CTI and incident-response teams needing deep domain, DNS, WHOIS, and infrastructure pivot capability as a specialist layer in a broader intel stack.
Buyers wanting a primary TIP (Recorded Future, Anomali, ThreatConnect win), dark-web depth (Flashpoint wins), or organizations without enrichment plumbing.
Is DomainTools Iris Investigate a trustworthy vendor?
- 2021-04-21DomainTools acquired Farsight Security; DNSDB passive DNS in-house
- 2024-09-10Iris Detect newly-observed-domain monitoring expanded
What 110 reviews actually say
Synthesized from G2, Capterra, Reddit, Trustpilot. Patterns >15% prevalence shown.
Praise patterns
- Best-in-class for domain and DNS investigations87% →
- Farsight DNSDB passive DNS depth71% →
- Iris pivot graph genuinely differentiated64% →
- Strong API for SOAR enrichment51% →
Complaint patterns
- Not a primary TIP; layered tool only47% →
- Narrow scope outside DNS and infrastructure41% →
- Less curated adversary research than competitors38% →
- Best value requires SOAR enrichment plumbing31% →
What buyers actually pay
31 anonymized deal disclosures · last updated 2026-05-01
| Company size | Median annual |
|---|---|
| 500-2,000 employees | $42,000 |
| 2,000-10,000 employees | $108,000 |
Auto-verified certifications
Editorial: Strengths
- Best-in-class for domain, DNS, WHOIS, and passive DNS
- Farsight DNSDB passive DNS depth (post-2021 acquisition)
- Iris Investigate pivot graph is genuinely differentiated
- Strong API and bulk enrichment for SOAR pipelines
- Mature reputation among DNS researchers and law enforcement
- Reasonable pricing relative to TIPs
Editorial: Weaknesses
- Not a primary TIP; layered tool only
- Narrow scope outside DNS and infrastructure
- Less curated adversary research than Mandiant or Recorded Future
- Smaller integration ecosystem than mainstream TIPs
- Best value requires SOAR enrichment plumbing
Key features & integrations
- +Iris Investigate pivot graph
- +WHOIS history and registrant intelligence
- +Farsight DNSDB passive DNS
- +SSL certificate intelligence
- +Hosting and infrastructure relationships
- +Domain risk scoring
- +Bulk API for SOAR enrichment
- +Iris Detect newly-observed domain monitoring
- +STIX/TAXII export
- +Phishing kit and brand-abuse monitoring
Read our full ranking of Threat Intelligence Software
DomainTools Iris Investigate ranks #10 in our editorial review of 10 threat intelligence software platforms. The deep-dive covers methodology, comparison tables, decision matrix, migration scoring, and FAQs.
Read the full rankingClosest alternatives in Threat Intelligence Software
Contribute your verified deal price
Pricing in B2B software is opaque because vendors want it that way. Verified buyer prices fix that, anonymously. Share what you actually paid for DomainTools Iris Investigate; we’ll add it to the verified pricing dataset on this page (with company size band only, no identifying details).
Submit anonymously