Five things a forensic expert checks before opening the email
There is a tool I used every day that at some point stopped being available as a standalone entry point. I was reminded of it this week, when a colleague called to warn me that a client would be contacting me the next day with an urgent case: someone had changed the IBAN on an invoice in transit.
The first thing I wanted to do was enter the suspicious domain and see what it told me. Without building an EML. Without going through the full scanner. Just the domain.
That reflex has a name: domain identification. And the five data points it returns explain, better than any definition, how a significant part of digital fraud works.
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
Does the domain exist?
The first question is the most basic: does this domain respond? A simple ping confirms whether there is anything on the other side. It sounds trivial, but it is not.
Attackers register domains that sometimes have no website, no visible mail server, nothing — they exist solely to send from. A domain that responds to a ping but has no active website is a signal worth noting, especially when the context is an invoice or a business communication.
How long has it been registered?
Domain age is one of the most reliable indicators in forensic analysis. A legitimate domain belonging to an established company has years of history. A domain registered three weeks ago, with the same name as a real company but a different extension, is an immediate red flag.
In this week's case, the likely scenario is exactly that: an attacker registered a domain imitating a real company — same name, different TLD — and used it to intercept an invoice and swap the IBAN. The age of the fake domain would have exposed it in seconds.
Is it on the whitelist?
A whitelist of verified domains is the accumulated memory of a forensic system. If the domain has already been analysed and classified as legitimate, it appears. If it does not appear, that does not necessarily mean it is fraudulent — but it means no one has verified it yet.
In the context of a suspicious invoice, a domain absent from the whitelist combined with low age and an atypical extension is enough to raise a flag before any transfer is made.
Does it have an MX record?
An MX record indicates whether the domain is configured to send and receive email. A domain without MX cannot handle email — meaning any message claiming to come from that domain is technically impossible through legitimate means.
But there is an important nuance: an active MX record is not a guarantee of legitimacy either. Attackers configure MX precisely so their emails pass basic filters. What matters is crossing this data point with the others: active MX + recent domain + suspicious extension is a combination that does not leave much room for interpretation.
What similar extensions exist?
This is the data point I find most useful to explain, because it surprises people who have not seen it before.
If a company operates from company.es, an attacker can register company.com, company.net, company.info or company.org — and use it to impersonate them. The name is identical. Only the extension changes. And in the daily workflow of a business, nobody checks the extension of the sender's domain.
Listing the extensions registered under the same name is a quick way to see whether someone has been laying the groundwork. If company.es has existed for ten years but company.com was registered two weeks ago, the question answers itself.
Five data points, thirty seconds, one decision
None of these five data points is conclusive on its own. A recent domain might belong to a new company. A domain without a website might be internal infrastructure. An alternative extension might be a legitimate defensive registration.
What makes this tool useful is not each data point in isolation — it is the combination. When a domain is recent, absent from the whitelist, has an active MX but no website, and exists alongside older extensions of the same name, the pattern is clear enough to act before the damage becomes irreversible.
In IBAN fraud cases, the money is usually already transferred by the time someone calls a forensic expert. The purpose of this tool is to make sure that call comes first.
Have you received an invoice with different bank details than usual, or do you suspect a domain is being used to impersonate a supplier? Oscar Orts — court-certified IT expert — can analyse the case and produce an expert report with full legal validity for judicial proceedings or insurance claims.