Signed JSON webhooks for every domain alert
Wire Domainyze alerts into your own systems with an HMAC-SHA256 signed POST for every event.
- A stable event name on every request
- HMAC-SHA256 signature over the raw body
- Retried for six hours, and replayable
Included with Pro and Business. Email alerts stay free on every plan.
- Content-Type:
- application/json
- X-Webhook-Signature:
- 6dcc21981ae0f3c05edb0f7ada178171a1c76ffcdfa7ac42a827fbcbd82247d3
- X-Webhook-Event:
- domain.available
{
"event": "domain.available",
"timestamp": "2026-09-28T19:28:07+00:00",
"data": {
"domain": "example.com",
"status": "available",
"expiry_date": null,
"checked_at": "2026-09-28T19:28:07+00:00"
}
}
What the webhook integration does
A webhook destination receives every alert you choose as an HTTPS POST with a JSON body. It is the integration point for anything Domainyze does not talk to directly: an incident platform, an internal dashboard, a ticketing system, a script that updates your own records. It receives the same alerts as Slack and Discord, routed by the same per-destination filters.
Every body has the same three keys. event is a stable, dotted name such as domain.available. timestamp is when the alert occurred, in ISO 8601. data holds the facts for that event type, and the table below lists them. The event name is also sent as a header, so a receiver can route before parsing.
Each destination gets its own signing secret, and every request carries an HMAC-SHA256 signature of the exact bytes sent. Verify it and you know the request came from Domainyze and was not altered on the way.
- Request
- POST, application/json
- Target
- any https:// URL
- Signature
- HMAC-SHA256, per destination
- Throttle
- 60 per minute per destination
- Plans
- Pro and Business
Every event's payload is documented in the webhook payload reference.
The exact request your endpoint receives
This is the Send test alert, a sample availability event for example.com, as the webhook channel builds it. The signature shown is computed over this body with the secret your-signing-secret.
- X-Webhook-Event repeats the event name, so you can route before parsing.
- X-Webhook-Signature is the lowercase hex HMAC-SHA256 of the raw body.
- data is the public fact set for the event; internal bookkeeping never appears in it.
Hash the body exactly as received. Parsing and re-encoding the JSON changes the bytes, and the signature will not match.
- Content-Type:
- application/json
- X-Webhook-Signature:
- 6dcc21981ae0f3c05edb0f7ada178171a1c76ffcdfa7ac42a827fbcbd82247d3
- X-Webhook-Event:
- domain.available
{
"event": "domain.available",
"timestamp": "2026-09-28T19:28:07+00:00",
"data": {
"domain": "example.com",
"status": "available",
"expiry_date": null,
"checked_at": "2026-09-28T19:28:07+00:00"
}
}
$expected = hash_hmac('sha256', $request->getContent(), $secret);
if (! hash_equals($expected, (string) $request->header('X-Webhook-Signature'))) {
abort(401);
}
Every event and the data it carries
Event names are a public contract and do not change. Each row is read from the payload the webhook channel builds for that alert type.
| Alert | event | data keys |
|---|---|---|
| Available | domain.available | domain, status, expiry_date, checked_at |
| SSL Error | ssl.invalid | domain, reason |
| Status Change | domain.status_changed | domain, old_stage, new_stage, expiry_date, checked_at |
| Ownership | watchlist.registration_changed | domain, registrar_changed, nameservers_changed, re_registered, previous_registrar, new_registrar, previous_nameserver_type, new_nameserver_type |
| Dropping | watchlist.drop_imminent | domain, threshold_minutes, predicted_drop_at |
| DNS Update | dns.records_changed | domain, changes |
| Nameservers | dns.delegation_changed | domain, changes, registry_mismatch |
| Email Auth | dns.email_auth_changed | domain, changes, findings, grade |
| DNS Failure | dns.connectivity_failed | domain, check_type, reason, failure_count |
| Paused | monitoring.auto_paused | domain, check_type, reason |
| Recovered | monitoring.recovered | domain, check_type |
| Wantlist Digest | aftermarket.wantlist_digest | wantlist_label, match_count, matches |
| Expiry Digest | domain.expiry_digest | domain_count, domains |
| SSL Digest | ssl.expiry_digest | domain_count, domains |
Digest events carry a count and a list instead of a single domain. Events come from domain monitoring, DNS monitoring and SSL monitoring.
