Practical reference material for domain investigations, suspicious-link analysis and evidence preservation. Grounded in technical standards, written for real investigations.
13 resources
Interpret email authentication policy without confusing a DNS record with proof of message authenticity.
Read resourceUnderstand registration events, redacted identity information and the limits of public domain records.
Read resourceA, AAAA, MX, TXT, CNAME, NS and SOA records, with their forensic significance and limitations.
Read resourceExamine typosquatting, brand impersonation and newly registered domains without jumping to conclusions.
Read resourceSeparate scheme, hostname, user information, path and query data when examining suspicious URLs.
Read resourceDocument intermediate destinations and understand why a final URL can vary between observations.
Read resourceA structured approach to suspected credential theft, malicious links and brand impersonation.
Read resourceCompare historical observations without treating incomplete coverage as a complete timeline.
Read resourceRecord provenance, timestamps and collection limitations for defensible investigative findings.
Read resourceDistinguish network infrastructure from the person or organization operating a suspicious website.
Read resourceWhat BEC is, how payment deception works and which email, domain and transaction evidence to preserve.
Read resourceVerify changed payment instructions, preserve invoice evidence and investigate supplier impersonation safely.
Read resourceDistinguish spoofed domains, lookalike senders and compromised mailboxes when investigating BEC.
Read resource