ActorStack.dev

A domain entering the zone is not always a domain being registered

Zone entry is the earliest public signal that a domain went live, and roughly 20–30% of those events are re-appearances rather than new registrations. The number is an outside estimate and is labelled as one.

By Oswaldo Carabano5 min read

Short answer

A domain appearing in today's zone file that was absent from yesterday's is a certain event: the registry delegated it in that window. What that event means is less certain, because a domain registered a year ago that sat on hold and has just had its nameservers restored looks identical from outside to one bought this morning. Published research puts the share of re-appearances at roughly 20–30%, cited as an outside estimate rather than an in-house measurement. For most security and monitoring uses the zone event is the signal actually wanted — it is the earliest public indication that a name went live — and calling the feed a newly registered domains list would be wrong on about a quarter of its rows.

Key points

  • A domain absent from yesterday's zone snapshot and present in today's has certainly been delegated in that window, which is the registry's own record.
  • A domain that sat on hold and has just had its nameservers restored is indistinguishable from a new registration when seen from the zone alone.
  • Published research puts the re-appearance share at roughly 20–30%, cited as an outside estimate because it has not been measured on this data.
  • Zone entry remains the earliest public signal that a name went live, which is why it is the right input for phishing and brand monitoring despite the ambiguity.
  • Resolving the ambiguity would need a WHOIS or RDAP query, which is prohibited at scale by the agreement that provides the zone data.
  • The registries publish once a day, so a domain delegated this morning appears in tomorrow's feed and no faster path exists from this source.
On this page5 sections

One event, two claims of very different strength, and a naming decision that follows from keeping them apart.

The part that is certain

A domain absent from yesterday's zone snapshot and present in today's was delegated in that window. That is the registry's own record compared against itself, and it is 100% reliable. It is also the earliest public signal that a name went live: before this, nothing outside the registrar knows the domain exists.

The part that is not

Whether the domain was registered in that window. A domain bought a year ago that sat on hold and has just had its nameservers restored produces exactly the same event as one bought this morning. From a source containing no registration date, the two are indistinguishable.

An outside estimate, labelled as one

Why the signal is still the one you want

For phishing and brand monitoring, the question is almost never “was this registered today”. It is “did this name become reachable, publicly, in the last day” — and that is precisely what a zone entry states with certainty. A restored domain pointing at new infrastructure deserves the same look as a fresh one.

The lookup that would resolve it, and why it is not made

A WHOIS or RDAP query would settle each row. Making that query at scale is prohibited by the agreement that provides the zone data in the first place, so the ambiguity is documented instead of removed. The same reasoning produces the equivalent caveat on the other side of the feed, and it is why neither product is named for the search term.

Frequently asked questions

Is a new zone entry a newly registered domain?
Usually, and not always. Published research puts the share of zone entries that are re-appearances rather than new registrations at roughly 20–30%, so a feed sold as 'newly registered domains' would be wrong on about a quarter of its rows.
What makes a domain re-appear in the zone?
A registration that was on hold and has been restored, a suspension that got resolved, or nameservers that were removed and later set again. All of those look identical from the zone to a brand new delegation.
Why is the 20–30% figure not measured here?
Because measuring it would require checking registration dates, which come from WHOIS or RDAP rather than from zone data. Quoting published research as an outside estimate is more honest than presenting a number this pipeline has not produced.
Is the feed still useful with that uncertainty?
Yes, because the zone event itself is exactly the signal most security uses want: this name became reachable, publicly, in the last day. Whether the registration behind it is new rarely changes what a defender does about it.

Sources

Every URL below was requested and returned a page on the date shown.

  1. Operator claimchecked 18 Sept 2026
    New Domain Delegations — Actor README and input schemaActorStack / Apify Store
  2. Platform docschecked 18 Sept 2026
    Centralized Zone Data ServiceICANN
  3. Law or regulatorchecked 18 Sept 2026
    EPP Status Codes — What Do They Mean, and Why Should I Know?ICANN
A row of residential mailboxes on posts in front of a wooden fence and trees.
DomainsGuide

Detecting domain hijacking

Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.

7 min
A white shuttered window on a peach-coloured building with a for-sale notice beside it.
DomainsExplainer

Zone exit is not expiry

Leaving the zone runs roughly 35 days ahead of a domain being released, and most exits are never releases at all. The `minDaysAbsent` filter is what turns the signal into something usable.

6 min
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsMeasured

What dns_provider can tell you

The nameserver identifies who runs the DNS for 69.1% of domains. It does not identify what a site is built with, and the measurement that settled that question is worth seeing.

5 min