Skip to content
Osintpro

Competitor Research and Analysis From Public Infrastructure

Most competitive research is assembled from marketing material, which tells you what a company wants said about it. Public infrastructure records tell you what it actually runs, and they are not written by a communications team.

Everything here is passive and about an organization. No individuals, no speculation, and every claim carries the record it came from.

See pricing
  • Authorized use only.
  • Domains only, never a person.
  • Every finding sourced and timestamped.
  • Passive collection only.

What a competitor publishes without meaning to.

A company's DNS zone is a public statement about how it operates. Read carefully it names the vendors it depends on, the products it has bought, the regions it serves and, over time, the direction it is moving in.

The clearest example is TXT verification strings. To prove domain ownership to a SaaS vendor, an organization publishes a token in DNS, and it usually stays there for years after the tool is adopted. The result is a public, timestamped list of a competitor's stack, published by the competitor.

Certificate transparency does something similar for product direction. Hostnames appear in the logs when certificates are issued, often before anything is announced, which is why a new product subdomain is one of the earliest public signals of a launch there is.

From record to competitive insight.

The derivation is shown so you can disagree with it. Nothing on this page is inferred from anything other than a record we can quote.

TXT verification strings

What it tells you
Which SaaS vendors the organization has verified a domain with
How to use it
A partial stack inventory. Useful for displacement plans and for partner conversations.

MX hostnames

What it tells you
Mail provider and any security gateway in front of it
How to use it
Vendor relationships, and whether they buy premium mail security.

Nameserver delegation

What it tells you
DNS vendor, and whether they run redundant providers
How to use it
Operational maturity and infrastructure spend.

New hostnames in CT logs

What it tells you
Product areas being built before they are announced
How to use it
The earliest public signal of a launch. Date it and watch it.

Apex address and reverse records

What it tells you
Hosting network and CDN posture
How to use it
Where the money goes and how the front door is architected.

Registration history and locks

What it tells you
Brand-protection maturity, portfolio behavior
How to use it
Corporate registrars indicate a brand program and a legal budget.

Map a competitor's public footprint now.

Pick "Acquisition target" or "Own estate review" as your declared scope, tick the authorization box, and run a domain. Passive throughout, so nothing reaches their systems and nothing appears in their logs.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

The discipline that keeps this credible.

Date everything

Infrastructure changes constantly. An undated claim about a competitor's stack will be wrong within a quarter and you will not know which quarter it broke.

Separate observation from inference

"They publish a verification token for vendor X" is an observation. "They are migrating to X" is an inference. Label which is which or your strategy deck will be challenged on the wrong point.

Never touch their systems

Passive only. The moment competitive research becomes active testing it stops being research and becomes a legal problem for your employer.

Stay on the organization

Employees are not the subject. Public infrastructure and corporate filings are. Our acceptable use boundary covers where this line sits.

Re-run for the trend

A single snapshot is a fact. Two dated snapshots are a direction, which is what a strategy audience actually wants.

Say what you did not find

Negative findings bound the work and stop a reader assuming coverage you did not have.

What public records will not tell you.

Infrastructure is a good proxy for engineering reality and a poor proxy for commercial reality.

Revenue, churn, headcount by function, roadmap intent and pricing power do not appear in DNS. Anyone claiming to derive them from infrastructure is guessing, and a strategy audience will find the guess.

Use this for what it is genuinely good at: the technology footprint, the vendor relationships, the direction of build, and the maturity signals. Then corroborate with filings, job posts and product announcements. The OSINT framework page maps which discipline answers which question.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.