Why young domains matter
Phishing, fake shops and impersonation campaigns frequently use domains registered shortly before use, because older abused domains are blocked and reported. Security teams therefore treat a very recent creation date as a risk signal, especially when combined with brand-like names or urgent payment requests.
Measuring age correctly
Use the registration (creation) event from RDAP rather than the last-changed date. Compare it with the certificate transparency log, which shows when TLS certificates were first issued for the name, and with passive DNS where available. A domain can be old but recently re-registered; a sudden change of registrar, nameservers and content suggests a new operator.
- Use the creation event, not last-updated.
- Check for re-registration after expiry.
- Compare first certificate issuance.
- Combine with name similarity and content evidence.
Avoiding false positives
Start-ups, campaigns and events legitimately register new domains. Report findings as ‘registered on this date’ rather than ‘suspicious because new’. URL Forensics never turns missing or recent data into a safety verdict.
