Examine public DNS, WHOIS-style registration, email policies, network records and certificate evidence. Preserve your findings in a SHA-256 hashed report.
A/AAAA, CNAME, NS and SOA records, with address and mail-server resolution.
Registry events, registrar details and domain status. Understand what public data can—and cannot—reveal.
SPF and DMARC records in context. Separate configuration signals from evidence of message authenticity.
Guides, protocol notes and investigation methods for reading DNS, registration and URL evidence.
Browse resourcesInterpret email authentication policy without confusing a DNS record with proof of message authenticity.
Understand registration events, redacted identity information and the limits of public domain records.
A, AAAA, MX, TXT, CNAME, NS and SOA records, with their forensic significance and limitations.
Examine typosquatting, brand impersonation and newly registered domains without jumping to conclusions.