Domain WHOIS Lookup: Find Out Who Owns a Website
Domain WHOIS lookup: owner, RDAP, reputation and risk scoring
Run a domain WHOIS lookup and go further: in seconds you’ll know its owner (RDAP and, if WHOIS is protected under GDPR, the legal identity published on the site itself), its reputation (VirusTotal, blacklists and a database of 2.2M malicious domains), TLS certificates, DNS and email configuration, subdomains and a 4-dimension risk score. More than 20 correlated sources, an actionable executive summary and a signed PDF with chain of custody.
example.com · No http:// or www · Ideal for due diligence, threat intel, vendor verification and phishing analysis👁 See a full sample report ▾

Real example analyzing the domain google.com: owner identity and WHOIS/RDAP, 4-dimension risk scoring with an actionable executive summary, DNS (SPF, DMARC, CAA), TLS certificate, VirusTotal (0/94), Shodan, DNS blacklists, subdomains and technology infrastructure (WhatWeb + WAF + AXFR).
What is this domain analysis tool?
IntelMind’s domain analysis is an OSINT engine that goes far beyond a simple WHOIS lookup. It combines more than 20 data sources in parallel to build the owner’s identity and a complete technical, reputational and infrastructure picture of any domain in seconds.
From the owner’s legal identity (legal notice, Impressum, mentions légales) and WHOIS/RDAP data, to reputation on VirusTotal, blacklists and a database of 2.2 million malicious domains, TLS certificates, DNS and email configuration, subdomains and technology stack. All correlated into a 4-dimension risk score with an actionable executive summary and a two-part professional report.
What you get with every lookup
- Full DNS: NS, MX, A, AAAA, TXT, SPF, DMARC, CAA. Detects missing or incorrect configurations that expose the domain.
- SSL/TLS: issuer, validity, days remaining, wildcard, self-signed. Flags expired or suspicious certificates.
- HTTP + security headers: status, server, detected CDN, HSTS, CSP, X-Frame-Options and 6 other key headers.
- RDAP record: registrar, age, expiration, WHOIS privacy and domain statuses with an exact date.
- Indexed emails (Hunter.io): confirmed emails and pattern-inferred emails, with confidence and department. Clearly separated.
- VirusTotal + Shodan: malware detections, open ports, CVEs, organization and technical exposure level.
- DNS blacklists: Spamhaus DBL, SURBL, URIBL. Clean or listed status with context calibrated by signal type.
- Subdomains: crt.sh (public SSL certificates) + subfinder (passive enumeration). The domain’s real attack surface.
- WhatWeb — fingerprinting: CMS (WordPress, Drupal…), web server + version, PHP, JS frameworks, analytics, detected CDN.
- WAF/CDN + Zone Transfer: active WAF detection (Cloudflare, Wordfence…) and an AXFR zone-transfer test — a critical finding if it’s open.
The complete guide to OSINT domain analysis
An OSINT domain analysis goes far beyond a WHOIS query or a ping. It means correlating data on DNS infrastructure, SSL certificates, antimalware engine reputation, service exposure and technology fingerprinting to build an accurate picture of any internet domain’s security posture and legitimacy. This guide explains each dimension of IntelMind’s analysis.
DNS infrastructure: NS, MX, SPF, DMARC and CAA
DNS records are a domain’s backbone. IntelMind queries NS (name servers), MX (mail), A/AAAA (IP resolution), TXT (SPF, DMARC, verifications) and CAA (authorized certificate authorities) records. A domain without SPF (RFC 7208) or DMARC (RFC 7489) is vulnerable to email impersonation. The presence of CAA records shows that the domain owner restricts which authorities can issue SSL certificates, reducing the risk of fraudulent issuance.
SSL/TLS and the certificate chain
IntelMind checks the domain’s SSL certificate: issuer, validity, days remaining, whether it’s a wildcard, and whether it’s self-signed. An expired or self-signed certificate triggers immediate alerts in the technical score. Let’s Encrypt certificates are legitimate, but being free makes them the default choice for phishing sites, so the system weighs them alongside domain age and VirusTotal reputation to avoid false positives.
Reputation: VirusTotal, blacklists and Shodan
The reputation dimension combines three complementary sources. VirusTotal scans the domain with more than 70 antivirus engines and reports malicious detections, suspicious flags and categories. DNS blacklists (Spamhaus DBL, SURBL, URIBL) detect domains used for spam or malware distribution. Shodan exposes open ports, visible services and known CVEs on the domain’s infrastructure. Correlating these three sources is what lets you tell an isolated false positive from a confirmed real threat.