How delivery behaves when things go wrong
Your endpoint will be down at some point. These are the rules that decide what happens to the alerts in the meantime.
Retried for six hours
A timeout or a non-2xx response is retried after roughly 10 seconds, 1 minute and 5 minutes, and delivery keeps trying for up to six hours from the event.
Your rate limits respected
Each destination is throttled to 60 per minute. A 429 with Retry-After is waited out, and waiting does not count as a failure.
Every attempt logged, any one replayable
The delivery log records each attempt and its response code. A replay rebuilds the original event, so it is safe for backfilling after an outage.
Resolved, checked, then pinned
The endpoint's hostname is resolved and refused if it points at a private, loopback or reserved address. The approved address is pinned for the connection, so the name cannot change underneath it.
HTTPS with real certificates
Endpoints must be HTTPS on a standard port, and the certificate is verified against the real hostname on every request.
A secret per destination
Each webhook destination has its own signing secret, so rotating one endpoint's secret leaves every other endpoint untouched.
Connect an endpoint in four steps
Your endpoint needs to accept a POST over HTTPS and answer 2xx within 10 seconds. Store the payload, answer, and do the work afterwards.
Add the endpoint URL
Step 1In Domainyze, open Settings, then Alerts, choose Webhook and enter your endpoint. Any https:// URL on a public host is accepted.
Save the signing secret
Step 2A signing secret is generated for the destination. Store it with the receiver; it is what the signature is checked against.
Verify every request
Step 3Compute the HMAC-SHA256 of the raw body with the secret and compare it with X-Webhook-Signature in constant time. Reject anything that does not match.
Send a test
Step 4Press Send test. The sample request above reaches your endpoint and its response code lands in the delivery log.
Who wires webhooks into their own systems
A webhook is how an alert becomes a ticket, a page or a database row. Each links to the full workflow.
IT teams and MSPs
TicketingA small receiver turns a certificate or nameserver alert into a ticket in the PSA, so it is assigned and tracked instead of read and forgotten.
How IT teams use DomainyzeEnterprise portfolios
Portfolio operationsEvents flow into the systems that already own the portfolio, routed per group, so each business unit hears about its own domains.
How enterprises use DomainyzeBrand and security teams
Incident responseA delegation or DNS change on a protected domain lands in the incident tooling as signed JSON, ready for automation to act on.
How security teams use DomainyzeDomain investors
AutomationA domain.available event can trigger your own registration script the moment a watched name is released.
How domain investors use DomainyzeStart Monitoring & Catching Domains Today
Join founders, agencies, and domainers already protecting their portfolio. Your first 5 domains are free.
No credit card required • Cancel anytime
Frequently Asked Questions
For whoever is writing the receiver.
Does Domainyze have domain monitoring webhooks?
Yes. Add any HTTPS endpoint as a webhook destination and each alert you choose is sent to it as a signed JSON POST, with a stable event name and a documented data object per event type.
Is the webhook integration on the free plan?
No. Webhook delivery is included with Pro and Business. A free account keeps email alerts on 5 domains.
How do I verify the webhook signature?
Compute an HMAC-SHA256 of the raw request body using the destination's signing secret and compare the lowercase hex result with the X-Webhook-Signature header, using a constant-time comparison. Hash the body before parsing it; re-encoded JSON will not match.
Is there a public API or a Zapier app?
Not today. Webhooks are the integration point. Any tool that accepts an incoming HTTP POST can receive them, including the catch-hook triggers in automation platforms.
What if my endpoint is down?
Failed deliveries are retried after roughly 10 seconds, 1 minute and 5 minutes, and delivery keeps trying for up to six hours. Every attempt is in the delivery log, and any delivery can be replayed from there once you are back.
Can a webhook point at a private network address?
No. The hostname is resolved before each request and refused if it points at a private, loopback or reserved address, and the approved address is pinned for the connection. Use a public HTTPS endpoint.
Start Monitoring Your Domains
Your first 5 domains are free, with email alerts, and no card required.