The same live check the site runs, as JSON.
Every domain page on this site is built from one live check: the registry, the DNS and the certificate the domain is serving right now. The same check is available as JSON. There is no key, no account and no signup; call it from a script, a monitoring job or a terminal.
curl https://renewatch.com/api/check/example.com
{
"domain": "example.com",
"rdap": { "status": "ok", "expires": "2027-08-13T04:00:00Z", "registrar": "...", "locked": true },
"expiry": { "days": 309, "level": "ok" },
"spf": { "level": "ok", "detail": "...", "record": "v=spf1 -all" },
"dmarc": { "level": "ok", "detail": "...", "record": "v=DMARC1; p=reject" },
"dkim": { "level": "unknown", "detail": "..." },
"tls": { "status": "ok", "expires": "2026-12-25T23:59:59Z", "days": 79 }
}
The fields to rely on:
rdap.expires: when the registration runs out, straight from the registry (absent for the few registries that publish no date).rdap.locked: whether the registrar transfer lock is set; rdap.registrar: who holds the domain.expiry.days: days until expiry; expiry.level: one of ok, warn, bad or unknown.spf.level, dmarc.level, dkim.level: the same four values, with a plain-words detail and the record found.tls.days: days until the certificate the domain serves expires.Other fields appear from time to time. Do not depend on one that is not listed here, and treat "unknown" as unknown, never as healthy.
A name that is not a domain gets status 400 and {"error": "..."}. Each caller can make 30 requests a minute;
beyond that the answer is status 429 with the same error shape, and you can try again a moment later.
Every call is a live lookup that costs the registry and the DNS something, which is why it is rate limited. Occasional lookups and scripts for domains you are responsible for are what it is for. Automated scraping of the endpoint is ruled out by the terms. To follow many domains over time, watch it instead: sign in, add the domains, and each one is checked every day, with an email when something changes.