Collection

Tools for Domain, DNS, and Web Infrastructure Research

Editorial 8 tools 3 curated picks

A stack for tracing ownership clues, certificates, hosting changes, and exposed web infrastructure.

Stack snapshot

8 tool profiles in this workflow, including 3 curated picks.

Best for

Researchers mapping digital infrastructure, ownership clues, exposed services, and related assets around a website or organization.

Methodology

Prioritized tools that expose different layers of the web stack so investigators can move from a domain name to corroborated infrastructure context.

Editorial note

Ranking reflects corroboration value and layer coverage, not enterprise pricing or vendor prestige.

Curated picks

Top pick

SecurityTrails

Budget pick

crt.sh

Open-source pick

SpiderFoot

Tools in this collection

Tools in this workflow

Researchers mapping digital infrastructure, ownership clues, exposed services, and related assets around a website or organization.

Primary job: Domain, DNS, IP and registration context

SecurityTrails

Role: Reconstruct DNS history

Use dated DNS, IP, and nameserver observations to understand infrastructure changes without treating shared hosting as shared ownership.

Editorial
crt.sh official-page screenshot

Official-page screenshot

Sectigo

Source checked 2026-05-27

Free certificate-transparency lookup for domain pivots

Verification: Verification status not listed Workflow: Discovery Pricing: Free

Best for: Certificate-transparency pivots around domains, organizations, hostnames, SAN entries, fingerprints, and historical infrastructure naming patterns.

Editorial

Primary job: Public Certificate Transparency record search

crt.sh

Role: Expand certificate-linked hostnames

Search Certificate Transparency records for hostnames and certificate history, then verify whether each discovered service is still relevant.

Editorial
DNSDumpster official-page screenshot

Official-page screenshot

DNSDumpster

Source checked 2026-05-07

Passive DNS and subdomain reconnaissance

Verification: Verification status not listed Workflow: Discovery, Pivoting Pricing: Freemium

Best for: Use it when a domain is already in scope and the next job is quick passive mapping before…

Editorial

Primary job: Discovering domain-related hosts and DNS infrastructure

DNSDumpster

Role: Map current DNS relationships

Build a quick view of public DNS records and related hosts for orientation before confirming important links with direct DNS queries.

Editorial
MXToolbox official-page screenshot

Official-page screenshot

MXToolbox

Source checked 2026-05-07

DNS, email, and blacklist diagnostics

Verification: Verification status not listed Workflow: Enrichment, Verification Pricing: Freemium

Best for: Use it when a domain or mail server needs quick deliverability, DNS, or blacklist context before deeper infrastructure…

Editorial

Primary job: Mail-routing DNS lookup and email-delivery diagnostics

MXToolbox

Role: Inspect mail and DNS posture

Check mail routing, authentication, blacklist, and DNS configuration when email infrastructure or delivery posture is part of the question.

Editorial

Primary job: Current and historical domain registration and DNS records

WhoisXML API

Role: Aggregate registration pivots

Use consolidated registration, DNS, and ownership-adjacent records for scoped pivots while respecting redaction and historical-data limits.

Editorial

Primary job: DNS, reverse-infrastructure and historical IP lookups

ViewDNS.info

Role: Run quick infrastructure cross-checks

Use focused DNS, reverse-IP, and domain utilities to test a lead quickly, then corroborate meaningful links with dated primary observations.

Editorial

Primary job: Internet-facing host banner and service search

Shodan

Role: Inspect internet-exposed services

Review observed service banners and exposure history for authorized passive research, verifying freshness before describing a current system.

Tested

Primary job: Module-driven collection and correlation of reconnaissance findings

SpiderFoot

Role: Automate a bounded domain pivot

Collect passive domain, host, and account relationships after defining the scope, then verify important edges against the underlying sources.

Tested

Workflow notes

This collection is built for analysts who start with a domain, host, or website and need to understand what is visible without jumping straight to attribution.

Use this stack when

The case needs domain history, certificate clues, web rendering, exposed-service context, or technology-stack evidence around a scoped web asset.

Recommended sequence

  • Start with SecurityTrails or crt.sh when the question is DNS history, subdomains, or certificates.
  • Use Shodan and Censys when the investigation shifts from domain clues into exposed services and host relationships.
  • Use urlscan.io when a suspicious page needs a preserved render and request snapshot.
  • Add Wappalyzer or BuiltWith when visible web stack, analytics tags, ecommerce tooling, or CMS footprint matters.
  • Use VirusTotal or GreyNoise only when the lead includes reputation, scanning, or background-noise questions.
  • Use SpiderFoot when a known domain deserves broader automated collection before manual narrowing.

Specialist infrastructure branches

  • Use DomainTools or RiskIQ PassiveTotal when commercial history and cross-source infrastructure pivots justify the access cost, while accounting for product, retention, and coverage changes.
  • Use BinaryEdge, FOFA, or ONYPHE as a second asset-search dataset when Shodan or Censys leaves a specific exposure question unresolved; dataset overlap is corroboration, not proof of control.

Editorial guardrail

No single tool here proves ownership, compromise, or attribution. Build a defensible chain from domain clue to web evidence to infrastructure context.

Related OSINT4ALL paths

Use these connected pages when the same investigation needs a different entry point or a deeper decision aid.