Subdomains and attack surface
IntelMind enumerates subdomains through two passive sources: crt.sh (Certificate Transparency logs) and subfinder (multi-source passive enumeration). A domain’s attack surface grows with every subdomain: forgotten admin panels, exposed staging environments, unauthenticated APIs or unpatched legacy servers. A domain with 200 subdomains has a radically different attack surface than one with 5, and the exposure score reflects that proportionally.
Technology fingerprinting with WhatWeb and WAF detection
WhatWeb identifies the domain’s full technology stack without sending invasive traffic: CMS (WordPress, Drupal, Shopify), web server and version, PHP version if exposed, JavaScript frameworks, analytics tools and CDN. WAF (Web Application Firewall) detection via wafw00f determines whether the domain is protected by Cloudflare, AWS WAF, Imperva or others. A domain with no WAF and exposed software versions is penalized in both the technical and exposure dimensions simultaneously.
Zone Transfer (AXFR) and critical exposure
Zone Transfer (AXFR) is a DNS function designed to replicate zones between authoritative servers. If a DNS server allows unrestricted AXFR, any attacker can obtain the full map of the internal infrastructure: hidden subdomains, internal IP addresses, mail servers and service records. IntelMind automatically tests every nameserver for the domain with dnsrecon. An open AXFR is a critical security finding per OWASP and is reflected as such in the score.
Risk scoring: technical, reputation, exposure and final risk
IntelMind’s risk score is consistent: four dimensions from 0 to 100, where 0 means no risk. Technical evaluates DNS configuration, certificates and AXFR status. Reputation integrates VirusTotal, DNS blacklists and the malicious-domain database — it carries more weight because a confirmed malicious detection invalidates any correct technical setup. Exposure measures the attack surface: subdomains, ports and visible services. The final risk is the weighted combination of all three, with a LOW, MEDIUM, HIGH or CRITICAL level and an executive summary with the recommended decision: trust, verify, treat with caution, or block.
Professional use cases
IntelMind’s domain analysis covers multiple professional profiles. In corporate due diligence, it verifies a vendor’s or partner’s digital infrastructure before signing a contract. In SOC and CSIRT teams, it complements the triage of domains observed in logs or SIEM alerts with immediate reputational and technical context. In phishing investigations, it helps determine whether a suspicious domain is new, has legitimate certificates, is blacklisted, or shares infrastructure with known malicious domains. In investigative journalism, infrastructure analysis reveals connections between seemingly independent domains that share an IP, registrar or nameservers.
Domain WHOIS lookup: what’s known today and what GDPR hides
A domain WHOIS lookup is the classic way to find a domain’s owner and contact details. GDPR changed the rules in 2018: today, the public WHOIS record for most TLDs (.com, .es, .org…) anonymizes individual registrants and only shows limited data (registrar, creation/expiration dates, nameservers, domain status). IntelMind queries WHOIS via RDAP (the modern protocol defined in RFC 7480-7484) to get the structured information that’s available: registrar, registration date, nameservers, domain age and EPP status. This information, while it doesn’t include the owner, is enough to answer the operational questions that matter: is this a new or established domain? Who registered it (a company or an individual via a proxy)? Has it been renewed for years? Has it changed registrar recently? Those four data points solve 80% of real-world WHOIS use cases.
Verify a domain: a quick checklist before trusting a website
Verifying a domain before buying from, hiring, or paying someone you found online is an increasingly common routine. IntelMind’s OSINT checklist to verify a domain covers six signals in order of importance: (1) age — a domain created a week ago is a red flag for a supposedly «established» business; (2) SSL certificate — it should be valid and not a Let’s Encrypt certificate issued the day before, unless that makes sense; (3) email authentication — well-configured SPF, DMARC and DKIM are a sign of professional domain management; (4) reputation on VirusTotal and blacklists — no active entries; (5) a coherent technology stack — a supposed bank shouldn’t be running on a generic Shopify store; (6) visible subdomains suggesting real activity (mail, www, app, api). If three or more fail, the domain doesn’t deserve trust by default.
