New Domain Protection: Stopping Phishing Sites Minutes After They Are Registered
A phishing domain registered four minutes ago is unknown to every blocklist on the planet. That is precisely why attackers use fresh domains. Our new domain protection reads the one signal that exists from second one: the registration date.
Ask yourself a simple question: how does a reputation service know that a website is dangerous? Someone has to see it first, report it, and somebody has to review that report. That takes time. Attackers know this, so they keep buying brand new domains for every campaign and throw them away a few days later.
For the first hours of a phishing campaign, the domain has no reputation at all. Not bad, not good, just unknown. And unknown is usually treated as allowed.
What attackers are doing right now
Look at the big phishing operations taken down in the past year and you see the same pattern again and again: lots of cheap, short lived domains.
- In September 2025 Microsoft's Digital Crimes Unit, together with Cloudflare, seized 338 websites belonging to RaccoonO365, a phishing service sold by subscription whose kits had stolen at least 5,000 Microsoft credentials from 94 countries.
- In March 2026 Microsoft, Europol and industry partners disrupted Tycoon 2FA, the kit behind roughly 62 percent of the phishing attempts Microsoft blocked by mid 2025. Microsoft seized 330 active domains hosting its control panels and fake login pages.
- In May 2025 Microsoft and international partners took action against roughly 2,300 domains used by the Lumma Stealer malware, which was often spread through fake "verify you are human" pages.
Hundreds or thousands of domains per operation. Each one gets a short life, and each one starts out with a perfectly clean record. A list based defence is always one step behind that.
The signal that exists from second one
Every domain has a birthday. When someone registers it, the registry records the date. That record exists the moment the domain exists, long before any security vendor has looked at it.
So we read it. When someone in your organisation opens a website, Cybereinforce checks how old the domain is, straight from the registry where that information is published. If the domain was registered within the last 12 months, the browser blocks it.
Yes, that is stricter than the industry habit of looking only at the last 30 days. We chose it on purpose. Phishing domains are sometimes registered weeks in advance and left to "age" so they slip past 30 day filters. A full year closes that trick, and the websites your business actually relies on are almost always much older than that.
Built to work everywhere
- More than 1,100 top level domains are covered, including 146 country code domains.
- Where a registry does not publish a registration date, we look at the public certificate history of the domain. A site whose first certificate is very recent is treated as new.
- Shared hosting platforms are handled separately, because the age of a big hosting service says nothing about the page someone just put on it. Those pages are covered by our other detections.
- If your own team launches a new website, an administrator can allow it with one entry.
You can check which domains are covered on our Threat Intelligence page.
How you would be protected with Cybereinforce
- A phishing site registered this morning is blocked on the first click, before anyone anywhere has reported it.
- Services like RaccoonO365 and Tycoon 2FA lose their head start. Rotating to fresh domains does not help when fresh domains are exactly what gets blocked.
- Fake "verify you are human" pages on brand new domains never load, so the user is never asked to paste anything.
- Every block shows its reason, for example "domain registered 3 days ago", so your SOC knows exactly why it happened.
- Microsoft On the Issues: Microsoft seizes 338 websites to disrupt rapidly growing RaccoonO365 phishing service (September 2025)
- Microsoft On the Issues: How a global coalition disrupted Tycoon 2FA (March 2026)
- Microsoft On the Issues: Microsoft leads global action against favored cybercrime tool (May 2025)