According to ICANN, over 42% of new gTLD registrations cluster into batches, meaning the domain your security systems just detected was likely registered alongside a pool of others waiting their turn.
Domain creation time, registrar, and nameserver data don’t confirm abuse on their own, but they can be used as additional signals that you get at the moment of registration, before any damage has been done.
Domains in each group come with shared cluster context as well as WHOIS and DNS details. This allows analysts to review related registrations together instead of repeatedly gathering the same data one domain at a time.
Domains are grouped using creation time, registrar, and nameserver data, the same registration signals shown to predict abuse across new gTLDs.
The Enriched data feed adds registration data (registrar, registrant, creation and expiration dates) and DNS data (nameserver and IP resolution) to every cluster.
Clusters include first-seen date, cluster ID, and group size, giving you the context to trace how a batch formed and gauge its scale.
Bulk Registration Risk Data Feed is updated daily. Weekly and monthly updates are also provided.
Explore a 5-day rolling sample of 1,000 recently observed bulk-registered domains to evaluate coverage and freshness. Contact us for full access to complete domain intelligence feeds.
| Bulk Registration Risk Domain List | Sample count | Creation Date | Access |
|---|---|---|---|
| 02 Sep, 2026 (Domains only, no WHOIS data) | 1,000 | 02 Sep, 2026 | Download |
| 01 Sep, 2026 (Domains only, no WHOIS data) | 1,000 | 01 Sep, 2026 | Download |
| 31 Aug, 2026 (Domains only, no WHOIS data) | 1,000 | 31 Aug, 2026 | Download |
| 30 Aug, 2026 (Domains only, no WHOIS data) | 1,000 | 30 Aug, 2026 | Download |
| 29 Aug, 2026 (Domains only, no WHOIS data) | 1,000 | 29 Aug, 2026 | Download |
Bulk Registration Risk Data Feed already delivers domains pre-grouped into clusters with metadata attached, so your SIEM or SOAR can ingest the whole cluster as ready-made indicators. No per-domain enrichment calls are needed to figure out what it's connected to.
Bulk-load entire clusters of related domains from the same campaign into threat intelligence platforms. So instead of your platform slowly building up a picture of a campaign, domain by domain over days or weeks, it gets the whole cluster at once and can immediately strengthen its existing threat data.
Most blocklists only add a domain after it's been detected in malicious activities, which means the rest of its cluster stays off the list until it is weaponized, too. Bulk Registration Risk Data Feed lets you block the entire cluster at once, including the dormant domains that haven't been deployed yet, so you're not waiting for each one to get caught individually.
Check whether a domain flagged by your existing security tools belongs to a larger bulk-registration group. Cluster size, registration timing, registrar, nameserver, WHOIS, and DNS data can help you assess the alert in context and identify other domains that may deserve review.
The Basic Data Feed is a structured list of domain names containing domain clusters. One domain per line.
Download Basic sampleThe Enriched database is an add-on to the Basic database and contains WHOIS records for each row.
Download Enriched sampleGet free access to the community version for security, law enforcement, and data science professionals.
Download Community sampleAccess bulk domain registration intelligence with the Snowflake platform.
Visit Snowflake Profile















Bulk registration lets one registrant buy hundreds or even thousands of domains, whether through a single transaction or an automated process that executes many separate transactions in quick succession. That volume creates risk for security teams and brands alike because:
No. Plenty of organizations register domains in bulk for good reasons.
Bulk registration itself isn't the problem. It's a tool that's used for both legitimate and malicious purposes.
The feed comes in three versions — Basic, Enriched, and Community, which have different data points. For more specific information, check out the documentation.
A group of domains is added to the Bulk Registration Risk Feed when at least three domains that appeared on the same day are found to share similar second-level domain naming patterns. These signals help identify likely bulk-registration activity rather than isolated look-alike domains.
Track domains registered in coordinated batches, complete with WHOIS and DNS details for every domain.
Learn more
Get the most relevant data to be ahead of emerging security threats.
Learn more
Get insights for the new business registered on the web.
Learn more
Get data feeds of SSL certificates along with their well parsed fields in real time. Accurate. Up-to-date.
Learn more
Monitor exact matches, variations and common misspellings of your brand name & trademarks.
Learn more
Find out the exact physical location of any IP address, email or domain name.
Learn more
Assess the domain's or IP addresses reputation and risk profile with a simple score based on a comprehensive...
Learn more
Find domains and subdomains related by specific terms in their hostnames.
Learn more
Easily identify malicious resources and retrieve their threat information.
Learn more
Get the most comprehensive database of SSL (Secure Sockets Layer) Certificates.
Learn more
Enhance your domain research toolkit by our enterprise-grade web-based solution that helps you in searching...
Learn more
Find out which domains were added or dropped by registrants, with given search criteria.
Learn more
Get well-parsed and normalized WHOIS information for any domain name, IP address or email.
Learn more
Get data feeds of new registered domains along with their WHOIS data generated in real time.
Learn more
Give the list of domain names tied to the specified DNS records via API calls with outputs in JSON and XML.
Learn more
We provide complete and relevant domain WHOIS data which can be customized and easily integrated as per your business needs.
Learn more