Reports
Executive and technical views for domain posture, platform exposure and remediation.
Internet Infrastructure Intelligence
Datazag maps malicious infrastructure at certificate issuance — surfacing whole campaigns before the first domain attacks — and delivers scored, annotated intelligence straight into your SIEM, warehouse and controls.
Coverage
Finding the other 149 domains means already holding the ones they connect to. This is what Datazag observes, and what each figure counts.
Distinct domains that resolve — every name answering with a record or an empty response. Names that no longer exist (NXDOMAIN) and names whose servers failed or timed out are excluded, so this counts the live corpus rather than every domain ever queried.
Measured 14 Sept 2026, 00:38 UTC
Distinct IPv4 addresses that a domain in the measured corpus resolves to, taken over the same population as the domain figure above.
Measured 14 Sept 2026, 00:38 UTC
IPv4 space announced in BGP and attributed to a network, counted once per address however many announcements cover it — a more-specific prefix inside its parent is not counted twice.
Measured 14 Sept 2026, 00:38 UTC
Autonomous systems with ownership and routing context attached, used to place infrastructure in the network that announces it.
Measured 14 Sept 2026, 00:38 UTC
Coverage measured 14 September 2026. What the internet is doing right now — certificates, newly observed domains, routing changes — lives in the Observatory.
Relationship Intelligence
A certificate, DNS change or routing event is only the first clue. Datazag uses it as a pivot into related domains, IPs, certificates, providers, networks and historical observations.
That relationship context turns one signal into a wider campaign view. Intelligence then becomes evidence packaged for the way each team works: reports, alerts, APIs and cloud data shares.
See this exact pivot run on a real criminal hosting cluster: One Signal, 150 Domains →
Into your stack
One platform · multiple delivery methods
Reports, alerts, APIs and datasets are not separate products. They are different ways to consume Datazag's continuously updated infrastructure intelligence.
Datazag Intelligence Platform
Infrastructure Graph
Domains, DNS, certificates, hosting, ASNs, platforms, history, evidence and risk context.
Executive and technical views for domain posture, platform exposure and remediation.
Real-time intelligence for SOC workflows, partner monitoring and platform abuse teams.
Lookup, score and enrich domains, infrastructure and platform indicators inside your products.
Continuously refreshed intelligence delivered into your analytics and marketplace stack.
Datazag Observatory
Search, pivot, visualize and download aggregated infrastructure intelligence from Datazag's continuously updated internet graph.
The same pivot builder mapped 150 domains from a single signal: read the investigation →
Snapshot 06:00 UTC
412
New domains
last hour
83
Alert candidates
scored
17
Routing changes
snapshot
Pivot builder
Preview
Timeline
Graph
Who it’s for
White-label investigations and earlier alerts across your whole client base.
Explore→External infrastructure signal for underwriting and portfolio monitoring.
Explore→Safer sending and onboarding decisions from infrastructure intelligence.
Explore→Scored, explainable intelligence delivered into the stack you already run.
Explore→Free Domain Health Report
Datazag reviews public DNS, visible platforms, subdomains, certificates and infrastructure exposure, then sends a detailed multi-page report for technical and executive teams.
Not ready to enter an email? View a sample report
We use publicly observable infrastructure signals. No agent, questionnaire or asset inventory is required.
Generated analysis
The report is generated from live checks, platform fingerprints, subdomain review and infrastructure intelligence.
Multi-page report
example.com
Executive summary
Overall risk · key exposure · priority actions
Platform exposure
Microsoft 365 · Cloudflare · Google Workspace
DNS & subdomain health
SPF · DMARC · MTA-STS · ownership · takeover signals
Technical findings
Evidence, context and prioritized remediation
Recommended action
Review email authentication, exposed platforms and subdomain ownership before attackers exploit weak signals.