Expand threat reports with hosted domain context
When a report includes a confirmed IP, have Notis check which domains are hosted there to help guide the next review.
Trigger
New Message Received
Triggered when your bot receives a new message in a private chat, group, or supergroup. To receive every message in a group, Privacy Mode must be disabled for the bot in BotFather.
Action
IP2WHOIS Hosted Domain
Tool to retrieve hosted domain names by IP address. Use when you need to list domains hosted on a given IP. Call after confirming the IP.
Why this helps
An abuse report can require follow-up research across multiple tools before you know what to investigate next.
- Add hosted-domain context to an IP-based report.
- Turn a report into a more actionable research lead.
- Reduce the chance of losing the next investigative step.
Setup
Build it in a few focused steps.
- 1Connect Telegram and Ip2location io to Notis once in the portal.
- 2Create the automation in the portal, or describe it to Notis conversationally.
- 3Ask Notis to confirm the IP in a new threat or abuse report message and retrieve domains hosted on that IP.
- 4Select Telegram's New Message Received trigger and choose a run-report channel.
- 5Test with a real report containing a confirmed IP.
Questions about this workflow
Why confirm the IP first?
The provided action is specifically for retrieving hosted domains by IP address.
Does this action provide geographic location?
No. Use the bulk geolocation action when location information is the desired result.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Telegram to Ip2location io. A trigger fires from one place; an action lands in another.
Telegram triggers
Ip2location io actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Bulk IP Geolocation
Tool to retrieve geolocation information for multiple IP addresses in bulk. Use when processing up to 1000 IPs at once.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Domain WHOIS Lookup
Tool to retrieve WHOIS information for a given domain. Use when you need domain registration and contact details via IP2WHOIS API.
New Message Received
Triggered when your bot receives a new message in a private chat, group, or supergroup. To receive every message in a group, Privacy Mode must be disabled for the bot in BotFather.
Get API Key
Tool to retrieve the configured API key. Use when authentication is needed for IP2Location.io requests.
New Channel Post
Triggered when a new post is published to a channel where your bot is an administrator.
IP2WHOIS Hosted Domain
Tool to retrieve hosted domain names by IP address. Use when you need to list domains hosted on a given IP. Call after confirming the IP.
Callback Query Received
Triggered when a user taps an inline keyboard button attached to one of your bot's messages.
Message Edited
Triggered when a message in a chat your bot can see is edited by its sender.
New Chat Member
Triggered when a new member joins a group or supergroup the bot belongs to, including when the bot itself is added.
Connect any two apps with Notis in the middle.
Telegram and Ip2location io, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Ip2location io.