---
title: "Domain Queries"
slug: "domain-queries"
status: "update"
updated: 2025-12-31T14:58:41Z
published: 2025-12-31T14:58:41Z
canonical: "help.silentpush.com/domain-queries"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.silentpush.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Domain Queries

Domain Queries provide a suite of specialized searches within Silent Push, enabling users to analyze domain-related data, including certificates, Whois records, name server changes, and risk scores. Designed for flexibility, these queries support optional parameters and saving options, catering to users. They address critical challenges like compliance, brand protection, and threat detection.

## Create Domain Queries

1. From the left navigation menu, select **Advanced Query Builder > Domain Queries**, select a query type, and specify parameters (e.g., **domain**, **date_min)**.
2. Click **Search**.
3. Save queries using **Save Query** to assign a name and description for reuse.

## Key query types

Domain Queries include:

- **Search for certificates**: Identifies domain certificates using filters such as date_min and cert_issuer for compliance.
- **Obtain domain information**: Provides basic (age, registrar) or summarized (WHOIS, Alexa ranking) data.
- **Obtain domain infratag**: Generates a custom string for threat pattern analysis.
- **Monitor Nameserver Changes:** Tracks changes to detect malicious hopping.
- **Obtain nameserver reputation**: Evaluates a nameserver's trustworthiness.
- **Obtain risk score**: Delivers a proprietary risk metric.
- **Advanced domain search**: Enables highly customized scans with multiple parameters.
- **Analyze domain relationships**: Identifies cousins (similar domains) and siblings (TLD variants).
- **Obtain domain WHOIS information**: Retrieves historical or live WHOIS data.

The human-readable name (e.g., example.com) associated with an indicator of compromise (IoC) or network resource, used to identify and access websites or services in threat intelligence analysis.

Publicly available data collected during domain registration or DNS updates, used to analyze domain ownership and history.

A query type that tracks modifications to a domain’s nameservers, detecting potential malicious domain hopping or infrastructure shifts through historical and live data analysis.
