A blocked domain should be the start of the next investigation.
Spilfri Intelligence turns a gambling domain, operator or official blocking list into a structured investigation. It maps the domains, companies, licence signals, payments, technical infrastructure and providers around the case, then keeps watching for what appears next.
Evidence first. Jurisdiction aware. Website claims stay separate from regulator evidence, and weak shared infrastructure is never treated as proof of common ownership.
500,000+domain records available as a discovery and comparison corpus. Corpus membership is not a legal conclusion.
37domains in the current 22bet.ng monitoring case shown below, compared with six 22Bet-family domains in the enforcement baseline used for the demo.
Retained scan, discovery, network and authority events appear here as they are written by the investigation system. A quiet feed means no new public event was retained; the connection indicator below still confirms live polling.
Live intelligenceLIVE
Investigation event stream
Operational activity in real time. Events are investigation signals, not automatic legal or regulatory conclusions.
No private evidence, contact details or sensitive case material is exposed in this public stream.
Why it exists
Blocking solves one URL. The network can keep moving.
Operators can change domains, mirrors, front ends and infrastructure. The useful question is not only “what should be blocked today?” but also “what sits around it, and what is likely to appear next?”
01
Start with what is already known
Use one suspicious domain, a known brand or operator, an authority-listed domain, or an existing enforcement/blocking list.
02
Build the case around it
Review live and archived pages, resolve legal identities, check authority records, discover sibling domains, map technical relationships, retain payment signals and inspect observed provider infrastructure.
03
Keep the case alive after action
Freeze the known enforcement baseline, continue monitoring the wider case, and surface new evidence-backed domains for review without rebuilding the investigation from zero.
A blocking list becomes the starting point, not the end of the case.
22Bet enforcement example
Use the block as a seed.
The Danish Gambling Authority announced a court-approved block of 98 illegal gambling websites. Six 22Bet-family domains from that enforcement baseline are used here as the starting point.
Case membership is an investigation lead, not proof of common ownership, illegality or a blocking decision.
What the platform can do now
From one hostname to a full investigation record.
Each layer answers a different question. The system keeps those layers separate so technical similarity, corporate identity and regulatory status do not get mixed into one unsupported conclusion.
01 · DOMAIN
Investigate a single hostname
Capture DNS, HTTP behaviour, redirects, TLS, page structure, gambling signals, country/currency cues and available first-party content.
Live capture can fall back to rendered-browser and public archive evidence when direct access is challenged or unavailable.
02 · DISCOVERY
Find mirrors, siblings and replacements
Search outside the original list for brand-family domains, redirect targets, official alternates, first-party references and other evidence-backed candidates.
Weak search hits remain leads. They do not become network members just because a search engine returned them.
03 · ENTITIES
Resolve brands, operators and companies
Retain company names, registrations, addresses, operator roles and legal disclosures from captured public evidence.
Technical suppliers and shared infrastructure are deliberately kept out of operator attribution.
04 · AUTHORISATION
Separate claims from regulator evidence
Keep website licence claims as claims, then check the relevant jurisdiction using regulator-owned pages and retained authority data.
A company match is not displayed as an exact-domain match, and a licence for one regional hostname is not transferred to another.
05 · PAYMENTS
Retain commercial identities
Store merchant descriptors, payment entities and related commercial signals when they are explicitly present in the evidence.
Provenance and verification state stay attached to the signal instead of turning an extracted phrase into a confirmed payment relationship.
A shared CDN, registrar or common analytics service is weak context, not proof of common ownership.
07 · NETWORK
Build explainable relationship maps
Connect domains to domains and entities using retained evidence, confidence, timestamps and the reason each edge exists.
The graph distinguishes investigated, connected, probable mirror, entity, candidate and monitoring-baseline context.
08 · MONITORING
Keep watching after blocking
Turn a known enforcement set into a living monitoring case. Freeze the baseline and surface later evidence-backed additions for review.
This is designed for repeated enforcement cycles rather than one-off static lists.
09 · EVIDENCE
Keep the case auditable
Retain source URLs, captured material, observation times, confidence, relationship basis, authority checks and investigation history.
Structured reports can be generated from the retained case record for review and hand-off.
Provider & supply-chain intelligence
See parts of the technical supply chain behind the gambling product.
Spilfri Intelligence can run a live rendered-browser capture and inspect the network traffic, retained endpoints, page content and bounded JavaScript sources that are visible from the front end.
01
Observe live endpointsRetain directly observed requests, hosts and technical context instead of relying on a brand-name guess.
02
Classify the supplier layerSportsbook platforms, sports data/odds, casino/game providers, aggregators and unattributed technical candidates stay separate.
03
Keep the evidence boundary visibleA browser-visible provider match can show technical use. It does not prove ownership, contractual responsibility or the provider's knowledge of how the operator uses the service.
In the current 22bet.ng demo capture, Sportradar / Betradar infrastructure is identified from directly observed technical endpoints with 99% technical attribution inside the case.
Investigation workflow
Locate. Verify. Connect. Monitor.
The system is built around a simple principle: discovery can be broad, but conclusions should get stronger only when the evidence gets stronger.
