Skip to main content
1 min read

Why domain age matters (and why it isn't the whole story)

A domain registered last week is a warning sign — but plenty of legitimate businesses are also new. Here's how to weigh it.

TrustDepth Team

What WHOIS tells you

WHOIS is the public record of who registered a domain and when. Most modern registrars hide the registrant name behind a privacy service, but the creation date is nearly always visible. That single date is one of the strongest predictors of scam behavior.

Young domains are disproportionately risky

Scam operations move fast. They register a domain, run a campaign for a few days, get burned, and move on. Studies consistently find that a large majority of phishing and fake-shop domains are under 90 days old when they cause harm.

That's why TrustDepth treats a domain younger than 90 days as a meaningful negative signal — not damning on its own, but enough to pull an otherwise-clean site out of "trusted" territory.

The obvious caveat

Every legitimate business had a first day. A brand-new coffee shop with a two-week-old domain is not a scam. That's why we combine WHOIS with SSL trust, DNS hygiene (SPF, DMARC, DNSSEC), reachability, blocklists, and naming heuristics. A young domain that also has proper DNS, a valid TLS certificate, and clean blocklist status gets treated fairly.

What to do with a young domain

If TrustDepth flags a domain as young, slow down. Look for an About page with real contact details, search for independent reviews, and prefer payment methods with buyer protection. If none of those check out, take your business elsewhere.

Tagged:whoistrust signalshow-it-works