Timeline

GET /pdns/timeline

Get a snapshot of passive DNS and Umbrella categorization history for a domain name.

curl -H "Authorization: Bearer %Token%" "https://investigate.api.umbrella.com/pdns/timeline/{domain}"

Note: %Token% must be replaced with your own Investigate API token. See About the API and Authentication for instructions on creating an Investigate API token.

Parameters

Mandatory Path Parameters

You must provide a query for the /pdns/timeline/ endpoint.

Parameter
Type
Description

domain

string

A domain name, such as example.com.

Optional Query String Parameters

Append a question mark to your request followed by any optional parameters.

Parameter
Type
Description

recordType

string

The record types to return.
For example: A, CNAME, NS, MX, and so on. Use commas to separate multiple record types.

Responses

Snapshots of passive DNS and Umbrella security categorization history is returned for the queried domain name.

Field Definitions

Name
Value Type
Description

date

string

The date.

startSeen

array of strings

Data that started being seen on the given date. May contain domains, IP addresses, and TXT records.

noLongerSeen

array of strings

Data that stopped being seen on the given date. May contain domains, IP addresses, and TXT records.

recordType

string

The DNS record type.

For example: A, CNAME, NS, MX, and so on.

Example Request

curl -H "Authorization: Bearer %Token%" "https://investigate.api.umbrella.com/pdns/timeline/umbrella.com"

Example Response

[
  {
    "date": "2016-11-09",
    "dnsData": [
      {
        "ipData": {
          "startSeen": [
            "146.112.62.25"
          ]
        },
        "recordType": "A"
      }
    ]
  }
]

IP Addresses < Timeline > Raw

Timeline


Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.