Infrastructure, not content
A website investigation conducted through URL Forensics focuses on the technical infrastructure behind a site, not on its visible content. The platform does not visit, render or crawl the site itself; it queries public registration, DNS, network and certificate authorities directly, which means the investigation does not depend on the website being online or on what it currently displays.
This approach is deliberate. Content can be changed or taken down in minutes, and visiting a suspect website can tip off an operator or expose an investigator's own infrastructure. Querying the public record around the domain avoids both problems while still producing substantive, citable evidence.
- RDAP and WHOIS registration history for the domain
- Resolved IP address and its network RDAP allocation
- Hosting provider attribution from IP and ASN data
- DNS record set: A, AAAA, MX, TXT, NS, CNAME
- Certificate transparency log entries via crt.sh
Building a usable evidence file
Each investigation produces a structured report rather than a raw data dump. Registration dates, hosting details and mail authentication findings are presented together so an investigator can see whether they tell a consistent story, for instance a newly registered domain pointed at hosting unrelated to the brand it claims to represent.
The report is sealed with a SHA-256 hash of its canonical JSON so that its integrity can be verified later. A downloadable DIGITPOL PDF version is provided for inclusion in case files, pleadings or regulatory submissions.
Scope and limits
URL Forensics does not scan the website for malware or vulnerabilities and does not evaluate page content, branding, or copy. It also does not provide historical DNS records; the report reflects the public data available at the time the investigation is run.
Because of this, the platform should be understood as an evidence-collection tool. It does not issue a safety verdict or a risk score claiming a site is safe or dangerous; interpretation of the findings remains the responsibility of the investigator or legal team using the report.
Monitoring a website over time
Infrastructure changes can themselves be evidence, for example a domain switching hosting providers shortly after a complaint is filed. Unlimited subscribers can set up weekly domain monitoring so that changes to registration or DNS data are captured as they occur, rather than only at the moment a case is opened.
This is particularly useful for ongoing matters such as brand abuse, phishing campaigns that rotate infrastructure, or disputes where the opposing party controls the domain in question.
Who uses it
- Brand protection teams
- Litigation support and e-discovery
- Corporate security teams
- Compliance officers
- Private investigators
Frequently asked questions
Does URL Forensics visit the website I'm investigating?
No. The platform queries public registration, DNS, network and certificate records directly. It does not render, crawl or scan the website's content.
Can I monitor a website for infrastructure changes over time?
Unlimited subscribers have access to weekly domain monitoring, which re-checks registration and DNS data on a regular schedule so changes can be noticed as they happen.
Will the report tell me if a website is safe to use?
No. The platform reports the facts of the public record, such as registration dates and hosting attribution. It does not produce a safety verdict, and interpreting the findings is left to the investigator.
Need evidence you can keep?
Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.