Detecting a fraudulent domain: phishing and typosquatting patterns
A modern fraudulent domain usually shows several of these patterns: (a) typosquatting on a known brand (paypa1.com, amaz0n.com, micros0ft-login.com with similar-looking characters); (b) homoglyphs using non-Latin alphabets (pаypal.com with a Cyrillic «a»); (c) very recent age + a freshly issued SSL certificate + WHOIS proxy; (d) unauthenticated DNS (no SPF/DMARC) that makes it easy to spoof emails from the domain; (e) presence on phishing blacklists like Spamhaus DBL or Anti-Phishing Working Group feeds; and (f) shared infrastructure with other malicious domains on the same IP. IntelMind automatically detects these patterns, weighs them in the risk score, and returns a plain-language professional verdict so an antifraud team or SOC can act immediately: block, flag for manual review, or accept.
Frequently asked questions
How do I find out who owns a domain?
IntelMind queries the official registry via RDAP (and classic port-43 WHOIS for ccTLDs without public RDAP, like .br or .ar): registrar, creation date, expiration, nameservers, DNSSEC and domain status. It also extracts the legal identity published on the site itself (legal notice, Impressum, mentions légales): owner or company name, responsible parties, business registry and tax IDs, cross-checking it against the organization validated on the TLS certificate. If WHOIS is privacy-protected, the identity declared on the website usually resolves ownership anyway.
How do I check if a domain is phishing or safe?
The domain is checked against VirusTotal, DNS blacklists (Spamhaus DBL, SURBL, URIBL) and an in-house database of more than 2.2 million malicious domains (phishing, malware, fraud). It also detects typosquatting and homoglyphs on known brands, recently registered or re-registered domains after expiring, and unauthenticated email configuration. The risk score and executive summary indicate whether to trust, verify or block the domain.
What is the risk score and how is it calculated?
Four consistent risk dimensions from 0 to 100, where 0 means no risk: technical (DNS configuration, SSL, AXFR), reputation (VirusTotal, blacklists, malicious-domain database), exposure (subdomains, ports, surface) and a weighted final risk. Each dimension shows a LOW, MEDIUM, HIGH or CRITICAL level. A clean, well-configured domain scores low; abuse signals raise it.
What WHOIS/RDAP data does the tool return?
Registration date and age, registrar, expiration date, nameservers, EPP status, DNSSEC signature and abuse contact. For ccTLDs without public RDAP (.br, .ar and others), it falls back to a port-43 WHOIS query, and detects possible re-registrations when certificates predate the domain’s current registration.
Does it analyze the domain’s email and DNS configuration?
Yes: NS, MX and A records, SPF/DKIM/DMARC email authentication with its policy, CAA certificate-authority records, MTA-STS and BIMI, and a zone-transfer (AXFR) test. A domain with no SPF or DMARC is vulnerable to email impersonation, and the score reflects it.
What does it detect in TLS/SSL certificates?
Issuer, validation type (DV, OV or EV), the organization legally validated by the certificate authority, validity and expiration, self-signed or wildcard status, alternative names (SAN), and the full certificate history in Certificate Transparency (crt.sh) — useful for discovering subdomains and detecting re-registrations.
Is it legal to analyze a third party’s domain infrastructure?
Yes, as long as it relies on public sources. DNS records, WHOIS/RDAP, certificates (Certificate Transparency), VirusTotal and Shodan are all publicly accessible information. IntelMind doesn’t run active vulnerability scanning, fuzzing or attacks — it only queries passive sources. Zone Transfer (AXFR) is a standard DNS request. Under GDPR, technical infrastructure data doesn’t constitute personal data.
What does the PDF report include?
A highlighted actionable executive summary (suggested decision, risk level and immediate action), a two-part professional report — one for non-technical readers and one technical — all the analysis data (identity, registration, reputation, DNS, certificates and exposure), the sources consulted with verifiable links, and a digital chain of custody: SHA-256 hash, RFC 3161 timestamp issued by FreeTSA and a public verification URL. Suitable as electronic evidence or a due diligence annex.
How many credits does it cost, and what does it offer over other tools?
12 credits per lookup. It correlates more than 20 sources (WHOIS/RDAP, Certificate Transparency, VirusTotal, Shodan, blacklists, a 2.2 million malicious-domain database, legal identity, DNS and certificates) into a single signed report. On the Profesional Plan (€79/month with 250 credits), that’s about 20 monthly lookups, at a much lower cost than combining SecurityTrails, DomainTools, Hunter and Shodan separately.
