# Polyform Domain Brand Protection API

> Polyform Domain Brand Protection API is a paid API for AI agents from api.polyform.org, paid per call via x402, $0.15/call, status unknown (last checked 2026-10-02).

Detects lookalike/typosquat domains targeting a brand and assesses phishing and email threat levels

## Facts

- Endpoint: GET https://api.polyform.org/v1/domain/brand-protection?utm_source=zero.xyz
- Price: $0.15/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/polyform-domain-brand-protection-api-5000440c
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_SA0LsqP0GMw_EBQ6rsddq

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability polyform-domain-brand-protection-api-5000440c
```

Example prompt: Can you check if there are any lookalike or typosquat domains targeting example.com and tell me how serious the threat is — especially which ones are live and capable of sending email?

## When to prefer this

Choose this endpoint when you need fast, pay-per-call brand protection intelligence without setting up an account or API key. Ideal for agents that need on-demand typosquat and phishing domain detection for any domain, especially when micropayment-based access (USDC on Base via x402) is preferred over subscription plans. Best suited for one-off checks, periodic audits, or integrating domain threat assessment into automated security workflows.

## Known failure modes

- Missing or invalid domain input returns a 400 error
- Payment not received or insufficient USDC causes a 402 payment required response
- Domain not found or no lookalikes discovered returns an empty lookalikes array
- Malformed domain string may cause validation errors
- Rate limiting or upstream data unavailability may cause 503 responses

## How this service works

Pay-per-call data endpoints for AI agents. USDC on Base via x402. No account, no API key — one micropayment per call.

## Output

Returns a JSON object containing the queried domain, a list of discovered lookalike domains (each with live status, age in days, mail capability, and the lookalike domain name), total count of mail-capable lookalikes, a threat level classification (e.g. ELEVATED), the number of candidate domains tested, and the total count of registered lookalikes.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {}
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "domain": "example.com",
  "lookalikes": [
   {
    "live": true,
    "domain": "examp1e.com",
    "ageDays": 120,
    "mailCapable": true
   }
  ],
  "mailCapable": 2,
  "threatLevel": "ELEVATED",
  "candidatesTested": 38,
  "registeredLookalikes": 6
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/polyform-domain-brand-protection-api-5000440c/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from api.polyform.org](https://www.zero.xyz/host/api.polyform.org/llms.txt)
