---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Reverse Whois integration

# Reverse Whois integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Reverse Whois is a service that
performs searches on domain names registered by individuals or organizations.

Perform domain lookups using search terms in observables that you attach to a security
incident. The Reverse Whois API searches
domain records based on search terms you enter, and it returns all records that correspond
with those terms.

Analysts sometimes use this integration along with the Whois integration for security incident
research. The Whois integration provides
additional enrichment information based on the domain lookups from the Reverse Whois integration.
1. [Install and configure Reverse Whois](https://servicenow-prod.fluidtopics.net/pIAQjImaUlBNtUXmMBRPYA)  
   Before you run the integration on your instance, complete the installation and configuration steps so the Reverse Whois application properly integrates with the Security Operations product.
2. [(Optional) Install and configure Whois](https://servicenow-prod.fluidtopics.net/o~hiAz9liOg8WCDGc2CrWg)  
   Install the Whois plugin to provide additional enrichment information on your domain lookups from the Reverse Whois API. This lookup provides additional enrichment data on the domain, such as the registration date, name of registrar, and country of origin.
3. [Initiate the lookup for Reverse Whois](https://servicenow-prod.fluidtopics.net/bSFwltLXq1vy4yvVDgcBOg)  
   Initiate domain lookups using search terms in observables that you manually attach to a security incident record.
4. [Verify expected results for Reverse Whois](https://servicenow-prod.fluidtopics.net/ZadtOPuVBrqyqTmIRZyUTA)  
   Enrichment results are displayed on the ReverseWhois Domains tab at the bottom of the security incident record. Locate the lookup results to verify that the lookup ran successfully.
5. [(Optional) Run enrichment lookup and verify expected results for Whois](https://servicenow-prod.fluidtopics.net/mmrWjBmOG8L8p13TsCqNrg)  
   Run the Whois integration to perform enrichment lookups on the domains returned from the Reverse Whois integration.

