HTTP API

웹 도구와 같은 점검을 HTTP로 부를 수 있습니다. 모두 읽기 전용이고, 대상 서버에 공격이나 데이터 전송을 하지 않습니다.

OpenAPI 문서

OpenAPI 3.1 형식의 전체 명세를 내려받아 API 도구(Postman, Swagger Editor 등)에 바로 불러올 수 있습니다.

openapi.json v2026-10-10

기본

  • 주소: https://dechonet.com — 응답은 모두 JSON입니다.
  • 인증: 없이 쓸 수 있습니다. API 키를 보내면 IP 대신 키별로 한도를 셉니다. 헤더 "Authorization: Bearer dn_…". 키는 보안 관제 계정 화면에서 만듭니다. 틀리거나 폐기된 키는 401입니다. 인프라 피벗(/api/util/pivot)만 키가 필요합니다.
  • 요청 한도: 클라이언트(IP 또는 키)마다 1분에 60회가 기본이고, 무거운 점검은 더 낮습니다. 넘으면 429와 Retry-After 헤더를 돌려줍니다.
  • POST 요청은 "Content-Type: application/json" 헤더가 있어야 합니다.
  • 해석 문구 언어: ?lang=ko 또는 ?lang=en.
  • 무료 이용은 비상업 용도입니다. 회사 업무나 서비스에 넣으려면 문의해 주세요.

응답 형식

모든 응답은 같은 형식(ok·data·error)으로 감싸져 옵니다. ok가 false면 error.code(INVALID_INPUT, RATE_LIMITED, UPSTREAM_ERROR 등)와 message를 보세요. 대부분의 점검은 data.raw(관측한 값)와 data.interpretation(상태·핵심 지표·이슈별 심각도·원인·조치)을 돌려줍니다. cached가 true면 최근에 저장된 결과입니다.

{
  "ok": true,
  "requestId": "…",
  "cached": false,
  "updatedAt": "2026-10-10T04:00:00.000Z",
  "data": { "raw": { … }, "interpretation": { "status": "…", "kpis": [ … ], "issues": [ … ] } },
  "error": null
}

엔드포인트

각 설명은 MCP 도구 설명의 첫 문장(영어)입니다.

GET /api/util/dns

DNS Lookup — Query DNS records (A, AAAA, MX, TXT, NS, SOA, CAA) for a domain and validate email-related records, including DNSSEC presence and SPF/DMARC syntax, returning severity-rated diagnostics.

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/dns?query=example.com'

GET /api/util/ssl

SSL Certificate Check — Inspect a host's served TLS/SSL certificate and connection: expiry date, issuer, SAN list, chain integrity, revocation (OCSP, then CRL; unknown when neither answers — not graded unless revoked), TLS version, and HSTS, returning an A+ to F grade weighted by certificate validity (40%), TLS version (25%), chain trust (15%), and HSTS (20%).

매개변수: host (필수), port

curl -s 'https://dechonet.com/api/util/ssl?host=example.com'

GET /api/util/http

HTTP Security Headers Audit — Follow a URL's HTTP redirect chain and audit response security headers (CSP, HSTS, X-Frame-Options, COOP, CORP, COEP, Permissions-Policy), grading A+ to F on the six core headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy; COOP/CORP/COEP are reported but not graded) and flagging information leaks such as server-version disclosure.

매개변수: url (필수)

curl -s 'https://dechonet.com/api/util/http?url=example.com'

GET /api/util/email

Email Authentication Check — Assess a domain's email authentication and deliverability posture: MX records, SPF, DMARC, DKIM (probes 15 common selectors), BIMI, MTA-STS, TLS-RPT, and DANE, plus a blacklist check across all MX hosts, returning a 0-100 deliverability score.

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/email?query=example.com'

GET /api/util/port

Open Port Scan — Probe a host for a fixed set of common TCP ports (HTTP, HTTPS, SSH, FTP, SMTP, DNS, and common databases) and report which are open, the service name, and the response time.

매개변수: host (필수)

curl -s 'https://dechonet.com/api/util/port?host=example.com'

GET /api/util/propagation

DNS Propagation Check — Query one DNS record across 8+ global public resolvers (Google, Cloudflare, Quad9, OpenDNS, and more) simultaneously and report which resolvers return stale versus updated values.

매개변수: domain (필수), type

curl -s 'https://dechonet.com/api/util/propagation?domain=example.com'

GET /api/util/reverse-dns

Reverse DNS (PTR) Lookup — Resolve the PTR (reverse DNS) record for an IPv4 or IPv6 address and verify forward-confirmed reverse DNS (FCrDNS) by checking that the PTR hostname resolves back to the same IP.

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/reverse-dns?query=example.com'

GET /api/util/asn

ASN / BGP Lookup — Look up Autonomous System (ASN) / BGP information for an IP address or AS number: the network operator, announced prefixes, abuse contact, and a classification (cloud, CDN, ISP, hosting, or enterprise).

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/asn?query=example.com'

GET /api/util/rdap

WHOIS / RDAP Domain Lookup — Retrieve domain registration data via RDAP (with WHOIS fallback): registrar, creation/expiry/update dates, nameservers, and EPP status flags, highlighting risk states such as clientHold and pendingDelete.

