What domain forensics is

Domain forensics is the collection and analysis of public evidence about a domain name to establish when it was registered, how it is configured, who provides its infrastructure and how it is used. It is the first step in most cybercrime investigations.

The workflow

1. Normalise the name to its registrable domain. 2. Collect RDAP/WHOIS registration data, focusing on creation date, registrar and status. 3. Query DNS: A, AAAA, NS, MX, TXT, SOA. 4. Evaluate SPF and DMARC. 5. Look up IP holders and hosting. 6. Search certificate transparency. 7. Compare with genuine domains and related cases. 8. Seal the evidence with a hash and record limitations.

Reporting

Present facts with sources and times, separate observation from interpretation, and state what could not be collected. A clear, verifiable report supports abuse takedowns, police referrals and civil recovery.

  • Every value has a source and timestamp.
  • Unavailable data is labelled, not guessed.
  • Interpretation is separated from evidence.
  • Report integrity can be verified.

Sources and further reading

ICANN, RDAPRFC 1034, DNS concepts
This resource supports investigative triage. It is not legal advice, an attribution finding or a certification that a website is safe.