Published · 6d agoProduct2 min read
Domain Age Stopped Being A Trust Signal
Security tools treat an old registration date as a proxy for trust. The supplied research shows why that is cheap to fake, though it does not contain the $7M spend the rail card advertised.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Anyone who re-registers an expired domain implicitly inherits the residual trust associated with the domain's prior use, which adversaries use to exploit ownership changes.
- Over a six-year period the Astrolavos Lab study identified 27,758 domains from public blacklists that had expired and were then maliciously re-registered.
- The same study identified 238,279 domains resolved by malware that had expired and were then maliciously re-registered.
- Using its Alembic algorithm the study found an expired APT domain that could be used to revive existing infections.
- Domain age is a simple calculation of the time between a domain's initial registration and the current date.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
A rail card sent you here with a single figure: $7M spent buying expired domains. That number does not appear in the supplied research, so treat it as unverified; what the research does explain is why anyone would spend the money at all.
Domain age is a plain calculation, the time between a domain's first registration and today [5]. Firewall and web security vendors promote it as a filtering shortcut, blocking or isolating newly registered domains on the theory that age signals legitimacy [6]. Palo Alto Networks counts a domain as new for only 32 days after registration or a change of ownership, and notes that most enterprise systems will not flag new domains at all [10][11]. Anything older gets waved through.
The flaw is that age no longer describes who controls a name. A registration date is preserved when a domain is reused, reassigned, or sold, and only resets when the domain expires and is re-registered [7]. So an attacker can buy an aged, legitimate-sounding domain and inherit its history: airnigeria.com, registered in 2003, was listed on GoDaddy for $65 at the time of Skyhigh's writing [8]. Skyhigh's own verdict is that domain age is an extremely inaccurate measure of when a destination actually became active [12].
Georgia Tech's Astrolavos Lab put numbers on the abuse. Across six years it identified 27,758 blacklisted domains and 238,279 domains that malware still tried to resolve, all of which had expired and were then maliciously re-registered by someone inheriting their residual trust [1][2][3]. One was an expired APT domain that could be used to revive existing infections [4].
The economics run on supply: over 40,000 new .com and .net domains are registered every day, according to Verisign, and every lapsed name becomes inventory with a reputation already attached [9]. Until filters weigh current control and reputation over a creation date, the purchase is rational.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Anyone who re-registers an expired domain implicitly inherits the residual trust associated with the domain's prior use, which adversaries use to exploit ownership changes.
- [2]
Over a six-year period the Astrolavos Lab study identified 27,758 domains from public blacklists that had expired and were then maliciously re-registered.
- [3]
The same study identified 238,279 domains resolved by malware that had expired and were then maliciously re-registered.
- [4]
Using its Alembic algorithm the study found an expired APT domain that could be used to revive existing infections.
- [5]
Domain age is a simple calculation of the time between a domain's initial registration and the current date.
- [6]
Firewall and web security vendors promote domain age as a filtering parameter, on the idea that newly registered domains should be blocked, isolated, or treated with high suspicion.
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- astrolavos.gatech.edu6d ago28 Registrations Later—Measuring the Exploitation of Residual Trust in Domains — Astrolavos Lab
- paloaltonetworks.com6d agoWhat Are Malicious Newly Registered Domains? - Palo Alto Networks
- skyhighsecurity.com6d agoDomain Age as Internet Filter Firewall - Skyhigh Security



