Domain public footprint

Map public DNS and web-technology signals before drawing any relationship claim.

DNS recordNameserverIP addressTechnologyEvidence artifact

Investigate

A public domain within the authorized investigation scope.

Outcome

Create a corroborated starting record of infrastructure and technology leads.

Method boundaries

Before starting

  • Record the target domain and the authorized purpose.
  • Use public lookup interfaces or approved API credentials only.

Stop when

  • Do not switch to port scanning, traceroute, or other active probing without separate authorization.
  • Treat co-hosting and shared technologies as leads, not evidence of common control.

Workflow

Review each step before adding.

  1. DNS record lookup

    ViewDNS.info

    Record time-sensitive DNS and nameserver observations with their source.

    Access, evidence, and limits
    low riskbrowserapi
    Access and disclosure

    public · none. Open and use the provider in your browser; OSINT Index does not send a target or read results. Use of the provider API happens outside OSINT Index; provider access requirements still apply.

    Result semantics

    Treat the returned entities as source-attributed leads until independently corroborated.

    Prerequisites
    • API use requires a ViewDNS account and key.
    Limitations
    • DNS observations are time-sensitive and tool or API completeness is not guaranteed.
  2. Domain technology profile

    BuiltWith

    Compare detected technologies with the target's public web presence.

    Access, evidence, and limits
    low riskbrowserapi
    Access and disclosure

    public · none. Open and use the provider in your browser; OSINT Index does not send a target or read results. Use of the provider API happens outside OSINT Index; provider access requirements still apply.

    Result semantics

    Treat the returned entities as source-attributed leads until independently corroborated.

    Prerequisites
    • Use a root domain for the standard Domain API lookup.
    • Use an authorized API key for programmatic requests and keep it out of public client code.
    Limitations
    • Technology detections are automated public-web signals and can be delayed, incomplete, stale, or false-positive after a technology is removed.
    • Detection dates describe BuiltWith's observations and do not establish a complete deployment, ownership, or incident timeline.
  3. Archived scan search

    urlscan.io

    Review only existing public scan records; do not submit the URL from this template.

    Access, evidence, and limits
    low riskbrowserapi
    Access and disclosure

    public · account, api-key. Open and use the provider in your browser; OSINT Index does not send a target or read results. Use of the provider API happens outside OSINT Index; provider access requirements still apply.

    Result semantics

    Treat the returned entities as source-attributed leads until independently corroborated.

    Prerequisites
    • Higher API quotas require an account and API key.
    Limitations
    • The archive only covers URLs previously submitted or automatically scanned.
    • Historical scan content may no longer match the live site.