Editorial OSINT Guide

OSINT Tools for Domain and DNS Investigation

A domain and DNS OSINT guide for certificates, redirects, DNS history, public scans, and safe infrastructure evidence.

Domains DNS Certificates

Map the footprint

Check DNS, certificates, redirects, scans, and archives as separate layers.

Avoid false links

Shared hosting, CDNs, parking, and resellers can create misleading overlap.

Document time

Record timestamps because infrastructure can change quickly.

Quick answer

Use infrastructure OSINT to build leads, not to declare attribution.

Domain and DNS investigation turns one public clue into adjacent evidence: certificates, redirects, DNS records, hosting, archived pages, public scans, and reputation context. The mistake is treating overlap as ownership. Shared hosting, CDNs, resellers, parked domains, and reused infrastructure can all create false links.

  • Start with: exact domain, current DNS, archives, redirects, and certificate history.
  • Add context with: urlscan.io, SecurityTrails, ViewDNS.info, DNSDumpster, crt.sh, Shodan, Censys, Netlas.io.
  • Escalate carefully: suspicious domains can be checked through VirusTotal, URLhaus, PhishTank, Cisco Talos, or AlienVault OTX.
  • Never overclaim: infrastructure overlap is a lead unless another evidence layer supports it.

Recommended investigation stack

Certificate leads

crt.sh

Useful for certificate transparency searches, subdomain discovery, historical certificate names, and clues that connect domains by certificate timing or naming.

Best for: first-pass subdomains and certificate history

Page-load evidence

urlscan.io

Shows redirects, requests, screenshots, scripts, response headers, and page-load behavior from public scans. Choose visibility carefully before submitting sensitive URLs.

Best for: redirects, scripts, visual evidence, scan snapshots

DNS and history

SecurityTrails, ViewDNS.info, DNSDumpster

Useful for current and historical DNS, related records, mail records, and adjacent host clues. Coverage varies by provider and time period.

Best for: DNS history, host pivots, infrastructure mapping

Exposed services

Shodan, Censys, Netlas.io

Useful for internet-facing hosts, ports, certificates, banners, and service metadata. Keep this passive and do not turn research into unauthorized testing.

Best for: passive host context and public exposure snapshots

Investigation order

  1. Normalize the domain and capture the original page, email, or source where it appeared.
  2. Check current DNS, MX, nameservers, redirects, and archive history.
  3. Search certificate transparency for related names and historical certificate clues.
  4. Use public scan tools to document page behavior, scripts, redirects, and visible infrastructure.
  5. Compare findings across at least two independent sources before drawing a relationship.

Safety boundary

This guide is for passive public-source research. Do not probe, exploit, bypass access controls, or interact with suspicious infrastructure beyond normal safe browsing and documented public lookup tools.

Where to go next

Use the domain and infrastructure collection, Investigate a Domain or Website, or Shodan vs Censys vs SecurityTrails.

Recommended tool path

Start with the evidence, then choose the tool.

Treat domains, certificates, DNS records, hosts, and detected technologies as separate observations with their own timestamps. Use shared infrastructure to generate pivots, not to prove that two sites share an owner or operator.

Browse all tools

Step 1

urlscan.io

Role: Start with the live web request graph

Inspect redirects, requests, hosts, certificates, and page artifacts to frame the domain's observable surface before widening into historical or infrastructure datasets.

Editorial

Step 2

crt.sh

Role: Discover certificate-linked hostnames

Search certificate transparency records for names and dates that can reveal subdomains or historical links, then verify whether each host remains active and relevant.

Editorial

Step 3

SecurityTrails

Role: Trace DNS and registration changes

Use current and historical DNS associations to develop infrastructure leads, accounting for data freshness, plan coverage, shared services, and privacy-protected registration.

Editorial

Step 4

DNSDumpster

Role: Build a quick DNS map

Use discovered records and relationships as an initial map of the domain footprint, then validate hosts and record timing before including them in an investigative conclusion.

Editorial

Step 5

BuiltWith

Role: Inspect detected web technologies

Use current and historical technology detections to understand a public website's stack, while treating signatures as fallible observations rather than proof of ownership or a business relationship.

Editorial