Step-by-step method
A reproducible path from question to conclusion.
- 1
Set the boundary
List officially published domains, relevant brands, subsidiaries and countries. Record exclusions and the people authorised to confirm ownership.
- 2
Collect public traces
Review accessible DNS records, public certificates, web archives and official pages. Record the publisher, observation date and period represented.
- 3
Connect the evidence
Link each domain, subdomain, certificate, provider and observed page with a precise relationship. Shared hosting or an IP address alone cannot prove common ownership.
- 4
Grade each asset
Mark assets confirmed, probable, possible or outside scope. Seek independent confirmation before assigning an asset to the organisation.
- 5
Rank the gaps
Look for expiring domains, old redirects, forgotten login pages, lookalike names and services without a known owner. Judge actual impact before acting.
- 6
Deliver an actionable inventory
For each asset, state evidence, date, confidence, owner to confirm and proposed action. Technical corrections belong with the authorised team.
A technical relationship is not proof of ownership
Thousands of sites may share a provider, address or protection service. A certificate may also include an old domain or predate a transfer.
Strong attribution combines an official publication, current configuration, consistent history and, where possible, owner confirmation. Preserve the type and date of every link.
The map needs a timeline
DNS and certificate records change. An archive shows a past state; a current response reflects only the time it was checked. Combining periods without labels creates false relationships.
Record discovery date, last observation and original source. A vanished relationship may still matter to a timeline without being called a current exposure.
Turn the map into defensive decisions
The inventory can find an ownerless asset, clarify an official channel or identify a lookalike domain. It is not permission to probe systems.
Connect each risk to an owner, proportionate action and evidence of correction. An unknown asset first needs internal validation.
Common pitfalls
Four shortcuts that weaken the result.
Attributing by IP
A shared address may connect unrelated organisations.
Treating archives as current
An old capture does not establish an active service.
Scanning without permission
Open-source mapping does not authorise testing systems.
Publishing a sensitive inventory
The list could aid impersonation; limit its circulation.
Practical questions
Frequently asked questions.
Can a certificate identify a domain owner?
It can provide a clue, but its names and date alone do not establish current ownership.
Does a shared IP mean a shared organisation?
No. Shared hosting, content delivery and protection services make this inference unreliable.
Should a scan be used to complete the map?
Only under a separately authorised technical scope. This guide uses public traces and owner validation.
Editorial scope
Written and reviewed by Internet Intelligence Service on 23 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.
