Domain Intelligence (DOMINT): Intelligence Discipline Guide
Domains are the cheapest and most disposable part of an attack, and the most revealing. Registration and DNS leave a paper trail adversaries rarely bother to clean.
Domains are the cheapest and most disposable part of an attack, and the most revealing. Registration and DNS leave a paper trail adversaries rarely bother to clean.
What Domain Intelligence is as a discipline
Domain intelligence is the collection and analysis of domain names, their registration records and their DNS configuration. It covers RDAP and whois registration data, registrar and nameserver relationships, resource records including A, AAAA, MX, NS, TXT, CNAME and SOA, passive DNS history showing what a name resolved to over time, and zone-level data such as newly registered domain feeds. Analysts use it to detect impersonation of their brand, map adversary infrastructure, and establish when a domain was created relative to observed campaign activity.
Sub-methods include registration monitoring for new domains matching brand patterns, resolution monitoring covering where a name points now and historically, configuration fingerprinting using distinctive TXT records, mail providers and nameserver sets, and clustering that groups domains by shared registrant fragments, nameservers or hosting. Because registration data has been broadly redacted since GDPR, mature practice weights infrastructure and behavioural pivots far above whois fields that are now uniformly empty.
Why it matters
Domain intelligence answers who set infrastructure up, when, and what else they set up at the same time. Creation date alone is often decisive: a domain registered three days before it appears in an inbound email is a phishing indicator regardless of content. Passive DNS resolves the historical question live lookups cannot, namely where a name pointed during the incident window. Clustering turns one observed phishing site into the full campaign footprint, enabling pre-emptive blocking.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Creation, expiry and last-updated timestamps from RDAP, establishing infrastructure age relative to the activity you observed
- Registrar and reseller identity, revealing operators who cluster on providers tolerant of abuse or accepting anonymous payment
- Nameserver sets shared across otherwise unrelated domains, a durable clustering key that survives hosting and address changes
- Passive DNS resolution history listing every address a name pointed to, with first-seen and last-seen timestamps for each
- MX records and SPF, DKIM and DMARC configuration showing whether a lookalike domain has been provisioned to send mail
- Registrant organisation, email and postal fields where unredacted, and privacy-service identity where redaction is applied
- Typosquat, homoglyph, combosquat and alternative-TLD variants of brand names surfacing in newly registered domain feeds
- Dangling CNAME and NS delegations pointing at deprovisioned third-party services, exposing subdomain takeover opportunities
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- RDAP endpoints — Structured, authoritative registration data from registries and registrars, replacing legacy whois with consistent fields
- ICANN CZDS — Access to gTLD zone files, the authoritative basis for genuine newly registered domain detection
- Passive DNS providers — Farsight DNSDB and Silent Push supply historical resolution records with first- and last-seen timestamps
- crt.sh — Certificate issuance as an independent signal that a domain and its subdomains were provisioned and when
- abuse.ch URLhaus and ThreatFox — Domains observed distributing malware or hosting command and control, with sample linkage
- VirusTotal — Domain reputation, resolution history and the samples observed communicating with the name
- dnstwist — Open-source permutation generation for typosquat, homoglyph and bitsquat discovery against a brand
- PhishTank and Google Safe Browsing — Independent third-party classification corroborating whether a domain is treated as phishing
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Define seeds — List owned domains, trademarks, product names and executive names to be monitored, together with the legitimate variants you already control.
- Generate and match permutations — Produce typo, homoglyph, hyphenation and alternative-TLD variants, and match them daily against zone and newly registered domain feeds.
- Enrich candidates — Pull RDAP dates, nameservers, hosting, certificates and mail configuration for each hit. Domain age and mail readiness drive priority.
- Classify intent — Resolve and capture served content. Separate parked speculation, defensive registration, unrelated legitimate use and active impersonation.
- Cluster the campaign — Pivot on nameservers, registrant fragments, hosting, certificate attributes and content hashes to find sibling domains not yet activated.
- Act and preserve — Block the whole cluster, file evidenced registrar and hosting abuse reports, and archive timestamped resolution history for the record.
