Domain and DNS
Use for DNS records, nameservers, mail security records, certificate pivots, passive history, and domain context.
Tie-in: pair with the DNS backup checklist and Cloudflare DNS Backup tool before changing client DNS.
A curated starting point for passive public-source research across domains, DNS, URLs, exposure, archives, breach context, and evidence preservation — built for cautious security workflows, not noisy recon theatre.
Passive first · Attribution safe · Evidence aware · Cybersecurity focused
Start with the evidence question. Then choose the smallest passive source set that can answer it without crossing into unauthorized testing.
Resolve ownership clues, DNS records, mail records, historical changes, and domain infrastructure context.
Capture redirects, page loads, screenshots, reputation labels, and suspicious resource chains.
Check passive scan indexes for exposed services, banners, certificates, and internet-facing context.
Save pages, archive copies, timestamps, screenshots, and source context before material changes.
Review exposure signals cautiously with authorization, minimization, and responsible disclosure discipline.
Corroborate legal entity, ownership, public contact, technology, and market-footprint claims.
Use maps, imagery, route context, sunlight, and movement data to test visual claims.
Decode, pivot, enrich, and record indicators without overclaiming attribution from shared infrastructure.
These are practical starting points. Tool output still needs source dates, caveats, and corroboration before it becomes a finding.
Use for DNS records, nameservers, mail security records, certificate pivots, passive history, and domain context.
Tie-in: pair with the DNS backup checklist and Cloudflare DNS Backup tool before changing client DNS.
Use passive indexed results to understand internet-facing services, banners, certs, and technology fingerprints.
Caveat: passive exposure context is not authorization to actively validate, exploit, or scan.
Use for redirects, screenshots, DOM/network traces, malware reputation, and community threat context.
Avoid submitting sensitive internal URLs to public services unless policy permits it.
Use to recover deleted pages, compare changed claims, preserve evidence, and build timelines.
Record capture time, source URL, final URL, and whether the archive is complete or partial.
Use when indicators need decoding, normalization, enrichment, sharing, or repeatable pivoting.
Do not turn infrastructure overlap into attribution without stronger independent evidence.
Use cautiously for exposure signals. Breach data is sensitive and should not become public accusation.
Use only with lawful basis, client authorization, and minimization of personal data.
Use for legal-entity checks, ownership clues, public documents, contact corroboration, and risk context.
Company data can be stale or jurisdiction-limited. Preserve dates and source links.
Use for location context, route checks, imagery, sunlight, aircraft movement, and environmental validation.
Treat geolocation as probabilistic unless corroborated by multiple independent signals.
Use curated directories when you need tool discovery by task, pricing, access model, or evidence type.
Directories help discovery; they do not remove the need to check tool limits and legal boundaries.
This page is for defensive triage and public-source research. It is not a guide for unauthorized scanning, exploitation, access bypass, doxxing, harassment, credential hunting, or public attribution from weak overlaps. Use authorization, minimization, and evidence discipline.
Pair this page with the DNS backup tooling, website security checklist, and future evidence-pack workflows so findings become defensible notes instead of scattered browser tabs.