New Domain Flagged as Phishing? Fixing the False Positive

By · Updated · 6 min read

If your brand-new domain is being blocked as phishing, suspicious or “newly registered”, it usually isn’t because anything is wrong with the site. Web filters treat young domains as risky by default, because most phishing runs on domains a few days old. The fix is to confirm the site is clean, request recategorisation from each vendor that’s blocking you, and — for some of them — simply let the new-domain window run out.

This is one of the few blacklist problems where I tell people up front that it may not be a hack at all. It’s still worth ten minutes of checking before you assume that.

Why new domains get flagged

Attackers register domains, use them for a few hours or days, and throw them away. Security vendors have responded by treating age itself as a risk signal. Palo Alto Networks, for example, has published analysis finding that the large majority of newly registered domains end up malicious, suspicious or not safe for work. So a new domain starts with no reputation, and several filters will block or warn on it simply because it’s new.

What pushes a new site from “unknown” to “phishing” is usually what’s on it. A login form, a payment page, a “verify your account” flow, a brand name in the domain, or a copy of a well-known site’s layout all look exactly like the phishing kits these systems are trained on. Launch day with a customer portal on a two-day-old domain is close to a worst case.

How the main vendors treat new domains

VendorNew-domain categoryWhat it means
Fortinet FortiGuardNewly Registered Domain; Newly Observed DomainNRD covers domains registered in the previous 10 days; NOD covers unrated domains first seen very recently. Both are commonly blocked by firewall policies.
Palo Alto Networksnewly-registered-domainDomains registered, or re-registered after an ownership change, within the last 32 days.
Cisco Umbrella / OpenDNSNewly Seen DomainsDomains first queried through Umbrella in the past 24 hours. They drop off the list after that.
Webroot / BrightCloudReputation scoreScores run from 1 to 100 in five tiers from High Risk to Trustworthy. A domain with no history has little to lift it, and phishing-like content drags it down fast.

Two things follow. First, the time-based categories expire on their own: a FortiGuard NRD tag or a Umbrella “newly seen” flag goes away without anyone doing anything. Second, the content-based verdicts — “Phishing”, “Suspicious”, a low BrightCloud score — don’t expire nearly as reliably. Those you have to ask to have changed.

Rule out a real problem first

New sites get hacked too, especially ones built on a template with a stack of freshly installed plugins, or migrated from an old site that was already compromised. Before you file anything:

If several engines on VirusTotal say “phishing” and Google Safe Browsing is among them, this is not a new-domain false positive. Google doesn’t block on age. Treat it as a compromise.

Requesting recategorisation, vendor by vendor

Once you’re confident the site is clean, request a review from each vendor that is actually blocking you. Be specific: what the business is, what the login or payment page is for, and that the domain is newly registered to you.

Submit once per vendor and keep the reference. Resubmitting daily doesn’t move you up the queue.

Launching a new domain without getting flagged

If you haven’t launched yet, you can avoid most of this:

  1. Register the domain early and put a plain, honest holding page on it with your business name and contact details. A few weeks of harmless history is worth more than any form you can fill in later.
  2. Don’t launch with the login page first. Bring the public content live before customer logins or payment pages.
  3. Avoid brand look-alikes. A domain containing someone else’s trademark, or words like secure, verify or login, is asking to be classified as phishing.
  4. Set up email authentication before you send anything from the domain. SPF, DKIM and DMARC are cheap signals of legitimacy.
  5. Use real, public WHOIS contact or a reputable privacy service, a valid SSL certificate, and a proper privacy policy and contact page.
  6. Check the day you launch. Run a blacklist check on day one, not after your first customer complains.

When a “new domain” flag won’t go away

If a month has passed, the time-based categories should be gone. If you’re still being blocked as phishing after that, something on the site is keeping the verdict alive: a hidden page, an injected redirect, or a login form that closely imitates a bank or a big brand. That’s when it’s worth having someone look properly. I’ll check what the filters are reacting to and, through my blacklist recovery service, file and follow up the requests with every vendor involved.

Common questions

Why is my new website flagged as phishing?

Because most phishing uses domains that are only days old, many web filters treat any new domain as risky, and a new site with a login or payment form looks exactly like a phishing kit to automated systems. Confirm the site is clean, then request recategorisation from each vendor blocking you.

How long does the newly registered domain category last?

It depends on the vendor. Fortinet's Newly Registered Domain category covers domains registered in the previous 10 days, Palo Alto Networks uses a 32-day window, and Cisco Umbrella's Newly Seen Domains flag lasts 24 hours from first query. Content verdicts such as Phishing do not expire on the same schedule.

How do I fix a Webroot BrightCloud newly registered domain phishing false positive?

Look the URL up on the BrightCloud lookup tool, then use the change request form to suggest the correct category and explain that the domain is new and legitimate. Tick the notification box. BrightCloud says requests are typically processed in 24 to 48 hours.

Could my new site actually be hacked?

Yes. Fresh WordPress installs with many new plugins, and sites migrated from an older infected host, are both common targets. If Google Safe Browsing or several VirusTotal engines call the site phishing, treat it as a real compromise rather than a new-domain false positive.

Will waiting fix a new domain being blocked?

Partly. Time-based categories like Newly Registered Domain and Newly Seen Domains expire by themselves. Verdicts based on what the site contains, such as Phishing or Suspicious, usually need a review request, and they will return if something on the site keeps triggering them.