Software / Cybersecurity Software / DomainTools Iris

DomainTools Iris

DomainTools Iris is a domain-intelligence platform for investigating internet infrastructure, assessing domain risk, and enriching security workflows through web tools, APIs, and integrations.

7.0/10 TechZella Score
Visit Website ↗
Editorial overview

Aggregated Overview

Official documentation verifies investigation, enrichment, detection, API access, and security-platform integrations. Public product-specific review evidence and published prices were not verified, limiting value and sentiment assessments.

This profile combines documented product information and independent evidence where available. It is not a hands-on test unless TechZella explicitly identifies one.

Decision guide

DomainTools Iris Decision Snapshot

A quick way to understand who this product may suit, where its limits matter, and which facts are most relevant before you compare alternatives.

Best suited to

Security operations teams and threat investigators that need to examine domain infrastructure, pivot across connected identifiers, and feed domain intelligence into established SIEM or SOAR workflows.

Look elsewhere if

Buyers seeking a general-purpose web-scraping product, or individuals seeking a self-serve commercial Iris Investigate subscription, should look elsewhere; the vendor describes Iris access as an Enterprise offering.

Platforms

Cloud, REST API, SaaS, Web

TechZella assessment

7.0/10

Overview

DomainTools Iris is a domain-intelligence suite for security investigations and operational workflows. Its products divide into Iris Investigate for analyst-led domain and infrastructure research, Iris Enrich for adding domain context at scale, and Iris Detect for discovering and monitoring suspicious or lookalike domains.

Iris Investigate supports searches and pivots across domain, IP, email, registration, DNS, and certificate data. Its workspace includes investigation history and specialized data panels. DomainTools also documents APIs and connectors that bring Iris data into security tools.

The requested Web Scraping category is not a supported fit: the reviewed product material describes threat intelligence and domain investigation, not a general-purpose web scraping tool.

Decision context

DomainTools Iris — What Sets It Apart?

These are the product-specific differences that may matter when deciding whether the software fits your workflow. They are based on documented evidence rather than a universal ranking.

  • Investigation workflows combine domain, IP, email, registration, DNS, and certificate pivots with historical panels and a graph-based investigation trail.
  • The Iris product suite spans interactive investigation, API enrichment, and domain monitoring and detection.
  • Documented integrations connect Iris capabilities with multiple SIEM, SOAR, threat-intelligence, and investigation platforms.
5 key claims verifiedOur editorial team checked this profile against product documentation, pricing information, vendor documentation. Supported by 3 documented sources.
Editorial assessment

DomainTools Iris Pros & Cons

Pros

  • Combines domain investigation with passive DNS, registration history, certificate, IP, and connected-infrastructure data.
  • Offers separate API products for investigation, enrichment, and monitoring or detection workflows.
  • Documents integrations with multiple SIEM, SOAR, threat-intelligence, and investigation platforms.

Cons

  • Public Iris pricing was not available in the reviewed sources; access is positioned through Enterprise membership.
  • A self-serve Iris Investigate free trial was not verified.
  • The product is designed for cybersecurity and domain intelligence, not general-purpose web scraping.
Operational limits

DomainTools Iris Gotchas & Operational Limits

These are documented constraints or practical friction points that may matter before you adopt the product.

Iris Investigate access is provisioned through a DomainTools Enterprise account.

Teams should confirm account authorization, API entitlement, and pricing with DomainTools before planning a rollout.

Evidence source ↗

In the documented Splunk command, an IrisQL query returns up to 500 matching domains and does not support pagination.

Large result sets may need narrower queries or another supported workflow.

Evidence source ↗
Security research

Security & Privacy

For security-sensitive software, TechZella focuses on documented architecture, authentication, data handling, deployment and privacy details that can affect a buying decision. This is product research, not an independent security audit.

What the documented evidence tells us

DomainTools documents integrations with security platforms including Splunk, Microsoft Sentinel, Elastic, and ServiceNow.

The integrations catalog maps DomainTools products and APIs to SIEM, SOAR, XDR, threat-intelligence, and investigation platforms.

Source ↗

Security claims are presented only when supported by documented sources. The presence of this section does not constitute a penetration test, certification or independent security audit.

Plans & pricing

DomainTools Iris Pricing & Plans

Enterprise membership

Contact vendor

DomainTools lists Iris Investigate and Iris APIs among Enterprise capabilities. Contact DomainTools for pricing and access levels.

Check current pricing →

Pricing may change. Verify current plans on the vendor's website.

Cost context

Total Cost & Hidden Costs

Additional costs or implementation requirements that are documented in the available evidence.

Enterprise subscription

Iris Investigate and Iris APIs are listed under DomainTools Enterprise membership. The vendor directs organizations to contact it for pricing and access levels; public Iris pricing was not found.

Evidence source ↗
Capabilities

DomainTools Iris Features

Investigation

  • Search domains and other supported identifiers, including IP addresses and email addresses
  • Pivot across connected domain and infrastructure attributes
  • View passive DNS, WHOIS history, SSL/TLS certificate, IP, screenshot, and domain history panels
  • Organize investigation searches, notes, tags, and sharing

Search and analysis

  • Use advanced search with multiple criteria and logical AND/OR operations
  • Use IrisQL as a text-based query language for advanced search
  • Explore connected infrastructure using a graph-based visualization

APIs and integrations

  • Iris Investigate API for domain analysis and infrastructure mapping
  • Iris Enrich API for higher-volume domain enrichment
  • Iris Detect API for domain discovery and monitoring workflows
  • Documented integrations for selected SIEM, SOAR, XDR, threat-intelligence, and investigation tools

Alternatives

DomainTools documents a Recorded Future integration that places Iris Investigate domain profiles in a Recorded Future Domain Intel Card. This is an adjacent workflow rather than a verified substitute comparison. Buyers comparing products should assess the coverage of domain and infrastructure data, investigation workflow, required integrations, API entitlements, and contract terms directly with vendors.

