Network functions
Functions in the network package
network.whois
network.whoisnetwork.whois(domain: Domain) -> WhoisOutput
network.whois performs a WHOIS lookup for domain registration on the .root_domain field of a Domain. It returns the domain age, registrar information, and timing information about the age of the registration record and when it was retrieved.
This function can be used to identify newly registered domains, by searching for domain age or if a domain is not found. Lookups are performed against Sublime's WHOIS service, which may be delayed by ~24 hours. Since new domains have a slight delay, searching for .found == false will identify both unregistered and newly registered domains. For some detections, the .found == false could be high enough signal.
View rules that use this function
network.whois(sender.email.domain).found == false or
network.whois(sender.email.domain).days_old <= 7any(body.links, network.whois(.href_url.domain).days_old <= 14)Updated about 13 hours ago