Investigate a suspicious domain
Work out whether a domain is malicious, who is behind it, and what else they run.
- Starts with
- Domain
- Useful for
- Phishing links, scam shops, brand impersonation, fake login pages.
- Time
- 30–60 minutes
- Progress
- 0 of 7 steps ·
Type a value into any step and every step of the same type fills in, with direct search links. Values stay in this tab and are not saved; only which steps you ticked is remembered, in your browser.
1. Check its reputation first
Why: If security vendors already flag it, you know what you are dealing with before you look any further.
Do: Search the domain in each tool. Note any verdicts, the dates they were first seen, and the category (phishing, malware, scam).
Look for:- Detections from several independent engines, not just one
- A first-seen date close to when the phishing started
- Related URLs or files the tools link to the domain
2. See the page without visiting it
Why: Opening a phishing page in your own browser can expose your IP and infect your machine. A sandbox visits it for you.
Do: Look for an existing scan first. Only submit a new one if there is none, and use a private scan if you can.
Look for:- Screenshots showing which brand it imitates
- Where the login form sends data (the "POST" requests)
- Redirect chains and the final landing domain
3. Find out when and by whom it was registered
Why: Phishing domains are usually days or weeks old, and registration details sometimes survive privacy protection.
Do: Look up WHOIS/RDAP. Record the creation date, registrar, name servers and any name, email or organisation that is not redacted.
Look for:- A very recent creation date
- A cheap or abuse-friendly registrar
- Any registrant email, even partial, to pivot on later
4. Map its infrastructure
Why: The server a site runs on often hosts the operator's other sites, which widens the picture.
Do: Find the IP addresses, hosting provider and certificate history, then list other domains on the same IP and certificate.
Look for:- Other look-alike domains on the same IP
- Subdomains in certificate logs (login., secure., account.)
- A shared hosting provider or name server pattern
5. Look for sibling domains
Why: Operators rarely register just one domain. Typo and look-alike variants are often live at the same time.
Do: Generate look-alike variants of the brand being impersonated, and check which are registered and resolving.
Look for:- Variants registered around the same date
- Variants on the same IP or name servers you found in step 4
6. Pivot on what you found
Why: The IP addresses and emails you collected link this domain to the rest of the operation.
Do: Search the IP from step 4 for reputation and other hosted sites. Search any registrant email in reverse WHOIS.
Look for:- Abuse reports and scanning activity from the IP
- Other domains sharing the registrant email
7. Report it
Why: Takedowns protect other victims, and registrars and hosts act faster with a clear evidence summary.
Do: Report the URL to Google Safe Browsing, the registrar's abuse contact and the hosting provider's abuse address. Include screenshots and scan links.
Look for:- The abuse contacts listed in the WHOIS and IP records you already pulled