Short answer
Newly registered domains (NRDs) are domain names registered within a recent window, usually the last 24 hours to 30 days. A daily NRD list pairs each new domain with its whois record, which makes it simultaneously a sales lead list, a brand-abuse watchlist and a security risk indicator.
Key takeaways
- Around 200,000 domains are registered globally each day across all TLDs and gTLDs.
- NRDs under 30 days old are a standard risk signal in security filtering.
- The same feed serves sales, brand protection and threat intel — only the filter changes.
- Collection to delivery is a four-stage pipeline that completes inside 24 hours.
- Freshness decays fast: an NRD list is most valuable in its first 48 hours.
Ask a sales director, a SOC analyst and a trademark lawyer what a newly registered domain is and you will get three different answers — a lead, a threat, and a possible infringement. All three are correct, and all three are reading the same file. This explainer covers what an NRD actually is, how the daily list is built, and why the definition of "new" varies by discipline.
The definition, and why the window matters
A newly registered domain is any domain whose creation date falls inside a defined recent window. There is no universal window; the useful one depends on what you are doing.
| Discipline | Typical window | Reason |
|---|---|---|
| Sales and outreach | 0-48 hours | The buying decision is still open; competitors have not arrived |
| Brand protection | 0-7 days | Catch infringing registrations before they resolve to content |
| Security filtering | 0-30 days | Malicious infrastructure is disproportionately young |
| Market research | 12-24 months | Trends need volume and seasonality to be visible |
How many domains are registered each day?
Global registrations run at roughly 200,000 per day across all extensions, with visible weekly seasonality — weekdays consistently outpace weekends — and spikes around registrar promotions and new gTLD launches. Legacy extensions still dominate by volume, with .com accounting for the largest single share, followed by .net, .org and the newer commercial gTLDs.
Of that raw daily volume, a substantial fraction arrives behind privacy proxies. Once those are stripped, the count of records carrying a real registrant email, phone or postal address is materially smaller — and that smaller number is the one that matters for anything involving contact.
The 24-hour collection pipeline
- 1T+0 — Zone file and registrar monitoring detects new delegations across every TLD and gTLD.
- 2T+2h — Each new domain is queried against the authoritative whois or RDAP server for its registry.
- 3T+6h — Records are normalised into a fixed field schema, deduplicated, and validated; malformed and empty responses are re-queried.
- 4T+18h — Privacy-proxy and whois-guard records are identified and split into a separate output so the clean file contains only usable rows.
- 5T+24h — Files are zipped per TLD, merged into an all-in-one, optionally split by registrant country, and pushed to FTP and web access.
Why the gap exists
A domain does not become queryable the instant it is paid for. Registry propagation, registrar batching and whois server rate limits mean a same-second feed is not physically possible at global scale. A complete, cleaned 24-hour file beats a fast, partial one.
Three teams, one file
Sales and demand generation
A new domain is a business at the exact moment it needs hosting, email, a website, branding and search visibility. Filtering the daily list by country, TLD or keywords in the domain name yields an outreach list that is fresher than anything a data broker can resell, because it did not exist yesterday.
Brand protection
Typosquats, homoglyph variants and hyphenated look-alikes are registered days or weeks before they are pointed at content. Fuzzy-matching a brand string against each day's list catches them at registration, when a takedown or UDRP filing is cheapest and the evidence trail is cleanest.
Security and threat intelligence
Phishing pages, malware command-and-control and spam infrastructure skew heavily toward domains under a month old — which is why NRD blocking is a standard control in secure web gateways and DNS filters. The whois record adds pivot points: a shared registrant email, phone number or nameserver often clusters an entire campaign that looked like unrelated domains.
What separates a good NRD feed from a bad one
- Completeness — does the feed cover ccTLDs and the long tail of gTLDs, or only .com?
- Punctuality — does yesterday's file land at the same hour every day, without silent gaps?
- Cleanliness — are proxy rows removed, fields normalised, and duplicates collapsed?
- History — can you backfill 30-40 days when you discover an incident after the fact?
- Transparency — does the provider publish raw versus usable counts, or only the flattering number?
GetWhoisData publishes the daily newly registered domain database across all TLDs and 677+ gTLDs, with proxy records removed, 30 days of history on the server, and unlimited FTP and web downloads.
Frequently asked questions
What does NRD mean?+
NRD stands for newly registered domain — a domain name whose creation date falls within a recent window, most commonly the last 24 hours to 30 days.
How many domains are registered every day?+
Approximately 200,000 domains are registered globally each day across all TLDs and gTLDs, with weekdays consistently higher than weekends.
Why are newly registered domains considered risky?+
Phishing, malware and spam infrastructure is disproportionately hosted on domains less than 30 days old, because attackers register fresh domains to evade reputation-based blocking. Many security gateways therefore block or sandbox NRDs by default.
How quickly can I get a list of domains registered today?+
Complete, cleaned files are typically available within 24 hours of registration. Registry propagation and whois rate limits make a genuinely real-time global feed impractical.
Can I get newly registered domains for one country only?+
Yes. Country-filtered delivery splits each day's registrations by registrant country, covering 285 countries and territories.