New Domain Flagged as Phishing? Fixing the False Positive
By Glenn Lyvers · Updated · 6 min read
If your brand-new domain is being blocked as phishing, suspicious or “newly registered”, it usually isn’t because anything is wrong with the site. Web filters treat young domains as risky by default, because most phishing runs on domains a few days old. The fix is to confirm the site is clean, request recategorisation from each vendor that’s blocking you, and — for some of them — simply let the new-domain window run out.
This is one of the few blacklist problems where I tell people up front that it may not be a hack at all. It’s still worth ten minutes of checking before you assume that.
Why new domains get flagged
Attackers register domains, use them for a few hours or days, and throw them away. Security vendors have responded by treating age itself as a risk signal. Palo Alto Networks, for example, has published analysis finding that the large majority of newly registered domains end up malicious, suspicious or not safe for work. So a new domain starts with no reputation, and several filters will block or warn on it simply because it’s new.
What pushes a new site from “unknown” to “phishing” is usually what’s on it. A login form, a payment page, a “verify your account” flow, a brand name in the domain, or a copy of a well-known site’s layout all look exactly like the phishing kits these systems are trained on. Launch day with a customer portal on a two-day-old domain is close to a worst case.
How the main vendors treat new domains
| Vendor | New-domain category | What it means |
|---|---|---|
| Fortinet FortiGuard | Newly Registered Domain; Newly Observed Domain | NRD covers domains registered in the previous 10 days; NOD covers unrated domains first seen very recently. Both are commonly blocked by firewall policies. |
| Palo Alto Networks | newly-registered-domain | Domains registered, or re-registered after an ownership change, within the last 32 days. |
| Cisco Umbrella / OpenDNS | Newly Seen Domains | Domains first queried through Umbrella in the past 24 hours. They drop off the list after that. |
| Webroot / BrightCloud | Reputation score | Scores run from 1 to 100 in five tiers from High Risk to Trustworthy. A domain with no history has little to lift it, and phishing-like content drags it down fast. |
Two things follow. First, the time-based categories expire on their own: a FortiGuard NRD tag or a Umbrella “newly seen” flag goes away without anyone doing anything. Second, the content-based verdicts — “Phishing”, “Suspicious”, a low BrightCloud score — don’t expire nearly as reliably. Those you have to ask to have changed.
Rule out a real problem first
New sites get hacked too, especially ones built on a template with a stack of freshly installed plugins, or migrated from an old site that was already compromised. Before you file anything:
- Run the domain through my free site scan and a website blacklist check to see exactly who is flagging you and with what label.
- Look for pages you didn’t create. Phishing kits are routinely dropped into new WordPress installs — see phishing pages on your website.
- If the site was moved from somewhere else, assume anything that came across could have come across infected. How to tell if a site is hacked is the checklist I’d use.
If several engines on VirusTotal say “phishing” and Google Safe Browsing is among them, this is not a new-domain false positive. Google doesn’t block on age. Treat it as a compromise.
Requesting recategorisation, vendor by vendor
Once you’re confident the site is clean, request a review from each vendor that is actually blocking you. Be specific: what the business is, what the login or payment page is for, and that the domain is newly registered to you.
- Webroot / BrightCloud — use the BrightCloud change request, suggest the correct category, and tick the notification box. BrightCloud says its analysts typically process requests in 24–48 hours. Details in my BrightCloud rating change guide.
- Fortinet — submit through the FortiGuard rating submission. If the only category is Newly Registered Domain, it will age out, but a request helps when the site was also given a content category like Phishing. See FortiGuard removal.
- Palo Alto Networks — use the change request on their URL filtering site; after the 32-day window they recrawl to recategorise. See Palo Alto removal.
- Microsoft SmartScreen — there’s no lookup, only the report form; steps in SmartScreen false positives.
- Cisco — Umbrella’s newly-seen flag expires in a day; a reputation problem goes through Cisco Talos.
Submit once per vendor and keep the reference. Resubmitting daily doesn’t move you up the queue.
Want the warnings gone without the paperwork?
Clearing a flag means cleaning the cause and then working each vendor's own queue. I do both.
Not sure which? Ask me first — I’ll tell you honestly if you can handle it yourself.
Launching a new domain without getting flagged
If you haven’t launched yet, you can avoid most of this:
- Register the domain early and put a plain, honest holding page on it with your business name and contact details. A few weeks of harmless history is worth more than any form you can fill in later.
- Don’t launch with the login page first. Bring the public content live before customer logins or payment pages.
- Avoid brand look-alikes. A domain containing someone else’s trademark, or words like secure, verify or login, is asking to be classified as phishing.
- Set up email authentication before you send anything from the domain. SPF, DKIM and DMARC are cheap signals of legitimacy.
- Use real, public WHOIS contact or a reputable privacy service, a valid SSL certificate, and a proper privacy policy and contact page.
- Check the day you launch. Run a blacklist check on day one, not after your first customer complains.
When a “new domain” flag won’t go away
If a month has passed, the time-based categories should be gone. If you’re still being blocked as phishing after that, something on the site is keeping the verdict alive: a hidden page, an injected redirect, or a login form that closely imitates a bank or a big brand. That’s when it’s worth having someone look properly. I’ll check what the filters are reacting to and, through my blacklist recovery service, file and follow up the requests with every vendor involved.
Common questions
Why is my new website flagged as phishing?
Because most phishing uses domains that are only days old, many web filters treat any new domain as risky, and a new site with a login or payment form looks exactly like a phishing kit to automated systems. Confirm the site is clean, then request recategorisation from each vendor blocking you.
How long does the newly registered domain category last?
It depends on the vendor. Fortinet's Newly Registered Domain category covers domains registered in the previous 10 days, Palo Alto Networks uses a 32-day window, and Cisco Umbrella's Newly Seen Domains flag lasts 24 hours from first query. Content verdicts such as Phishing do not expire on the same schedule.
How do I fix a Webroot BrightCloud newly registered domain phishing false positive?
Look the URL up on the BrightCloud lookup tool, then use the change request form to suggest the correct category and explain that the domain is new and legitimate. Tick the notification box. BrightCloud says requests are typically processed in 24 to 48 hours.
Could my new site actually be hacked?
Yes. Fresh WordPress installs with many new plugins, and sites migrated from an older infected host, are both common targets. If Google Safe Browsing or several VirusTotal engines call the site phishing, treat it as a real compromise rather than a new-domain false positive.
Will waiting fix a new domain being blocked?
Partly. Time-based categories like Newly Registered Domain and Newly Seen Domains expire by themselves. Verdicts based on what the site contains, such as Phishing or Suspicious, usually need a review request, and they will return if something on the site keeps triggering them.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.