High-risk tools in DomainKits
9 of the 38 tools in DomainKits are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
activeExecuteSearch active gTLD domains from a database of ~240 million registered domains. This tool is primarily a market analysis instrument — use it to understand keyword distribution, s...
-
agedExecuteSearch currently registered domains with 5-20+ years of history. These are live domains owned by someone — not available for free registration. Use has_sale=true to filter to do...
-
deletedExecuteSearch domains that have completed the deletion cycle and are open for immediate registration at standard cost — no auction or backorder needed. These are the highest-value find...
-
keywords_trendsExecuteGet trending keywords in domain registrations. Mainly used for investors to find new opportunities, but also useful for brand protection. Three modes: - hot: High-volume keyword...
-
marketExecuteSearch currently registered domains with marketplace listing data. These are live domains owned by someone — not available for free registration. Use status=forsale to filter to...
-
nrdsExecuteSearch newly registered domains by keyword. Use for tracking competitor registrations, spotting trending keywords, monitoring brand squatting, or finding resale opportunities. ...
-
ns_reverseExecuteReverse NS lookup. Find all gTLD domains hosted on a specific nameserver. Useful for mapping domain portfolios, understanding the scale of a nameserver's usage, and discovering ...
-
sale_chanceExecuteDomain buyer discovery workflow. Call when a user wants to find potential end-user buyers for a domain they own or are considering selling. When to use: user asks 'who would bu...
-
tld_trendsExecutegTLD registration trends over time. Analyze historical registration patterns for specific gTLDs — spot hype cycles, compare competing extensions, or check long-term health. Two...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.