Our distributed, global crawler diligently ingests DNS records for every active TLD, identifying and adding 200–500k new domains to our dataset each day.
Leveraging advanced machine‑learning models, we tag domains with crucial context: identifying phishing, malware, disposable, and parked domains, and precisely mapping MX records to over 63k mailbox providers worldwide.
Access the intelligence seamlessly. Query specific domains via our low‑latency REST API, stream real‑time delta files directly to your S3 bucket, or read the complete, live dataset natively inside your Snowflake or BigQuery data warehouse.
Automatically enrich SIEM alerts for faster investigations, proactively block Business Email Compromise (BEC) attempts at your MTA, or cleanse customer email lists within your CDP to improve deliverability and reduce fraud.
Prioritise IOCs: “domain registered 3 days ago, tagged phishing → escalate”
Strip parked or disposable domains, analyse mailbox‑provider mix, boost inbox rates.
Remove junk traffic and fake sign‑ups by scoring domains at ingest.
Analysts query zag.domains
directly in Snowflake; pay by rows scanned.
Threat intelligence feeds lack the latest data
90% of all public & live domains
New domains added daily – typically 200-500k
domains
Domains checked and updated every minute
Raw DNS data without any business meaning
MX – Mailbox Provider mapping intelligence plus trusted provider flag
Domains - phishing / malware / parked / new domain flags
IPs - Geo & ISP designations
Need to know if a domain is safe now
New domains added daily. Unknown domains updated within 60 minutes.
APIs don’t fit your workflows
Plugs into any SIEM or MTA without heavyweight portal lock-in