Skip to content
← UserSearch.comLog in ↗

Website forensics search: overview

The Website Forensics search type lets you investigate a domain — its current and historical ownership, how its pages changed over time, third-party lookups, and favicon matching. Pick it from the search composer when your starting identifier is a domain name (or, for one Module, an email address) rather than a username, phone number, wallet address, or other identifier.

The UserSearch composer with the Website Forensics search type active and the default Website Domain Ownership (by Domain) Module selected, showing the five Module tiles, an empty query input, and a "Cost per search: Free" line
The UserSearch composer with the Website Forensics search type active and the default Website Domain Ownership (by Domain) Module selected, showing the five Module tiles, an empty query input, and a "Cost per search: Free" line

Use the Website Forensics search type when you have a domain (or an email to reverse-look-up) and want to:

  • Retrieve a domain’s current and historical ownership — registration data, registration history, and associated contacts (via the Website Domain Ownership (by Domain) Module).
  • Find the domains registered under a given email address — a reverse-WHOIS pivot (via the Website Domain Ownership (by Email) Module).
  • Review how a site’s pages changed over time through archived snapshots (via the Website Change History Module).
  • Run a third-party website lookup, or match a site by its favicon (via the 3rd Party Website Lookup and Search by Favicon Modules).

This search type exposes five Modules, all single-purpose. For the full breakdown of each Module, its input, cost, and data source, see Website forensics modules & options.

The Website Forensics search type follows the same search composer flow as every other search in UserSearch — see How UserSearch works for the general model.

  1. In the composer header, open the Search type selector and choose Website Forensics.
  2. Pick a Module from the grid — Website Domain Ownership (by Domain) (selected by default), Website Domain Ownership (by Email), Website Change History, 3rd Party Website Lookup, or Search by Favicon. The Module grid is single-select: selecting one deselects the rest. The selected tile is drawn with a coral-orange highlighted border, and it loads its description, its Cost per search value, and its query form below.
  3. Enter your identifier. For the default Module this is a Domain Name; the Website Domain Ownership (by Email) Module instead takes an email address and returns the domains registered under it (reverse-WHOIS).
  4. Confirm the Cost per search line beneath the input before you run. With Website Domain Ownership (by Domain) selected it reads “Cost per search: Free” — the Module consumes no Credits per search.
  5. Select Search Now (the coral-orange button with a magnifier icon at the right of the input row) to run the query.

Selecting Website Domain Ownership (by Domain) and running a search returns, per its Module description, the domain’s current and historical ownership — WHOIS registration data, registration history, and associated contacts. Results populate the Search Results panel on the right, which carries the standard Found / Enriched / Connections counters and Details / Graph tabs.

The two Domain Ownership Modules are attributed to a WHOIS data source, and Website Change History to the Internet Archive — but both attributions are inferred from the Module names, not confirmed on screen. See Website forensics modules & options for the per-Module data-source detail and cautions.

For how to read and verify those results — the counters, the results table columns, and the Details panel — see Reading Website forensics results.

Verified against UserSearch v2.0.20