- Watch for reactivation — Keep dormant clusters under passive DNS monitoring, because parked domains are routinely weaponised weeks after registration.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Applied in these mission domains
Operates on these data points
- SSL/TLS Certificate — A digital certificate binding a public key to an identity.
- Malware Family — A named class of related malicious software.
- File Hash — Cryptographic fingerprint of a file, used for malware identification.
- IP Address — Internet Protocol address identifying a device or server on a network.
- Domain Name — Human-readable address that maps to IP infrastructure via DNS.
- Detection Signature — A YARA/Sigma/Snort rule encoding detection logic for a malware family or behavior.
Related disciplines
- Attack Surface Intelligence — Your Own Exposed Attack Surface
- Breach Intelligence — Exposed Credentials and Compromised Data
- Certificate Intelligence — TLS Certificates and Certificate Transparency
- Cyber Intelligence — Adversary Activity in Networks and Systems
- Dark Web Intelligence — Hidden Services and Closed Criminal Venues
- Malware Intelligence — Understanding Malicious Code
Inside the platform: where Domain Intelligence lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
discipline.php?d=DOMINT— Discipline hubsource-catalog.php?disc=DOMINT— Source catalogue filtered to this disciplineurl-profile.php— SSL/TLS Certificate profilehash-profile.php— Malware Family profileip-profile.php— IP Address profilesearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Correlate Infrastructure
- DNS Audit
- Threat Hunt
- Detection Rules
- Enrichment Runner
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Define seeds is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Enrich candidates turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Watch for reactivation feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Domain Intelligence
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence practitioners use domain intelligence for infrastructure characterisation and for protecting the organisational name space. Passive registration and resolution data supports mapping of adversary phishing and command infrastructure, identification of impersonation targeting service personnel and families, and monitoring of names associated with deployments and exercises. Products feed sensor tuning, operational security advisories and cyber terrain understanding. Collection is entirely from public sources and generates no target contact, which is why it is available where more intrusive techniques are not. Constraint: registrant details are personal data in most jurisdictions and are increasingly redacted, so an analyst cannot expect identity from a lookup and must not build products that assume it.
🕵 National intelligence
National services treat registration and resolution data as a high-yield passive collection stream that can be run continuously at scale. Requirements typically involve mapping the infrastructure of entities of interest, detecting preparation of influence or intrusion campaigns through bulk registration patterns, and identifying the service providers that adversaries habitually use. Passive DNS is particularly valuable because it records historical resolution that no live query can recover. Fusion with certificate, routing and scan data resolves ownership questions that registration alone cannot. Handling reflects that the data is open while the target set is not, so products are structured to release the infrastructure findings while protecting the requirement that drove collection.
👮 Law enforcement
Investigators use domain records to identify infrastructure, establish timelines and route legal process. Registration timestamps, nameserver changes and historical resolution provide corroborating evidence independent of anything the suspect controls. Because registrant contact data is now largely redacted for privacy, identity normally requires a production order or a request through the registrar or registry, and cross-border cases need mutual legal assistance or a recognised cooperation route. Preservation requests should be issued early because registration data changes on transfer and passive DNS coverage is not guaranteed. Evidential use requires recorded retrieval time, tool and hash, since lookups return different answers on different days.
🔍 Private investigation and corporate security
Corporate practitioners use domain intelligence for brand protection, phishing detection, portfolio management and diligence on counterparties. Monitoring newly registered domains for lookalikes of your brands is one of the highest-return controls available. Passive lookups against third parties are lawful because the data is published, but a private actor must not probe the resulting hosts, must not attempt to access them, and must not use pretext to obtain registrant data from a registrar. Findings are actioned through takedown providers, registrar abuse channels, blocklist submissions and internal blocking, and through the uniform dispute resolution process where trademark rights support recovery of the name.
