What Is an Online Investigation Tool and How Do You Use One?
An online investigation tool is a web service that queries public internet records — DNS, WHOIS, IP allocations, and historical data — to reveal who is behind a domain, IP address, or hosting provider and how they connect to each other. DNSlytics is one such tool: it lets you look up a domain, IP, or provider, then pivot across shared infrastructure to find related properties. Use it when you need to trace ownership, spot fraud infrastructure, or check whether a brand is being impersonated — not as a substitute for legal process when you need identity behind a privacy-protected registration.
What the tool actually queries
The service pulls from several public record types. Knowing which one answers your question saves time.
| Record type | What it tells you | Typical question it answers |
|---|---|---|
| WHOIS | Registrar, registration and expiry dates, sometimes registrant org | Who registered this domain, and when? |
| DNS (A, AAAA, MX, NS, TXT) | Where the domain points and which servers handle mail | What infrastructure does this domain use? |
| Reverse IP | Other domains hosted on the same IP | What else lives on this server? |
| Reverse NS / MX | Domains sharing the same name servers or mail servers | Which domains belong to the same operator? |
| Reverse PTR | Hostnames mapped to an IP | What is this IP called internally? |
| AS/BGP | The autonomous system and network block an IP belongs to | Which provider owns this address space? |
| Hosting history | Where a domain was hosted over time | Where did this domain used to live? |
DNSlytics states its IP/DNS data is refreshed every 14 days and that it holds 10+ years of historical data, with 330+ million active domains and 20+ billion historical events indexed. That scale is what makes pivoting useful: a single shared name server or analytics ID can surface dozens of related domains.
Starting from a domain
Enter the domain name into the search field. The tool accepts domains, IPv4 addresses, IPv6 addresses, and AS numbers — the site's own examples are verizon, google.com, 188.114.96.3, 2a06:98c1:3120::3, and as40528.
From a domain result, the useful next steps are:
- WHOIS lookup — confirm registrar and key dates. If the registration is days old and the brand is well known, that is a signal worth noting.
- DNS records — check where it resolves and which mail servers it uses.
- Subdomains — enumerate what else is published under the domain; staging or admin hosts often appear here.
- Hosting history — see whether the domain moved recently. A sudden host change can explain a change in behaviour.
- Reverse tools — take the name servers, mail servers, or IP and search those to find sibling domains.
Starting from an IP address
An IP-first workflow is common in fraud and abuse work, because the same server often hosts many domains.
- Reverse IP returns other domains on that address. This is the fastest way to find a cluster of related sites.
- Reverse PTR shows the hostname the address resolves back to, which sometimes names the provider or customer.
- AS/BGP report places the IP inside a network block and identifies the operator. This matters when you need to decide whether to report abuse to a hosting company or an upstream network.
A practical pivot: start with one suspicious domain → get its IP → run reverse IP → collect the other domains → run reverse NS or reverse MX on those → group them into a cluster. Domains that share both an IP and a name server are far more likely to be operated together than domains that share only one.
Why reverse lookups matter more than single lookups
A single WHOIS record tells you about one domain. Reverse tools tell you about relationships, which is usually the actual question. Reverse IP, reverse NS, reverse MX, reverse PTR, reverse SPF, reverse Analytics, and reverse Adsense each expose a different shared identifier:
- Shared name servers suggest the same DNS operator or reseller.
- Shared mail servers suggest the same mail infrastructure.
- Shared analytics or AdSense IDs are strong signals, because a publisher ID is tied to one account holder.
- Shared SPF records can link domains that send mail through the same authorised infrastructure.
No single shared attribute proves common ownership — shared hosting alone means little. Treat each as one piece of evidence and look for two or more independent overlaps before drawing a conclusion.
Using historical data
Current records only describe the present. If a domain changed hands, moved hosts, or was cleaned up after an abuse report, the live record will not show it. DNSlytics keeps historical events, which lets you:
- See what a domain pointed to before a recent change.
- Check whether an IP previously hosted known-bad domains.
- Compare a domain's history against the date of an incident.
This is the main reason to prefer a tool with a historical index over a plain live DNS lookup. The site reports 20+ billion historical events and 10+ years of coverage.
A repeatable investigation workflow
- Define the question. Ownership, infrastructure, or relationship? This decides your starting record.
- Start with the strongest identifier you have — a domain, an IP, or an AS number.
- Run the direct lookups (WHOIS, DNS) to establish the baseline.
- Pivot on shared infrastructure using reverse IP, NS, MX, and analytics/AdSense.
- Check history for each candidate to see whether the relationship is current or stale.
- Verify before concluding. Confirm a shared attribute on a second, independent record. Note dates, because a shared IP today may be coincidental hosting.
Practical limits to keep in mind
- WHOIS registrant details are frequently redacted for privacy; the tool cannot reveal what the registry does not publish.
- Shared hosting means many unrelated sites share an IP, so reverse IP results need filtering.
- Historical data shows what was recorded, not necessarily everything that existed.
- Data is refreshed on a cycle (the site states every 14 days for IP/DNS), so very recent changes may not yet appear.
DNSlytics offers a free toolset plus premium website access and a premium API for higher page views, more monitors, and additional data — check the pricing page for current plan details rather than assuming limits. For a one-off lookup, the free tools cover the core records; for repeated monitoring or programmatic access, the API is the relevant option.