Inspect one domain
Check registration first, then review DNS, certificate and website context.
- Lookup
- Review sources
- Save useful evidence
Guide and glossary
Start with the task you need to complete, then learn how to read source states, registration evidence and supporting signals without turning uncertainty into a claim.
Start here
There is no single required route through the console. These paths cover the most common starting points.
Check registration first, then review DNS, certificate and website context.
Define the official brand, find candidates and focus deeper checks on the most useful leads.
Keep a case or watchlist and compare later observations without treating a failed check as absence.
Workspace guide
Each workspace has a distinct role. Deeper collection is deliberate and does not begin merely because you open a page.
Read the result
Registration status is authority-aware. DNS, certificates, websites and external intelligence add context, but do not override an authoritative registry answer.
The named source returned usable evidence. Read the source label and collection time before interpreting it.
Some usable evidence was collected, but a stated limit or failed step prevents a complete result.
The source or operation is not available for this target. It is not a negative finding.
A configured source could not be reached or used. Try again later or review the source detail.
The available evidence cannot support a reliable yes or no answer.
Glossary
Short definitions for the protocols, records and workflow labels used throughout WHOISleuth.
FAQ
Practical answers about interpretation, privacy and saved investigation work.
No. It organises observed evidence and provides an explainable Risk score for prioritisation. An analyst must review the sources and context.
Registries and registrars often redact personal or organisation details. A missing public field can reflect policy or privacy protection rather than a lookup failure.
They can be updated at different times, apply different redaction rules or come from different registry and registrar systems. WHOISleuth keeps them separate and highlights material differences.
The registry operates the database for a domain ending, the registrar manages registrations for customers, and the registrant is the recorded holder of a domain.
Use Fast for quick triage or larger candidate sets. Use Deep when one target merits more registration, DNS, website, certificate and optional enrichment context.
A Deep domain lookup can make bounded requests to public website and certificate endpoints. Fast lookup avoids those deeper checks. The interface shows the request implications before you run a check.
It ranks observed signals using a versioned heuristic model and lists every contributing factor. It does not establish intent, ownership, harm or safety.
They describe source health and collection limits. None of them means that the searched evidence is absent or that a target is safe.
They are stored in the current browser profile by default. A workspace archive can move supported records deliberately. Optional hosted monitoring is a separate configured feature.
Not automatically. The shared password grants console access, but browser-local cases, profiles and watchlists remain in the browser profile where they were saved.
Only enabled providers run. Each provider states the target representation, privacy decision, request limits and result provenance. A provider miss or outage does not imply safety.
Monitor can export individual cases, and Dashboard can export or import a bounded workspace archive. Saved browser records can be removed from their workspace or cleared through the documented local-storage controls.
Common mistakes