Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
Threat feeds rely on domain age, but attackers let lookalikes sit dormant for months. Learn how attackers game threat feeds and how state-change monitoring stops them.

Take a tour through almost any SOC. You’ll find dashboards filled with rules designed to block newly registered domains (NRDs) (opens in new tab).
On paper, the logic feels bulletproof. When threat syndicates spin up infrastructure for a massive phishing wave or credential-harvesting campaign (opens in new tab), they need digital real estate. So they buy a domain to host counterfeit login pages and send malicious emails.
If your secure email gateway (SEG) (opens in new tab) automatically blocks any domain registered within the last 30 days, you cut off the attack before it ever starts, right?
One problem: Cybercriminals figured that out long ago.
Legacy threat feeds and perimeter filters rely on static domain age to determine trust. Adversaries know these rules inside and out, so instead of battering down the front door with fresh infrastructure, they simply manipulate the calendar.
Palo Alto Networks’ Global Incident Response Report shows that just 7% of active phishing domains are under 30 days old (opens in new tab).
Attackers aren't running sloppy, frantic smash-and-grab operations. They operate patient, highly capitalized syndicates. They buy domains in bulk, park them in complete silence for months, and simply wait out your security filters. By the time they attack your workforce, the domain has aged past every static threshold your security stack uses to flag danger.
If your team is still relying on legacy threat intelligence lists to spot social engineering (opens in new tab), you’re fighting a ghost.
The lifecycle of an advanced cyberattack doesn't start the morning a phishing lure lands in an inbox. It starts 6 to 12 months earlier in a phase of calculated, strategic hibernation.
Threat actors don’t want to trigger your alarms prematurely. Here’s the playbook adversaries use to manufacture digital trust out of thin air:
The attacker bypasses the entire concept of a newly registered domain filter by letting the clock run.
Day by day, the domain ages. It crosses the 30-day threshold, clears the 60-day mark, and eventually passes 90 days. It quietly transitions from a suspicious new asset into an established, trusted entity in the eyes of almost every traditional email security gateway on the market.
The real danger of an aged lookalike domain isn't just that it flies under the radar. It’s how fast an attacker can turn that benign parked page into a devastating weapon.
When the threat syndicate is finally ready to launch their high-velocity campaign, they execute a rapid series of technical state changes. This is the moment the attack goes live, and it’s exactly when legacy threat feeds fail completely.
The attacker logs into their registrar console and rewrites the domain's architectural reality on the fly:
This entire transformation, from a sleepy placeholder to a fully operational phishing engine, takes less than a minute.
Traditional cybersecurity relies on static lists and retrospective analysis. Threat intelligence vendors maintain massive databases of known bad domains and IP addresses.
But these lists are reactive. A domain only makes its way onto a legacy threat feed after a specific sequence of events:
That process takes hours (or sometimes days).
When an attacker weaponizes a dormant domain, that domain isn't on any threat list anywhere in the world. The legacy threat feed checks the domain registration date from 9 months ago, sees a positive reputation score, and lets the traffic flow directly into your network.
By the time a static feed pushes an alert to your manual ticketing queue, the attack is already over. The threat actor has dropped their payloads, harvested the administrative credentials they need, and burned down the campaign.
Relying on manual triage to catch dynamic attacks is an unwinnable math equation. You cannot manually refresh registrar data every five seconds, hoping to catch the exact moment a dormant domain suddenly sprouts active MX records.
Stopping an adversary who uses time as a shield requires shifting away from brittle, list-based security. Move toward dynamic, reasoning-based detection.
Here’s how the two approaches compare:

Adversaries use agile, automated infrastructure to build attacks, and you need native, agentic AI to dismantle them: Enter Doppel (opens in new tab).
Instead of relying on easily manipulated metrics like domain age, we engineered the Doppel Threat Graph (opens in new tab) to map the open web and track the continuous, holistic state of external infrastructure.
Domain age isn’t a proxy for trust. As long as security tools rely on static NRD filters and retrospective blocklists, cybercriminals will happily buy domains, wait out the clock, and strike when your defenses assume they are safe.
Stop relying on legacy threat feeds that give attackers a massive operational head start.
By deploying an agentic defense that tracks dynamic real-time state changes, you neutralize the time, capital, and effort the attacker invested in aging the domain. You pull the rug out from underneath them the very moment they try to flip the switch.
Experience the structural difference of true agentic defense: Schedule a demo (opens in new tab) with Doppel to see how our Frontier AI Social Engineering Defense platform (opens in new tab) tracks dynamic state changes and executes multi-channel takedowns at machine speed, destroying attacker infrastructure before the damage is done.
BLOG
Detection isn't enough. Disruption is the difference. Meet Doppel Email Security: the most advanced agentic solution that progresses beyond blackbox ML and whitebox rule-based systems to detect, investigate, and disrupt social engineering campaigns end-to-end.
by Kevin Tian and Rahul Madduluri