Here’s a small test. Which of these are run by the same company?
tumblr.com— a blogging platformwoocommerce.com— e-commerce softwaregravatar.com— profile avatarsjetpack.com— WordPress security and performanceakismet.com— spam filtering
They present as five separate products, with five different brands, five different visual identities, five different audiences. The answer is that all five are operated by Automattic — the company behind WordPress.com. This is publicly documented, which is exactly why it makes a good worked example: you can check every claim here against the public record. The interesting part is that you wouldn’t need the public record to connect them. The infrastructure connects them on its own.
What ties a portfolio together
When one company operates many domains, they reuse decisions — and that reuse is the signal. Across a portfolio you tend to find overlaps in categories like:
- Account-scoped identifiers — the same analytics, tag-manager, or platform-verification tokens embedded across sites, because they map to one billing account.
- Certificate and hostname structure — shared certificate authorities, naming conventions, and subject patterns issued the same way across properties.
- Mail and DNS configuration — the same mail provider setup, the same nameserver choices, the same record layout reflecting one operations team.
- Origin infrastructure — once you resolve past any CDN, the real hosting and network the properties share.
- Content and legal fingerprints — shared copyright holders, terms-of-service entities, and boilerplate that name the operating company directly.
No single one of these is proof. A shared cloud provider or a shared CDN is a coincidence half the internet also shares — we’ve written before about why that trap produces confident, wrong answers. But when account-scoped, operator-specific signals line up across several domains, and they corroborate each other, the portfolio resolves to one operator.
The method, not the magic
The reason Automattic is a good illustration is that the answer is checkable. The reason it’s a useful illustration is that the same method works when the answer isn’t public — when the domains are a threat actor’s infrastructure, a brand-protection target’s grey-market portfolio, or a set of sites an operator would rather keep unlinked. There’s no public “these are all the same company” record for those. The infrastructure overlap is the only record there is.
That’s the shift: instead of asking “is there a document that says these are related,” you ask “do these domains share the operator-specific fingerprints that only a common operator would leave.” Portfolio correlation reads the second question directly.
Correlation with discipline
Two rules keep this honest, and they’re the same two that keep single-domain attribution honest:
- Weight by specificity. An account-scoped identifier that someone deliberately configured counts for a lot. Popular shared infrastructure counts for almost nothing. Get that backwards and every site on a big host falsely clusters into one imaginary operator.
- Require independent corroboration. Never cluster domains on a single signal, and never on a purely infrastructural one. Two properties that merely sit behind the same CDN are not a portfolio; two that share an account identifier and a mail configuration and an origin network are.
Applied with that discipline, correlation is one of the highest-leverage things you can do with domain intelligence — it turns a list of domains into a map of who’s behind them. Applied without it, it’s a machine for inventing conspiracies. The difference is entirely in the weighting.
This example uses a publicly documented ownership structure to illustrate the method. The point is that the same signals resolve portfolios that are not documented anywhere.
Want to trace a portfolio of your own? WhoisGenius correlates domains to shared operators with the per-signal evidence behind every link. Start free with 75 credits.