What domain intelligence adds to a single lookup
A single WHOIS or DNS lookup answers one question at a time. Domain intelligence combines registration history, DNS configuration, hosting attribution, mail authentication and certificate transparency data for the same domain so that an analyst can see the full infrastructure picture at once, rather than piecing it together from five separate tools.
URL Forensics structures this picture consistently across every domain queried, which makes it practical to compare domains against each other, for example when screening a batch of counterparties or vetting a new vendor before onboarding.
- Registration timeline: creation, updates, expiry, registrar changes
- DNS footprint: nameservers, mail exchangers, TXT records
- Hosting and network attribution from IP and RDAP data
- Mail authentication posture: SPF, DMARC, MTA-STS
- Certificate issuance history via certificate transparency logs
Using domain intelligence in due diligence
Before onboarding a new vendor, partner or payment recipient, compliance and fraud teams often want to check whether the domain in a business's correspondence matches its claimed age, location and infrastructure. A domain that is weeks old, uses a free email provider's mail exchanger, and has no SPF or DMARC record is a different risk profile from an established business domain with years of stable registration history.
URL Forensics does not score or rate a domain's trustworthiness. It presents the underlying facts so that a compliance analyst can apply their own risk criteria and documented procedures, which keeps the decision auditable and consistent with internal policy rather than dependent on an opaque third-party score.
Evidence integrity for intelligence records
Because domain intelligence is often used to support a decision, such as declining to onboard a counterparty, it is useful to retain a tamper-evident record of what was checked and when. Every URL Forensics report is sealed with a SHA-256 hash of the canonical JSON, so the report can later be shown not to have been edited after it was produced.
This hash is not a digital signature or a trusted timestamp issued by a third party; it is a cryptographic fingerprint that allows the report's integrity to be verified against the original data. A downloadable DIGITPOL PDF provides a portable version of the same report for internal files or audit trails.
Ongoing monitoring
Domain intelligence is most useful when it is not a one-time check. Weekly domain monitoring, available to Unlimited subscribers, re-runs the underlying lookups on a schedule and can surface changes such as a sudden registrar transfer, a new hosting provider, or a dropped DMARC policy.
For organisations screening many domains, a combination of a single structured report and recurring monitoring gives both a point-in-time due diligence record and a way to catch meaningful infrastructure changes afterward.
Who uses it
- Compliance and AML teams
- Fraud prevention teams
- Procurement and vendor risk teams
- Banks and payment providers
- Insurance underwriters
Frequently asked questions
Does domain intelligence give a risk score for a domain?
No. URL Forensics presents the underlying public facts, such as registration age and mail authentication posture, rather than an opaque score. Analysts apply their own documented criteria to interpret the data.
Can domain intelligence be used for ongoing vendor monitoring?
Yes. Unlimited subscribers can enable weekly domain monitoring, which re-checks registration and DNS data on a schedule and can surface changes such as a registrar transfer or hosting change.
How is the intelligence report preserved for audit purposes?
Each report is sealed with a SHA-256 hash of its canonical JSON, which allows later verification that the report content has not been altered, and is available as a downloadable DIGITPOL PDF.
Need evidence you can keep?
Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.
