Skip to main content

 AD_4nXcWPVQ9cTxMNbqhIV57ovhvaFaXKg7gEnu-ca6Tgp3AxvJzkUV7PSZlz4S8EUsmEycULyk0A_RoT2r0zUisQ1YQbmI8FeBkQ3Rr5MXPVE7T3blsPXnrjqbU0ju7y-H2BqrCThLC2A?key=f5H03EvbVu4bUe9s3axrrQ

Netskope Global Technical Success (GTS)

Best Practices - Newly Registered Domains (NDRs)

 

Netskope Cloud Version - 125

 

Objective

What are the recommended best practices in Netskope for handling Newly Registered Domains (NRDs)?

 

Prerequisite

SWG or Next-Gen SWG License

 

Context

Newly Registered Domains (NRDs) are often used in malicious campaigns, including phishing, malware distribution, and command-and-control communications, as they typically have little to no reputation history. Given their potential risk, it is critical to implement appropriate controls and policies.

 

Do You Know?

  • As of May 09, 2025, Netskope maintains a set of 132 predefined web categories, with every internet destination classified into one of these categories. List of Netskope predefined web categories - Link
  • What are Newly Registered Domains?

Domains registered for the first time or changed ownership in the last 30 days. Threat actors like to use newly registered URLs for malevolent activities, such as malware hosting and phishing campaigns.

  • What are Newly Observed Domains?

Domains observed as active in the last 30 days. Similar to NRDs, NODs might not necessarily be registered in the last 30 days. Threat actors might register a domain and leave it dormant for a period of time to avoid NRD classification. Later, they can use the domain for malicious activities, such as malware hosting and phishing.

  • If a domain is registered on the internet today, how long does it take for that domain to be categorized?
  1. Netskope employs its own engines for URL scanning, and in addition, collaborates with globally recognized partners who provide live feed on newly registered domains. 
  2. Newly registered domains are detected almost immediately, especially if flagged by threat intelligence sources, typically within minutes to hours.
  3. By default, Netskope classifies new domains as 'NRD' (Newly Registered Domain) for the first 30 days until a customer chooses to recategorize the domain to a non-security risk category.
  • What are Netskope recommendations for Newly Registered Domains (NRDs)?
 

Option 1 (Recommended)

Option 2

Solution

Route NRD traffic to Netskope Remote Browser Isolation (RBI)

Block Web category ‘Newly Registered Domain’

Policy Action

Isolate

Block

License Needed

Remote Browser Isolation (RBI)

SWG or Next Gen SWG

Notes

RBI license has it additional cost attached

 

 

  • Apart from web category NRD what other similar web categories should be blocked?

There are a few web categories which are similar in nature to web category NRD

  1. Newly Observed Domain (NOD)
  2. Uncategorized
  3. No Content
  4. Parked Domains

For details about the above web categories - Link

 

Configuration

  • Realtime Protection Policy Configuration

Option 1                                                                                                                                                                   

Path: Netskope Tenant UI >>> Policies >>> New Policy >>> RBI

AD_4nXd4Ug2WmhoTR3g5aF78C7z5z9tSgJqdiuLVf0fecXWpMr_p9IZE3SfLPAy2OVASoCZaXCQDYxRcMqV2SjE9hkfBKvD9fWA-59O4LbuTcS9kTfI9U3TMiTO7DBF5JQUtprjy_hgBjQ?key=f5H03EvbVu4bUe9s3axrrQ

AD_4nXc6G6ofnHyZiIhfxW056zfRu32ObfAc6k50Wqy552IUtx9sVkT5U4G_PH6sSWnWfi3IV7bXM3QeU7Vh8R6hwrXHhhike4A2-QZ6qLTwSEA94ewj9LhxG_mcuguZ6HnkQZCJfgvO3w?key=f5H03EvbVu4bUe9s3axrrQ

All about RBI - Link

 

Option 2                                                                                                                                                                   

Path: Netskope Tenant UI >>> Policies >>> New Policy >>> Web Access

AD_4nXdw8iDYr62ItALM7jP3Up5NDFhQRvtt8VGUGPEyg-EAlj4AK0-ukF4YS3qAZnV9fTr8YSgdAZQfW3z5RNlWJUKxF2kWRZTzECkTQqJLEGH33GVyovjpllEQjjH_MYHodZHmTjOiFg?key=f5H03EvbVu4bUe9s3axrrQ

 

Author Notes

Path: Netskope Tenant UI >>> Skope IT >>> URL Lookup

AD_4nXcO1OIyVVLXOGyW41j0shCOc7gkv5cn2rT7ii3KTdz8WBsFuVHG37dhiu77N6Xu70evuSIl07J9NOsuyB48gQg8Kwaw3y0a96YkTf5EHEaNB-VQI_86AfwokM8ytod5_7AHDD6JZQ?key=f5H03EvbVu4bUe9s3axrrQ

or

  1. Raise a support case with Netskope Customer Service

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the application's functionality may be altered by the vendor. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.

 

Be the first to reply!