Start with a verifiable record

A domain investigation begins with a preserved target and its context: the original message, suspected impersonation, transaction or incident. Public DNS and registration queries add technical observations. They do not independently identify a suspect or prove fraud.

Build the infrastructure picture

Review address records, nameservers, aliases, mail exchangers and registration events. Record the source and UTC time for every observation. Distinguish the registrar, DNS provider, network holder and website operator; these roles often belong to different parties.

Corroborate before concluding

Shared hosting, redacted registration data and recent domain creation are not conclusive indicators. Compare them with incident artifacts, authorized historical sources and other independently verified evidence. Report uncertainty and alternative explanations alongside findings.