📰 Journalism and OSINT media
Journalists use domain records to evidence who is behind a website, when a campaign was set up, and whether apparently separate outlets share infrastructure. The verification standard is to record the exact lookup, the source and the retrieval time, and to recognise that historical registration data and passive DNS are the useful part while current lookups are usually redacted. Do not assert ownership from a shared hosting provider or a shared nameserver, since these are shared by millions. Corroborate infrastructure inference with editorial, financial or personnel evidence before naming anyone, and give the subject a right of reply that specifies the technical basis.
🌍 NGO, humanitarian and human rights
Civil society organisations use domain intelligence defensively to detect lookalike domains used to phish staff and partners, and analytically to document censorship, disinformation and surveillance infrastructure. Because the data is fully public and collection touches nothing, it is one of the few techniques safely usable from a hostile environment. Do-no-harm considerations attach to publication rather than collection: exposing infrastructure used against a specific community can trigger rebuilding that leaves those people less protected, so coordinate with the technical responders supporting them. Preserve records with timestamps, since registration data is routinely altered once an investigation becomes visible.
🎓 University and research
Researchers use registration and resolution data to study abuse concentration by registrar and top level domain, the lifecycle of malicious domains, typosquatting prevalence and the effects of privacy regulation on registration data availability. Methodology must state the data source, its collection vantage and its date, because passive DNS coverage differs sharply between sensor networks and no provider sees everything. Ethics review applies where registrant records contain personal data, and bulk republication of registrant details is restricted in several jurisdictions. Prefer zone file access programmes and documented passive DNS providers over ad hoc scraping, and archive the snapshot used since the underlying records change continuously.
Playbook: working Domain Intelligence end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the name space you protect
Establish what belongs to you before watching for what does not: every registered domain across all top level domains, including defensive registrations, expired names still referenced in print, acquisition inheritances and country-code variants. Include brands, product names, campaign names and executive names. Assign an owner and a renewal accountability for each. A good output is a complete domain portfolio register reconciled against registrar accounts and finance records. Stop when every domain in the portfolio has an owner and every brand in the marketing catalogue has a corresponding monitoring pattern.
Phase 2 — Understand what registration data now shows
Establish what the registration lookup can and cannot tell you in the jurisdictions and top level domains you care about. Since privacy regulation, most generic top level domain records show redacted registrant contact fields, while some country-code registries publish more and some publish less. Registration and expiry dates, registrar, status codes and nameservers remain visible and are the analytic backbone. A good output is a written expectation of field availability per registry so analysts do not build workflows that assume identity data. Stop when the team knows where redaction applies and what the lawful route to identity is.
Phase 3 — Establish a monitoring pipeline
Ingest newly registered and newly observed domain feeds, plus zone file data where you have access, and apply your brand pattern set continuously. Registration usually precedes weaponisation by days, which is the window the whole capability exists to exploit. Enrich each candidate before it reaches an analyst with registrar, registration date, nameservers, resolution status, hosting and any certificate issuance. A good output is an alert stream with enough enrichment that triage takes seconds per item. Stop tuning when analysts examine every alert rather than filtering the queue.
Phase 4 — Match brands intelligently
Build the matching rules to catch what attackers actually register: character substitutions and homoglyphs, insertions and omissions, hyphenation, brand plus a service word such as login or support, brand in a subdomain of an unrelated domain, and the same patterns across alternative top level domains. Score by visual similarity and by whether the registrable domain itself contains the brand. Suppress the systematic noise from platforms that issue customer subdomains at volume. A good output is a scored pattern set with measured precision. Stop when precision is high enough that alerts are trusted and acted on.
Phase 5 — Assess intent and stage
For each candidate, determine where it is in its lifecycle. A registered name with no resolution is preparation; a resolving name with a parked page may be speculative or dormant infrastructure; a name with a certificate, a mail exchanger record and a cloned login page is imminent or live. Mail exchanger records on a lookalike domain are a strong signal of intended business email compromise. A good output is a triage disposition per candidate with a stage classification and a recommended action. Stop when each candidate is escalated, blocked, monitored or dismissed with a recorded reason.
