A domain can look legitimate while being used for phishing, malware, scams, brand impersonation, or other malicious activity. That makes domain analysis an important part of identifying potential threats.
There is no single test that can determine whether every domain is malicious. Instead, look at several signals together, including the domain name, registration data, DNS and hosting infrastructure, reputation, TLS certificate, and website behavior.
If a domain looks suspicious, avoid visiting it directly. Use reputation services or automated scanning tools to investigate it safely.
Start by examining the domain itself. Suspicious domains often show characteristics associated with impersonation or phishing, such as:
A domain’s extension should not be treated as a verdict by itself. The important question is whether multiple signals point toward the same risk.
Registration and DNS data can provide useful context about a domain’s infrastructure.
1. Check domain registration data
For current generic top-level domain (gTLD) registration information, use RDAP rather than relying on the older WHOIS workflow. ICANN made RDAP the definitive source for gTLD registration data from January 28, 2025.
Look for information such as:
A very recently created domain is worth investigating further, especially when it also contains a brand name or appears alongside other suspicious indicators.
2. Check DNS and hosting information
DNS records can help connect a domain to its underlying infrastructure. Useful records and relationships to examine include:
The goal isn’t to label a domain malicious based on one IP address or hosting provider. Instead, look for relationships between the domain and other infrastructure associated with suspicious activity.
Tools such as VirusTotal can bring together domain creation information, DNS records, certificates, registrar data, scanner results, and reputation information in one place.
No. HTTPS does not mean a website is legitimate.
A valid TLS certificate helps establish that the connection is encrypted and that the certificate is associated with control of the domain. It does not establish that the website itself is trustworthy.
This distinction is important because malicious websites can also use HTTPS.
Therefore, don’t treat the presence of a padlock or a valid certificate as evidence that a domain is safe. Consider the certificate alongside the domain, infrastructure, reputation, and website behavior.
Reputation services can show whether a domain or URL has already been associated with known threats.
Useful tools include:
| Tool | What it can help you check |
| Google Safe Browsing | Whether a URL is associated with known unsafe resources |
| VirusTotal | Reputation, security detections, DNS, registration and related context |
| urlscan.io | Website behavior, requests, infrastructure, screenshots and page content |
| ICANN RDAP Lookup | Available domain registration information |
Google Safe Browsing checks URLs against continually updated lists of unsafe web resources, including phishing and malware-related sites. However, Google notes that these lists cannot identify every risky site and can sometimes produce false positives or miss threats.
Similarly, a clean result from a reputation service should not automatically be interpreted as proof that a domain is safe. A newly created malicious domain may simply not have accumulated enough reputation data yet.
For potentially dangerous websites, urlscan.io can be useful because it analyzes a URL through an automated browser and records information such as contacted domains and IPs, requested resources, screenshots, DOM content, and other observations.
Security note: Before submitting an internal, private, or sensitive URL to a public scanning service, check your organization’s security and privacy policies.
Website content can provide another important layer of evidence. Common warning signs include:
Don’t manually browse a suspicious website just to inspect its content. If the URL could be malicious, use an automated scanner or security sandbox where appropriate.
If multiple indicators suggest that a domain may be malicious:
The key is to correlate evidence rather than making a decision based on one characteristic.
Checking one suspicious domain manually is relatively straightforward. Monitoring large numbers of domains is more difficult because useful evidence can be spread across registration data, DNS, hosting infrastructure, certificates, reputation feeds, website content, and relationships between domains and IP addresses.
Effective domain threat detection therefore relies on correlating multiple signals continuously, rather than waiting for a domain to appear on a blocklist after an attack is already underway.
For organizations monitoring their external attack surface, this can also include identifying newly created domains, lookalike infrastructure, phishing pages, and other malicious assets before they become active threats.
Related Read: How to Find Malicious Domains
A domain should not be considered safe simply because it has HTTPS, uses a familiar domain extension, or has not yet appeared on a reputation list.
A more reliable domain security check combines domain characteristics, registration data, DNS and infrastructure, reputation, certificates, and website behavior. The more independent signals that point in the same direction, the stronger the basis for investigation or action.
Need to Monitor Malicious Domains at Scale?
Bfore’s PreCrime™ Defense helps organizations identify malicious infrastructure, phishing domains, impersonation sites, and other external threats before they develop into active attacks.