Domain public footprint
Map public DNS and web-technology signals before drawing any relationship claim.
Investigate
A public domain within the authorized investigation scope.
Outcome
Create a corroborated starting record of infrastructure and technology leads.
Method boundaries
Before starting
- Record the target domain and the authorized purpose.
- Use public lookup interfaces or approved API credentials only.
Stop when
- Do not switch to port scanning, traceroute, or other active probing without separate authorization.
- Treat co-hosting and shared technologies as leads, not evidence of common control.
Workflow
Review each step before adding.
DNS record lookup
ViewDNS.info
Record time-sensitive DNS and nameserver observations with their source.
Access, evidence, and limits
low riskbrowserapiAccess and disclosure
public · none. Open and use the provider in your browser; OSINT Index does not send a target or read results. Use of the provider API happens outside OSINT Index; provider access requirements still apply.
Result semantics
Treat the returned entities as source-attributed leads until independently corroborated.
Prerequisites
- API use requires a ViewDNS account and key.
Limitations
- DNS observations are time-sensitive and tool or API completeness is not guaranteed.
Domain technology profile
BuiltWith
Compare detected technologies with the target's public web presence.
Access, evidence, and limits
low riskbrowserapiAccess and disclosure
public · none. Open and use the provider in your browser; OSINT Index does not send a target or read results. Use of the provider API happens outside OSINT Index; provider access requirements still apply.
Result semantics
Treat the returned entities as source-attributed leads until independently corroborated.
Prerequisites
- Use a root domain for the standard Domain API lookup.
- Use an authorized API key for programmatic requests and keep it out of public client code.
Limitations
- Technology detections are automated public-web signals and can be delayed, incomplete, stale, or false-positive after a technology is removed.
- Detection dates describe BuiltWith's observations and do not establish a complete deployment, ownership, or incident timeline.
Archived scan search
urlscan.io
Review only existing public scan records; do not submit the URL from this template.
Access, evidence, and limits
low riskbrowserapiAccess and disclosure
public · account, api-key. Open and use the provider in your browser; OSINT Index does not send a target or read results. Use of the provider API happens outside OSINT Index; provider access requirements still apply.
Result semantics
Treat the returned entities as source-attributed leads until independently corroborated.
Prerequisites
- Higher API quotas require an account and API key.
Limitations
- The archive only covers URLs previously submitted or automatically scanned.
- Historical scan content may no longer match the live site.