Fresh domains raise fewer flags in reputation systems, but registrars hand them out in seconds. Understanding the tactics scammers use — and the RDAP trails they leave — changes how you evaluate a suspicious link.
The 30-day window is a practical constraint, not an aesthetic choice. Most reputation scoring systems — web proxies, email security gateways, browser safe-browsing lists — give a domain some benefit of the doubt for the first few weeks of its life. A domain registered yesterday with no traffic history has no reputation, negative or positive. Abuse scoring systems often treat "unknown" more leniently than "bad."
Attackers respond rationally to incentives. They register domains well in advance, let them sit quietly (called "parking"), build minimal legitimate-looking content, and only activate the phishing infrastructure after the domain has aged past the hair-trigger detection window. Waiting 30 days typically means cleaner delivery, fewer CAPTCHA challenges, and lower spam scoring.
Some sophisticated operators run "pre-warming" periods where the parked domain serves innocuous redirects or static content pages to generate real user traffic and click-through signals — making the domain look lived-in before it's weaponised.
Generating lookalike domains is a solved problem. Tools that automate permutation generation are freely available. For any target domain, the attack surface includes:
Character substitution: Replacing visually similar characters. rn → m, l → 1, 0 → o. paypaI.com (capital I) is indistinguishable from paypal.com in many serif fonts. Punycode makes this worse — xn--pypa-rnb.com renders as a Cyrillic version of "paypa" that looks identical in some browsers.
rn
m
l
1
0
o
paypaI.com
paypal.com
xn--pypa-rnb.com
Insertion: Adding a word around the brand. barclays-secure.com, natwest-account-verify.co.uk, amazon-prime-renewal.com. Users often read these as subdomains of the legitimate brand.
barclays-secure.com
natwest-account-verify.co.uk
amazon-prime-renewal.com
TLD swap: The same SLD on a different TLD. amazon.co, gov.uk-refund.org, hmrc.info.
amazon.co
gov.uk-refund.org
hmrc.info
Combosquatting: Appending a service-related word. appleidsupport.com, netflixbillingerror.com, lloydsbankonline.com.
appleidsupport.com
netflixbillingerror.com
lloydsbankonline.com
The Registration Data Access Protocol replaced WHOIS for most major registrars. It returns structured JSON rather than free-text output and provides the key fields you need to assess domain risk:
clientHold
pendingDelete
A parked domain serving a "coming soon" page or a default registrar placeholder looks very different to a reputation system than a domain with no DNS records at all. Sophisticated operators:
The switch is fast — A record TTLs can be set to 60 seconds. By the time abuse reports propagate and blocklists update, the campaign may already be over.
Domain age is a single signal, not a verdict. A 3-day-old domain is not automatically malicious, and a 10-year-old domain is not automatically safe (account takeover is real). But in context:
The combination of registration age, registrar identity, status flags, and the specific string of the domain gives you enough context to make a fast, confident call on most suspicious links.