01 · Intake
Domain or list
Start from a suspicious hostname, a brand, an operator or an authority's existing blocking/enforcement list.
02 · Capture
Public evidence
Review direct pages, rendered content, archives, DNS/RDAP/TLS, legal disclosures and public authority sources.
03 · Resolve
Identity & scope
Resolve brands, companies, operators, licence claims and jurisdiction relevance without transferring evidence across unrelated hostnames.
04 · Expand
Related domains
Search for mirrors, siblings, official alternates and other candidates, then keep weak leads separate from stronger network evidence.
05 · Verify
Authority checks
Use regulator-owned sources to corroborate an exact domain, retained legal identity or licence reference where the jurisdiction supports it.
06 · Correlate
Network & supply chain
Compare entities, payment signals, technical infrastructure and observed providers across the retained corpus.
07 · Monitor
Post-action change
Freeze the known baseline and keep watching for evidence-backed domains that appear after the original action.
08 · Report
Evidence trail
Review the sources, confidence, timestamps, graph edges and case history behind the result instead of receiving only a URL list.
Evidence before conclusions
The system is designed to say what the evidence does — and what it does not.
This matters in regulatory work. A tool that finds more domains is only useful if an investigator can understand why a connection exists and how strong it really is.
What is retained
Source and provenance
Capture and observation timestamps
Relationship basis and confidence
Website licence claims separately from authority findings
Operator, company, payment, provider and technical signals
Monitoring baseline, later discoveries and case history
Live and archived public evidence where available
What is not assumed
No authority match does not automatically mean illegal
A licence is not transferred from one hostname or regional service to another
A shared CDN, registrar, analytics ID or hosting provider is not proof of common ownership
A monitoring-case member is not automatically a mirror
A newly discovered domain is a candidate for review, not an automatic blocking decision
A technical provider match is not proof that the provider owns or controls the operator
AI output is not treated as regulator evidence
Who can use it
Same evidence. Different investigative questions.
Spilfri Intelligence is not limited to one workflow. The same domain graph can support regulatory, enforcement, financial and technical review from different angles.
Regulation
Gambling regulators & licensing authorities
Use existing blocking lists as seeds, check licence claims, map operators and mirrors, prepare review candidates and continue monitoring after a court or regulatory action.
Typical question: “What should we review before the next blocking round?”
Enforcement
Law enforcement & cybercrime teams
Work from a domain into legal entities, historical material, technical infrastructure, related domains and an auditable chronology of what was observed when.
Typical question: “What connects these sites, and what evidence supports the link?”
Financial crime
Banks, acquirers, PSPs & AML teams
Review operator/company identities, payment entities, merchant descriptors and recurring commercial signals across domains where the evidence exposes them.
Typical question: “Does this merchant or legal identity appear elsewhere in the network?”
Supply chain
Sports integrity, data & supplier compliance teams
Inspect where browser-visible supplier technology appears in gambling investigations, while keeping technical use separate from ownership or contractual conclusions.
Typical question: “Where is our technology visibly present, and what was actually observed?”
Enforcement layer
ISPs, DNS/filtering & blocking partners
Work from regulator-approved domain decisions and continuously maintained case intelligence rather than treating a static list as permanently complete.
Typical question: “What changed after the last approved block set?”
Open-source research
Researchers, journalists & investigators
Use traceable public sources, company links, archived material and network context to understand a gambling brand or cluster beyond a single homepage.
Typical question: “What sits behind this domain, and which parts can be independently sourced?”
What you get back
Not just a score. A case you can inspect.
The useful output is the retained reasoning around the domain: what was observed, what was inferred, what was verified and what still needs human review.
Connected domains and entities with relationship type, confidence, evidence weight and the reason each connection exists.
03
Authority & licence view
Jurisdiction-scoped claims and regulator corroboration, with exact-domain evidence kept separate from company or licence-identity matches.
04
Monitoring case
A frozen enforcement baseline, current case members, newly surfaced post-baseline candidates, actions and retained monitoring history.
05
Provider & technical record
Observed sportsbook/data/casino supplier signals, endpoints, browser traffic, infrastructure and fingerprints with explicit evidence boundaries.
06
Structured evidence report
Sources, timestamps, entity relationships, authority checks, network evidence and case history for review, discussion or hand-off.
Built for messy real-world websites
Deterministic evidence first. AI where it helps.
Direct HTTP, rendered-browser capture, archives, public search, legal extraction and authority checks work together. AI can help resolve brands and structure public evidence, but the platform is designed to remain useful when an AI provider is unavailable and does not use AI as proof of regulatory status.
Send a gambling domain and I’ll run it through Spilfri Intelligence and send the results back. Regulators and organisations can also start with an existing blocking list.
For regulators and organisations
Import of an existing blocking list
Network and mirror mapping
Authority and licence checks
Operator, payment, provider and technical profiling
Continuous post-action monitoring and evidence reports
Spilfri Intelligence
Find the domain. Understand what sits behind it. Keep watching what appears next.
The goal is not the biggest URL list. It is to make the next investigation faster, more explainable and less dependent on starting from zero.