Domain intelligence
The most productive starting point in most investigations. A domain exposes its DNS, its registration history, every certificate ever logged for it, and the infrastructure it runs on, all from public, authoritative sources.
Example: example.com
What this module collects
- A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV and DS records
- DNSSEC status from both the DS record and resolver validation
- SPF, DKIM, DMARC and MTA-STS policies
- RDAP registrar, registration and expiry dates, and status codes
- Derived domain age, flagged when recently registered
- Registrant organisation where the registry publishes it
- Certificate transparency history from crt.sh
- Passive subdomain discovery from certificate SAN entries
- Live TLS certificate, chain validation and negotiated parameters
- Resolved IP addresses, ASN and network operator
- HTTP response, redirect chain, security headers and technologies
- Historical capture activity from the Internet Archive
What this module will not do
These limits are deliberate. Each one is a place where a tool could produce a confident-looking answer that is not supported by public evidence.
No brute-force subdomain enumeration
Subdomains come from passive sources, certificate transparency logs. Dictionary-based DNS brute forcing generates large volumes of unsolicited traffic against infrastructure the researcher does not own.
No port scanning or service probing
Active scanning is intrusive and, in many jurisdictions, legally fraught without authorisation. The platform observes what is published, not what can be forced open.
Redacted registrant data is reported as redacted
Most registrant contacts are withheld under privacy rules. Where a record is redacted, no owner is inferred from the registrar, the name servers, or anything else.