Visual preview

Demo & Screenshots

DomainTools Iris product screenshotDomainTools Iris product screenshotDomainTools Iris product screenshotDomainTools Iris product screenshotDomainTools Iris product screenshotDomainTools Iris product screenshot
Product details

DomainTools Iris Specifications

AccessEnterprise account provisioning
InterfaceWeb application
APIREST APIs; API access requires authorized DomainTools account access
Free trialNo product trial verified; no-charge API test queries are available for configuration
IntegrationsDocumented connectors and workflows for selected security platforms, including Splunk, Microsoft Sentinel, Elastic, and ServiceNow
Deployment

Deployment & System Footprint

Verified installation, hosting, administration, or environment details that can affect implementation.

Installation or hostingIris Investigate is accessed through a web application. DomainTools also provides REST APIs and integrations; the reviewed sources do not document customer-managed on-premises installation of Iris itself. Source ↗
Our evidence-based assessment

TechZella Score

A proprietary editorial score based on product capabilities, usability, value, performance, support and user sentiment evidence.

7.0/10Low confidence
Features8.5
Ease of Use7.0
Value for Money6.0
Performance8.0
Support7.0
User Sentiment5.0

Official documentation verifies investigation, enrichment, detection, API access, and security-platform integrations. Public product-specific review evidence and published prices were not verified, limiting value and sentiment assessments.

Methodology v1.0. The assessment weighs feature coverage (25%), ease of use (15%), value for money (20%), performance (15%), support (10%) and user sentiment (15%), using researched product evidence and verified review evidence where available. It is a TechZella editorial assessment, not a direct user-review average.

Editorial transparency

Our Review Methodology

Key claims are linked to the sources used to verify them. This evidence record is separate from third-party user ratings.

TechZella evaluates software using documented product capabilities, pricing information, usability and value considerations, independent user evidence where available, and competitive context. The assessment is an editorial review, not a hands-on test unless one is explicitly identified. Our editorial assessment is based on 3 documented sources.

What TechZella adds
  • Investigation workflows combine domain, IP, email, registration, DNS, and certificate pivots with historical panels and a graph-based investigation trail.
  • The Iris product suite spans interactive investigation, API enrichment, and domain monitoring and detection.
  • Documented integrations connect Iris capabilities with multiple SIEM, SOAR, threat-intelligence, and investigation platforms.
Important limitations
  • Iris Investigate and its APIs are listed as Enterprise membership capabilities; public per-seat or per-query prices were not found.
  • The vendor's Personal membership is described as non-commercial and does not include Iris Investigate.
Evidence-backed claims
Iris Investigate supports domain infrastructure investigation and pivoting.

The product guide documents searching on domains and other identifiers, pivoting across connected data, and reviewing domain, passive DNS, WHOIS history, certificate, and visualization panels.

View source ↗Verified 2026-10-08
The Iris API suite includes Investigate, Enrich, and Detect APIs.

DomainTools API documentation distinguishes these three APIs and describes their investigation, enrichment, and monitoring workflows.

View source ↗Verified 2026-10-08
Iris API access is offered through DomainTools Enterprise accounts.

The API documentation says the Iris APIs are available as part of Enterprise accounts and directs organizations to contact DomainTools about pricing and access levels.

View source ↗Verified 2026-10-08
DomainTools documents integrations with security platforms including Splunk, Microsoft Sentinel, Elastic, and ServiceNow.

The integrations catalog maps DomainTools products and APIs to SIEM, SOAR, XDR, threat-intelligence, and investigation platforms.

View source ↗Verified 2026-10-08
Iris Investigate is a web application.

The user guide directs users to access Iris Investigate through its web interface and explains organization-provisioned access.

View source ↗Verified 2026-10-08
Community feedback

Reviews

No reviews yet. Be the first to share your experience.

Write a Review

FAQ

Is DomainTools Iris a web-scraping tool?
No. The reviewed documentation describes domain threat intelligence, infrastructure investigation, enrichment, and monitoring.

Does Iris have an API?
Yes. DomainTools documents REST APIs for Iris Investigate, Iris Enrich, and Iris Detect. Access is associated with DomainTools Enterprise accounts.

What platforms does Iris integrate with?
Documented examples include Splunk, Microsoft Sentinel, Elastic, Google Chronicle, IBM QRadar, ServiceNow, Palo Alto Cortex, CrowdStrike, Anomali, MISP, and Maltego. Availability depends on the specific integration and account.

How much does Iris cost?
Public Iris pricing was not found. DomainTools directs organizations to contact it about Enterprise pricing and access.

Is there a free trial?
A product trial was not verified. The API guide provides no-charge test queries for configuration, which should not be treated as a full trial.

What is Iris Investigate best suited for?
It is suited to security analysts and threat hunters investigating suspicious domains and connected internet infrastructure.

Directory

Recently added software