---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# WhoisXML API integration

# WhoisXML API integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The WhoisXML API integration enables you to submit Whois lookups on domain names and
URLs to obtain context on URL observables, and to make better determination on threats.

|-|-|
| Explore [Threat Intelligence integrations](https://servicenow-prod.fluidtopics.net/9sJ8C7LcH1yxYckRbWLCuw "The Threat Intelligence base system includes integrations to third-party malware-detection software packages. This section provides instructions for activating the plugins and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system.") | Set up * [WhoisXML API integration setup](https://servicenow-prod.fluidtopics.net/xgxALrhlFm5b0rUTrjZQVg "Before you can use the Whois integration, you must activate the plugin and add the credentials. If necessary, you can also update your X509 SSL certification.") * [Activate and configure the Security Operations Whois integration](https://servicenow-prod.fluidtopics.net/zNG6mC~jnNf6iSIhZC~1Gw "The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the Security Operations Whois integration. Before you can use the Security Operations Whois integration, you must download it from the ServiceNow Store, and you must have a valid account from WhoisXML API.") {#whois-landing-page__ul_kmj_mrn_lw} |
| Use [Threat Intelligence - Run IoC Lookup workflow](https://servicenow-prod.fluidtopics.net/wXHirx65mUlkB5ZFwJvaRg#threat-intelligence-run-scan-workflow "The Threat Intelligence - Run IoC Lookup workflow checks whether there is an unexpired observable and if so, the lookup is set to Complete and updated with the data from the observable.") | Develop * [ServiceNow Security Operations integration development guidelines](https://servicenow-prod.fluidtopics.net/bvG2Jf6vlu8fw3IEOvGdMg "The ServiceNow platform provides several mechanisms for developing integrations with external systems. The ServiceNow Security Operations product suite adds integration capabilities intended to streamline the process of integrating with security-focused external systems.") * [Tips for writing integrations](https://servicenow-prod.fluidtopics.net/WrftS4_aOuJx7CfDqNBj1g "Avoid some of the pitfalls you can encounter when writing your own integrations by following these guidelines.") * [Developer training](https://developer.servicenow.com/app.do#!/training/landing) * [Developer documentation](https://developer.servicenow.com/app.do#!/documentation) * [Find components installed with an application](https://www.servicenow.com/docs/access?context=find-components&version=australia&pubname=australia-platform-administration&ft:locale=en-US) {#whois-landing-page__ul_zsn_wnv_qx} |
| Troubleshoot and get help * [Integration troubleshooting](https://servicenow-prod.fluidtopics.net/_DwvxRbS3tQogK5A_dB8UQ "These troubleshooting suggestions can help you resolve common issues you can encounter when setting up or running integrations.") * [Ask or answer questions in the Security Operations community](https://community.servicenow.com/community/security-operations) * [Search the Known Error Portal for known error articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477) * [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case) {#whois-landing-page__ul_zyk_3j4_qx} |   |
[Table 1.]

{#whois-landing-page__simpletable_g33_wwg_vt}

