4 hours ago · Tech · hide · 0 comments

The single best signal for identifying a phishing domain is the domain registration date, and yet domain registrars still limit access to such data. For certificates, we have Certificate Transparency Logs where every issued TLS certificate is publicly visible within seconds of issuance. For domains, we used to use WHOIS protocol, which returned plaintext data: It was pretty hard to deal with, because every domain zone used its own format that was hard to parse. In the last five years, a new RDAP protocol has grown in popularity. Instead of plaintext, it now outputs JSON data. It became a mandatory protocol in 2025 and more than 1440 TLDs (domain zones) support it now. Despite the new protocol, the problem persists - registrars are still rate limiting access.[......]

No comments yet. Log in to reply on the Fediverse. Comments will appear here.