spilfrıIntelligence
Gambling intelligence

A blocked domain should be the start of the next investigation.

Spilfri Intelligence turns a gambling domain, operator or official blocking list into a structured investigation. It maps the domains, companies, licence signals, payments, technical infrastructure and providers around the case, then keeps watching for what appears next.

Evidence first. Jurisdiction aware. Website claims stay separate from regulator evidence, and weak shared infrastructure is never treated as proof of common ownership.

500,000+domain records available as a discovery and comparison corpus. Corpus membership is not a legal conclusion.
37domains in the current 22bet.ng monitoring case shown below, compared with six 22Bet-family domains in the enforcement baseline used for the demo.
8 layersdomain, entity, authorisation, payments, providers, technical infrastructure, evidence and continuous monitoring.
Live investigations

See the system working.

Retained scan, discovery, network and authority events appear here as they are written by the investigation system. A quiet feed means no new public event was retained; the connection indicator below still confirms live polling.

Live intelligenceLIVE

Investigation event stream

Operational activity in real time. Events are investigation signals, not automatic legal or regulatory conclusions.

Visible events12Last event03:16:34 UTCConnectionChecking…
SCAN1xbet-oy.topScan completed · 0% gambling · HTTP 200 · browser-compatible-curl · live captureLIVE
SCAN1xbet-oxxe.topScan completed · 0% gambling · HTTP 200 · browser-compatible-curl · live captureLIVE
NETWORK1xbet-oxxe.top ↔ 1xbet-jkki.topProbable mirror · Mirror similarity98%
DISCOVERY1xbet-jkki.topDiscovered from 1xbet-oxxe.top · HTTP redirect from 1xbet-oxxe.top to 1xbet-jkki.top100%
SCAN1xbet-oxx.topScan completed · 60% gambling · HTTP 200 · browser-compatible-curl · live capture60%
NETWORK1xbet-bem24.top ↔ 1xbet-oxx.topMirror candidate · Mirror similarity75%
NETWORK1xbet-oxo.top ↔ 1xbet-oxx.topMirror candidate · Mirror similarity75%
NETWORK1xbet-ouo.xyz ↔ 1xbet-oxx.topMirror candidate · Mirror similarity75%
NETWORK1xbet-otv.top ↔ 1xbet-oxx.topMirror candidate · Mirror similarity75%
NETWORK1xbet-ott.xyz ↔ 1xbet-oxx.topMirror candidate · Mirror similarity75%
SCAN1xbet-oxt.topScan completed · 65% gambling · HTTP 200 · browser-compatible-curl · live capture65%
NETWORK1xbet-3on8j.cfd ↔ 1xbet-oxt.topMirror candidate · Mirror similarity75%
No private evidence, contact details or sensitive case material is exposed in this public stream.
Why it exists

Blocking solves one URL. The network can keep moving.

Operators can change domains, mirrors, front ends and infrastructure. The useful question is not only “what should be blocked today?” but also “what sits around it, and what is likely to appear next?”

01

Start with what is already known

Use one suspicious domain, a known brand or operator, an authority-listed domain, or an existing enforcement/blocking list.

02

Build the case around it

Review live and archived pages, resolve legal identities, check authority records, discover sibling domains, map technical relationships, retain payment signals and inspect observed provider infrastructure.

03

Keep the case alive after action

Freeze the known enforcement baseline, continue monitoring the wider case, and surface new evidence-backed domains for review without rebuilding the investigation from zero.

A real enforcement example

6 enforcement domains → 37-domain monitoring case.

A blocking list becomes the starting point, not the end of the case.

22Bet enforcement example

Use the block as a seed.

The Danish Gambling Authority announced a court-approved block of 98 illegal gambling websites. Six 22Bet-family domains from that enforcement baseline are used here as the starting point.

22bet.co.ke22bet.ng22bet4u.com22bet.ug22win-bet.com22wingo.com
6domains in the demo enforcement baseline
37domains in the current monitoring case

The other 31 are investigation leads, not automatic blocking decisions. They can be reviewed before the next enforcement round starts.

Spilfri Intelligence 22bet.ng relationship map showing the wider 37-domain monitoring case
Case membership is an investigation lead, not proof of common ownership, illegality or a blocking decision.
What the platform can do now

From one hostname to a full investigation record.

Each layer answers a different question. The system keeps those layers separate so technical similarity, corporate identity and regulatory status do not get mixed into one unsupported conclusion.

