A domain can be legitimate for years. It can belong to a trusted service, have a clean reputation, and appear in security databases as safe.
And then, one day, everything changes.
A legitimate domain can be compromised, redirected, or abused as part of a phishing campaign. A previously trusted website can become the delivery point for a malicious attack, while its historical reputation remains unchanged.
The same challenge exists with newly registered domains. When a phishing campaign appears for the first time, its domains may not yet appear on blocklists or threat intelligence feeds. There is simply no history to rely on.
This creates a fundamental challenge for traditional security approaches. Reputation and historical data are valuable, but they can only tell us what is known about a domain. They cannot always tell us what that domain is doing right now.
Modern phishing detection needs to look beyond whether a domain is known or unknown. It needs to analyze multiple signals, understand context, identify suspicious behavior, and recognize when something that once appeared legitimate has suddenly changed.
Because attackers don’t always use domains that were created to be malicious.
Sometimes, they use domains that were perfectly legitimate until the moment they became part of an attack.
The question isn’t whether a domain was legitimate yesterday. The question is whether it is safe today.