Skip to content
osint.platform

Domain intelligence

The most productive starting point in most investigations. A domain exposes its DNS, its registration history, every certificate ever logged for it, and the infrastructure it runs on, all from public, authoritative sources.

Accepts an email address, username, domain, IP address or URL.

Example: example.com

What this module collects

  • A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV and DS records
  • DNSSEC status from both the DS record and resolver validation
  • SPF, DKIM, DMARC and MTA-STS policies
  • RDAP registrar, registration and expiry dates, and status codes
  • Derived domain age, flagged when recently registered
  • Registrant organisation where the registry publishes it
  • Certificate transparency history from crt.sh
  • Passive subdomain discovery from certificate SAN entries
  • Live TLS certificate, chain validation and negotiated parameters
  • Resolved IP addresses, ASN and network operator
  • HTTP response, redirect chain, security headers and technologies
  • Historical capture activity from the Internet Archive

What this module will not do

These limits are deliberate. Each one is a place where a tool could produce a confident-looking answer that is not supported by public evidence.

  • No brute-force subdomain enumeration

    Subdomains come from passive sources, certificate transparency logs. Dictionary-based DNS brute forcing generates large volumes of unsolicited traffic against infrastructure the researcher does not own.

  • No port scanning or service probing

    Active scanning is intrusive and, in many jurisdictions, legally fraught without authorisation. The platform observes what is published, not what can be forced open.

  • Redacted registrant data is reported as redacted

    Most registrant contacts are withheld under privacy rules. Where a record is redacted, no owner is inferred from the registrar, the name servers, or anything else.