What goes into the report

A URL Forensics domain forensic report brings together RDAP and WHOIS registration data, the domain's DNS record set, network RDAP for the resolved IP address, hosting provider attribution, SSL/TLS certificate details, certificate transparency log entries, and the domain's SPF and DMARC configuration.

Each data point is retrieved directly from its authoritative public source at the time the report is generated. The report presents the data as collected, with clear labelling of each source, rather than paraphrasing or summarising it in a way that could obscure what was actually found.

  • Registration data: registrar, creation date, expiry date, status codes
  • Full DNS record set at the time of the check
  • Resolved IP, its network allocation, and hosting provider
  • SSL/TLS certificate details and certificate transparency log history
  • SPF and DMARC records and their configured policy

Sealing the report

Once generated, the report's underlying data is serialised into canonical JSON and hashed with SHA-256. The resulting hash is included with the report, so that anyone with the report and the hash can later verify that the content has not been edited since it was produced.

This is a tamper-evidence mechanism, not a digital signature and not a trusted timestamp issued by a certification authority. It confirms that the report file matches what was generated; it does not independently verify that every underlying public record, such as a WHOIS registrant field, is itself accurate, since that data originates with registries and registrars rather than with URL Forensics.

Exporting and using the report

Every report can be exported as a downloadable DIGITPOL PDF, formatted for inclusion in a case file, a regulatory filing, a demand letter, or a referral to law enforcement. The PDF preserves the same data and the same hash as the underlying report.

Because the report is a static, dated snapshot, it is good practice to generate a new report, rather than relying on an old one, whenever the current state of a domain's infrastructure is material to a decision or filing.

What the report is not

The report is not a malware scan, a content review, or a safety verdict. It does not state that a domain is safe or dangerous, and it does not include historical DNS records from before the report was generated.

It is also not a substitute for legal advice or for a full investigation where the stakes require it. For matters that go beyond what an automated report can address, Digitpol offers specialist investigation support that can be arranged through the contact page.

Who uses it

  • Law firms and litigation support
  • Fraud investigators
  • Compliance and AML teams
  • Law enforcement liaisons
  • Corporate security teams

Frequently asked questions

Can a domain forensic report be used as court evidence?

The report documents the public record at a point in time and is sealed with a SHA-256 hash for tamper-evidence, which can support its use in a case file. Whether it is admissible in a particular jurisdiction and proceeding is a legal question for counsel to assess.

What format is the report delivered in?

The report is available on the platform and as a downloadable DIGITPOL PDF suitable for case files, filings or referrals.

Does the hash prove the WHOIS data itself is accurate?

No. The SHA-256 hash proves the report content has not been altered after it was generated. It does not verify the accuracy of underlying source data such as WHOIS registrant fields, which originate with registrars and registries.

How much does a single report cost?

A single report is €15. Visitors get three free checks per day, a free account includes 20 checks, and an Unlimited subscription is €5 per month with weekly domain monitoring included.

Need evidence you can keep?

Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.

Need specialist help with a case? Contact Digitpol