Repository navigation
new: [expansion] OTI Labs Domain Intelligence module - #913
Merged
Merged
Conversation
Enriches a domain or hostname with WHOIS/RDAP, DNS, the TLS certificate, live subdomains and SPF/DMARC/DKIM from the OTI Labs Domain Intelligence API.
Member
|
Thank you! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
otilabs, an expansion and hover module for the OTI Labs Domain Intelligence API. Disclosure: I run this API.Input:
domainorhostname. Config:apikey(a RapidAPI key subscribed to the API; the free plan is 1,000 requests a month) and an optionalsubdomain_limit(default 50).One request to
/lookup/{domain}is mapped to:whoisobject: registrar, creation/modification/expiration dates and nameservers (RDAP first, with a port-43 WHOIS fallback for TLDs RDAP doesn't cover). Free-text dates that some ccTLD registries return are skipped rather than stored in a datetime field.x509object for the certificate the domain serves: issuer, subject, serial number, signature algorithm, validity dates and SANs (wildcards skipped, capped at 50).dns-recordobject: MX, NS, SOA and TXT records, with CAA as text.domain-ipobject for the domain: its A/AAAA addresses plus the SPF, DMARC and DKIM results as text attributes with correlation disabled, the same wayemail_security_checkreports them.domain-ipobject per live subdomain (hostname plus its current IP, or its CNAME target as text), up tosubdomain_limit, and a text attribute summarising how many subdomains were found and how many resolve now.A section the API couldn't fetch (for example a WHOIS timeout) is skipped and the rest is still returned. Rejected keys (401/403), quota errors (429), network errors and responses with no usable data return an error message.
Tests:
tests/test_otilabs.py(13 tests) mocksrequests.getwith a trimmed copy of a real/lookupresponse for stripe.com, so it runs offline without a key. I also ran the handler against full live responses for stripe.com and bbc.co.uk.black --check(project settings),isort --check-onlyandflake8pass.I haven't touched the generated documentation;
moduleinfois filled in, so it should come through the usual docs generation.AI use disclosure
Written collaboratively with Claude (Anthropic, Claude Opus 5.5), modelled on the existing
whoisfreaks,lamis_networkandemail_security_checkmodules, then reviewed and tested before submitting.