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/rdap?query=example.com'

GET /api/util/subdomains

Subdomain Discovery — Enumerate the subdomains of a domain from Certificate Transparency logs — fully passive (no packets are sent to the target; CT logs are public records of every TLS certificate ever issued).

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/subdomains?query=example.com'

GET /api/util/lookalike

Lookalike Domain Check — Generate the typosquat/lookalike variants of a domain that phishers actually register — homoglyph swaps (l→1, o→0, rn→m), TLD swaps (.com→.co), character omissions, transpositions, repetitions, hyphenations — and check which of them are currently registered (live NS delegation via DoH).

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/lookalike?query=example.com'

GET /api/util/ip

My IP Info — Report information about the caller's own public IP as seen by the server: IPv4/IPv6 address, ISP, ASN, approximate geolocation, and proxy/VPN heuristics.

curl -s 'https://dechonet.com/api/util/ip'

POST /api/util/email-header

Email Header Analysis — Parse raw email headers to reconstruct the delivery path (each Received hop in order), extract SPF/DKIM/DMARC authentication results, measure per-hop delays, and flag unencrypted (non-TLS) hops.

JSON: headers

curl -s -X POST https://dechonet.com/api/util/email-header \
  -H 'Content-Type: application/json' \
  -d '{"headers": "…"}'

GET /api/util/owasp

OWASP Security Checkup — Assess a domain's OWASP posture from EXTERNAL OBSERVATION only: the OWASP Secure Headers Project plus the externally observable Top 10 subset — A02 Cryptographic Failures (TLS/cert), A05 Security Misconfiguration (header/info leaks), and A06 Vulnerable & Outdated Components (version disclosure) — returning an A+ to F grade.

매개변수: host (필수)

curl -s 'https://dechonet.com/api/util/owasp?host=example.com'

GET /api/util/impersonation

Brand Impersonation Exposure — Assess how exposed a domain is to brand impersonation and phishing, PASSIVELY: live typosquat/lookalike domains (homoglyph, omission, transposition, TLD swap) that actually resolve, operational subdomains (dev/staging/admin) exposed in CT logs, and whether a wildcard certificate exists — returning an A+ (low exposure) to F (high exposure) grade.

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/impersonation?query=example.com'

GET /api/util/changes

Domain Change History — Report what has changed for a domain over time — the security regressions and drift that DechoNet's daily monitoring has recorded across every watch on the domain (SSL grade, headers, DNS, OWASP posture, impersonation exposure, etc.).

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/changes?query=example.com'

GET /api/util/history

Infrastructure History — Show how a domain's (or IPv4 address's) infrastructure has changed over time from DechoNet's stored observations: nameservers, A/AAAA, MX, CNAME, certificate issuer, registrar, RDAP nameservers and status, and for an IP its ASN and PTR — each value with when it was first and last seen.

매개변수: target (필수)

curl -s 'https://dechonet.com/api/util/history?target=example.com'

GET /api/util/pivot

Infrastructure Pivot — Find other domains DechoNet has seen with the same infrastructure value — a nameserver, IP address, MX host, certificate issuer or registrar — with first and last seen, to map related infrastructure (e.g.

매개변수: kind (필수), value (필수)

curl -s 'https://dechonet.com/api/util/pivot?kind=example.com&value=example.com'

GET /api/util/golive

Go-Live Readiness Checklist — Check whether a domain is ready to launch or migrate — a go/no-go verdict over five essentials: DNS resolves to an IP, has propagated consistently across global resolvers, SSL/TLS is ready, the site is reachable over HTTPS, and the domain registration is not about to expire.

매개변수: query (필수)

curl -s 'https://dechonet.com/api/util/golive?query=example.com'

GET /api/util/pqc

Post-Quantum TLS Readiness — Check whether a website's public TLS endpoint is ready for post-quantum cryptography: does it complete a TLS 1.3 handshake that offers only the hybrid X25519MLKEM768 key exchange (ML-KEM), and does the organisation's own server provide it or a CDN edge in front of it.

매개변수: host (필수)

curl -s 'https://dechonet.com/api/util/pqc?host=example.com'

GET /api/util/exposure

Exposed Admin Page Check — Map what an organisation exposes to the internet beyond its home page: subdomains from Certificate Transparency logs (plus hosts DechoNet has already observed), each opened once from outside and sorted into developer/ops tools, directory listings, admin screens, VPN/remote-access logins, staging servers, default install pages, login pages and so on — the forgotten assets AI-driven attack tools look for first.

매개변수: domain (필수)

curl -s 'https://dechonet.com/api/util/exposure?domain=example.com'

GET /api/util/gate

Pre-deploy gate — Runs the SSL and HTTP checks against a deployed URL and answers pass or fail per check, for failing a CI build.

매개변수: url (필수), min_ssl, min_headers, min_days, require_https

curl -s 'https://dechonet.com/api/util/gate?url=example.com'

AI 에이전트에서는 같은 점검을 MCP 도구로 쓸 수 있습니다: MCP →