Platform

Our Data

Validin collects DNS, host responses, certificates, registration records, and curated OSINT for every domain we know about, every day, and keeps all of it. This page explains what we collect, how, and why it is different.

Collected every day
15 minutes

to discover and scan new domains

4 Million

DNS answers processed every second

3 Million

host scans every 5 minutes

7 years

of history, stored forever

Collection

We ask the internet directly, every day

Most DNS history is collected passively, by recording the queries other people happen to make. Popular domains show up constantly. The domain registered yesterday for next week’s phishing campaign may never show up at all.

We work the other way around. We run our own DNS infrastructure — no third-party resolvers — and resolve every name in our database at least once a day, with the most active domains refreshed up to five times a day. New domains come from hundreds of independent sources and our own discovery engine.

  • Our own closed recursive resolvers — we are the requester, the resolver, and the observer
  • Every domain queried at least daily; hundreds of millions refreshed five times a day
  • DNS queried across 11 different DNS record types
SEEN FOR THE FIRST TIME NOTHING AGES OUT DNS · up to 5 times a day Crawled · up to daily

The lifecycle of a domain, tracked automatically - forever

What we collect

Many datasets, one history

Each dataset is collected and indexed on its own schedule, and all of them correlate: a certificate links to the hosts that served it, an IP address to the domains that resolved there, a domain to the actor reported behind it.

DNS

11 different DNS record types, each timestamped individually, with history back to 2019.

OSINT

Hundreds of public lists refreshed regularly, along with curated sources feeding more than 2,500 named threat profiles tied to observed infrastructure.

Host responses

Around 875 million virtual-host requests a day, capturing headers, response body, favicon, and the served certificate.

Certificates

Continuous monitoring of global CT logs since 2020: including hashes, issuers, subjects.

Registration

WHOIS and RDAP queried directly at registries and registrars, normalized into consistent fields, and re-checked monthly.

History

Nothing is aged out

Threat infrastructure moves. The domain in your logs may resolve somewhere new by the time you investigate it, and a feed with a thirty-day window will tell you it is clean.

We keep everything we collect, and we record every measurement — including the ones where nothing changed. With our point-in-time granularity, you can query any record as it stood at a specific date and time, going back to 2019 for DNS data, and see exactly what a host was doing during the window you care about.

  • Point-in-time history kept for every record, so you can query the past as it stood
  • Additions, removals, updates, and delegation changes all tracked
  • Resolved within 15 minutes of first discovery
2021 2022 2023 2024 2025 2026 192.0.2.41 192.0.2.77 198.51.100.12 198.51.100.203 2001:db8:2f::a1 ns1.example.net ns2.example.net

One domain's resolution history. Every record carries the dates it held.

Extraction

Dozens of features from every response

Collecting a response is the easy part. From each one we extract and index dozens of categories of features: body hashes, headers, favicons, certificate fields, and TLS fingerprints, including JARM and JA4X.

These extracted features make the data pivotable. Two hosts that share no domain and no IP address still match on how they respond, and that match is a search you can run.

  • TLS fingerprints computed on every negotiation
  • Use shared fingerprints to identify a single campaign
SHARED FINGERPRINT SERVER BODY ETAG FAVICON TLS mail-01.example mail-07.example pay-a2.example pay-b9.example vault-x.example vault-z.example

Six unique hosts, two shared fingerprints.

Read the full documentation

Every dataset above is documented in detail, down to field definitions and refresh schedules.

View the data docs

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company