ZERO-TRUST FORENSIC THREAT INTELLIGENCE

Instant Link, Redirect & DNS Threat Audit

Trace hidden 301/302 redirect loops, unmask phishing traps, check domain creation age, and validate enterprise email protocols (SPF, DKIM, DMARC, SSL) — 100% in-memory with zero data logging.

Quick Audit:
Engines12 Zero-Trust
Retention0 Bytes Logged
ResolversCloudflare DoH
StandardsRFC Compliant

Trace multi-hop redirects, detect IDN homograph spoofs, audit domain registration age, and inspect SSL/TLS handshakes.

6 Diagnostic Engines

Redirect Checker

Trace full 301 and 302 HTTP redirect chains, spot redirect loops, and uncover the real final destination URL.

Domain Age Checker

Find out when any domain was registered, its exact age in years, months, and days, and inspect registrar WHOIS/RDAP records.

Safe Link Checker

Verify if any link or web address is safe to open. Inspect for phishing traps, IDN homograph spoofing, and malicious scripts.

URL Threat Scanner

Deep-scan any web address for phishing signatures, malware domains, Cyrillic lookalikes, DGA entropy, and brand impersonation.

SSL Certificate Checker

Verify SSL/TLS certificate validity, inspect Certificate Authority issuer, calculate expiration dates, and test TLS 1.3.

QR Code URL Scanner

Extract and safely audit web links encoded in QR codes. Detect quishing scams and malicious downloads before opening.

Email Security & Anti-Spoofing Protocols

Verify RFC 7208 SPF syntax, lookup 2048-bit DKIM keys, enforce DMARC p=reject, inspect BIMI brand marks, and analyze RFC 822 relay headers.

6 Authentication Tools

SPF Record Checker

Lookup published SPF DNS TXT records, validate mechanism syntax, and count DNS lookups against the 10-lookup limit.

DKIM Key Lookup

Lookup DKIM public key TXT records, inspect cryptographic key length (1024 vs 2048-bit), and verify email signatures.

DMARC Policy Enforcer

Inspect DMARC DNS records, verify enforcement policies (p=reject / p=quarantine), and protect your domain from spoofing.

BIMI Logo Inspector

Inspect published BIMI DNS records, validate SVG logo formatting, and verify VMC certificate compliance for Gmail and Yahoo.

Email Security Score

Calculate your domain's comprehensive email authentication score, detect anti-spoofing gaps, and ensure inbox delivery.

Email Header Analyzer

Paste raw email headers to trace originating sender IP addresses, audit SPF/DKIM/DMARC authentication results, and detect spoofing.

Forensic Architecture

The 7 Pillars of Zero-Trust Verification

How IncogSay evaluates threat vectors without storing or retaining your data.

1IDN Homograph Filter

Detects Cyrillic, Greek, and Unicode lookalike glyphs masquerading as legitimate Latin brand domains.

2Shannon Entropy Meter

Calculates string entropy to flag algorithmic Domain Generation Algorithms (DGA) used by malware command centers.

3Redirect Cloak Unmasking

Recursively evaluates HTTP 301, 302, 307, and 308 response chains to reveal intermediate tracking gateways.

4RDAP Domain Longevity

Queries ICANN accredited RDAP endpoints to isolate domains registered within the last 30 days.

5SPF Lookup Exhaustion

Calculates mechanism lookups against RFC 7208 limits to stop permanent evaluation failures (PermError).

6DMARC Alignment Check

Audits anti-spoofing enforcement (p=reject / p=quarantine) mandated by Google Workspace and Yahoo Mail.

Frequently Asked Questions

Learn more about redirect tracing, domain age lookups, email security protocols, and link auditing.

What is a redirect checker and how does it work?
A redirect checker traces the full path a URL takes from its initial address to its final destination. It follows 301 (permanent), 302 (temporary), 307, and 308 HTTP redirects, meta refreshes, and JavaScript redirects. Use IncogSay's free redirect checker to check redirects on website links, verify where a link goes, trace redirect chains, detect redirect loops, and confirm HTTP to HTTPS redirection.
How do I check domain age and find out when a website was created?
To check domain age, enter any domain name into IncogSay's domain age checker. The tool performs a live WHOIS / RDAP lookup to retrieve the domain registration date, domain creation date, last updated date, and expiration date. It calculates the exact age of a domain or website in years, months, and days so you can know how old a website is.
How do I check if a link is safe before clicking?
To check if a link is safe: (1) Copy the link URL without clicking it. (2) Paste it into IncogSay's safe link checker. (3) The tool analyzes the domain for IDN homograph attacks (Cyrillic lookalikes), typosquatting, high Shannon entropy (DGA domains), hidden redirect chains, domain age, and SSL certificate validity. This gives you a clear safety verdict to verify if a link is safe.
What is an SPF checker and why do I need to validate my SPF record?
An SPF checker (Sender Policy Framework validator) checks your domain's DNS TXT record for SPF compliance (RFC 7208). It verifies SPF record syntax, counts the number of DNS lookups to ensure you stay under the 10-lookup limit, checks for ~all (softfail) vs -all (hardfail), and flags common errors that cause email delivery failures or allow email spoofing.
How do I check DKIM records and lookup my public key?
To check a DKIM record: enter your domain name and DKIM selector into IncogSay's DKIM checker. The tool queries DNS at selector._domainkey.yourdomain.com and retrieves your published public key, verifies its key length (2048-bit recommended vs 1024-bit legacy), and confirms the record is correctly formatted for email signature verification.
What is a DMARC policy checker and why is DMARC enforcement important?
A DMARC checker inspects your _dmarc.yourdomain.com DNS record to verify your domain's anti-spoofing policy. It checks whether your policy is set to p=reject (maximum protection), p=quarantine (send to spam), or p=none (monitoring only). DMARC is required by major email providers like Google Gmail and Yahoo to ensure legitimate email delivery.
How do I check an SSL certificate and verify HTTPS encryption?
Enter any domain into IncogSay's SSL checker to perform a live TLS handshake inspection. The tool checks certificate validity, issuer Certificate Authority (e.g. Let's Encrypt, DigiCert), valid from and expiration dates, days remaining before expiry, TLS protocol version (TLS 1.2 / TLS 1.3), and Subject Alternative Names (SANs).
What is BIMI and how do I inspect my BIMI record and logo?
BIMI (Brand Indicators for Message Identification) allows your verified brand logo to appear next to your emails in supporting inboxes like Gmail and Yahoo. IncogSay's BIMI checker queries default._bimi.yourdomain.com, validates your SVG Tiny P/S logo formatting, and checks for a Verified Mark Certificate (VMC).
Can I analyze email headers to trace the sender IP address?
Yes. IncogSay's email header analyzer parses raw RFC 822 email headers (from Gmail, Outlook, Apple Mail) to extract the originating sender IP address, reconstruct the full hop-by-hop relay server chain with timestamps and delays, and verify SPF, DKIM, and DMARC authentication results.
Is IncogSay free to use and does it log my search data?
IncogSay is 100% free with no registration required. It operates under a strict zero-trust and zero-logging policy: all diagnostic scans are executed in-memory on Cloudflare edge isolates or directly in your browser using public DNS-over-HTTPS. No URLs, domain names, or email headers are ever stored in a database.