Why infrastructure changes matter
A domain's registrar, nameservers, mail provider and hosting can all change over time, sometimes as routine maintenance and sometimes because control of the domain has moved to a different party, legitimately or otherwise. A sudden change shortly before a domain is used in a fraud report, or a change affecting a domain already known to be sensitive such as a supplier's or a brand's own domain, is a meaningful event worth investigating even though change itself is not inherently suspicious.
What to compare
Compare successive RDAP records for the same domain: registrar, status codes, nameservers and the last-changed event timestamp. A transfer to a new registrar combined with new nameservers in a short window is more notable than either change alone. On the DNS side, compare NS records for a nameserver migration, MX records for a change of mail provider, and A/AAAA records for a change of hosting, each timestamped at the point of collection.
Certificate transparency logs add a further comparison point: a sudden new certificate issued for a domain shortly after other infrastructure changes can mark when a new operator actually brought the site online, which is often more informative than the DNS change date alone, since DNS can be changed well before new content is published.
Detecting change without a historical feed
A single point-in-time public DNS or RDAP lookup only shows the current state; it cannot by itself show you what changed or when. Detecting change requires either comparing against a previously saved snapshot taken by the same investigator, or relying on a service that performs that comparison for you. Treat any gap between observations as a period during which multiple changes could have occurred without being individually captured.
Using ongoing monitoring
For domains that matter to an organisation on an ongoing basis, such as its own domains, its suppliers' domains or previously flagged lookalikes, periodic automated comparison is more reliable than ad hoc manual checks. For Unlimited subscribers, domain monitoring performs weekly WHOIS diffs on tracked domains and checks for newly registered lookalikes, surfacing registrar, nameserver and registrant-visible changes for review shortly after they occur rather than only when someone happens to look again.
- Save a timestamped snapshot of RDAP and DNS data for domains you track.
- Compare registrar, status, nameservers and last-changed events over time.
- Compare MX and A/AAAA records to detect mail or hosting provider changes.
- Cross-check certificate transparency for a new issuance around the same time.
- Use weekly monitoring diffs for domains that need ongoing attention.
