The first question in most domain investigations
Fraudulent domains are used in cybercrime, email fraud and online scams. In most cases the first practical question is simple: when was this domain registered? The creation date recorded in WHOIS or RDAP tells an investigator when the current registration event began, and that single date often reshapes the whole case.
A supplier domain that was registered years ago and a near-identical domain registered three days before a fraudulent invoice arrived tell very different stories. The creation date lets an investigator place the domain on the timeline of the incident: before the first contact, during the negotiation, or immediately before the payment request.
What the creation date can show
Timeline anchoring: a domain created shortly before a phishing campaign or invoice change is a strong investigative lead. Lookalike detection: impersonation domains are frequently registered close to the time they are used. Linking cases: several domains created on the same day, through the same registrar and with the same nameservers can point to a common campaign and justify further enquiries.
The date also helps decide urgency. A recently created domain that is already sending mail or hosting a payment page may still be early in its abuse lifecycle, so prompt abuse reports to the registrar and host can prevent further victims.
What the creation date cannot show
A creation date is not a verdict. New legitimate businesses register domains every day, and an old domain can be expired, re-registered or compromised. Some registries reset the date when a domain is deleted and registered again; others expose only limited data. Treat the date as evidence of a registration event, then corroborate it with DNS, hosting, certificate and email evidence.
Always record the source (registry RDAP, registrar RDAP or port-43 WHOIS), the exact value with its time zone, and the collection time. URL Forensics records these alongside the raw response and seals the report with a SHA-256 hash.
- Record creation, last-changed and expiration events separately.
- Compare the creation date with the first fraudulent contact or payment request.
- Check certificate transparency for the first certificate issued to the name.
- Look for sibling domains created on the same day with the same registrar or nameservers.
- Never treat a recent date alone as proof of fraud.
