Domain Intelligence
Domain intelligence is the body of evidence about a domain name: when and where it was registered, who operates its nameservers, what it has resolved to over time, what certificates it has carried, which sources list it and for what activity. It is the domain-side counterpart of IP intelligence and the more durable of the two, because names persist while addresses rotate.
A domain is a decision someone made. Somebody chose the name, paid a registrar, picked nameservers and pointed records at hosting. Each of those decisions leaves a trace with a date, and the traces together describe the domain’s life: born last Tuesday on a cheap registrar with privacy protection and a nameserver used by three phishing kits is a very different biography from registered in 2009 with the same corporate nameservers throughout.
Domain intelligence versus IP intelligence: they answer different questions and are strongest together. An address describes where something is hosted right now, and a busy address hosts thousands of unrelated things; a domain describes what an actor built and keeps across hosting changes. Investigations usually start from whichever one appeared in the alert and pivot to the other.
The signals that matter most are age, registration pattern and resolution history. Very new domains are disproportionately malicious; domains registered in batches with identical settings are campaigns; domains whose history includes known-bad addresses carry that history forward.
Example
A domain in a phishing e-mail was registered 31 hours earlier through a reseller with WHOIS privacy, uses nameservers shared with 60 other domains registered the same day, and resolved to an address listed for phishing within its first hour. No source lists the domain yet; the intelligence around it is already conclusive.
In isMalicious
The domain lookup at /threat-intel/domain and every domain report assemble this evidence: WHOIS and registration age, nameservers, DNS history, certificates, hosting and source listings, streamed as each arrives so the verdict does not wait for the slowest lookup.
Frequently Asked Questions
What is Domain Intelligence?
Domain intelligence is the body of evidence about a domain name: when and where it was registered, who operates its nameservers, what it has resolved to over time, what certificates it has carried, which sources list it and for what activity. It is the domain-side counterpart of IP intelligence and the more durable of the two, because names persist while addresses rotate.
How is Domain Intelligence related to Domain Reputation?
Domain Intelligence and Domain Reputation are both key concepts in threat intelligence. Domain reputation is a classification of a domain based on its history of malicious activity, registration patterns, and content. Factors include age, registrar, phishing/malware associations, WHOIS data, and appearance on threat feeds.
Related Terms
Domain Reputation
Domain reputation is a classification of a domain based on its history of malicious activity, registration patterns, and content. Factors include age, registrar, phishing/malware associations, WHOIS data, and appearance on threat feeds.
WHOIS
WHOIS is a protocol that returns registration information for a domain or IP address — including registrant, registrar, registration and expiration dates, and nameservers. Threat analysts use WHOIS to investigate ownership, identify registration patterns of malicious actors, and find related infrastructure.
DNS History
DNS history is a record of historical DNS resolution data for a domain — including all IP addresses it has ever resolved to, when changes occurred, and what nameservers have been used. It is used in threat investigations to trace infrastructure reuse and identify related malicious domains.
IP Intelligence
IP intelligence is the evidence available about an IP address: the network that announces it, its geography, its classification (datacenter, residential, mobile, VPN, proxy, Tor), the names that have pointed at it, and its record across abuse and threat sources with dates. It describes where something is hosted right now, which is exactly what a firewall or a rate limiter needs to know.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.