# how.is

> Domain and IP intelligence priced per call, for AI agents and people: DNS, WHOIS, TLS,
> DNSSEC, email auth (SPF/DKIM/DMARC), security score, blacklists, IP lookups, live site
> status and page-change watching. No subscription. Unpaid calls return HTTP 402 with
> machine-readable payment terms. Every check has a free sample input so you can see the
> real response before paying.

## Quick start

- Free sample, no key: `curl "https://how.is/v1/domain/whois?domain=example.com"`
- Paid call: `curl -X POST https://how.is/v1/domain/whois -H "Authorization: Bearer $KEY" -d '{"domain":"github.com"}'`
- MCP (Claude, Cursor, Codex): add the remote server `https://how.is/mcp` with header `Authorization: Bearer <key>`.
- Every response is `{"result": "<summary>", "data": {...}, "receipt": {...}}`.
- Every endpoint accepts POST with a JSON body or GET with the same field as a query parameter.

## Paying

- **x402, per call, no account** — network `eip155:84532` (Base Sepolia (testnet — test USDC, no real value)). Call any endpoint; the 402 carries a `PAYMENT-REQUIRED` header (base64 JSON, x402 v2, also copied into the body as `x402`). Sign it with any x402 client and retry with `PAYMENT-SIGNATURE: <base64 payload>`.
- **Prepaid key** (Stripe test mode — test cards only) — a person buys credit by card: `POST https://how.is/topup/checkout {"amount": 10}` → `checkout_url`; after payment the key is shown on how.is. Send it as `Authorization: Bearer <key>`. Each key has a daily spend cap (default $0.10); past it you get a 402 until 00:00 UTC.

Failed single checks are refunded automatically. Bad input gets a 400 with the schema and nothing is charged.

## Checks

- [Domain profile (bundle)](https://how.is/docs.md#domain_profile) `/v1/domain/profile` — $0.025. Everything about a domain in one call: DNS, WHOIS, TLS, DNSSEC, email auth, security score, blacklist status, plus IP intelligence for its A record.
- [DNS records](https://how.is/docs.md#domain_dns) `/v1/domain/dns` — $0.005. A, AAAA, MX, NS, TXT and other records for a domain, with resolve timing.
- [WHOIS / RDAP](https://how.is/docs.md#domain_whois) `/v1/domain/whois` — $0.005. Registrar, creation and expiry dates, nameservers and status codes for a domain.
- [TLS certificate](https://how.is/docs.md#domain_tls) `/v1/domain/tls` — $0.005. Certificate validity, issuer, protocol and days until expiry for a domain.
- [DNSSEC](https://how.is/docs.md#domain_dnssec) `/v1/domain/dnssec` — $0.005. Whether DNSSEC is signed and validates for a domain.
- [Email authentication](https://how.is/docs.md#domain_email_auth) `/v1/domain/email-auth` — $0.005. SPF, DKIM and DMARC records and posture for a domain.
- [Security score](https://how.is/docs.md#domain_security_score) `/v1/domain/security-score` — $0.005. A letter grade and point score for a domain security posture, with the scored items behind it.
- [Blacklist status](https://how.is/docs.md#domain_blacklist) `/v1/domain/blacklist` — $0.005. Whether the addresses behind a domain appear on spam and abuse blocklists.
- [IP intelligence](https://how.is/docs.md#ip_lookup) `/v1/ip` — $0.005. Network owner (ASN), company, geolocation, privacy flags and abuse contact for an IP address.
- [Site status](https://how.is/docs.md#site_status) `/v1/check/site` — $0.005. Live check of one or more URLs: HTTP status, latency, DNS resolve time, resolved IP, TTL, nameservers, TLS days remaining.
- [Page-change watch](https://how.is/docs.md#page_watch) `/v1/watch/page` — $0.005. Has this page changed since your last call, and how much? The first call stores a baseline; later calls return a text diff (2% threshold).
- [Bot observatory feed](https://how.is/docs.md#bot_observatory) `/v1/bots` — $0.050. Partner tier of the dns.pizza bot observatory: every network (ASN), named crawler, TLS (JA4) fingerprint and firewall rule seen in the last 7 days, refreshed hourly. The public tier is free at https://dns.pizza/bots.

## Docs

- [Full reference (markdown)](https://how.is/docs.md): inputs, outputs, examples, billing rules
- [OpenAPI 3.1](https://how.is/openapi.json)
- [JSON index](https://how.is/v1)
- [Prices](https://how.is/prices)

## Optional

- [Scheduled monitors](https://how.is/docs.md#monitors): recurring site/page checks charged to a key
- [Bot observatory, free public tier](https://dns.pizza/bots)