Phase 6 — Pivot to related infrastructure
Use each confirmed malicious domain as a pivot point. Look at the nameservers, the hosting address and its neighbours, the certificate, the registration timing relative to other names, the registrar and any remaining registrant artefacts, and historical resolutions. Bulk registrations made in the same session at the same registrar with sequential patterns frequently expose an entire campaign from one observation. Weight the pivots, since shared hosting and shared nameservers are weak on their own. A good output is a campaign cluster with per-edge evidence. Stop when pivots produce candidates that fail corroboration.
Phase 7 — Use passive DNS for history
Query passive DNS to establish what a name resolved to over time and what other names resolved to the same address. This recovers history that no live lookup can, which matters because adversaries move infrastructure once they are noticed and because timelines are frequently the point of the investigation. Record the provider and the observation window, since coverage varies by sensor network and absence is not evidence. A good output is a resolution timeline with provider and coverage stated. Stop when the timeline covers the period of interest or the coverage limit is documented.
Phase 8 — Act through registrars and providers
Route confirmed abuse to the parties who can stop it: the registrar abuse contact, the hosting provider, the certificate authority where appropriate, national CERTs and blocklist providers. Supply an evidence pack with the domain, the observed abuse, capture artefacts with timestamps and hashes, and a clear statement of the harm, so the recipient can act without further enquiry. Where trademark rights apply, consider the uniform dispute resolution process to recover the name rather than merely suspend it. A good output is a submission with a reference and a tracked outcome. Stop when the outcome is recorded.
Phase 9 — Protect the portfolio operationally
Reduce your own exposure: enable registrar and registry lock on critical domains, use registrar accounts with strong authentication and restricted access, monitor for unauthorised nameserver or registrant changes, set renewal automation with independent alerting, and ensure DNS records for decommissioned services are removed so nothing dangles. Domain hijack and lapse are low-frequency, very high-impact events. A good output is a control state where a hostile change or an imminent expiry raises an alert to a named owner. Stop when the critical domains are locked, monitored and cannot lapse silently.
Phase 10 — Preserve evidence and record retrieval
Capture registration records, resolution data and page content with the exact retrieval time, the source queried and a hash of the artefact. Registration data changes on transfer and is routinely altered once an investigation becomes visible, so contemporaneous preservation is the only reliable record. Where legal action is likely, capture through a process that a third party could authenticate. A good output is an evidence set that supports the assertion made months later when the record itself has changed. Stop when every material assertion has a preserved and dated artefact behind it.
Phase 11 — Review coverage and outcomes
Measure whether the monitoring is delivering warning: for each phishing incident, check whether the domain had been detected at registration and how much lead time existed before it was used. Feed misses back into the pattern set. Track takedown acceptance rates and time to suspension by registrar, since that determines which providers need escalation routes. A good output is a periodic effectiveness review with specific pattern and process changes. Stop reviewing only when lead time is consistently longer than the time your takedown process requires.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| ICANN lookup and RDAP | Open | Registration data access protocol lookup returning registrar, creation and expiry dates, status codes and nameservers. | Authoritative current registration state for a domain, including status codes indicating locks or disputes. |
| ICANN | Open | Coordinating body publishing registration data policy, registrar accreditation, dispute procedures and contractual compliance mechanisms. | Establishes what data registrars must hold and disclose, and the route for abuse and dispute escalation. |
| ICANN Centralized Zone Data Service | Registration | Programme providing access to generic top level domain zone files listing delegated domains and their nameservers. | Authoritative bulk enumeration of registered names and nameserver relationships for portfolio and campaign analysis. |
| crt.sh | Open | Searchable Certificate Transparency log index exposing hostnames for which certificates have been issued. | Reveals subdomains and lookalike names at certificate issuance, often the earliest signal of imminent use. |
| DomainTools | Licensed | Commercial provider of historical registration records, passive DNS and infrastructure pivoting datasets. | Historical registrant data predating redaction, and pivoting across registration artefacts no longer publicly visible. |
