IT.COM

Looking into DNS and IP Footprints for Domain Name Investing

Spaceship Spaceship
Watch
A high-quality and lucrative domain portfolio can take time and a lot of resources to build. Most domain name investors go for domain names that they “feel” will become marketable in the future. But choosing domain names should be based on more than gut feeling or market predictions. Domain Name System (DNS) and IP intelligence, among other sources, can help bring an informed perspective.

IP and DNS intelligence sources already benefit the cybersecurity sector in detecting cyber incidents such as phishing and malware attacks, among others. Here’s a blog post that cites three specific cybersecurity practices that IP intelligence can enhance.

Aside from cybersecurity, DNS and IP intelligence can help in domain name investing. Gleaning into these intelligence sources would tell you more about a domain name’s infrastructure—both current and historic. It enables you to answer the following questions:
  • Who has hosted the domain name?
  • Was it used for something that you may get in trouble with?
  • Was it associated with activities that may affect its marketability?
  • Could the domain name be blacklisted?
The answers to these questions can indicate whether or not the domain name should be part of your portfolio.

DNS and IP Footprints
Consider the domain name classicpictures[.]com, which could be a lucrative investment since people place a high value on pictures. The domain is currently parked and owned by an organization called “Tfourh, LLC.” Still, domainers can make an offer through entities such as GoDaddy, NameCheap, and Sedo. But before you go ahead and make an offer, let’s dig into its DNS and IP footprints first.

Interestingly, running the classicpictures[.]com on DNS Lookup returned six A records. We ran each IP address on IP Geolocation API to learn more about them. The IP addresses, along with their geolocations, are listed below.
  • 45[.]56[.]79[.]23 Dallas, Texas
  • 45[.]79[.]19[.]196 Dallas, Texas
  • 45[.]33[.]2[.]79 Dallas, Texas
  • 45[.]33[.]23[.]183 Dallas, Texas
  • 96[.]126[.]123[.]244 Chicago, Illinois
  • 198[.]58[.]118[.]167 Chicago, Illinois
All IP addresses belong to Internet service provider (ISP) Linode, LLC. Any domain name can resolve to multiple IP addresses since the practice helps in load balancing and provides fallbacks.

According to VirusTotal, all of the IP addresses above are tagged as malicious by at least 2 or 3 threat detection data feeds. But Reverse IP Lookup revealed that hundreds of other domains share all six IP addresses. The IP address 198[.]58[.]118[.]167, for instance, is associated with about 300 domain names. As such, it’s not necessarily because of classicpictures[.]com that they were dubbed malicious. The domain name itself has no ties to malicious reports on VirusTotal. However, the domain may get blocked by organizations that implement IP-level blacklisting.

Additionally, you may perform a reverse WHOIS search on the registrant organization to learn more about it. More than 3,000 domains are registered under Tfourh, LLC, so it looks like it has a rich portfolio.

RGYR_W9Us1gHpPqC6hxAQqGKLq9r-Yqpnq-rRl019FN1y8Ez_2xiR2VpFo5ruQJc2pZnA7dAL1F8DSukEdk_CHLzMnFUQdkOGOF3nbzoFDZ2a-2IOYJg5HU5jMSa8hRLCFgX36xT


With this information, you may get a better understanding of whether or not the domain name should be included in your portfolio.

---

Like any other investment venture, domain name investing has accompanying risks. Still, these risks can be minimized by studying each domain name before sealing any deal. DNS and IP intelligence can help contribute to that decision.

This was a promoted post.
 
Last edited by a moderator:
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
I don't understand:
If the domain itself is not tied to anything malicious, why where it is currently hosted is of importance?

When the domain is acquired, the owner can set it up any way they want and ask for removal (in the case the domain is in some security blacklists).
 
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back