Skip to content

Stable NS Usage Long Term

It shows that the domain has maintained the same nameserver configuration without fluctuations, suggesting predictable and well-managed DNS infrastructure.

Also surfaces as:
Stable NS Usage Consistent ProviderStable NS Usage Since Creation
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Stable NS Usage' indicate?

It shows that the domain has maintained the same nameserver configuration without fluctuations, suggesting predictable and well-managed DNS infrastructure.

Why it matters02

Why is long-term NS stability relevant for SOC and CTI teams?

Stable NS patterns often correlate with legitimate operational behavior. Threat actors typically rotate NS providers aggressively, so stability reduces suspicion in triage.

How analysts use it03

How should analysts use this signal?

Treat stable NS usage as a low-risk contextual indicator—use it to support safe classification when other signals are inconclusive.

Evidence shape

What Stable NS Usage Long Term looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "stable_ns_usage",
  "name": "Stable NS Usage Long Term",
  "group": "dns_history",
  "subgroup": "dns_records_mx_ns",
  "direction": "safe",
  "evidence": {
    "ns_provider": "cloudflare.com",
    "ns_provider_tier": "paid_public",
    "ns_stability_days": 412,
    "mx_provider": "google.com",
    "mx_provider_tier": "paid_mail"
  }
}
See in API reference
Siblings

Peers in DNS Records (MX/NS)

8 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Stable MX Usage Long Term

It shows the domain has been using the same mail exchange servers for an extended period, reflecting stable and predicta

Safe
Paid Public NS Usage Premium Provider

It indicates that the domain is backed by a paid, reputable DNS provider rather than free or disposable nameservers. Thi

Safe
Self-Managed Name Server Detected

It indicates that the domain operates using its own name server infrastructure rather than a reputable third-party DNS p

Malicious
Double-Flux Behavior Detected

It indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-F

MaliciousCore
Show 4 more in DNS Records (MX/NS)
In the wild

See Stable NS Usage Long Term fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Stable NS Usage Long Term. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.