Practical, sourced explanations of how domain and internet infrastructure investigations work, linked to the tools you need to run them.
How to read a domain’s age, registration and infrastructure as one picture. Domain Age CheckerWHOIS Lookup
A step-by-step approach to website forensics: domain, hosting, certificates, content and preserved evidence.
Read resourceAn end-to-end domain forensics workflow covering registration, DNS, hosting, email, certificates and evidence sealing.
Read resourceHow the WHOIS/RDAP creation date helps investigators date a fraud, link domains and spot newly registered impersonation sites.
Read resourceWhy many scam and phishing domains are young, how to measure domain age, and how to avoid false positives.
Read resourceHow to detect and interpret changes in a domain’s registration, DNS and hosting, and how ongoing monitoring supports earlier detection.
Read resourceDNS records, what they reveal, and how they change during an incident. DNS LookupNS LookupCNAME Lookup
A, AAAA, MX, TXT, CNAME, NS and SOA records, with their forensic significance and limitations.
Read resourceCompare historical observations without treating incomplete coverage as a complete timeline.
Read resourceWhat a PTR record actually confirms, why it often does not match the hostname, and how investigators should weigh it as evidence.
Read resourceHow DNS record changes fit into incident timelines, what they can confirm about an attack, and how to collect that evidence correctly.
Read resourceRegistration data, registrants, redaction and the move from WHOIS to RDAP. RDAP LookupRegistrar Lookup
Understand registration events, redacted identity information and the limits of public domain records.
Read resourceHow to read registrant, registrar and contact data, what redaction means, and how to request nonpublic data lawfully.
Read resourceA practical routine for finance and compliance teams: check a domain’s age before paying, onboarding or trusting a new contact.
Read resourceWhat public WHOIS, RDAP and DNS lookups cannot tell an investigator, and which other sources are needed to fill those gaps.
Read resourceIP networks, hosting providers and the limits of IP attribution. IP LookupHosting Provider Lookup
How to trace the IP address behind a website or email, find the network holder and understand the limits of IP evidence.
Read resourceSeparate the registrar, DNS provider and web host so abuse reports and legal requests reach the right organisation.
Read resourceDistinguish network infrastructure from the person or organization operating a suspicious website.
Read resourceBusiness email compromise, mail servers and SPF, DKIM and DMARC. SPF CheckerDMARC CheckerMail Server Lookup
What BEC is, how payment deception works and which email, domain and transaction evidence to preserve.
Read resourceVerify changed payment instructions, preserve invoice evidence and investigate supplier impersonation safely.
Read resourceDistinguish spoofed domains, lookalike senders and compromised mailboxes when investigating BEC.
Read resourceInterpret email authentication policy without confusing a DNS record with proof of message authenticity.
Read resourceHow a domain investigation obtains the IP address an email was sent from and checks it against the SPF record.
Read resourceUse MX records and mail provider data to understand how a fraudulent domain receives and sends email.
Read resourceHow to read MX records, SPF and DMARC together to spot mail setups commonly associated with abuse, without overstating what they prove.
Read resourceFake shops, phishing sites and lookalike domains. SSL Certificate LookupDomain Age Checker
A practical sequence for examining a suspected fake shop or scam site: domain history, hosting, certificates and claims on the page.
Read resourceA structured way to map the domains, hosting, mail and certificates behind a phishing campaign using public evidence sources.
Read resourceExamine typosquatting, brand impersonation and newly registered domains without jumping to conclusions.
Read resourceThe common techniques behind lookalike and impersonation domains, how to recognise them, and how ongoing monitoring helps catch new ones early.
Read resourceA structured approach to suspected credential theft, malicious links and brand impersonation.
Read resourcePreserving domain evidence and producing a defensible report. DNS LookupWHOIS Lookup
Record provenance, timestamps and collection limitations for defensible investigative findings.
Read resourceHow to structure a defensible domain and URL evidence report: what to collect, how to present it, and how to seal it for integrity.
Read resourceAn end-to-end approach to examining suspicious links: parsing, redirects, hosting, domain age and evidence.
Read resourceSeparate scheme, hostname, user information, path and query data when examining suspicious URLs.
Read resourceDocument intermediate destinations and understand why a final URL can vary between observations.
Read resourceCertificate transparency and infrastructure pivots for threat research. Certificate Transparency Search