Most DNS resolvers offer good protection against known scam sites. But “known” is the catch. The ones that usually slip through are the ones too new to be on any list. That's mostly not a problem with NextDNS because it has a feature that fixes that gap. It works on a simple rule that blocks any domain that’s younger than 30 days.

Most phishing sites usually have one thing in common

They’re almost always brand new

Fake PayPal Invoice Scam Email on a wooden surface Credit: Ben Stegner/MakeUseOf

The way most scam emails or texts work is they get you to click a link. It could be a FedEx delivery notice, your bank asking you to verify your account, or an offer from a brand you shop at. Whatever the hook, there’s a good chance the link underneath is pointing you to a domain that didn’t exist a week ago.

That’s not a coincidence. Scammers typically burn through domains the way most of us burn through paper towels — simply because they have to. Once a domain gets flagged and backlisted, it’s mostly useless. And that usually doesn’t take long, so they have to register another one to continue running their scam. That part isn't hard either. Setting up a convincing phishing page takes maybe an hour, even less with AI. Registering a fresh domain takes five minutes and a few dollars.

But that reliance on fresh domains is also their biggest weakness. A site being almost brand new is the biggest giveaway because legitimate services simply don’t work that way. Even new businesses typically operate on a domain they’ve held for at least a few months before they’re sending you emails or running ad campaigns.

Of course, I can’t go around checking for domain registration details any time I land on something that looks off. Thankfully, I don’t have to because my DNS resolver does it for me. NextDNS has a weird rule that can automatically block domains that are less than 30 days old, and it’s quite effective.

NextDNS has a simple setting that blocks them

The block happens before anything even loads

NextDNS showing NRD setting page
Screenshot by Pankil Shah -- No attribution required

If you haven’t heard about NextDNS, here’s the short version: it’s a cloud-based DNS resolver that goes way beyond simply translating domain names into IP addresses. It offers a personal dashboard where you can stack up blocking rules, see a full log of every DNS query across your devices, and fine-tune what gets through and what doesn’t.

One of the options under the Security tab is called Block Newly Registered Domains. It’s not enabled by default, but once you turn it on, it blocks any domain that was registered within the last 30 days. The way it works is simple but genius. DNS queries have to pass through NextDNS before your device connects to anything. When you click a link, NextDNS checks the destination domain against its data on registration dates. If the domain is less than 30 days old, the query gets blocked and the connection never happens.

That means the scam domain doesn't get a chance to load on the device at all. The obvious advantage of this is that it can detect scam sites that haven’t even been reported yet. Most blocklists are reactive. A domain gets reported, someone adds it to a list, and that list eventually reaches you. By that point, a lot of people may have already been caught. NRD blocking is proactive and targets the structural pattern scammers rely on.

The only tradeoff with this is occasional false positives. If a legitimate site has recently moved to a new domain, for instance, it’ll get blocked too. But this doesn’t happen often in my experience, and if it does, you can always add exceptions.

NextDNS is packed with such useful settings

Most of them aren’t enabled by default, though

NRD locking is just one example. NextDNS is full of such security and privacy features. AI-Driven Threat Detection, for instance, is their proprietary model that uses machine learning to identify malicious domains based on patterns rather than blacklists. The same proactive logic applies here too.

Block Parked Domains is another one. It blocks those single page sites that are registered but largely empty with no real content. Its Block Disguised Third-Party Trackers feature goes after trackers that disguise themselves as first-party domains to slip past conventional blocking. The trick works because most ad and tracker blockers give first-party domains a pass, so trackers routing through subdomains look like they belong to the site you’re visiting. NextDNS can see through this and block them anyway.

So yes, NextDNS is great overall. The only thing is that it’s not entirely free. Its free tier limits you to 300,000 queries, which may sound like a lot, but you’ll likely burn through them in less than a day. After that, you’ll need to pay $2 per month or $20 a year to enjoy the benefits.