Patterns common to phishing infrastructure

Many phishing and lookalike domains share a technical fingerprint even when their content is a convincing copy of a legitimate brand: a very recent creation date, a registrar favoured for low-friction bulk registration, privacy-redacted WHOIS contacts, and hosting that has no connection to the organisation being impersonated.

URL Forensics collects these data points through RDAP, DNS, network RDAP and certificate transparency lookups in a single pass, letting an investigator compare a suspected domain's infrastructure directly against what would be expected of the legitimate organisation.

  • Domain creation date relative to the incident timeline
  • Registrar and privacy/proxy status on the registration
  • Hosting provider and IP allocation versus the legitimate brand's known infrastructure
  • SPF and DMARC presence and policy strength
  • Certificate transparency log entries, including subdomains issued under the domain

Why mail authentication checks matter for phishing

Phishing and business email compromise frequently rely on domains with no SPF record, a permissive SPF record, or no DMARC policy at all, because this makes it easier to send mail that appears to originate from the domain. URL Forensics checks SPF and DMARC configuration as part of every investigation.

A domain with a strict DMARC policy and a tightly scoped SPF record is less likely to be the source of the spoofed mail itself, though an investigator should still consider that the attacker may be using a separate, newly registered domain rather than spoofing the legitimate one directly.

Capturing evidence before infrastructure disappears

Phishing infrastructure is often short-lived; domains are taken down, DNS is repointed, or hosting is abandoned once a campaign is detected. Capturing the public record promptly, and sealing it with a SHA-256 hash of the canonical report JSON, preserves the state of the evidence before it changes or disappears.

A downloadable DIGITPOL PDF report gives investigators, legal teams and takedown providers a document they can attach to abuse complaints, law enforcement referrals or internal incident records, with the hash available to confirm the report has not been altered after the fact.

Limits of automated phishing triage

URL Forensics does not visit the suspected phishing page, does not scan it for credential-harvesting scripts or malware, and does not provide historical DNS data showing how the domain's configuration looked before the investigation was run.

The platform does not label a domain as a confirmed phishing site. It reports the public infrastructure facts; confirming phishing activity and taking enforcement action remains the responsibility of the investigator, the brand owner, or, where appropriate, law enforcement.

Who uses it

  • SOC and incident response teams
  • Fraud investigators
  • Brand protection teams
  • Banks and payment providers
  • Managed security service providers

Frequently asked questions

Can URL Forensics confirm a domain is being used for phishing?

No. It collects public registration, DNS and certificate data that often correlates with phishing infrastructure, such as a very recent creation date or missing DMARC policy, but confirming phishing activity requires investigator judgment and, often, additional evidence.

Does the platform scan the suspected phishing page for malicious code?

No. URL Forensics does not visit or scan website content. It focuses on the public registration, DNS, hosting and certificate record associated with the domain.

How quickly should I capture evidence on a suspected phishing domain?

As soon as possible. Phishing infrastructure is frequently taken down or reconfigured, and a sealed report captures the public record at that moment, before it can change.

Can I escalate a phishing case beyond the automated report?

Yes. Digitpol provides specialist investigation support for cases that need more than an automated report; use the contact page to get in touch.

Need evidence you can keep?

Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.

Need specialist help with a case? Contact Digitpol