The toolbox is provided to investigate websites, IP address, Hosting providers, email servers, domain creation date, registrant information, DMARC & SPF data.
URL forensics is the practice of examining a web address and the public records behind it, the domain registration, the DNS configuration, the hosting and mail infrastructure, and the email authentication policy, to establish what a site is, where it sits and how long it has existed. URL Forensics turns that examination into a single repeatable check: you enter a domain or URL, the toolset queries the public sources directly, and every finding is returned with the source it came from and the UTC time it was observed.
What the toolset examines
Each part of a domain or URL investigation answers a different question. Together they place a web address in time and in infrastructure, which is what a first triage needs before a case goes further.
- Website and URL
- The address under investigation is separated into scheme, host, path and parameters, so the registered domain actually behind a link is clear before any conclusion is drawn.
- IP address
- The public address a name resolves to, with its network block, country and the abuse contact responsible for the allocation.
- Hosting provider
- Where that address is allocated, hosting company, cloud platform or content delivery network, which usually explains infrastructure shared between unrelated sites.
- Email servers (MX)
- The mail servers a domain accepts post for, in priority order, and the public addresses behind them.
- Domain creation date
- When the registration was first created, last changed and when it expires. A domain registered days before a message arrived is often the strongest early signal in a case.
- Registrant information
- The registered holder, registrar and name servers recorded for the domain, together with the registration age available from public sources.
- SPF data
- Which servers a domain authorises to send mail on its behalf, and whether the address that actually sent a message appears in that list.
- DMARC data
- The policy a domain publishes for messages that fail authentication, and the address that receives the resulting reports.
- DNS records
- Address, alias, mail, name server and text records read directly from public resolvers, with the observation time recorded.
Fraudulent domains
Fraudulent Domains are used in cybercrime, email fraud and online scams, the analysis of fraudulent domains is the first step in most cybercrime investigations, often the domain creation date and email servers are a critical starting point.
Because the registration and DNS records are public, they can be checked in seconds and preserved before a site is taken down. Age, registrar, name servers and mail policy routinely separate a freshly registered lookalike from the established domain it imitates.
How a domain investigation runs
A Domain investigation is used to obtain the IP address the email is sent from and it then verifies it with the ones mentioned in the SPF record. URL Forensics is a tool developed by DIGITPOL.
In practice the check follows the same order every time: the name is resolved, its DNS records and registration data are read, the hosting and mail infrastructure is identified, and the published SPF and DMARC policies are compared with what the address actually does. The result is one evidence report rather than a score with no explanation.
Evidence, not assumptions
Findings come from public sources only, and each one names that source and its observation time. Fields that a source does not publish stay empty rather than being guessed, and illustrative records are labeled. The toolset does not visit the website behind an address, does not claim to identify the person behind a registration and does not certify that a destination is safe, it supplies the technical record an investigator or analyst works from.
Every completed check is sealed with a SHA-256 digest of its own contents, so a saved report can be shown to be unchanged since it was produced.
Who provides URL Forensics
URL Forensics is developed and operated by Digitpol, a cyber crime investigation, intelligence and digital forensics firm. Digitpol is the owner and provider of the toolset; the toolset itself is the subject of this page. If a case needs help beyond technical indicators, suspected fraud, attribution, evidence handling or incident response, contact Digitpol to discuss the scope and the appropriate next steps.
Contact Digitpol