01
What it is
Shodan OSINT is the use of Shodan's pre-built index of internet-connected devices and services to find exposed servers and infrastructure tied to a domain or IP range, by querying data Shodan has already collected rather than scanning the target directly.
Step 05 of the Email OSINT guide covers domain infrastructure analysis using MXToolbox and WHOIS lookups, cross-referenced against the DIG-001 WHOIS card. That step establishes the registrant, DNS records, and hosting provider for a domain. Shodan extends that step: once a domain's IP address or hosting range is known, Shodan reveals what services are actually running there, what ports are open, and whether any exposed software is outdated enough to carry a known vulnerability.
Shodan is a search engine, not a scanner an investigator runs live. It continuously crawls the internet on its own schedule and indexes what it finds; searching Shodan queries that existing index rather than sending any request to the target. That distinction matters for both the legal analysis and for understanding how current the results are.
When to use this guide
- Identifying exposed services or devices tied to a domain's IP infrastructure
- Checking whether a custom mail or web server is running outdated, potentially vulnerable software
- Confirming a hosting provider or IP range identified through WHOIS or DNS records
- Investigating infrastructure clusters that share a hosting footprint across multiple domains

