Detection Method: Whois

Whois analysis retrieves and examines domain registration information from global Whois databases to spot suspicious or recently created domains that could indicate phishing attempts. This method helps you understand key domain details like the age, ownership, and registration patterns, which can be red flags for malicious activity.
Whois analysis can detect:
  • Newly registered domains that might have been set up just for phishing campaigns
  • Domains with suspicious registration patterns or incomplete Whois records
  • Mismatched registration details that don’t align with the claimed organization
  • Domains registered via privacy services to conceal true ownership
  • Domains with upcoming expiration dates, which could indicate temporary use
For example, established organizations often use domains that have been registered for long periods. So, if you get an email from a financial institution using a domain that was registered only a few days ago, that’s a huge red flag.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Spam: Fake photo share
4d ago
Oct 2nd, 2026
Sublime Security
Evasion: Credential phishing with newly registered domain redirecting to Wikipedia
5d ago
Oct 1st, 2026
Sublime Security
Service abuse: Self-service platform redirecting to newly registered suspicious domain
5d ago
Oct 1st, 2026
Sublime Security
Link: Romance/Sexual Language With Suspicious Link
7d ago
Sep 29th, 2026
Sublime Security
Link: Newly registered domain in reference lure
7d ago
Sep 29th, 2026
Sublime Security
Attachment: ICS calendar with suspicious link Leading to minimal JS landing page
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS file with credential theft indicators
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS voicemail lure with suspicious link
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Embedded MSG file with payment lure and newly registered domain
11d ago
Sep 25th, 2026
Sublime Security
Link: Newly registered suspicious domain with single-character HTML filename
11d ago
Sep 25th, 2026
Sublime Security
Brand impersonation: SharePoint PDF attachment with credential theft language
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: DocuSign impersonation via PDF linking to new domain
13d ago
Sep 23rd, 2026
Sublime Security
Suspicious newly registered reply-to domain with engaging financial or urgent language
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: Stripe notification
13d ago
Sep 23rd, 2026
Sublime Security
Credential phishing: Fake security alert from newly registered domain
19d ago
Sep 17th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
21d ago
Sep 15th, 2026
Sublime Security
Link: Fake video link from newly registered domain
28d ago
Sep 8th, 2026
Sublime Security
BEC: Wealth management lure from newly registered domain
28d ago
Sep 8th, 2026
Sublime Security
Service abuse: Zoom Clips with suspicious reply-to address or links
1mo ago
Sep 1st, 2026
Sublime Security