A phishing domain moves through a predictable sequence, and each stage leaves a different trace. Knowing where a domain sits tells you what you can still do about it.
The stages
| Stage | Duration | What is observable |
|---|---|---|
| Registration | Day 0 | An RDAP record appears. Nothing else. Nothing is resolving yet. |
| Infrastructure | Days 0–7 | Nameservers set, A record appears, sometimes an MX. Still no content. |
| Certificate | Hours before use | A Certificate Transparency entry. The strongest timing signal available. |
| Active | Hours to weeks | Content served, mail sent. This is the earning window. |
| Burned | After detection | Blocklisted, taken down, or abandoned. Content pulled, registration retained. |
| Dormant or reused | Indefinite | Parked and monetised, or held for a later campaign. |
The certificate is the alarm
The gap between registration and use can be days or months — attackers age domains deliberately, because age is a signal defenders weight. The gap between certificate issuance and use is usually hours, because nobody obtains a certificate for a site they are not about to serve.
registered -> could sit dormant for months nameservers set -> preparation, no urgency implied A record appears -> getting closer CERTIFICATE -> they intend to serve HTTPS, now MX appears -> they intend to send or receive mail, now
Those last two are the escalation triggers. Everything before them is a watchlist entry.
What each stage permits
| Stage | Available response |
|---|---|
| Registration only | Watch. A takedown request against a domain doing nothing gets nowhere. |
| Infrastructure appearing | Raise priority. Prepare evidence. Still nothing to report. |
| Certificate issued | Escalate. Capture evidence now, before the content changes. |
| Active | Report to the hosting provider and the registrar. This is where takedown works. |
| Burned | Too late to matter. Record it, and check whether the registrant reused infrastructure. |
Evidence captured after takedown is worthless
The moment a host suspends the content, the evidence of what it was disappears — and a registrar asked to act on a domain that now serves nothing will decline. Screenshots, DNS snapshots and RDAP records have to be captured while the campaign is live, which means at the moment of detection rather than at the start of the response process.