to discover and scan new domains
DNS answers processed every second
host scans every 5 minutes
of history, stored forever
Validin collects DNS, host responses, certificates, registration records, and curated OSINT for every domain we know about, every day, and keeps all of it. This page explains what we collect, how, and why it is different.
to discover and scan new domains
DNS answers processed every second
host scans every 5 minutes
of history, stored forever
Most DNS history is collected passively, by recording the queries other people happen to make. Popular domains show up constantly. The domain registered yesterday for next week’s phishing campaign may never show up at all.
We work the other way around. We run our own DNS infrastructure — no third-party resolvers — and resolve every name in our database at least once a day, with the most active domains refreshed up to five times a day. New domains come from hundreds of independent sources and our own discovery engine.
The lifecycle of a domain, tracked automatically - forever
Each dataset is collected and indexed on its own schedule, and all of them correlate: a certificate links to the hosts that served it, an IP address to the domains that resolved there, a domain to the actor reported behind it.
DNS
11 different DNS record types, each timestamped individually, with history back to 2019.
OSINT
Hundreds of public lists refreshed regularly, along with curated sources feeding more than 2,500 named threat profiles tied to observed infrastructure.
Host responses
Around 875 million virtual-host requests a day, capturing headers, response body, favicon, and the served certificate.
Certificates
Continuous monitoring of global CT logs since 2020: including hashes, issuers, subjects.
Registration
WHOIS and RDAP queried directly at registries and registrars, normalized into consistent fields, and re-checked monthly.
Threat infrastructure moves. The domain in your logs may resolve somewhere new by the time you investigate it, and a feed with a thirty-day window will tell you it is clean.
We keep everything we collect, and we record every measurement — including the ones where nothing changed. With our point-in-time granularity, you can query any record as it stood at a specific date and time, going back to 2019 for DNS data, and see exactly what a host was doing during the window you care about.
One domain's resolution history. Every record carries the dates it held.
Collecting a response is the easy part. From each one we extract and index dozens of categories of features: body hashes, headers, favicons, certificate fields, and TLS fingerprints, including JARM and JA4X.
These extracted features make the data pivotable. Two hosts that share no domain and no IP address still match on how they respond, and that match is a search you can run.
Six unique hosts, two shared fingerprints.
Every dataset above is documented in detail, down to field definitions and refresh schedules.
Get in touch
Validin is the first tab I open every morning.