> ## Documentation Index
> Fetch the complete documentation index at: https://docs.infrawatch.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List typosquatting domain findings.

> Lists detector-owned domain typosquatting findings for the authenticated project. Users cannot create these findings; lifecycle actions use the generic finding UUID endpoints.



## OpenAPI

````yaml https://api.infrawatch.com/openapi.json?contract=d15375c get /projects/{project_uuid}/esi/findings/typosquatting-domains
openapi: 3.1.0
info:
  description: >-
    Customer-facing Infrawatch APIs. Authenticate with an API key unless an
    operation documents another supported credential.


    ### Infrawatch Public API


    Public API authenticated exclusively with Infrawatch API keys.


    ### Infrawatch Customer Alerting API


    Project alert rules, destinations, silences, inbox state, and delivery
    history.


    ### Infrawatch Remote Browser API


    Project-scoped interactive browser sessions owned by Platform Core.


    Session admission, lifecycle, RBAC, audit, usage, screenshot history, and

    stream tickets are Platform Core resources. The browser master is private

    infrastructure and its identifiers, proxy routes, process options, and

    credentials are never exposed by this API.


    A session and all of its evidence are private to the credential that created

    it. Project managers may list project session metadata, inspect one
    session's

    metadata, and terminate it, but cannot access its live stream, screenshots,

    or network events.


    Terminal session metadata and screenshots are retained indefinitely. A

    creator can replay a terminal session as a new queued resource while

    preserving a durable link to the source session.


    ### Infrawatch ESI API


    Customer-facing External Surface Intelligence API for project-scoped

    product data authenticated by an Infrawatch API key. API keys

    are constrained to their immutable owner's project ceiling and assigned

    ESI scopes; human project-manager fallback never expands an API key.

    Authorised API-key requests are rate-limited and consume monthly quota.


    ### Infrawatch Reports API


    Threat report discovery API authenticated by an Infrawatch API key.


    ### Infrawatch Public Rules API


    Account-aware rule authoring, taxonomy, catalogue, and runtime observations
    for API clients.


    ### Infrawatch Search API


    Search hosts, services, DNS records, and certificates. Complete
    percent-encoded query strings are limited to 65536 bytes.
  title: Infrawatch Customer API
  version: 1.0.0
servers:
  - description: Infrawatch customer API
    url: https://api.infrawatch.com/api/v1
security: []
tags:
  - name: API Usage
  - name: Projects
  - name: Alert destinations
  - name: Alert rules
  - name: Alert silences
  - name: Alerts
  - name: Browser sessions
  - name: Browser evidence
  - name: Browser streaming
  - name: Access
  - name: Inventory
  - name: Dangling DNS
  - name: Findings
  - name: Secrets
  - name: Typosquatting
  - name: Services
  - name: AI Surface
  - description: Search hosts, services, DNS records, certificates, and open directories.
    name: Search
  - name: Dashboard
  - name: Reports
  - name: Rules
  - name: Rule tags
  - name: Rule observations
paths:
  /projects/{project_uuid}/esi/findings/typosquatting-domains:
    servers:
      - url: https://api.infrawatch.com/api/v1
    parameters:
      - $ref: '#/components/parameters/esi_v1_ProjectUUID'
    get:
      tags:
        - Typosquatting
      summary: List typosquatting domain findings.
      description: >-
        Lists detector-owned domain typosquatting findings for the authenticated
        project. Users cannot create these findings; lifecycle actions use the
        generic finding UUID endpoints.
      operationId: listTyposquattingDomainFindings
      parameters:
        - in: query
          name: limit
          schema:
            default: 100
            maximum: 500
            minimum: 1
            type: integer
        - in: query
          name: offset
          schema:
            default: 0
            minimum: 0
            type: integer
        - in: query
          name: q
          schema:
            maxLength: 256
            type: string
        - description: >-
            Exact normalized finding UUID, used to deep-link to one
            project-scoped record.