| SecurityTrails | Registration | Historical DNS records, subdomain data and registration history with an interface designed for pivoting. | Recovers historical resolution and nameserver changes that establish infrastructure timelines. |
| RIPEstat | Open | Query interface over registry allocation, routing, reverse DNS and related network data for addresses and prefixes. | Resolves the hosting context of a domain and identifies the network operator responsible for abuse handling. |
| URLhaus | Open | Open database of malware distribution URLs with hosting metadata, payload references and observation timestamps. | Checks whether a candidate domain is already documented as distributing malware, accelerating triage. |
| OpenPhish | Open | Feed of confirmed phishing URLs with targeted brand attribution and first observation timestamps. | Corroborates that a lookalike domain has become an operational phishing site targeting your brand. |
| Spamhaus | Open | Reputation datasets covering domains, addresses and networks associated with spam, malware and abuse. | Assesses registrar and hosting reputation context when prioritising which candidates to escalate. |
| AbuseIPDB | Registration | Community-reported database of addresses associated with abusive activity, with categorised reports and confidence scoring. | Provides additional context on the hosting address behind a suspicious domain during triage. |
| WIPO arbitration and mediation | Open | Dispute resolution provider administering the uniform domain name dispute resolution policy with published decisions. | Route for recovering infringing domains where trademark rights apply, rather than merely suspending them. |
| IANA | Open | Registry of top level domains, root zone data and delegation records with responsible registry operators. | Identifies the registry operator for any top level domain, which determines escalation routes and policy. |
| Shadowserver | Registration | Non-profit reporting operation providing free notifications of malicious and compromised infrastructure to responsible parties. | External corroboration and a reporting channel for domains resolving to compromised hosting. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Domain Intelligence. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- RDAP and whois clients — Retrieve current registration state directly from registries and registrars. Limitation: contact fields are redacted in most generic top level domains since privacy regulation.
- Newly registered domain feeds — Provide the daily list of new registrations for pattern matching against brands. Limitation: coverage varies by top level domain and country-code registries often supply nothing.
- Passive DNS query platforms — Recover historical resolutions and reverse lookups that live queries cannot. Limitation: coverage depends on sensor placement, so absence of a record proves nothing.
- Homoglyph and permutation generators — Produce candidate lookalike patterns for monitoring and defensive registration. Limitation: naive permutation explodes the rule set and buries analysts in noise.
- DNS resolution and record enumeration tools — Establish current records including mail exchanger and text records that indicate intended use. Limitation: active queries reveal interest and can be logged by an attacker-controlled nameserver.
- Certificate Transparency monitors — Detect issuance for lookalike names, often before the site is live. Limitation: covers only publicly trusted issuance, so some infrastructure never appears.
- Registrar portfolio management platforms — Centralise renewals, locks and access control across a large domain estate. Limitation: coverage stops at domains registered through the managed accounts.
- Takedown and brand protection services — Handle submission and escalation with registrars and hosts at volume. Limitation: outcomes depend heavily on registrar responsiveness, which varies enormously.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- DNS Audit — Bulk-resolves A/AAAA/MX/NS/TXT/CNAME/SOA records and stores them as observations, building passive DNS from your own collection.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Detection Rules — Generates YARA, Sigma and Snort/Suricata logic from the selected indicators, ready to deploy.
- Enrichment Runner — Walks the indicator set through a chosen provider in time-boxed, cursor-based batches that resume rather than restart.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Registration usually precedes weaponisation by days. Detecting a lookalike at registration rather than at first phishing report is the entire value of the discipline, and it only works if the monitoring runs continuously.
- Mail exchanger records on a lookalike domain are a distinct and urgent signal. Web phishing needs a website; business email compromise needs mail, and a lookalike configured to receive mail indicates a different and more expensive attack.
- Stop expecting registrant identity from a lookup. Redaction is now the norm, so the analytic backbone is dates, status codes, nameservers and resolution history, and identity comes through legal process rather than through a query.
- Shared nameservers and shared hosting are weak links. Millions of unrelated domains share both, so a pivot on either needs corroboration from timing, registrar, certificate or content before it supports any claim of common control.
