Skip to main content
Threat IntelligenceUpdated September 3, 2026

Domain Intelligence

Domain intelligence is the body of evidence about a domain name: when and where it was registered, who operates its nameservers, what it has resolved to over time, what certificates it has carried, which sources list it and for what activity. It is the domain-side counterpart of IP intelligence and the more durable of the two, because names persist while addresses rotate.

A domain is a decision someone made. Somebody chose the name, paid a registrar, picked nameservers and pointed records at hosting. Each of those decisions leaves a trace with a date, and the traces together describe the domain’s life: born last Tuesday on a cheap registrar with privacy protection and a nameserver used by three phishing kits is a very different biography from registered in 2009 with the same corporate nameservers throughout.

Domain intelligence versus IP intelligence: they answer different questions and are strongest together. An address describes where something is hosted right now, and a busy address hosts thousands of unrelated things; a domain describes what an actor built and keeps across hosting changes. Investigations usually start from whichever one appeared in the alert and pivot to the other.

The signals that matter most are age, registration pattern and resolution history. Very new domains are disproportionately malicious; domains registered in batches with identical settings are campaigns; domains whose history includes known-bad addresses carry that history forward.

Example

A domain in a phishing e-mail was registered 31 hours earlier through a reseller with WHOIS privacy, uses nameservers shared with 60 other domains registered the same day, and resolved to an address listed for phishing within its first hour. No source lists the domain yet; the intelligence around it is already conclusive.

In isMalicious

The domain lookup at /threat-intel/domain and every domain report assemble this evidence: WHOIS and registration age, nameservers, DNS history, certificates, hosting and source listings, streamed as each arrives so the verdict does not wait for the slowest lookup.

Frequently Asked Questions

What is Domain Intelligence?

Domain intelligence is the body of evidence about a domain name: when and where it was registered, who operates its nameservers, what it has resolved to over time, what certificates it has carried, which sources list it and for what activity. It is the domain-side counterpart of IP intelligence and the more durable of the two, because names persist while addresses rotate.

How is Domain Intelligence related to Domain Reputation?

Domain Intelligence and Domain Reputation are both key concepts in threat intelligence. Domain reputation is a classification of a domain based on its history of malicious activity, registration patterns, and content. Factors include age, registrar, phishing/malware associations, WHOIS data, and appearance on threat feeds.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary