draconic21
Guide + free tool · domain identity data

Domain Age / WHOIS RDAP API

Before you trust an email or a link, check the domain behind it: how old is it, who's the registrar, and does it even publish SPF/DMARC so its mail can't be spoofed? Here's a free live check, then the paid API behind it.

Try it free — check a domain

Live, no signup. Reads IANA's RDAP bootstrap + the TLD registry's own RDAP server, plus a live DNS read.


RDAP, not legacy WHOIS

WHOIS was a loosely-standardized, free-text protocol with no consistent schema across registries. RDAP (Registration Data Access Protocol) is its IETF-standardized, structured-JSON successor — IANA publishes a bootstrap registry mapping each TLD to its authoritative RDAP server, and this route reads that bootstrap live, then queries the right registry directly. Some ccTLD registries still publish no RDAP server at all; the response says so honestly (rdap.supported: false) instead of guessing or silently falling back to something else.

Post-GDPR, most registries redact registrant contact PII from public RDAP output by design ("differentiated access"). This route only surfaces what remains public everywhere — registrar, creation/expiration/last-changed dates, status, and nameservers — never private registrant details, and it is not a KYC/AML identity-verification or business-registration check.

Two signals, one call

SignalSourceWhat it tells you
RDAP registration dataIANA bootstrap + TLD registry RDAP serverRegistrar, creation/expiration/last-changed dates, status, nameservers — domain age is one of the strongest cheap fraud signals (a domain registered 3 days ago sending you an urgent invoice is a red flag most WHOIS/RDAP lookups would catch).
DNS email-auth postureThis server's own DNS resolver (no third-party DoH relay)MX (accepts mail?), SPF and DMARC (can mail from this domain be spoofed?), NS — combined into a heuristic posture.level (e.g. accepts mail + no SPF/DMARC = elevated).

Free before paying: /v1/domain_intel/availability + .../example.

Need a daily cap removed, or agent/API access?

Same feed, no cap

This free page calls the identical live builder used by the paid API.

Domain intel with no daily cap — $0.02/call, USDC on Base, no account → Prefer card billing? Subscribe on the RapidAPI Web Intelligence API → MCP tools — call domain_intel from any MCP-enabled agent →

Example (x402 pay-per-call)

curl -X POST https://draconic21-x402-api.onrender.com/v1/domain_intel \
  -H "content-type: application/json" \
  -d '{"domain":"example.com"}'
# unpaid: HTTP 402 + PAYMENT-REQUIRED header (sign with a Base USDC wallet, retry)

Agent / funded runtime? After you verify this feed, the cold-start buy on this origin is POST /v1/signal_latest — $0.03 USDC (Daily Agent Signal). Free wake: GET /health. Skill card: /skill.md · buyer loop: /agent-buy.md.

Independent public-data helper. This page and its linked API read public RDAP registry data (via IANA's bootstrap) and live DNS records — it is not affiliated with, endorsed by, or an official product of IANA, ICANN, or any registry/registrar. Not a KYC/AML identity-verification, business-registration, or fraud-scoring service, and not legal or compliance advice.