Enter a CVE ID, IP address, Domain, Email, Phone Number, File Hash or URL to analyse.
Nothing searched yet

Domain lookup

Domains carry phishing, host payloads, redirect traffic and serve as command-and-control. The lookup covers reputation, registration and where the domain actually points.

What you can paste

These are format examples. Clicking one puts it in the search box — it does not run a search, so you choose when to spend a lookup.

How to run one
  1. 1Paste the domain into the box above. The type is already set to Domain on this page.
  2. 2Press Analyze. If the indicator is new to the platform it is queued for enrichment, and the page holds a progress view while that runs rather than telling you to come back later.
  3. 3Read the report top-down. The verdict is the headline; the sections below it are the evidence, and the evidence is the part worth your time.
  4. 4Pivot. Almost every value in the report is itself searchable, which is how one indicator becomes an investigation.
Where to go next
  • Search the IPs in the DNS records
  • Cross-reference to find malware that reached for this domain
  • Compare the JARM fingerprint against other suspect hosts
What comes back, and how to read it

These are the sections of the report, in the order you will meet them.

  1. 01Risk Score and Engine Detections

    The aggregate call and the engines behind it. As with any indicator, read how many sources agree rather than the number alone.

  2. 02Registration & Ownership

    Registrar, creation and expiry dates. Registration age is one of the strongest cheap signals available: a domain registered three days ago and already sending mail deserves suspicion on that basis alone.

  3. 03Lifecycle and Domain Age

    How long the domain has existed and how long it has left. Disposable infrastructure tends to be young and short-dated.

  4. 04DNS Records

    What the domain resolves to now -- the A, MX and NS records that tell you where traffic and mail actually go, which is often not what the domain name implies.

  5. 05Hosting Footprint

    The infrastructure behind it, including the JARM fingerprint. A matching JARM across unrelated-looking domains is a strong hint they are the same operator.

  6. 06Raw WHOIS record

    The unparsed record, for when the normalised fields have dropped the detail you need. Always there, never summarised away.