          in: query
          name: finding_uuid
          schema:
            format: uuid
            type: string
        - description: >-
            Matches any protected project inventory domain attached to the
            candidate. Repeat or comma-separate for multi-select filtering.
          explode: true
          in: query
          name: source
          schema:
            items:
              maxLength: 256
              type: string
            maxItems: 25
            type: array
          style: form
        - description: Repeat or comma-separate for multi-select filtering.
          explode: true
          in: query
          name: domain
          schema:
            items:
              maxLength: 256
              type: string
            maxItems: 25
            type: array
          style: form
        - description: >-
            Registrable candidate domain. Repeat or comma-separate for
            multi-select filtering.
          explode: true
          in: query
          name: registrable_domain
          schema:
            items:
              maxLength: 256
              type: string
            maxItems: 25
            type: array
          style: form
        - description: >-
            Detector facts or typosquatting techniques. Repeat or comma-separate
            for multi-select filtering.
          explode: true
          in: query
          name: tag
          schema:
            items:
              maxLength: 256
              type: string
            maxItems: 25
            type: array
          style: form
        - description: >-
            Detector-owned domain status. Repeat or comma-separate for
            multi-select filtering.
          explode: true
          in: query
          name: status
          schema:
            items:
              maxLength: 128
              type: string
            maxItems: 25
            type: array
          style: form
        - description: >-
            Repeat the query parameter for multi-select filtering. Commas are
            treated literally because provider names may contain them.
          explode: true
          in: query
          name: provider
          schema:
            items:
              maxLength: 256
              type: string
            maxItems: 25
            type: array
          style: form
        - description: >-
            Repeat the query parameter for multi-select filtering. Commas are
            treated literally because registrar names may contain them.
          explode: true
          in: query
          name: registrar
          schema:
            items:
              maxLength: 256
              type: string
            maxItems: 25
            type: array
          style: form
        - description: >-
            Exact case-insensitive page-title values. Repeat the query parameter
            for multi-select filtering; commas are treated literally.
          explode: true
          in: query
          name: title
          schema:
            items:
              maxLength: 1024
              type: string
            maxItems: 25
            type: array
          style: form
        - description: >-
            Shared finding lifecycle state. Repeat or comma-separate for
            multi-select filtering.
          explode: true
          in: query
          name: state_status
          schema:
            items:
              $ref: '#/components/schemas/esi_v1_FindingStatus'
            maxItems: 25
            type: array
          style: form
        - description: >-
            Shared finding confidence. Repeat or comma-separate for multi-select
            filtering.
          explode: true
          in: query
          name: confidence
          schema:
            items:
              $ref: '#/components/schemas/esi_v1_FindingConfidence'
            maxItems: 25
            type: array
          style: form
        - description: Filter to findings that do or do not have a captured screenshot.
          in: query
          name: has_screenshot
          schema:
            type: boolean
        - description: >-
            Exact detector edit distance. Repeat or comma-separate for
            multi-select filtering.
          explode: true
          in: query
          name: distance
          schema:
            items:
              minimum: 0
              type: integer
            maxItems: 25
            type: array
          style: form
        - in: query
          name: min_distance
          schema:
            minimum: 0
            type: integer
        - in: query
          name: max_distance
          schema:
            minimum: 0
            type: integer
        - in: query
          name: registered_from
          schema:
            format: date-time
            type: string
        - in: query
          name: registered_to
          schema:
            format: date-time
            type: string
        - in: query
          name: first_seen_from
          schema:
            format: date-time
            type: string
        - in: query
          name: first_seen_to
          schema:
            format: date-time
            type: string
        - description: Ordered fields. Repeat the parameter to add secondary sorts.
          explode: true
          in: query
          name: sort
          schema:
            items:
              enum:
                - finding
                - signal
                - status
                - evidence
                - title
                - has_title
                - registered
                - registered_at
                - last_seen
                - last_seen_at
              type: string
            maxItems: 10
            type: array
          style: form
        - description: >-
            Directions aligned by position with each sort field. Repeat for
            secondary sorts.
