Skip to content

Newly-Activated Domain

It indicates that the domain has recently become active for the first time, either by starting to resolve in DNS or by responding to network probes. This behavior is common in newly registered or reactivated malicious domains, which threat actors often deploy shortly before launching attacks.

Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Newly-Activated Domain' mean in DNS-layer or SOC analysis?

It indicates that the domain has recently become active for the first time, either by starting to resolve in DNS or by responding to network probes. This behavior is common in newly registered or reactivated malicious domains, which threat actors often deploy shortly before launching attacks.

Why it matters02

Why is the activation timing of a domain important for analysts?

Because newly activated domains often precede phishing, malware distribution, or command-and-control operations. Monitoring domain activation recency helps analysts detect emerging threats before they gain reputation or traffic volume.

How analysts use it03

Can legitimate domains also appear as newly activated?

Yes, legitimate organizations may launch new services or migrate infrastructure, causing domains to appear newly active. Analysts should cross-check WHOIS registration time, SSL issuance date, and reputation data to distinguish between benign and malicious activations.

Often paired with:alert_only
Evidence shape

What Newly-Activated Domain looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "newly_up_domain",
  "name": "Newly-Activated Domain",
  "group": "dns_history",
  "subgroup": "domain_lifecycle",
  "direction": "malicious",
  "evidence": {
    "first_seen_days_ago": 4,
    "activation_event": "newly_resolved",
    "dormancy_days_before": 0,
    "registered_days_ago": 7
  }
}
See in API reference
Siblings

Peers in Domain Lifecycle

4 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Newly-Activated Subdomain

It indicates that one or more subdomains under a given domain have recently become active or resolvable in DNS. This pat

Malicious
Reputation Hijacked Domain

It refers to a domain that previously maintained a clean reputation and was considered safe, but has later been repurpos

MaliciousCore
Newly-Associated IP

It indicates that the domain has started resolving to a new IP address for the first time. This event often marks a chan

Malicious
Subdomain-Only Active Domain

It refers to domains where only subdomains are active and the apex (root) domain does not serve any content or DNS respo

Malicious
In the wild

See Newly-Activated Domain fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Newly-Activated Domain. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.