01 · DOMAIN

Investigate a single hostname

Capture DNS, HTTP behaviour, redirects, TLS, page structure, gambling signals, country/currency cues and available first-party content.

Live capture can fall back to rendered-browser and public archive evidence when direct access is challenged or unavailable.
02 · DISCOVERY

Find mirrors, siblings and replacements

Search outside the original list for brand-family domains, redirect targets, official alternates, first-party references and other evidence-backed candidates.

Weak search hits remain leads. They do not become network members just because a search engine returned them.
03 · ENTITIES

Resolve brands, operators and companies

Retain company names, registrations, addresses, operator roles and legal disclosures from captured public evidence.

Technical suppliers and shared infrastructure are deliberately kept out of operator attribution.
04 · AUTHORISATION

Separate claims from regulator evidence

Keep website licence claims as claims, then check the relevant jurisdiction using regulator-owned pages and retained authority data.

A company match is not displayed as an exact-domain match, and a licence for one regional hostname is not transferred to another.
05 · PAYMENTS

Retain commercial identities

Store merchant descriptors, payment entities and related commercial signals when they are explicitly present in the evidence.

Provenance and verification state stay attached to the signal instead of turning an extracted phrase into a confirmed payment relationship.
06 · TECHNICAL

Map infrastructure without over-grouping

Compare DNS, IP, ASN, TLS, redirects, endpoints, tracking identifiers, page/application fingerprints and selected shared assets.

A shared CDN, registrar or common analytics service is weak context, not proof of common ownership.
07 · NETWORK

Build explainable relationship maps

Connect domains to domains and entities using retained evidence, confidence, timestamps and the reason each edge exists.

The graph distinguishes investigated, connected, probable mirror, entity, candidate and monitoring-baseline context.
08 · MONITORING

Keep watching after blocking

Turn a known enforcement set into a living monitoring case. Freeze the baseline and surface later evidence-backed additions for review.

This is designed for repeated enforcement cycles rather than one-off static lists.
09 · EVIDENCE

Keep the case auditable

Retain source URLs, captured material, observation times, confidence, relationship basis, authority checks and investigation history.

Structured reports can be generated from the retained case record for review and hand-off.
Provider & supply-chain intelligence

See parts of the technical supply chain behind the gambling product.

Spilfri Intelligence can run a live rendered-browser capture and inspect the network traffic, retained endpoints, page content and bounded JavaScript sources that are visible from the front end.

01
Observe live endpointsRetain directly observed requests, hosts and technical context instead of relying on a brand-name guess.
02
Classify the supplier layerSportsbook platforms, sports data/odds, casino/game providers, aggregators and unattributed technical candidates stay separate.
03
Keep the evidence boundary visibleA browser-visible provider match can show technical use. It does not prove ownership, contractual responsibility or the provider's knowledge of how the operator uses the service.

In the current 22bet.ng demo capture, Sportradar / Betradar infrastructure is identified from directly observed technical endpoints with 99% technical attribution inside the case.

Spilfri Intelligence provider evidence showing observed Sportradar and Betradar technical endpoints
Investigation workflow

Locate. Verify. Connect. Monitor.

The system is built around a simple principle: discovery can be broad, but conclusions should get stronger only when the evidence gets stronger.

01 · Intake

Domain or list

Start from a suspicious hostname, a brand, an operator or an authority's existing blocking/enforcement list.

02 · Capture

Public evidence

Review direct pages, rendered content, archives, DNS/RDAP/TLS, legal disclosures and public authority sources.

03 · Resolve

Identity & scope

Resolve brands, companies, operators, licence claims and jurisdiction relevance without transferring evidence across unrelated hostnames.

04 · Expand

Related domains

Search for mirrors, siblings, official alternates and other candidates, then keep weak leads separate from stronger network evidence.

05 · Verify

Authority checks

Use regulator-owned sources to corroborate an exact domain, retained legal identity or licence reference where the jurisdiction supports it.

06 · Correlate

Network & supply chain

Compare entities, payment signals, technical infrastructure and observed providers across the retained corpus.

07 · Monitor

Post-action change

Freeze the known baseline and keep watching for evidence-backed domains that appear after the original action.

08 · Report

Evidence trail

Review the sources, confidence, timestamps, graph edges and case history behind the result instead of receiving only a URL list.

Evidence before conclusions

The system is designed to say what the evidence does — and what it does not.

This matters in regulatory work. A tool that finds more domains is only useful if an investigator can understand why a connection exists and how strong it really is.