          explode: true
          in: query
          name: direction
          schema:
            items:
              enum:
                - asc
                - desc
              type: string
            maxItems: 10
            type: array
          style: form
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  findings:
                    items:
                      $ref: '#/components/schemas/esi_v1_TyposquattingDomainFinding'
                    type: array
                  pagination:
                    $ref: '#/components/schemas/esi_v1_Pagination'
                required:
                  - findings
                  - pagination
                type: object
          description: Typosquatting domain findings.
        '400':
          $ref: '#/components/responses/esi_v1_BadRequest'
        '401':
          $ref: '#/components/responses/esi_v1_Unauthorized'
        '403':
          $ref: '#/components/responses/esi_v1_Forbidden'
      security:
        - apiKeyAuth: []
components:
  parameters:
    esi_v1_ProjectUUID:
      in: path
      name: project_uuid
      required: true
      schema:
        format: uuid
        type: string
  schemas:
    esi_v1_FindingStatus:
      enum:
        - open
        - accepted
        - resolved
        - ignored
        - false_positive
      type: string
    esi_v1_FindingConfidence:
      enum:
        - low
        - medium
        - high
      type: string
    esi_v1_TyposquattingDomainFinding:
      properties:
        activity:
          type: string
        brand_analysis:
          $ref: '#/components/schemas/esi_v1_TyposquattingBrandAnalysis'
        brand_matches:
          description: >-
            Protected brand assets whose stored reference images this candidate
            served, as recorded by the scanner at observation time. Absent when
            nothing matched.
          items:
            $ref: '#/components/schemas/esi_v1_TyposquattingBrandMatch'
          type: array
        cname_records:
          items:
            type: string
          type: array
        confidence:
          $ref: '#/components/schemas/esi_v1_FindingConfidence'
        distance:
          minimum: 0
          type: integer
        dns_a_records:
          items:
            type: string
          type: array
        dns_aaaa_records:
          items:
            type: string
          type: array
        domain:
          type: string
        favicon_sha256:
          pattern: ^[0-9a-fA-F]{64}$
          type: string
        final_url:
          type: string
        finding_key:
          description: >-
            Stable detector-owned logical ID and dedupe key built from the
            candidate domain. Project scope is enforced separately.
          type: string
        finding_type:
          description: Surface-lib-owned customer-facing finding classification.
          enum:
            - domain_typosquatting
            - domain_for_sale
          type: string
        finding_uuid:
          description: >-
            Normalized ESI finding UUID. Use
            `/projects/{project_uuid}/findings/{finding_uuid}` for shared
            lifecycle actions.
          format: uuid
          type: string
        first_seen_at:
          format: date-time
          type: string
        ip_addresses:
          items:
            type: string
          type: array
        last_seen_at:
          format: date-time
          type: string
        name_servers:
          items:
            type: string
          type: array
        page_sha256:
          pattern: ^[0-9a-fA-F]{64}$
          type: string
        protected_domains:
          description: >-
            Every project inventory domain this candidate may impersonate,
            ordered by active state and closest distance.
          items:
            $ref: '#/components/schemas/esi_v1_TyposquattingProtectedDomain'
          type: array
        provider:
          type: string
        registered_at:
          format: date-time
          type: string
        registrable_domain:
          description: Registrable form of the observed candidate domain.
          type: string
        registrar:
          type: string
        screenshot_sha256:
          description: SHA-256 key for the captured screenshot image, when present.
          pattern: ^[0-9a-fA-F]{64}$
          type: string
        severity:
          $ref: '#/components/schemas/esi_v1_FindingSeverity'
        source:
          description: Closest protected-domain target retained as a compact list summary.
          type: string
        source_asset_uuid:
          description: >-
            Inventory asset UUID for the closest protected-domain target. Use
            `protected_domains` for the complete target set.
