Investigate domains with OSINT tools. Start with WHOIS and DNS, then pivot into infrastructure, hosting history, and reputation signals to uncover ownership, relationships, and threats.
Follow the highest-ranked tools first, then expand into supporting pivots for deeper investigation.
Use this page as a working sequence, not just a list. Start broad, preserve volatile evidence, and corroborate before reporting.
Record target values, search terms, timestamps, and the first source that produced each lead.
Move from identifiers to related accounts, infrastructure, images, archives, or records only when the link is explainable.
Save screenshots, archive URLs, and keep original source links before pages change or accounts disappear.
Avoid single-source conclusions. Confirm important claims with independent tools, dates, and source types.
Start with the highest-confidence tools for the first pass.
ArchiveBox is self-hosted open-source web archiving for preserving websites, social posts, and online evidence for investigations.
Internet-wide search interface for hosts and certificates with large-scale host, service, and virtual host coverage plus API access.
Move to these once you need validation, pivots, and broader collection.
SecurityTrails provides historical DNS records, WHOIS history, subdomain enumeration, and IP intelligence for domain and infrastructure investigation.
Whoisology is a cross-referenced database of current and historic domain ownership records for InfoSec, legal, and research professionals.
ViewDNS provides reverse IP lookup, WHOIS, DNS records, subdomain finder, port scanner, and 20+ free network investigation tools.
DNS History archives historical DNS records, letting investigators track IP changes, hosting migrations, and infrastructure pivots over time.
Free online network tools, including traceroute, nslookup, dig, whois, ping, and our own Domain Dossier and Email Dossier. Works with IPv6.
InfoByIP provides bulk IP and domain lookups returning geolocation, ASN, hostname, and WHOIS data for multiple targets simultaneously.
Web Extension for saving a faithful copy of a complete web page in a single HTML file
Use supporting tools when you need corroboration or specialized enrichment.
No additional keyword-based matches.
Before turning this workflow into a finding, make the chain of reasoning easy to audit.
Quote or summarize the source output and keep the original URL.
Record collection time, page timestamps, and archive timestamps separately.
State the investigative relevance and whether it is direct evidence or a lead.
List independent corroboration and note any uncertainty or gaps.