12 July 2026 · Gumshoe

Web, WHOIS and Threat Check: Reading Gumshoe's Domain Signals

Domain signals are a critical component of supplier risk assessment, providing insights into the legitimacy, stability, and security of a supplier's online presence.

Domain signals are a critical component of supplier risk assessment, providing insights into the legitimacy, stability, and security of a supplier's online presence. In this article, we'll delve into the Web, WHOIS, and Threat Check features on the Gumshoe platform, exploring what each tile checks, what the different statuses mean, and how to interpret the results.

42% of Australian businesses have been targeted by cybercrime
$1.3 billion annual cost of cybercrime to Australian businesses
12% of Australian businesses have experienced a data breach

What the Web Tile Checks

The Web tile on the Gumshoe platform performs a comprehensive check of a supplier's domain, providing insights into their online presence and legitimacy. The check includes:

Domain discovery: The Web tile checks if the supplier has a valid domain and if it's correctly configured. Liveness: The tile verifies if the domain is active and responding to requests. HTTPS: The check ensures the supplier's website has a valid HTTPS certificate, indicating a secure connection. Hosting: The tile identifies the supplier's hosting provider and checks if it's a reputable and secure host. Homepage ABN cross-check: The Web tile verifies if the supplier's ABN is displayed on their homepage, as required by the Australian Business Register.

What WHOIS Adds

The WHOIS tile on the Gumshoe platform provides additional information about a supplier's domain, including:

Domain age: The WHOIS tile checks the age of the supplier's domain, which can indicate the legitimacy and stability of the business. Registrar: The tile identifies the registrar of the domain, which can help identify potential red flags. Expiry: The WHOIS tile checks the expiry date of the domain, which can indicate if the supplier is likely to be a legitimate business. Sub-180-day domains matter in payment fraud: Domains registered within the last 180 days are more likely to be used for fraudulent activities, such as phishing or invoice scams.

Threat Check Lists Explained

The Threat Check tile on the Gumshoe platform checks a supplier's domain against several threat lists, including:

Spamhaus: A global threat intelligence provider that tracks malicious IP addresses and domains. SURBL: A list of domains known to be involved in spam and phishing activities. URIBL: A list of domains known to be involved in spam and phishing activities. OpenPhish: A community-driven list of phishing sites. These threat lists help identify potential security risks associated with a supplier's domain.

cybersecurity-threat-lists

Interpreting the Web, WHOIS and Threat Check Results

The Web, WHOIS and Threat Check feature provides a comprehensive overview of a supplier's domain, including its registration details, website content, and potential security risks. The results are presented in a clear and concise format, making it easy to identify potential issues. In this section, we'll delve deeper into the different statuses that may be displayed and what they mean. A PASS status indicates that the supplier's domain has been registered for a reasonable amount of time, has a valid WHOIS record, and does not appear on any of the threat lists. A WARN status may indicate that the domain is relatively new or has some inconsistencies in its WHOIS record. A FAIL status suggests that the domain is not registered, has an invalid WHOIS record, or appears on one or more of the threat lists. An NA status indicates that the domain is not available or could not be checked.

Understanding the Threat List Matches

If a supplier's domain appears on one or more of the threat lists, it's essential to investigate further. The threat lists used in the Web, WHOIS and Threat Check feature are reputable and widely used in the industry. However, it's possible that a domain may be incorrectly listed or have been compromised by a third party. In such cases, it's crucial to contact the supplier and request an explanation. You may also want to conduct further research to verify the accuracy of the listing. If the supplier's domain is indeed compromised, it's essential to take immediate action to protect your organization's interests.

Example: Analyzing a Supplier's Domain

Let's consider an example of a supplier's domain that has been checked using the Web, WHOIS and Threat Check feature.
Example Web, WHOIS and Threat Check Results
Category Status Details
Domain Registration PASS Registered for 5 years, valid WHOIS record
Website Content WARN No website content available, possible issues with DNS configuration
Threat List Matches FAIL Appears on URIBL list, possible spam or phishing activity
WHOIS Record PASS Valid WHOIS record, contact information available
]

Uncommon Insights

When reviewing a supplier's domain signals, it's essential to consider the broader implications under the Australian Securities and Investments Commission's (ASIC) regulatory framework. For instance, ASIC's Regulatory Guide 168 (RG 168) emphasizes the importance of verifying the identity of counterparties in business transactions, which includes scrutinizing domain registration details. Failure to do so can lead to penalties under Section 12GB(1) of the Australian Securities and Investments Commission Act 2001, as seen in the case of ASIC v Australian Institute of Management Education and Training Pty Ltd (2019) FCA 1694, where the respondent was fined $290,000 for failing to comply with ASIC's requirements. Furthermore, the Australian Taxation Office (ATO) also relies on domain registration data to identify and prevent tax evasion. According to the ATO's Tax Crime Factsheet, in 2020-21, the ATO initiated 1,444 tax crime investigations, resulting in 233 convictions and over $1.1 billion in tax liabilities. By analyzing a supplier's domain signals, businesses can better assess their tax compliance risks and avoid potential penalties under the Taxation Administration Act 1953. In addition, the Web, WHOIS and Threat Check can also help identify potential red flags under the Modern Slavery Act 2018 (Cth). For example, if a supplier's domain registration details indicate a high-risk country or suspicious activity, it may trigger further due diligence to ensure compliance with the Act's reporting requirements. Lastly, it's worth noting that the Web, WHOIS and Threat Check can also provide valuable insights into a supplier's potential cybersecurity risks. According to the Australian Cyber Security Centre's (ACSC) 2020-21 Annual Report, the ACSC received over 67,500 reports of cybercrime, resulting in estimated losses of over $33 million. By analyzing a supplier's domain signals, businesses can better assess their cybersecurity risks and take proactive measures to protect themselves. Domain name red flags

Key Takeaways

  • Verify domain registration details to ensure compliance with ASIC's RG 168 and the Australian Securities and Investments Commission Act 2001.
  • Assess tax compliance risks by analyzing a supplier's domain signals and reporting any suspicious activity to the ATO.
  • Identify potential modern slavery risks by scrutinizing a supplier's domain registration details and conducting further due diligence as necessary.
  • Proactively manage cybersecurity risks by analyzing a supplier's domain signals and taking steps to protect your business.
VERIFY NOW

Run a free supplier check in seconds

Search by business name, ABN, or ACN. Instant PASS/WARN/FAIL across 8 verification signals.

Start verifying →