Skip to content
VetThisVendor

Recently registered domain

If the sending-domain check reported that a domain was registered less than a month ago, that is the strongest single signal on the result page. It is not proof of anything, and new businesses are entirely real — but it deserves the phone call before the payment.

Why age matters more than the email records

The domain check looks at SPF, DKIM and DMARC, which answer one question: can somebody forge mail that appears to come from this domain? For an established supplier that is a useful answer.

For a domain registered a fortnight ago it is close to meaningless, and the reason is worth sitting with: whoever registers a domain controls its DNS records. An attacker setting up acme-invoices.com to impersonate acme.com configures SPF, DKIM and DMARC properly, because they need the invoice to reach your inbox rather than your spam folder. Modern mail providers set all three up automatically.

So the impersonator’s brand-new domain often has better email authentication than the real supplier’s twenty-year-old one. Reading the DMARC policy alone would hand the most professional impersonators the most reassuring result on the page. Registration age is the field that separates them.

The two frauds this distinguishes

The compromised mailbox. A real supplier’s email account is broken into and the invoice is sent from their genuine domain. Age looks fine — the domain is as old as the business. Nothing on this page catches it; only the phone call does.

The lookalike domain. A domain is registered that reads almost like the supplier’s, and invoices go out from it. Everything about the email is technically valid, because it is a real domain properly configured. The age is the tell.

A check that only reads DMARC sees these as opposite results. In truth they are both worth the same phone call.

What to actually do

  1. Read the domain character by character, right to left. rn looks like m at a glance. l looks like I in many fonts. A hyphen added or removed is invisible when you already know what the word says. Compare it against an older invoice or your accounting system, not against memory.
  2. Check whether it matches the domain you already had. If you have paid this supplier before, the domain on the old invoice is the reference. A different one — however plausible — is the whole finding.
  3. Phone them on a number you already had. Not the number on this invoice, not the one in the signature. One from an earlier invoice or your own records.
  4. Look at the VAT registration name. If the registry returns a company name that does not match the business you think you are dealing with, that is a second signal. See valid VAT number, different name.

When a new domain is genuinely fine

Plenty of reasons exist and most of them will apply to somebody you pay this year:

None of these is undermined by a phone call, which is the only thing this result asks you to do.

Why the check does not simply fail the domain

The result is amber, not red, and it never becomes a “do not pay”. The tool has no way to distinguish a fraudulent new domain from a legitimate one, and pretending otherwise would be the same mistake as issuing a single “safe to pay” verdict — see about. What it can do is put the one fact that matters where you will see it, rather than leaving it as a grey line under a green tick.

Between one and six months old, the check says so in the text but does not change colour. That range is ordinary for a real business, and a warning that fires on a large share of honest invoices is a warning people learn to click past.

Run a vendor check →Registry, IBAN, EU sanctions and sending domain, in one pass. Free, no signup.