Internet Infrastructure Intelligence

Your threat feeds see attacks. We see them being built.

Datazag maps malicious infrastructure at certificate issuance — surfacing whole campaigns before the first domain attacks — and delivers scored, annotated intelligence straight into your SIEM, warehouse and controls.

150 domains from one signal — 0 in public domain feeds→
Detection at certificate issuance, before DNS resolves
Every alert ships with its evidence

Coverage

The graph behind that answer.

Finding the other 149 domains means already holding the ones they connect to. This is what Datazag observes, and what each figure counts.

360M+
Domains monitored

Distinct domains that resolve — every name answering with a record or an empty response. Names that no longer exist (NXDOMAIN) and names whose servers failed or timed out are excluded, so this counts the live corpus rather than every domain ever queried.

Measured 24 Sept 2026, 00:27 UTC

13M+
IPs hosting domains

Distinct IPv4 addresses that a domain in the measured corpus resolves to, taken over the same population as the domain figure above.

Measured 24 Sept 2026, 00:27 UTC

3.1B
IPv4 addresses indexed

IPv4 space announced in BGP and attributed to a network, counted once per address however many announcements cover it — a more-specific prefix inside its parent is not counted twice.

Measured 24 Sept 2026, 00:27 UTC

79k
Networks profiled

Autonomous systems with ownership and routing context attached, used to place infrastructure in the network that announces it.

Measured 24 Sept 2026, 00:27 UTC

Coverage measured 24 September 2026. What the internet is doing right now — certificates, newly observed domains, routing changes — lives in the Observatory.

Relationship Intelligence

Signals reveal relationships. Relationships become intelligence.

A certificate, DNS change or routing event is only the first clue. Datazag uses it as a pivot into related domains, IPs, certificates, providers, networks and historical observations.

That relationship context turns one signal into a wider campaign view. Intelligence then becomes evidence packaged for the way each team works: reports, alerts, APIs and cloud data shares.

1Signal
2Relationships
3Campaign surface
4Intelligence
5Evidence packages

See this exact pivot run on a real criminal hosting cluster: One Signal, 150 Domains →

New certificate or DNS change
First suspicious domain
Shared IPs
Related domains
Shared certificates
Providers
ASN / prefix
Historical context
Campaign blast area
Relationship Intelligence
Reports
Alerts
API
Data shares

Datazag Observatory

The internet, measured daily.

Open statistics from Datazag's continuously updated internet graph: email authentication, routing hygiene, hosting concentration, domain parking and impersonation. Explore, compare, visualize and cite — every figure carries its date and population.

The same graph mapped 150 domains from a single signal: read the investigation →

Free Domain Health Report

See your organization through an attacker's eyes—for free.

Datazag reviews public DNS, visible platforms, subdomains, certificates and infrastructure exposure, then sends a detailed multi-page report for technical and executive teams.

Not ready to enter an email? View a sample report

No questionnaire
No asset inventory
Public infrastructure only
Delivered by email

We use publicly observable infrastructure signals. No agent, questionnaire or asset inventory is required.

Generated analysis

What happens next

The report is generated from live checks, platform fingerprints, subdomain review and infrastructure intelligence.

DNS analyzed✓
Platforms mapped✓
Subdomains reviewed✓
Certificates checked✓
Risk calculated✓

Multi-page report

Domain Health Report

example.com

Multi-page
Medium risk

Executive summary

Overall risk · key exposure · priority actions

Platform exposure

Microsoft 365 · Cloudflare · Google Workspace

DNS & subdomain health

SPF · DMARC · MTA-STS · ownership · takeover signals

Technical findings

Evidence, context and prioritized remediation

Recommended action

Review email authentication, exposed platforms and subdomain ownership before attackers exploit weak signals.