Webhook integration

Signed JSON webhooks for every domain alert

Wire Domainyze alerts into your own systems with an HMAC-SHA256 signed POST for every event.

  • A stable event name on every request
  • HMAC-SHA256 signature over the raw body
  • Retried for six hours, and replayable

Included with Pro and Business. Email alerts stay free on every plan.

12K+
Domains monitored
700+
Active users
33K+
Daily domain checks
POST /your-endpoint
Content-Type:
application/json
X-Webhook-Signature:
6dcc21981ae0f3c05edb0f7ada178171a1c76ffcdfa7ac42a827fbcbd82247d3
X-Webhook-Event:
domain.available
{
    "event": "domain.available",
    "timestamp": "2026-09-28T19:28:07+00:00",
    "data": {
        "domain": "example.com",
        "status": "available",
        "expiry_date": null,
        "checked_at": "2026-09-28T19:28:07+00:00"
    }
}

What the webhook integration does

A webhook destination receives every alert you choose as an HTTPS POST with a JSON body. It is the integration point for anything Domainyze does not talk to directly: an incident platform, an internal dashboard, a ticketing system, a script that updates your own records. It receives the same alerts as Slack and Discord, routed by the same per-destination filters.

Every body has the same three keys. event is a stable, dotted name such as domain.available. timestamp is when the alert occurred, in ISO 8601. data holds the facts for that event type, and the table below lists them. The event name is also sent as a header, so a receiver can route before parsing.

Each destination gets its own signing secret, and every request carries an HMAC-SHA256 signature of the exact bytes sent. Verify it and you know the request came from Domainyze and was not altered on the way.

At a glance
Request
POST, application/json
Target
any https:// URL
Signature
HMAC-SHA256, per destination
Throttle
60 per minute per destination
Plans
Pro and Business

Every event's payload is documented in the webhook payload reference.

01 · The request

The exact request your endpoint receives

This is the Send test alert, a sample availability event for example.com, as the webhook channel builds it. The signature shown is computed over this body with the secret your-signing-secret.

  • X-Webhook-Event repeats the event name, so you can route before parsing.
  • X-Webhook-Signature is the lowercase hex HMAC-SHA256 of the raw body.
  • data is the public fact set for the event; internal bookkeeping never appears in it.

Hash the body exactly as received. Parsing and re-encoding the JSON changes the bytes, and the signature will not match.

POST to your endpoint
Content-Type:
application/json
X-Webhook-Signature:
6dcc21981ae0f3c05edb0f7ada178171a1c76ffcdfa7ac42a827fbcbd82247d3
X-Webhook-Event:
domain.available
{
    "event": "domain.available",
    "timestamp": "2026-09-28T19:28:07+00:00",
    "data": {
        "domain": "example.com",
        "status": "available",
        "expiry_date": null,
        "checked_at": "2026-09-28T19:28:07+00:00"
    }
}
Verify it (PHP)
$expected = hash_hmac('sha256', $request->getContent(), $secret);

if (! hash_equals($expected, (string) $request->header('X-Webhook-Signature'))) {
    abort(401);
}
02 · Events

Every event and the data it carries

Event names are a public contract and do not change. Each row is read from the payload the webhook channel builds for that alert type.

Alert event data keys
Available domain.available domain, status, expiry_date, checked_at
SSL Error ssl.invalid domain, reason
Status Change domain.status_changed domain, old_stage, new_stage, expiry_date, checked_at
Ownership watchlist.registration_changed domain, registrar_changed, nameservers_changed, re_registered, previous_registrar, new_registrar, previous_nameserver_type, new_nameserver_type
Dropping watchlist.drop_imminent domain, threshold_minutes, predicted_drop_at
DNS Update dns.records_changed domain, changes
Nameservers dns.delegation_changed domain, changes, registry_mismatch
Email Auth dns.email_auth_changed domain, changes, findings, grade
DNS Failure dns.connectivity_failed domain, check_type, reason, failure_count
Paused monitoring.auto_paused domain, check_type, reason
Recovered monitoring.recovered domain, check_type
Wantlist Digest aftermarket.wantlist_digest wantlist_label, match_count, matches
Expiry Digest domain.expiry_digest domain_count, domains
SSL Digest ssl.expiry_digest domain_count, domains

Digest events carry a count and a list instead of a single domain. Events come from domain monitoring, DNS monitoring and SSL monitoring.

