Investigate a suspicious domain
For a phishing or look-alike domain, check the network behind its addresses and what else shares them.
A new phishing or brand-abuse domain is usually not in our history: we resolve popular domains, and these are new and long-tail. Start from its addresses instead.
1. Resolve it yourself
dig +short A suspicious.example
dig +short AAAA suspicious.example2. Look up each address
IP=203.0.113.7 # one of the addresses from step 1
curl "https://api.ipalmanac.com/v1/ip/$IP" \
-H "Authorization: Bearer $IPALMANAC_API_KEY"lookup_ip tells you:
- The network:
asnnames the network that routes the address, its registry country, and what kind of network it is (asn.category: our classification, or ipverse's where we have none). - The provider range:
providerandprefixwhen the address is in a range a cloud, hosting or CDN provider publishes. Behind a CDN, you are looking at the CDN's edge, not the site's own server. - The PTR name, when we have checked it.
- The neighbors:
domainslists established sites seen on the same address. Sharing an address says nothing about sharing an owner.
3. Check the domain's history, if we have it
curl https://api.ipalmanac.com/v1/domain/suspicious.example/history \
-H "Authorization: Bearer $IPALMANAC_API_KEY"observed: false means we don't resolve that name, so there is no history to show: report it as not covered, not as
clean. For a domain we do resolve, domain_history and
domain_hosting show where it pointed and when it moved.
What this doesn't tell you
We report what we observe and what operators publish. We don't score domains or IPs, and nothing in an answer says whether a site is malicious.