Skip to content
DnsLister Forum

Where domain hunters compare notes

WHOIS Forge to make RDAP, DNS and infrastructure data easier to interpret

I’ve just released WHOIS Forge, a tool focused on responsible domain investigation

The starting point was fairly simple: domain lookup tools can expose a lot of technical data without always explaining what that information can actually establish

For example :

  • a domain registration date is not necessarily the date a website was created or published
  • a shared IP address, ASN, nameserver or mail provider does not prove that two domains have the same owner
  • DNSSEC helps authenticate DNS data and verify its integrity, but it is not a reputation or trust indicator

I therefore tried to build WHOIS Forge around three questions :

What am I actually observing ?

What could this mean ?

What can I NOT conclude from it ?

The tool currently provides :

  • current registration data through RDAP
  • DNS and mail records
  • IP/ASN context when available
  • the source and time of observations
  • explanations of their limitations
  • suggested investigation pivots

The scope is deliberately limited to a domain and its current state

There is no reconstruction of historical WHOIS data and no persistent user search history

The goal is also not to generate a generic “suspicion score”

Instead, I want the tool to help maintain a clear distinction between observation, hypothesis and attribution. If you regularly use domain intelligence or OSINT tools, I’d be particularly interested in hearing what existing tools still make difficult, misleading or unnecessarily opaque

https://i.redd.it/fnlo5zwdxwlh1.png

Source: r/osintforge · by /u/Azouris

Leave a Reply

Your email address will not be published. Required fields are marked *