WHOISleuthDomain intelligence

Guide and glossary

Use WHOISleuth with confidence.

Start with the task you need to complete, then learn how to read source states, registration evidence and supporting signals without turning uncertainty into a claim.

Start here

Choose the outcome you need.

There is no single required route through the console. These paths cover the most common starting points.

Inspect one domain

Check registration first, then review DNS, certificate and website context.

  1. Lookup
  2. Review sources
  3. Save useful evidence

Find brand lookalikes

Define the official brand, find candidates and focus deeper checks on the most useful leads.

  1. Brands
  2. Discover
  3. Bulk
  4. Lookup

Track important findings

Keep a case or watchlist and compare later observations without treating a failed check as absence.

  1. Save
  2. Monitor
  3. Review changes

Workspace guide

Know where to go next.

Each workspace has a distinct role. Deeper collection is deliberate and does not begin merely because you open a page.

Lookup

Use it when
You have one domain, IP address or ASN to investigate.
What you provide
Enter one target and choose Fast or Deep collection.
What you receive
Registration evidence and available supporting context are shown by source.
What to do next
Review conflicting or incomplete sources, then save a useful domain finding to Monitor.

Brands

Use it when
You want searches and comparisons to reflect an official brand.
What you provide
Add official domains, product names, preferred domain endings and known trusted infrastructure.
What you receive
A browser-local profile provides a comparison boundary for discovery and analysis.
What to do next
Open Discover to generate or find related candidates.

Discover

Use it when
You want possible lookalikes or names observed in public certificate logs.
What you provide
Choose a Brand Profile or enter a focused keyword.
What you receive
Generated and certificate-log candidates retain their discovery source and limits.
What to do next
Send a focused shortlist to Bulk rather than scanning every possible name.

Bulk

Use it when
You need to compare several candidate domains consistently.
What you provide
Paste domains or accept a shortlist from Discover.
What you receive
Fast or Deep checks prioritise candidates and expose related infrastructure already observed in the scan.
What to do next
Open the strongest or most uncertain leads in Lookup for source-level review.

Monitor

Use it when
You want to retain a finding, document a decision or compare later observations.
What you provide
Save a case or watchlist from Lookup or Bulk.
What you receive
Browser-local timelines, notes, relationships and exports keep the review trail together.
What to do next
Rescan deliberately or use optional hosted monitoring when it is configured.

Registry support

Use it when
You want to know how a domain ending is handled before relying on a result.
What you provide
Search for a domain ending such as com or au.
What you receive
The catalogue shows tested WHOIS parsing, query rules and known RDAP access limits.
What to do next
Treat a limitation as a source constraint, not evidence that a domain is available.

Read the result

Source health is part of the evidence.

Registration status is authority-aware. DNS, certificates, websites and external intelligence add context, but do not override an authoritative registry answer.

Observed

The named source returned usable evidence. Read the source label and collection time before interpreting it.

Partial

Some usable evidence was collected, but a stated limit or failed step prevents a complete result.

Unsupported

The source or operation is not available for this target. It is not a negative finding.

Unavailable

A configured source could not be reached or used. Try again later or review the source detail.

Inconclusive

The available evidence cannot support a reliable yes or no answer.

Glossary

Domain investigation terms.

Short definitions for the protocols, records and workflow labels used throughout WHOISleuth.

