← Back to overview
Capability explained
Domains, DNS and networks
This tool examines the technical environment of an internet address: who operates its domain and servers, how they can be reached and which protections have been published.
What can be examined?
- Domain names and IP addresses
- DNS records, name servers and mail servers
- SPF, DKIM, DMARC, DNSSEC, MTA-STS and TLS-RPT
- Certificates and public registration data
- IP networks, operators and autonomous systems (ASN)
- Ping, TCP 80/443 and traceroute with approximate hop locations
- Signals from public reputation lists
What can you find out?
- Whether a domain exists technically and where it points
- Which organisation operates the network
- Which mail protections are published
- Which path a connection takes from the application server
- Whether a checked warning list contains the domain or IP
Example from journalistic work
A reporter receives a link to an alleged company website. The technical footprint points to unrelated infrastructure and weak mail protection. That provides reporting leads, but is not proof of fraud.
What does the result not prove?
- IP geolocation is approximate, not proof of location.
- A listing must be verified; no listing does not mean “clean”.
- Traceroute starts at the application server, not the reporter’s computer.
Evidence and privacy
Only tools actually used and their inputs are recorded. Results, sources, timestamps, hashes and embedded evidence remain attributable. External services are only contacted where the tool expressly states this.