Skip to content
Notis

Start domain research in the incident thread

When an incident raises a domain question, let Notis fetch its WHOIS details as one focused research step for the team.

Trigger

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

Action

IP2WHOIS Domain Lookup

Tool to retrieve WHOIS information for a domain. Use when you need registrar and contact details for a specific domain.

Why this helps

During triage, even small investigative steps can disappear among urgent updates and handoffs.

  • Begin domain research from the incident discussion.
  • Retrieve available registrar and nameserver details for investigation.
  • Keep a useful lookup close to the triage context.

Setup

Build it in a few focused steps.

  • 1Connect Slack and Ip2whois to Notis once in the portal.
  • 2Create an automation in the portal, or tell Notis to look up a domain raised in an incident channel.
  • 3Describe in one plain-language instruction how to recognize an incident domain request and which domain to inspect.
  • 4Choose the Slack channel-message trigger and run-report channel, then test with a non-sensitive incident example.

Questions about this workflow

Does this determine whether a domain caused an incident?

No. WHOIS data supplies registration context; the team must assess its relevance to the incident.

Should I use it for every message in an incident channel?

Describe the specific domain-check signals in your prompt so the workflow focuses on relevant requests.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Slack to Ip2whois. A trigger fires from one place; an action lands in another.

Slack triggers

Ip2whois actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

IP2WHOIS Domain Lookup

Tool to retrieve WHOIS information for a domain. Use when you need registrar and contact details for a specific domain.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Hosted Domains Lookup

Tool to retrieve hosted domains for a given IP address. Use this after validating the IP.

ActionInstant

New Channel Created Trigger

Triggered when a new channel is created in Slack.

TriggerInstant

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

TriggerInstant

Direct Message Received

Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.

TriggerInstant

Message Reaction Added

Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Message Reaction Removed

Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Reaction Added Trigger

DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.

TriggerInstant

Connect any two apps with Notis in the middle.

Slack and Ip2whois, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Ip2whois.