          format: uuid
          type: string
        state:
          $ref: '#/components/schemas/esi_v1_TyposquattingFindingState'
        status:
          description: Detector-owned domain status.
          type: string
        tags:
          description: >-
            Detector facts for the closest protected-domain target. Use
            `protected_domains` for every target-specific technique.
          items:
            type: string
          type: array
        title:
          type: string
      required:
        - finding_uuid
        - finding_key
        - finding_type
        - severity
        - source_asset_uuid
        - source
        - domain
        - registrable_domain
        - distance
        - tags
        - status
        - confidence
        - dns_a_records
        - dns_aaaa_records
        - ip_addresses
        - name_servers
        - cname_records
        - first_seen_at
        - last_seen_at
        - protected_domains
        - state
      type: object
    esi_v1_Pagination:
      properties:
        limit:
          type: integer
        offset:
          type: integer
        total:
          type: integer
      required:
        - limit
        - offset
        - total
      type: object
    esi_v1_TyposquattingBrandAnalysis:
      description: >-
        Evidence emitted by the separately deployed brand-intelligence service.
        Finding type, severity, confidence, and lifecycle remain surface-owned
        fields outside this object.
      properties:
        brand_intent:
          type: string
        component_versions:
          additionalProperties:
            type: string
          type: object
        confidence:
          enum:
            - low
            - medium
            - high
          type: string
        credential_intent:
          type: string
        domain_relationship:
          type: string
        signals:
          items:
            type: string
          type: array
        target_brand_id:
          type: string
        target_brand_name:
          type: string
        verdict:
          enum:
            - abstain
            - benign_consistent
            - possible_impersonation
            - likely_impersonation
            - likely_phishing
          type: string
        warnings:
          items:
            type: string
          type: array
      required:
        - verdict
        - confidence
      type: object
    esi_v1_TyposquattingBrandMatch:
      properties:
        asset_uuid:
          description: UUID of the matched brand inventory asset.
          format: uuid
          type: string
        kinds:
          description: How the candidate matched, such as `favicon_exact`.
          items:
            type: string
          type: array
      required:
        - asset_uuid
        - kinds
      type: object
    esi_v1_TyposquattingProtectedDomain:
      properties:
        active:
          type: boolean
        distance:
          minimum: 0
          type: integer
        first_seen_at:
          format: date-time
          type: string
        last_seen_at:
          format: date-time
          type: string
        source:
          type: string
        source_asset_uuid:
          format: uuid
          type: string
        tags:
          items:
            type: string
          type: array
      required:
        - source_asset_uuid
        - source
        - distance
        - tags
        - active
        - first_seen_at
        - last_seen_at
      type: object
    esi_v1_FindingSeverity:
      enum:
        - critical
        - high
        - moderate
        - low
        - informational
      type: string
    esi_v1_TyposquattingFindingState:
      properties:
        status:
          $ref: '#/components/schemas/esi_v1_FindingStatus'
        updated_at:
          format: date-time
          type: string
      required:
        - status
      type: object
    esi_v1_ErrorResponse:
      properties:
        error:
          properties:
            code:
              type: string
            field_errors:
              items:
                properties:
                  code:
                    type: string
                  field:
                    type: string
                  message:
                    type: string
                required:
                  - field
                  - code
                  - message
                type: object
              type: array
            message:
              type: string
            request_id:
              type: string
          required:
            - code
            - message
          type: object
      required:
        - error
      type: object
  responses:
    esi_v1_BadRequest:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/esi_v1_ErrorResponse'
      description: Invalid request.
    esi_v1_Unauthorized:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/esi_v1_ErrorResponse'
      description: Authentication required.
    esi_v1_Forbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/esi_v1_ErrorResponse'
      description: Required scope or project access missing.
  securitySchemes:
    apiKeyAuth:
      description: >-
        Infrawatch API key. Supply the complete key directly as the header
        value.
      in: header
      name: X-API-Key
      type: apiKey

````