resolved to over time, each entry carrying the address, geographic location, owning ISP or hosting provider and the date it was last seen. Used to trace hosting migrations and support infrastructure forensics.
  • Discover Subdomains Enumerates known subdomains of a domain with resolved IP addresses and last resolution timestamps, plus total count and pagination metadata. Used for attack surface mapping, shadow IT discovery and inventorying forgotten staging hosts.
  • Check Free Email Domain Determines whether a domain is used to provide free or disposable email addresses and returns a plain language verdict. Used as a quick gate on signups and lead quality inside a broader domain investigation.
  • Get Abuse Contact Resolves the abuse reporting email address responsible for a domain or IP address. Used to route phishing, spam and network abuse complaints to the correct registrar, hosting provider or network operator.
  • Download Newly Registered Domains Downloads the newly registered domains feed for a single calendar day into FlowRunner file storage and returns the file URL. Choose the plain domain list or the enriched variant. The feed is delivered as a gzip archive and can be large.

IP Intelligence

3
  • Get IP Location Geolocates an IP address, returning city, postal code, region, country, latitude and longitude plus GMT and daylight saving offsets. Used to localise content, enrich visitor analytics and add geographic context to security events.
  • Check Spam Databases Checks an IP address against more than thirty spam blacklists including Spamhaus and SORBS, returning each database with its listing status. Used before sending campaigns, when diagnosing delivery failures, and to monitor outbound mail server reputation.
  • Lookup MAC Address Identifies the hardware manufacturer registered to a MAC address by querying the IEEE OUI database, returning the manufacturer name and registered address. Used for asset inventory and network device identification.

Network Diagnostics

4
  • Ping Host Pings a host from locations across Asia, Oceania, Africa, Europe, North America and South America, reporting the resolved IP address, minimum, maximum and average round trip times and packet loss per location. Used for global latency benchmarking and regional performance monitoring.
  • Run Traceroute Traces the network path to a domain or IP address, returning every hop in order with hostname, IP address and round trip time. Used to diagnose routing problems and confirm which transit or CDN providers traffic passes through.
  • Scan Ports Scans a host for a fixed set of commonly targeted ports covering FTP, SSH, Telnet, SMTP, DNS, HTTP, POP3, NetBIOS, IMAP, HTTPS, SMB, MSSQL, Oracle, MySQL, RDP and common alternate web ports, returning each port with its service name and open or closed state. The port list is fixed and cannot be customised.
  • Get HTTP Headers Retrieves and parses every HTTP response header returned by a web server, including the status line, content type, caching directives, cookies and security headers. Returns name and value pairs for auditing security posture or verifying CDN and caching configuration.

Censorship Tests

2
  • Test Chinese Firewall Tests whether a domain or URL is reachable from inside mainland China by running DNS and HTTP checks from multiple Chinese locations, returning expected addresses, per location results and an overall visibility summary.
  • Test Iran Firewall Tests whether a site is accessible from inside Iran, returning a censorship test result for the supplied domain or URL. Used alongside the Chinese firewall test to monitor which national filtering regimes are blocking a web property.

Frequently Asked Questions

What can FlowRunner do with ViewDNS?

FlowRunner agents can run Lookup DNS Records, Check DNS Propagation, and Reverse DNS Lookup in ViewDNS, plus 19 more actions.

Does connecting ViewDNS to FlowRunner require OAuth?

No. ViewDNS connects to FlowRunner with an API key, no OAuth flow required.

Can ViewDNS trigger a FlowRunner workflow automatically?

ViewDNS doesn't currently expose triggers in FlowRunner. It connects as an action step inside workflows started by another trigger.

Start building with ViewDNS

$100 in credits. No card required. Connect in minutes.