What a domain forensics investigation is
A domain forensics investigation is the structured examination of a domain name and its infrastructure: when it was created, who registered it, where it is hosted, which email servers it uses and how its configuration has changed over time. It is the first step in most cybercrime investigations, because fraudulent domains underpin phishing, business email compromise, online scams and brand impersonation.
The creation date as a starting point
The WHOIS or RDAP creation date anchors the entire investigation. A domain created days before a fraudulent invoice or phishing campaign points to premeditation; a domain that predates an incident may have been compromised rather than registered for fraud. Every other observation is tested against this timeline.
Registrant and registrar analysis
Registration records show the registrar, the stated registrant organisation and country, and whether privacy shielding is used. Investigators compare these details with the legitimate entity being impersonated and with other domains registered in the same pattern. Redacted data limits attribution, the record shows infrastructure and timelines, not a person's identity.
DNS, hosting and email infrastructure
Address records, nameservers and hosting providers reveal where the domain lives and what it shares infrastructure with. Mail exchanger records, SPF and DMARC policy show how the domain sends email and whether its policy is enforced. In email-fraud investigations, verifying the sending IP against the SPF record is a standard step that often separates spoofing from account compromise.
History and change over time
Passive DNS and registration history show whether a domain changed hands, moved hosting or altered its email servers around the time of an incident. A sudden change of nameserver or mail provider can be as significant as the creation date itself.
Evidence handling
Every observation is recorded with its public source and UTC timestamp, and the finished report is sealed with a verifiable SHA-256 hash so any later change is detectable. The report states what the data shows and what it cannot show, technical association is not identity, and suspicion is not proof.
Start an investigation
The URL Forensics toolbox, developed and operated by Digitpol, gathers the creation date, registrant data, DNS records, hosting provider, email servers and DMARC & SPF policy into a single sealed evidence report. Run a domain check, read the domain forensics methodology, or contact Digitpol for a specialist investigation.