- Bulk registration patterns expose campaigns. Names registered within minutes of each other at the same registrar with a consistent construction rule reveal the whole estate from a single observation, and this habit is expensive for an adversary to change.
- Registration data changes and is not versioned. Preserve the record with a retrieval timestamp at the moment of observation, because transfers, privacy changes and deliberate alteration will erase the state you relied on.
- Registrar and registry lock is the cheapest high-impact control you can apply to your own portfolio. Domain hijack is rare and catastrophic, and the control that prevents it takes minutes to enable on the domains that matter.
- Expired domains that still appear in printed material, email footers and hard-coded configurations are a standing risk. Re-registration by a third party hands them a credible platform under your name with no compromise required.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Domain Intelligence is producing anything, and they are worth baselining before you change process or tooling.
- Median lead time between a malicious lookalike domain being registered and being detected, compared against the time it takes to complete a takedown.
- Proportion of phishing incidents involving a domain that had already been detected and actioned by the monitoring capability before use.
- Alert precision on brand monitoring, measured as the share of alerts dispositioned individually rather than bulk-dismissed.
- Median time from confirmed malicious domain to internal blocking, and separately to registrar suspension, tracked by registrar.
- Percentage of critical domains under registry or registrar lock with monitored nameserver and registrant change alerting.
- Number of organisational domains that lapsed or were transferred without authorisation in the period, which should be zero.
- Share of takedown submissions accepted without a follow-up request, which measures the quality of the evidence pack.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Over-reliance on whois registrant fields that redaction has emptied, so the pivot that once worked now yields nothing
- Using shared hosting or CDN addresses as a linking key, generating vast false clusters of unrelated legitimate domains
- Relying on live DNS lookups, which answer only about now and cannot establish what a name resolved to during the incident
- Treating domain age as proof rather than probability, when aged domains are bought and repurposed precisely to defeat that heuristic
- Failing to normalise internationalised domain names, so visually identical homoglyph registrations are never matched
- Treating a single takedown as closure, when the operator re-registers within hours unless the cluster and provider are addressed
Legal and ethical considerations
Registration and DNS data is published for operational purposes and lawful to query, but bulk collection and reuse are constrained by registry and zone-access terms and by GDPR, which drove whois redaction in the first place. Requests for unredacted registrant data must go through the registrar or legal process with a stated legitimate interest. Retrieving content from a suspected phishing site is generally acceptable for defensive analysis but should use isolated infrastructure. Abuse reports must be evidence-backed, since erroneous takedown requests against a legitimate registrant carry liability.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Domain Intelligence, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 6 data points, 2 mission domains, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Why does whois no longer show the registrant?
Because privacy regulation, principally the General Data Protection Regulation, made publication of registrant personal data unlawful without a basis, and ICANN policy now requires redaction of most contact fields in generic top level domains. Registrars still hold the data and must disclose it to parties with a legitimate interest through a defined request process, and to law enforcement under legal process. Country-code registries set their own policies and vary widely, with some publishing organisational registrant details and others publishing nothing. Plan workflows around the fields that remain, and treat identity as something obtained through process rather than lookup.
How do I distinguish a real threat from a defensive or speculative registration?
Look at configuration rather than the name alone. A registration with no nameservers or resolution is inert, and many similar names are held by brand protection services or domain investors. The signals that matter are mail exchanger records, certificate issuance, hosting on a provider with abuse history, content that clones your branding, and registration timing that correlates with a campaign or an event. Score these and set the escalation threshold where your response capacity actually is. Keep low-scoring items on passive watch rather than dismissing them, because inert names get activated later.
Is passive DNS complete?
No, and treating it as complete produces wrong conclusions. Passive DNS is assembled from sensors placed at resolvers, so a provider only sees the queries that traverse its sensors. Coverage differs sharply between providers, is weaker for regionally used infrastructure, and is often thin for very short-lived records. This means absence of a resolution record is not evidence that a resolution never happened. Always state the provider and the observation window when citing passive DNS, and where a finding is important, check a second provider, because the disagreement between them is frequently informative in itself.
What is the fastest route to get a phishing domain taken down?
