What domain forensics is
Domain forensics is the collection and analysis of public evidence about a domain name to establish when it was registered, how it is configured, who provides its infrastructure and how it is used. It is the first step in most cybercrime investigations.
The workflow
1. Normalise the name to its registrable domain. 2. Collect RDAP/WHOIS registration data, focusing on creation date, registrar and status. 3. Query DNS: A, AAAA, NS, MX, TXT, SOA. 4. Evaluate SPF and DMARC. 5. Look up IP holders and hosting. 6. Search certificate transparency. 7. Compare with genuine domains and related cases. 8. Seal the evidence with a hash and record limitations.
Reporting
Present facts with sources and times, separate observation from interpretation, and state what could not be collected. A clear, verifiable report supports abuse takedowns, police referrals and civil recovery.
- Every value has a source and timestamp.
- Unavailable data is labelled, not guessed.
- Interpretation is separated from evidence.
- Report integrity can be verified.
