Investigate a suspicious domain

Work out whether a domain is malicious, who is behind it, and what else they run.

Starts with
Domain
Useful for
Phishing links, scam shops, brand impersonation, fake login pages.
Time
30–60 minutes
Progress
0 of 7 steps ·

Type a value into any step and every step of the same type fills in, with direct search links. Values stay in this tab and are not saved; only which steps you ticked is remembered, in your browser.

  1. 1. Check its reputation first

    Why: If security vendors already flag it, you know what you are dealing with before you look any further.

    Do: Search the domain in each tool. Note any verdicts, the dates they were first seen, and the category (phishing, malware, scam).

    Look for:
    • Detections from several independent engines, not just one
    • A first-seen date close to when the phishing started
    • Related URLs or files the tools link to the domain
  2. 2. See the page without visiting it

    Why: Opening a phishing page in your own browser can expose your IP and infect your machine. A sandbox visits it for you.

    Do: Look for an existing scan first. Only submit a new one if there is none, and use a private scan if you can.

    Look for:
    • Screenshots showing which brand it imitates
    • Where the login form sends data (the "POST" requests)
    • Redirect chains and the final landing domain
  3. 3. Find out when and by whom it was registered

    Why: Phishing domains are usually days or weeks old, and registration details sometimes survive privacy protection.

    Do: Look up WHOIS/RDAP. Record the creation date, registrar, name servers and any name, email or organisation that is not redacted.

    Look for:
    • A very recent creation date
    • A cheap or abuse-friendly registrar
    • Any registrant email, even partial, to pivot on later
  4. 4. Map its infrastructure

    Why: The server a site runs on often hosts the operator's other sites, which widens the picture.

    Do: Find the IP addresses, hosting provider and certificate history, then list other domains on the same IP and certificate.

    Look for:
    • Other look-alike domains on the same IP
    • Subdomains in certificate logs (login., secure., account.)
    • A shared hosting provider or name server pattern
  5. 5. Look for sibling domains

    Why: Operators rarely register just one domain. Typo and look-alike variants are often live at the same time.

    Do: Generate look-alike variants of the brand being impersonated, and check which are registered and resolving.

    Look for:
    • Variants registered around the same date
    • Variants on the same IP or name servers you found in step 4
  6. 6. Pivot on what you found

    Why: The IP addresses and emails you collected link this domain to the rest of the operation.

    Do: Search the IP from step 4 for reputation and other hosted sites. Search any registrant email in reverse WHOIS.

    Look for:
    • Abuse reports and scanning activity from the IP
    • Other domains sharing the registrant email
  7. 7. Report it

    Why: Takedowns protect other victims, and registrars and hosts act faster with a clear evidence summary.

    Do: Report the URL to Google Safe Browsing, the registrar's abuse contact and the hosting provider's abuse address. Include screenshots and scan links.

    Look for:
    • The abuse contacts listed in the WHOIS and IP records you already pulled

Other playbooks