RelayShield Security Intelligence
RelayShield gives AI agents and developers real-time identity and infrastructure threat detection via a single REST API. Available endpoints: Email breach detection — 13B+ compromised account records Check infostealer logs - Checks an email address against infostealer malware log databases ingested from dark web markets and underground forums. Provides near real-time detection of active device…
RelayShield Security Intelligence endpoints
| Method | Endpoint | Description |
|---|---|---|
| v1 | ||
| POST |
checkDomain /v1/domain |
Detect lookalike and typosquat domains targeting your brand — homoglyph attacks, combo-squatting, and phishing infrastructure. |
| POST |
checkOAuth /v1/oauth |
Check whether an OAuth application client ID is on a known malicious or suspicious watchlist. |
| POST |
scanUrl /v1/scan/url |
Submit a URL for malware and phishing scanning. Returns a verdict on whether the URL is malicious. |
| POST |
checkBreach /v1/breach |
Check if an email address appears in known data breach databases. Returns breach details including source, date, and exposed data types. |
| POST |
checkSimSwap /v1/sim-swap |
Check whether a phone number has recently been ported or SIM-swapped, indicating potential account takeover risk. |
| POST |
scanFile /v1/scan/file |
Submit a file (base64-encoded) for malware scanning. Returns a verdict on whether the file is malicious. |
| POST |
scanWallet /v1/wallet |
Score a cryptocurrency wallet address for risk — sanctions exposure, darknet market activity, mixer usage, and other on-chain red flags. |
| POST |
checkInfostealer /v1/infostealer |
Detects whether an email address appears in infostealer malware logs — credential-harvesting trojans such as RedLine, Raccoon, and Vidar that silently exfiltrate all… |
RelayShield Security Intelligence pricing
| Plan | Price | Rate limit | Quotas |
|---|---|---|---|
| BASIC | Free | — |
|
| PRO Recommended | $29 / month | — |
|
| ULTRA | $99 / month | — |
|
| MEGA | $299 / month | — |
|