What URL forensics is

URL forensics examines a link itself and the infrastructure behind it: how the URL is constructed, where it leads, which domain really controls it and how old that domain is. It is used for phishing triage, scam investigations and incident response.

The workflow

1. Parse the URL and identify the real hostname and registrable domain. 2. Decode Punycode and encoded parameters. 3. Follow redirects in a controlled way and record each hop. 4. Run domain forensics on every domain in the chain, including the creation date. 5. Identify hosting and certificates. 6. Preserve the evidence with a hash.

Common traps

Brand names in subdomains or paths, user-info tricks with @, shortened links and open redirects on trusted sites all disguise the true destination. The controlling registrable domain and its registration date usually cut through the disguise.

  • Identify the registrable domain.
  • Record every redirect hop.
  • Check the creation date of each domain.
  • Never enter credentials or pay to test a link.

Sources and further reading

RFC 3986, URI syntaxPublic Suffix List
This resource supports investigative triage. It is not legal advice, an attribution finding or a certification that a website is safe.