What is retained

  • Source and provenance
  • Capture and observation timestamps
  • Relationship basis and confidence
  • Website licence claims separately from authority findings
  • Operator, company, payment, provider and technical signals
  • Monitoring baseline, later discoveries and case history
  • Live and archived public evidence where available

What is not assumed

  • No authority match does not automatically mean illegal
  • A licence is not transferred from one hostname or regional service to another
  • A shared CDN, registrar, analytics ID or hosting provider is not proof of common ownership
  • A monitoring-case member is not automatically a mirror
  • A newly discovered domain is a candidate for review, not an automatic blocking decision
  • A technical provider match is not proof that the provider owns or controls the operator
  • AI output is not treated as regulator evidence
Who can use it

Same evidence. Different investigative questions.

Spilfri Intelligence is not limited to one workflow. The same domain graph can support regulatory, enforcement, financial and technical review from different angles.

Regulation

Gambling regulators & licensing authorities

Use existing blocking lists as seeds, check licence claims, map operators and mirrors, prepare review candidates and continue monitoring after a court or regulatory action.

Typical question: “What should we review before the next blocking round?”
Enforcement

Law enforcement & cybercrime teams

Work from a domain into legal entities, historical material, technical infrastructure, related domains and an auditable chronology of what was observed when.

Typical question: “What connects these sites, and what evidence supports the link?”
Financial crime

Banks, acquirers, PSPs & AML teams

Review operator/company identities, payment entities, merchant descriptors and recurring commercial signals across domains where the evidence exposes them.

Typical question: “Does this merchant or legal identity appear elsewhere in the network?”
Supply chain

Sports integrity, data & supplier compliance teams

Inspect where browser-visible supplier technology appears in gambling investigations, while keeping technical use separate from ownership or contractual conclusions.

Typical question: “Where is our technology visibly present, and what was actually observed?”
Enforcement layer

ISPs, DNS/filtering & blocking partners

Work from regulator-approved domain decisions and continuously maintained case intelligence rather than treating a static list as permanently complete.

Typical question: “What changed after the last approved block set?”
Open-source research

Researchers, journalists & investigators

Use traceable public sources, company links, archived material and network context to understand a gambling brand or cluster beyond a single homepage.

Typical question: “What sits behind this domain, and which parts can be independently sourced?”
What you get back

Not just a score. A case you can inspect.

The useful output is the retained reasoning around the domain: what was observed, what was inferred, what was verified and what still needs human review.

01

Domain intelligence profile

Gambling signals, ownership visibility, entities, licence claims, payment signals, infrastructure, captured pages and jurisdiction view.

02

Evidence-backed network map

Connected domains and entities with relationship type, confidence, evidence weight and the reason each connection exists.

03

Authority & licence view

Jurisdiction-scoped claims and regulator corroboration, with exact-domain evidence kept separate from company or licence-identity matches.

04

Monitoring case

A frozen enforcement baseline, current case members, newly surfaced post-baseline candidates, actions and retained monitoring history.

05

Provider & technical record

Observed sportsbook/data/casino supplier signals, endpoints, browser traffic, infrastructure and fingerprints with explicit evidence boundaries.

06

Structured evidence report

Sources, timestamps, entity relationships, authority checks, network evidence and case history for review, discussion or hand-off.

Built for messy real-world websites

Deterministic evidence first. AI where it helps.

Direct HTTP, rendered-browser capture, archives, public search, legal extraction and authority checks work together. AI can help resolve brands and structure public evidence, but the platform is designed to remain useful when an AI provider is unavailable and does not use AI as proof of regulatory status.

DNS / RDAPHTTP / redirectsRendered browserPublic archivesTLSLegal extractionAuthority sourcesSearch locatorsNetwork fingerprintsProvider trafficIncremental rescansEvidence cache
Try it on something you already know

Send me a gambling domain.

Send a gambling domain and I’ll run it through Spilfri Intelligence and send the results back. Regulators and organisations can also start with an existing blocking list.

For regulators and organisations
  • Import of an existing blocking list
  • Network and mirror mapping
  • Authority and licence checks
  • Operator, payment, provider and technical profiling
  • Continuous post-action monitoring and evidence reports
Spilfri Intelligence

Find the domain. Understand what sits behind it. Keep watching what appears next.

The goal is not the biggest URL list. It is to make the next investigation faster, more explainable and less dependent on starting from zero.