Guide
Written By Usama Shabbir, WhoisFreaks Team Published: December 26, 2024, Last Updated: August 24, 2026
Not necessarily, and the assumption that they are is what attackers exploit.
Newly registered domains carry obvious risk and most security teams already block them. Palo Alto Networks defines a newly registered domain as one registered or transferred within the last 32 days, and Unit 42's analysis of 1,530 top-level domains found more than 70% were malicious, suspicious, or not safe for work.
The number that matters more is the one nobody blocks on. In Unit 42's study of strategically aged domains, 3.8% showed malicious behaviour, which the researchers state is more than three times higher than the 1.27% rate among newly registered domains. Domains that have sat quietly for years are more dangerous than domains registered last week, precisely because age reads as trust.
This chapter covers how attackers use both ends of the age range, what each signal is actually worth, and where domain age stops being useful on its own.
A newly registered domain is one registered, or transferred to a new owner, within roughly the last month. Palo Alto Networks uses 32 days as the cutoff, based on its finding that this is the window in which new domains are most likely to be detected as malicious. We use 30 days window for NRDs.
The risk is concentrated because registration is cheap and disposable. Attackers register in bulk, use a domain for hours or days, and abandon it before most detection systems catch up. Common uses:
Most malicious new domains are short-lived, which inverts the usual detection trade-off. A system that flags a domain accurately three days after registration has already missed the campaign.
That is why we recommends blocking the entire newly registered category for 30 days rather than attempting to sort good from bad within it. The false positives are real: a customer launching a genuinely new product will be blocked. The recommendation stands anyway, because the base rate is so unfavourable that per-domain judgment costs more than it saves.
If blanket blocking is too aggressive for your environment, the fallback is to alert rather than block, which preserves visibility without breaking legitimate access.
To protect against potential threats from WhoisFreaks' Newly Registered Domains, you can take the following steps to analyze a domain like 'amazon.com':

amazon. Just for your information, there are 57 Generic Top-Level Domains (gTLDs) and 10 Country Code Top-Level Domains (ccTLDs) newly registered on 2024-03-11 containing amazon.An expired domain hands an attacker something a new registration cannot buy: history. Search engines, reputation systems, and email filters all treat age as a proxy for legitimacy, and a domain that has existed for a decade inherits that assumption regardless of who controls it now.
The same logic drives a related and more serious pattern. Rather than buying an expired domain, an attacker registers one and simply waits. Unit 42 documented that the command-and-control domain behind the SolarWinds compromise was registered in 2018 and sat dormant for two years before its traffic increased roughly 165 times as the campaign activated. Its detection system captured around 26,000 such domains per day, and they show a characteristic signature: long dormancy followed by a traffic jump averaging more than ten times in a single day.
Expired domains can lead to vulnerabilities such as
To mitigate the threats posed by expired domains, organizations should implement a comprehensive domain management strategy. This includes;
Age is one signal among several, and its meaning changes across the range. This table summarises what each band actually tells you, based on the Unit 42 malicious rates cited above.
| Domain age | Malicious rate | What it means | Reasonable action |
|---|---|---|---|
| Under 30 days | Over 70% malicious, suspicious, or NSFW | The category itself is the signal. Per-domain judgment is slower than the attack. | Block the category, or alert if blocking is too disruptive |
| Dormant, then sudden traffic spike | 3.8% malicious, over three times the NRD rate | The strongest single indicator in the set. Long quiet followed by a jump of ten times or more in a day. | Investigate as a priority, regardless of age |
| Recently expired and re-registered | Not separately measured | Inherits reputation it did not earn. Check whether ownership changed at expiry. | Check registration history before trusting |
| Established and consistently active | 0.07% for Alexa Top 1,000 | Age plus stable traffic is a genuine trust signal. | Normal handling |

The row that matters are the second one. It is the only band where age alone actively misleads you, and it is where the most capable attackers operate.
Recently expired and re-registered. The distinction between expired and fully dropped matters here, and is covered in dropped vs expired domains
Three limits are worth stating plainly, because a screening programme built on age alone will miss things in predictable ways.
For the raw feeds behind this work, see newly registered domains and the expired domains database. For a fuller treatment of accessing and using NRD data, see how to access and use newly registered domains.