Send a complete evidence pack to the registrar abuse contact and the hosting provider simultaneously, with the domain, the observed phishing content captured with timestamps and hashes, the brand being impersonated and the harm. Submit in parallel to blocklist and browser safe browsing providers, which protects users within minutes even if the domain stays live. Notify the relevant national CERT for infrastructure in their constituency. Block internally immediately rather than waiting. Registrar responsiveness varies enormously, so track time to suspension by registrar and build escalation contacts for the slow ones.
Should we defensively register lookalike domains?
Selectively. Registering every permutation is unaffordable and unnecessary, because the attacker space is effectively infinite. Register the small set that would be most convincing in a targeted attack: close homoglyphs of your primary domain, the common service-word combinations such as brand plus login or support, and the equivalents in the country-code domains where you operate. Beyond that, monitoring is better value than acquisition. Also make sure defensive registrations are properly parked and locked, since a forgotten defensive registration that lapses is worse than never having registered it.
How do I evidence that two sites share an operator?
Build the case from multiple weak signals rather than one strong-looking one. Registration timing within the same session, identical registration construction rules, the same registrar and payment method where visible, matching certificate issuance patterns, shared unusual DNS record content, correlated content changes, and the same analytics or advertising identifiers embedded in pages are each partial. Shared nameservers and shared hosting on a large provider are close to worthless alone. State the inference explicitly with the alternative explanation, and where publication or a legal claim is involved, corroborate with non-technical evidence.
How long should we retain domain monitoring data?
Retain the enriched records and evidence for detected malicious domains for as long as the associated incident or legal process requires, typically several years, because campaigns recur and historical registration state becomes unavailable. Retain the raw alert stream for a shorter period sufficient for tuning analysis. Registrant personal data obtained through a disclosure request should be retained under the stated purpose and deleted on schedule, since it was disclosed for a specific legitimate interest. Document the schedule, because domain monitoring archives quietly accumulate personal data over time.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- ICANN Registration Data Policy and the registrar accreditation agreement, which govern what registration data is collected, published and disclosed.
- RFC 9082 and RFC 9083 defining the registration data access protocol, which govern the structure and semantics of modern registration lookups.
- The Uniform Domain Name Dispute Resolution Policy, which governs recovery of domains registered and used in bad faith against trademark rights.
- The EU General Data Protection Regulation, which governs why registrant contact data is redacted and how disclosure requests must be justified.
- RFC 1034 and RFC 1035, which define the domain name system record types and resolution behaviour underlying all analysis in this discipline.
- RFC 6962 on Certificate Transparency, which governs the public issuance logging used alongside registration data for early detection.
- ISO/IEC 27037 on digital evidence handling, which governs preservation of registration and resolution records for evidential use.
- The Budapest Convention on Cybercrime, which governs cross-border preservation and production requests to registrars and registries.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Registration data lookup — ICANN. Authoritative interface for current domain registration state and status codes
- Registration data policy and registrar accreditation — ICANN. Rules governing collection, publication and disclosure of registration data
- Centralized Zone Data Service — ICANN. Access programme for generic top level domain zone files
- Root zone database and top level domain registry list — IANA. Authoritative record of top level domains and their registry operators
- Certificate Transparency log search — Sectigo crt.sh. Public certificate issuance index used for early detection of lookalike hostnames
- URLhaus malware URL database — abuse.ch. Open database of malware distribution URLs with hosting metadata
- Phishing URL feed — OpenPhish. Confirmed phishing URLs with targeted brand attribution
- Domain and network reputation datasets — Spamhaus. Reputation data on domains, addresses and networks associated with abuse
- Uniform Domain Name Dispute Resolution Policy decisions — World Intellectual Property Organization. Published dispute decisions and the process for recovering infringing domains
- RIPEstat data service — RIPE NCC. Registry, routing and reverse DNS data for resolving hosting context
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: watches permutations, enriches with RDAP and passive DNS, and clusters campaigns across your brand domains. Explore the platform, or browse the rest of the library by following any tag above.