ASN
An Autonomous System Number identifies a network that announces groups of IP addresses.
Browser-local
Saved data remains in this browser profile unless you deliberately export or configure a hosted feature.
CAA
A DNS record that states which certificate authorities may issue certificates for a domain.
Case
A saved analyst record containing selected evidence, notes, status and observation history.
Certificate Transparency
Public logs of issued TLS certificates. A log timestamp records certificate observation, not website activation or maliciousness.
Confusable
A character or label that can look similar to another, including internationalised domain characters.
Deep lookup
A broader lookup that can add WHOIS, DNS, website, TLS and optional enrichment checks to RDAP.
DKIM
A mail authentication method that lets a domain sign outgoing messages.
DMARC
A mail policy that builds on SPF and DKIM and can tell receivers how to handle failures.
DNS
The system that maps domain names to addresses and other records such as mail servers and nameservers.
DNSSEC
Cryptographic DNS signatures that help resolvers verify that answers have not been altered.
Fast lookup
A lower-request lookup intended for quick triage. It keeps the authoritative RDAP path and omits deeper collection.
Favicon
A small website icon. Exact or similar icons can be a useful lead, but do not prove common ownership.
Hosted monitoring
An optional scheduled service that stores compact encrypted watchlist evidence outside the browser.
IDN and Punycode
Internationalised domain names can contain non-ASCII characters. Punycode is their ASCII representation.
IP address
A numeric network address used by an internet-connected host.
MX
A DNS record that identifies the servers expected to receive email for a domain.
Nameserver
A DNS server responsible for publishing records for a domain.
RDAP
A structured registration-data protocol used by registries and some registrars.
Registrant
The person or organisation recorded as holding the domain registration. Public data may be redacted or privacy-protected.
Registrar
The company through which a registrant manages a domain registration.
Registry
The operator responsible for the registration database for a domain ending.
Risk score
An explainable prioritisation aid based on observed signals. It is not a verdict of maliciousness.
SAN
A certificate Subject Alternative Name listing a hostname or other identity covered by that certificate.
SPF
A DNS-based mail policy that lists systems allowed to send mail for a domain.
TLS certificate
A certificate used to authenticate an encrypted connection. Its presence does not prove that a website is safe or active.
Watchlist
A saved set of domains whose compact evidence can be compared across later checks.
WHOIS
A text-based registration-data service whose format and availability vary between registries.

FAQ

Common questions.

Practical answers about interpretation, privacy and saved investigation work.

Does WHOISleuth decide whether a domain is malicious?

No. It organises observed evidence and provides an explainable Risk score for prioritisation. An analyst must review the sources and context.

Why are owner details sometimes missing?

Registries and registrars often redact personal or organisation details. A missing public field can reflect policy or privacy protection rather than a lookup failure.

Why can WHOIS and RDAP disagree?

They can be updated at different times, apply different redaction rules or come from different registry and registrar systems. WHOISleuth keeps them separate and highlights material differences.

What is the difference between a registry, registrar and registrant?

The registry operates the database for a domain ending, the registrar manages registrations for customers, and the registrant is the recorded holder of a domain.

Should I use Fast or Deep lookup?

Use Fast for quick triage or larger candidate sets. Use Deep when one target merits more registration, DNS, website, certificate and optional enrichment context.

Does a lookup contact the website?

A Deep domain lookup can make bounded requests to public website and certificate endpoints. Fast lookup avoids those deeper checks. The interface shows the request implications before you run a check.

What does the Risk score mean?

It ranks observed signals using a versioned heuristic model and lists every contributing factor. It does not establish intent, ownership, harm or safety.

What do partial, unavailable and inconclusive mean?

They describe source health and collection limits. None of them means that the searched evidence is absent or that a target is safe.

Where are cases and watchlists saved?

They are stored in the current browser profile by default. A workspace archive can move supported records deliberately. Optional hosted monitoring is a separate configured feature.

Can another person using the shared login see my saved browser work?

Not automatically. The shared password grants console access, but browser-local cases, profiles and watchlists remain in the browser profile where they were saved.

What is sent to optional intelligence providers?

Only enabled providers run. Each provider states the target representation, privacy decision, request limits and result provenance. A provider miss or outage does not imply safety.

How do I export or delete saved work?

Monitor can export individual cases, and Dashboard can export or import a bounded workspace archive. Saved browser records can be removed from their workspace or cleared through the documented local-storage controls.

Common mistakes

Keep the conclusion narrower than the evidence.

  • Treating a missing or failed source as proof that evidence does not exist.
  • Treating the Risk score as a malicious or safe verdict.
  • Assuming shared nameservers, IP addresses, certificates or favicons prove common ownership.
  • Reading a Certificate Transparency timestamp as the date a website became active.
  • Confusing a registrar contact with the registrant or current website operator.

WHOISleuth keeps registration and supporting evidence separate, so missing or inconclusive data is not presented as proof.

© 2026 Created by slicedearth · Guide · Privacy