OBSCURYN · BRAND PROTECTION

Domain investigation for suspicious, phishing, and clone hosts

A hostname in a chargeback ticket is not a case file. Obscuryn pulls live status, screenshots, registrar and hosting signals, then drafts the abuse notice with somewhere to send it.

The problem

  • WHOIS privacy hides the registrant. You still need the registrar and the host to file.
  • A lookup tool without a cart screenshot does not get a clone shop taken down.
  • Abuse inboxes ignore reports that skip the live URL, timestamp, and what the page is doing.

How Obscuryn detects it

  • Open the host: live vs parked vs redirect, storefront vs phishing kit.
  • Identify domain registrar and hosting / CDN signals from the evidence we already attach to alerts.
  • Keep the investigation next to monitoring so the next rotated domain stays in the same queue.

Evidence we collect

  • Registrar, hosting provider when available, and live-page screenshots.
  • Enough infrastructure context to brief counsel without a separate OSINT pass.

How takedowns work

  • Drafts aimed at registrar abuse and host/CDN abuse desks. You send them.
  • We surface the abuse path from the evidence; we do not guarantee every registrar publishes a working mail address on RDAP.

Frequently asked questions

Is this a domain investigation tool or a WHOIS lookup?

Investigation on top of a live impersonation alert: registrar, hosting provider, screenshots, and a notice draft. For a one-off WHOIS on an unrelated domain, use RDAP. Obscuryn is for hosts that are impersonating your brand.

Can you identify the domain registrar and hosting provider?

Yes, when those signals are available on the alert. Privacy WHOIS still names a registrar; hosting is often a CDN (Cloudflare) plus an origin. That is usually enough to file.

Do you find the abuse contact or registrar abuse email?

Takedown drafts are written for registrar and host abuse desks. The exact mailbox comes from RDAP/WHOIS and the provider’s published abuse path. If RDAP is empty, the draft still has the evidence packet for counsel to place.

Can I investigate a phishing domain I already have?

Add the brand domain, run a scan, and open the matching alert. If you only have the official hostname, start with obscuryn.com/free-scan. We classify live phishing vs parked vs redirect.