What a domain investigation covers
A domain investigation is the process of collecting and interpreting the public technical record attached to a domain name: who registered it, when, through which registrar, where it currently resolves, and how its mail and web infrastructure are configured. On its own, none of these facts proves fraud or legitimacy; together, they establish a timeline and an infrastructure footprint that an investigator can test against the facts of a case.
URL Forensics automates the collection step so that an investigator does not need to run WHOIS, RDAP, DNS and certificate transparency lookups separately and then reconcile the results by hand. The platform queries each source, normalises the output and presents it alongside the other data points for the same domain at the same point in time.
- Registration data: creation date, expiry date, registrar, status codes
- DNS records: A/AAAA, MX, TXT, NS, CNAME
- Network RDAP for the resolved IP address and its allocation
- Certificate transparency logs via crt.sh
- Mail authentication posture: SPF, DMARC, MTA-STS where published
Why point-in-time evidence matters
Domain infrastructure changes. A registrant can update nameservers, a hosting provider can reassign an IP address, and a certificate can be reissued within hours. A domain investigation is therefore only meaningful if it records what was publicly observable at a specific moment, and if that record can later be shown not to have been altered.
Every URL Forensics report is sealed with a SHA-256 hash of the canonical JSON underlying the report. The hash lets anyone verify that the report content has not been modified after it was generated. It is a tamper-evidence mechanism, not a digital signature and not a trusted timestamp, and it does not attest that the underlying source data (for example, a WHOIS registrant field) is itself accurate or true.
What the platform does not do
URL Forensics does not visit, render or crawl the website behind the domain, and it does not scan for malware, exploits or malicious scripts. It also does not provide historical DNS data; every lookup reflects the current public record at the time the report is generated, not past configurations.
The output is evidence for an investigation, not a verdict. The platform does not and cannot tell you whether a domain is safe, malicious, or fraudulent; it reports what the public record says so that a trained investigator or legal team can draw conclusions in the context of the wider case.
Using a domain investigation in casework
Investigators typically combine registration dates, hosting attribution and mail authentication posture to establish whether a domain's infrastructure is consistent with the narrative they have been given: a domain registered days before an invoice fraud email, hosted on infrastructure unrelated to the claimed sender, with no SPF or DMARC record, is a different fact pattern from a domain that has been stable for a decade with properly configured mail authentication.
A downloadable DIGITPOL PDF report packages the findings for inclusion in a case file, a demand letter, or a referral to law enforcement, with the SHA-256 hash recorded so the report's integrity can be checked later.
Who uses it
- Fraud investigators
- Law firms and litigation support
- Banks and payment providers
- Compliance and AML teams
- SOC and incident response teams
- Insurance claims investigators
Frequently asked questions
Does a domain investigation prove that a website is fraudulent?
No. It documents the public technical record attached to a domain at a point in time. Determining whether a domain is being used fraudulently requires combining that record with the wider facts of the case and is a judgment for the investigator, not an automated verdict.
Can the report show how a domain's DNS records looked last year?
No. URL Forensics only queries current public DNS, RDAP and certificate transparency data. It does not maintain or provide historical DNS records.
What does the SHA-256 hash on a report actually prove?
It proves that the report content has not been altered since it was generated. It does not act as a digital signature or a trusted timestamp, and it says nothing about whether the underlying source data, such as a registrant name in WHOIS, is accurate.
What if my case needs more than the automated report?
Digitpol offers specialist investigation support beyond the automated platform. You can reach the team through the contact page to discuss case-specific needs.
Need evidence you can keep?
Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.
