[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs-the-graph":3},[4,9,12,14,18,20,29,31,34,38,65,68,70,77,79,82,84,91,93,96,101,104,106,111,113,116],{"type":5,"level":6,"text":7,"id":8},"heading",1,"The Graph","the-graph",{"type":10,"text":11},"paragraph","A single scan tells you what a domain looks like. The graph tells you what it's **connected to**.",{"type":10,"text":13},"Behind every result page is a property graph. Domains, IPs, SSL certificates, regulator warnings and other forensic signals are stored as nodes and connected by typed edges. When you open the **Network** tab on a [scan result](\u002Fdocs\u002Fscan-url-checker#network-tab), you're looking at a slice of that graph centred on the domain you scanned.",{"type":5,"level":15,"text":16,"id":17},2,"Why a graph","why-a-graph",{"type":10,"text":19},"Scammers reuse things. A single individual or operation typically runs many domains, but they share:",{"type":21,"ordered":22,"items":23},"list",false,[24,25,26,27,28],"The same hosting IP or nameserver","The same SSL certificate fingerprint","The same analytics or AdSense ID","The same favicon, the same build hash, the same image set","The same registrant email, phone, or crypto wallet",{"type":10,"text":30},"In a relational database, surfacing those reuse patterns means stitching joins together every time you ask a question. In a graph, the relationships are first-class. \"Show me every domain sharing this IP\" is a one-hop traversal, not a query plan negotiation.",{"type":5,"level":15,"text":32,"id":33},"The model","the-model",{"type":5,"level":35,"text":36,"id":37},3,"Nodes","nodes",{"type":39,"head":40,"rows":43},"table",[41,42],"Node type","What it is",[44,47,50,53,56,59,62],[45,46],"**Domain**","A scanned hostname with its trust score, status, and metadata",[48,49],"**IP**","A resolved IP address",[51,52],"**SSL certificate**","A unique certificate fingerprint",[54,55],"**Nameserver**","A DNS nameserver hostname",[57,58],"**Identifier**","Analytics IDs, AdSense IDs, registrant emails, phones, crypto wallets",[60,61],"**Regulator warning**","A published warning from a financial authority",[63,64],"**Signal**","A forensic fingerprint (favicon hash, build hash, content hash, image set)",{"type":5,"level":35,"text":66,"id":67},"Edges","edges",{"type":10,"text":69},"Edges are typed by **why** two nodes are connected. The colour you see on the network graph reflects the family:",{"type":21,"ordered":22,"items":71},[72,73,74,75,76],"**Code \u002F Content** (cyan): `content_hash`, `build_hash`, `similar_content`, `same_images`, `favicon_hash`","**Infrastructure** (mint): `ip_address`, `nameserver`, `ssl_fingerprint`","**Identity** (gold): `email`, `registrant`, `registrar`, `analytics_id`, `adsense_id`, `tracking_id`","**Financial** (white): `phone_number`, `crypto_wallet`","**Regulator warning** (magenta): co-listing in the same warning by a non-dragnet regulator",{"type":10,"text":78},"A connection between two domains can come from any of these, and a [forensic cluster](\u002Fdocs\u002Fscan-url-checker#network-tab) is almost always a stack of several signals on top of each other.",{"type":5,"level":15,"text":80,"id":81},"How the graph powers a scan","how-the-graph-powers-a-scan",{"type":10,"text":83},"When you scan a domain, here's what happens behind the bubble graph:",{"type":21,"ordered":85,"items":86},true,[87,88,89,90],"The scan extracts every signal it can (IPs, certificates, identifiers, hashes) and writes them as nodes","The domain is linked to each signal it touched","The query that builds the **Network** tab asks: \"give me every other domain reachable in one or two hops from here\"","Those neighbours and their edges are rendered as the force-directed bubble map",{"type":10,"text":92},"Bubble colour reflects trust score. The ring around a node reflects uptime. Edge colour reflects the signal family. Filtering by signal in the UI is a graph traversal, not a recomputation.",{"type":5,"level":15,"text":94,"id":95},"What it does not do","what-it-does-not-do",{"type":21,"ordered":22,"items":97},[98,99,100],"**No private data.** Every signal in the graph comes from a scan we ran or a public regulator publication. There is no purchased dataset, no user PII, no scraped social profiles.","**No predictive verdicts.** The graph surfaces structural reuse. It is evidence, not a verdict. Two domains sharing a CDN IP is much weaker signal than two domains sharing a favicon hash, a tracking ID, and a registrant email.","**No infinite expansion.** Each network view is bounded to a sensible neighbourhood. Otherwise a single hosting provider IP would pull in millions of unrelated sites.",{"type":5,"level":15,"text":102,"id":103},"Reading a cluster honestly","reading-a-cluster-honestly",{"type":10,"text":105},"A few practical rules when you look at a connected component:",{"type":21,"ordered":22,"items":107},[108,109,110],"**Infrastructure links alone are weak.** Shared Cloudflare IPs mean almost nothing on their own.","**Identity + content links are strong.** A shared analytics ID and a shared favicon hash justify closer investigation. Copied templates and third-party services can also produce shared identifiers; ownership needs corroboration.","**Regulator warnings are direct evidence.** A magenta edge means a named authority publicly co-listed the two domains in the same warning.",{"type":10,"text":112},"The Network tab on a [scan result](\u002Fdocs\u002Fscan-url-checker) labels each edge so you can see what kind of evidence you're looking at, not just a line on a screen.",{"type":5,"level":15,"text":114,"id":115},"Related","related",{"type":21,"ordered":22,"items":117},[118,119,120],"See the graph in action on any [scan result page](\u002Fdocs\u002Fscan-url-checker) under the **Network** tab","Read about the [trust score](\u002Fdocs\u002Ftrust-score) we attach to each domain node","Submit a [community report](\u002Fdocs\u002Fcommunity-reports). Confirmed reports become first-class nodes too"]