Detection Method: Whois

Whois analysis retrieves and examines domain registration information from global Whois databases to spot suspicious or recently created domains that could indicate phishing attempts. This method helps you understand key domain details like the age, ownership, and registration patterns, which can be red flags for malicious activity.
Whois analysis can detect:
  • Newly registered domains that might have been set up just for phishing campaigns
  • Domains with suspicious registration patterns or incomplete Whois records
  • Mismatched registration details that don’t align with the claimed organization
  • Domains registered via privacy services to conceal true ownership
  • Domains with upcoming expiration dates, which could indicate temporary use
For example, established organizations often use domains that have been registered for long periods. So, if you get an email from a financial institution using a domain that was registered only a few days ago, that’s a huge red flag.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
2d ago
Aug 25th, 2026
Sublime Security
Attachment: ICS calendar invite with financial lure and suspicious link
5d ago
Aug 22nd, 2026
Sublime Security
Link: Document-themed link to newly registered domain
9d ago
Aug 18th, 2026
Sublime Security
Spam: Cold outreach from Cloudflare-hosted newly registered domain
10d ago
Aug 17th, 2026
Sublime Security
New link domain (<=10d) from untrusted sender
17d ago
Aug 10th, 2026
Sublime Security
Spam: Fake photo share
21d ago
Aug 6th, 2026
Sublime Security
Spam: Large financial amount mention from newly registered sender domain
24d ago
Aug 3rd, 2026
Sublime Security
Service abuse: Adobe message from newly registered domain
27d ago
Jul 31st, 2026
Sublime Security
Impersonation: Suspected supplier impersonation with suspicious content
1mo ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Microsoft fake sign-in alert
1mo ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Anthropic/Claude with newly registered domain
1mo ago
Jul 24th, 2026
Sublime Security
Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain
1mo ago
Jul 24th, 2026
Sublime Security
Service abuse: Coursera callback scam
1mo ago
Jul 21st, 2026
Sublime Security
Service abuse: Zoom Clips with unregistered reply-to domain
1mo ago
Jul 17th, 2026
Sublime Security
Service abuse: Microsoft Forms Pro with suspicious links or QR codes
1mo ago
Jul 14th, 2026
Sublime Security
BEC: Financial fraud from newly registered sender domain
2mo ago
Jun 25th, 2026
Sublime Security
Brand Impersonation: OpenAI with ChatGPT Ads lure
2mo ago
Jun 24th, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
2mo ago
Jun 18th, 2026
Sublime Security
Link: Romance/Sexual Language With Suspicious Link
2mo ago
Jun 17th, 2026
Sublime Security
Link: Observed URL pattern with specific domain registrar
2mo ago
Jun 12th, 2026
Sublime Security