03 · Delivery

How delivery behaves when things go wrong

Your endpoint will be down at some point. These are the rules that decide what happens to the alerts in the meantime.

Retried for six hours

A timeout or a non-2xx response is retried after roughly 10 seconds, 1 minute and 5 minutes, and delivery keeps trying for up to six hours from the event.

Your rate limits respected

Each destination is throttled to 60 per minute. A 429 with Retry-After is waited out, and waiting does not count as a failure.

Every attempt logged, any one replayable

The delivery log records each attempt and its response code. A replay rebuilds the original event, so it is safe for backfilling after an outage.

Resolved, checked, then pinned

The endpoint's hostname is resolved and refused if it points at a private, loopback or reserved address. The approved address is pinned for the connection, so the name cannot change underneath it.

HTTPS with real certificates

Endpoints must be HTTPS on a standard port, and the certificate is verified against the real hostname on every request.

A secret per destination

Each webhook destination has its own signing secret, so rotating one endpoint's secret leaves every other endpoint untouched.

04 · Setup

Connect an endpoint in four steps

Your endpoint needs to accept a POST over HTTPS and answer 2xx within 10 seconds. Store the payload, answer, and do the work afterwards.

Add the endpoint URL

Step 1

In Domainyze, open Settings, then Alerts, choose Webhook and enter your endpoint. Any https:// URL on a public host is accepted.

Save the signing secret

Step 2

A signing secret is generated for the destination. Store it with the receiver; it is what the signature is checked against.

Verify every request

Step 3

Compute the HMAC-SHA256 of the raw body with the secret and compare it with X-Webhook-Signature in constant time. Reject anything that does not match.

Send a test

Step 4

Press Send test. The sample request above reaches your endpoint and its response code lands in the delivery log.

05 · Who uses it

Who wires webhooks into their own systems

A webhook is how an alert becomes a ticket, a page or a database row. Each links to the full workflow.

IT teams and MSPs

Ticketing

A small receiver turns a certificate or nameserver alert into a ticket in the PSA, so it is assigned and tracked instead of read and forgotten.

How IT teams use Domainyze

Enterprise portfolios

Portfolio operations

Events flow into the systems that already own the portfolio, routed per group, so each business unit hears about its own domains.

How enterprises use Domainyze

Brand and security teams

Incident response

A delegation or DNS change on a protected domain lands in the incident tooling as signed JSON, ready for automation to act on.

How security teams use Domainyze

Domain investors

Automation

A domain.available event can trigger your own registration script the moment a watched name is released.

How domain investors use Domainyze
Start Today

Start Monitoring & Catching Domains Today

Join founders, agencies, and domainers already protecting their portfolio. Your first 5 domains are free.

Create Free Account

No credit card required • Cancel anytime

FAQ

Frequently Asked Questions

For whoever is writing the receiver.

Does Domainyze have domain monitoring webhooks?

Yes. Add any HTTPS endpoint as a webhook destination and each alert you choose is sent to it as a signed JSON POST, with a stable event name and a documented data object per event type.

Is the webhook integration on the free plan?

No. Webhook delivery is included with Pro and Business. A free account keeps email alerts on 5 domains.

How do I verify the webhook signature?

Compute an HMAC-SHA256 of the raw request body using the destination's signing secret and compare the lowercase hex result with the X-Webhook-Signature header, using a constant-time comparison. Hash the body before parsing it; re-encoded JSON will not match.

Is there a public API or a Zapier app?

Not today. Webhooks are the integration point. Any tool that accepts an incoming HTTP POST can receive them, including the catch-hook triggers in automation platforms.

What if my endpoint is down?

Failed deliveries are retried after roughly 10 seconds, 1 minute and 5 minutes, and delivery keeps trying for up to six hours. Every attempt is in the delivery log, and any delivery can be replayed from there once you are back.

Can a webhook point at a private network address?

No. The hostname is resolved before each request and refused if it points at a private, loopback or reserved address, and the approved address is pinned for the connection. Use a public HTTPS endpoint.

Start Today

Start Monitoring Your Domains

Your first 5 domains are free, with email alerts, and no card required.

Create Free Account