Skip to content
Notis

Start an IP hosted-domain check during triage

An IP in an incident channel can trigger a hosted-domain lookup, giving your team one concrete research result while triage is underway.

Trigger

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

Action

Hosted Domains Lookup

Tool to retrieve hosted domains for a given IP address. Use this after validating the IP.

Why this helps

Urgent channel activity can crowd out the small, useful research steps that help a team understand an IP.

  • Begin the lookup from the active incident discussion.
  • Retrieve hosted-domain results for a valid IP.
  • Reduce the chance of forgetting an early research step during handoffs.

Setup

Build it in a few focused steps.

  • 1Connect Slack and Ip2whois to Notis once in the portal.
  • 2Create an automation in the portal, or tell Notis to retrieve hosted domains when an IP is raised for incident research.
  • 3Use one plain-language prompt to describe how to recognize the incident context and identify a valid IP.
  • 4Choose the Slack channel-message trigger and report channel, then test with a non-sensitive example IP.

Questions about this workflow

Does the lookup identify the cause of an incident?

No. It returns hosted-domain information for the IP; it does not diagnose an incident.

Can it process an invalid IP?

The action is intended to be used after validating the IP.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Slack to Ip2whois. A trigger fires from one place; an action lands in another.

Slack triggers

Ip2whois actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

IP2WHOIS Domain Lookup

Tool to retrieve WHOIS information for a domain. Use when you need registrar and contact details for a specific domain.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Hosted Domains Lookup

Tool to retrieve hosted domains for a given IP address. Use this after validating the IP.

ActionInstant

New Channel Created Trigger

Triggered when a new channel is created in Slack.

TriggerInstant

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

TriggerInstant

Direct Message Received

Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.

TriggerInstant

Message Reaction Added

Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Message Reaction Removed

Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Reaction Added Trigger

DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.

TriggerInstant

Connect any two apps with Notis in the middle.

Slack and Ip2whois, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Ip2whois.