Skip to content

Paid Public NS Usage Premium Provider

It indicates that the domain is backed by a paid, reputable DNS provider rather than free or disposable nameservers. This often aligns with legitimate infrastructure investment.

Also surfaces as:
Paid Public NS Usage Enterprise GradePaid Public NS Usage Long TermPaid Public NS Usage
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Paid Public NS Usage' imply?

It indicates that the domain is backed by a paid, reputable DNS provider rather than free or disposable nameservers. This often aligns with legitimate infrastructure investment.

Why it matters02

Why is paid NS usage considered a safe supporting indicator?

Threat actors typically avoid premium DNS services due to cost and traceability. Long-term or enterprise-grade paid NS usage reduces the likelihood of throwaway or malicious operations.

How analysts use it03

How should SOC and CTI analysts use this signal?

Use it as a confidence-boosting safe context indicator—especially when other signals are neutral or borderline. It helps push the verdict toward low-risk unless contradictory malicious evidence exists.

Evidence shape

What Paid Public NS Usage Premium Provider looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "paid_public_ns_usage",
  "name": "Paid Public NS Usage Premium Provider",
  "group": "dns_history",
  "subgroup": "dns_records_mx_ns",
  "direction": "safe",
  "evidence": {
    "ns_provider": "cloudflare.com",
    "ns_provider_tier": "paid_public",
    "ns_stability_days": 412,
    "mx_provider": "google.com",
    "mx_provider_tier": "paid_mail"
  }
}
See in API reference
Siblings

Peers in DNS Records (MX/NS)

8 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Paid Mail Service Detected

It indicates that the domain uses a paid or premium email service provider. This is typically associated with legitimate

Safe
Self-Managed Name Server Detected

It indicates that the domain operates using its own name server infrastructure rather than a reputable third-party DNS p

Malicious
Stable NS Usage Long Term

It shows that the domain has maintained the same nameserver configuration without fluctuations, suggesting predictable a

Safe
Double-Flux Behavior Detected

It indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-F

MaliciousCore
Show 4 more in DNS Records (MX/NS)
In the wild

See Paid Public NS Usage Premium Provider fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Paid Public NS Usage Premium Provider. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.