Skip to content
Private preview: new accounts are by invitation only. Ask for one

Investigate a suspicious domain

For a phishing or look-alike domain, check the network behind its addresses and what else shares them.

A new phishing or brand-abuse domain is usually not in our history: we resolve popular domains, and these are new and long-tail. Start from its addresses instead.

1. Resolve it yourself

dig +short A suspicious.example
dig +short AAAA suspicious.example

2. Look up each address

IP=203.0.113.7  # one of the addresses from step 1
curl "https://api.ipalmanac.com/v1/ip/$IP" \
  -H "Authorization: Bearer $IPALMANAC_API_KEY"

lookup_ip tells you:

  • The network: asn names the network that routes the address, its registry country, and what kind of network it is (asn.category: our classification, or ipverse's where we have none).
  • The provider range: provider and prefix when the address is in a range a cloud, hosting or CDN provider publishes. Behind a CDN, you are looking at the CDN's edge, not the site's own server.
  • The PTR name, when we have checked it.
  • The neighbors: domains lists established sites seen on the same address. Sharing an address says nothing about sharing an owner.

3. Check the domain's history, if we have it

curl https://api.ipalmanac.com/v1/domain/suspicious.example/history \
  -H "Authorization: Bearer $IPALMANAC_API_KEY"

observed: false means we don't resolve that name, so there is no history to show: report it as not covered, not as clean. For a domain we do resolve, domain_history and domain_hosting show where it pointed and when it moved.

What this doesn't tell you

We report what we observe and what operators publish. We don't score domains or IPs, and nothing in an answer says whether a site is malicious.

On this page