---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Verify expected results for Reverse Whois

# Verify expected results for Reverse Whois {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Enrichment results are displayed on the ReverseWhois Domains
tab at the bottom of the security incident record. Locate the lookup results to verify that
the lookup ran successfully.

## Before you begin

Role required: sn_si.analyst

## Procedure

1. If not already open, navigate to Security IncidentsIncidentsShow All Incidents and locate the security incident you're working with.  
   After the application is configured and you have attached an observable, the flow launches automatically. The work notes on the security incident record display the execution and completion status of the lookup.
2. If you can't verify that the lookup ran successfully, review the work notes for more information on how to proceed.
3. Navigate to the bottom of the security incident and select Show All Related Lists related link.  
   Enrichment results are displayed on the ReverseWhois Domains tab. The active domains for this observable are displayed in the Domain column.
4. Select the blue information icon next to an item then select Open record in the dialog box that is displayed.  
   The record is displayed with enrichment details, including the raw data.
5. Navigate back to the security incident, and with the ReverseWhois Domains tab selected, click an observable in the Observable column to open a record.  
   The child observables are displayed on the Child Observables tab on the Observable record. The child observables are generated only if the Reverse Whois application has returned domains.
{#verify-expected-rslts-rvrsewhois__steps_j2d_pht_ycb} If the lookup does not successfully complete, verify that the search terms you entered are supported by the integration. Review the work notes for more information.

## What to do next

For more enrichment data on the domain lookup results, you can run the Whois integration to perform enrichment lookups on the child observables returned by the Reverse Whois integration. This enrichment data on the child observables includes information on registration date, name of registrar, and country of origin.
**Previous topic:** [Initiate the lookup for Reverse Whois](https://servicenow-prod.fluidtopics.net/bSFwltLXq1vy4yvVDgcBOg "Initiate domain lookups using search terms in observables that you manually attach to a security incident record.")  
**Next topic:** [(Optional) Run enrichment lookup and verify expected results for Whois](https://servicenow-prod.fluidtopics.net/mmrWjBmOG8L8p13TsCqNrg "Run the Whois integration to perform enrichment lookups on the domains returned from the Reverse Whois integration.")

*[\>]: and then


