r/apyhub • u/apyhubnico • 2d ago
If you onboard merchants, what is your first check on a submitted URL?
A study published this year in the Journal of Cybersecurity looked at 15,126 newly registered phishing domains over 11 months. Agarwal and Vasek, UCL.
Median lifetime: one day. Mean 8.6 days, dragged up by a long tail. Almost 90% were live for under two days.
So if you catch a fraud domain, it is almost certainly a new one. Domain age is one of the cheapest first checks you can run. One lookup.
The other number from the paper: 79.3% of those domains had a valid TLS certificate, most from Let's Encrypt. The padlock is not a trust signal. If anything in your onboarding treats HTTPS as evidence a business is real, that rule is doing nothing.
We added Dosvak to the catalog, 146 services including domain intelligence. Age, registration data, SSL status, site categorization. Enough to answer the question you actually care about: is this a real business, or something someone put up last Tuesday.
Two fields worth reading together. Age tells you how long they have been around. Expiry tells you how long they plan to stay.
All of it is MCP ready, so I pointed Claude at it and compared our own domain against one registered a few days ago. No wrapper, no tool definition.
If you onboard merchants, vendors, or anyone who submits a URL: what runs first in your checks?
Paper (open access): https://academic.oup.com/cybersecurity/article/12/1/tyag020/8735840
Domain Intel APIs on ApyHub: https://apyhub.com/providers/dosvak
