Start with the creation date
The single most revealing fact about a suspicious domain is when it was created. Fraudulent domains are usually registered days or weeks before they are used, a domain that claims to represent an established supplier but was created last month is a strong warning sign. Retrieve the creation date through WHOIS or RDAP and record the source and the UTC time of your observation.
Examine the registrant information
Compare the registrant organisation, country and registrar with the legitimate business being impersonated. Redacted or privacy-shielded registration is common and not proof of fraud on its own, but a registrant that does not match the claimed entity, or a registrar known for bulk, low-cost registrations, adds weight to other indicators.
Map the infrastructure
Resolve the domain's address records, nameservers and hosting provider. Fraudulent domains frequently sit on cheap shared hosting, use free DNS services, or share infrastructure with other suspicious domains. Identify the network holder separately from the website operator, they are rarely the same party.
Check the email servers and policy
Review the MX records to see which provider handles the domain's email, then read the SPF and DMARC records. A domain used for email fraud often has a freshly configured mail server, a permissive or absent DMARC policy, or an SPF record that authorises unexpected sending servers. In business email compromise, the difference between the real and fraudulent domain's email setup is often the decisive clue.
Compare against the genuine domain
Look for lookalike techniques: added or swapped characters, different top-level domains, hyphens, or homoglyphs. Place the suspected domain's creation date, registrant, hosting and email configuration side by side with the genuine domain's, the contrasts usually make the picture clear.
Know where the evidence ends
No single indicator proves fraud. A recent creation date, redacted registrant or shared hosting each have innocent explanations. Treat the checklist as a way to build and document suspicion: preserve every observation with its source and timestamp, corroborate with incident evidence such as the original message or payment instruction, and report uncertainty alongside findings. A domain check does not identify a person, it identifies infrastructure and timelines that investigators and courts can test.
Run a check now
The URL Forensics toolbox gathers the creation date, registrant data, DNS records, hosting provider, email servers and DMARC & SPF policy in a single evidence report, sealed with a verifiable hash. Run a domain check or read the domain forensics methodology.
