# Option to block recently created domains (DGA)

**URL:** <https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700>\
**Category:** Closed or Out Of Scope\
**Created:** [June 12, 2019, 3:25am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700 "2019-06-12T03:25:39Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![slawa](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/slawa/32/19727_2.png) [@slawa](https://discourse.pi-hole.net/u/slawa)\
**Post date:** [June 12, 2019, 3:25am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/1 "2019-06-12T03:25:39Z")

</div>

Pi-hole is mainly for blocking ads. But it also can serve to stop malware.

> [@Problem](#):
>
> "Attackers use domain generation algorithm (DGA) to make a resilient Command and Control (C2) infrastructure. Automatic and large scale malware operations pose a challenge on the C2 infrastructure of malware. If defenders identify key domains of the malware, these can be taken down or sinkholed, weakening the C2. To overcome this challenge, attackers may use a domain generation algorithm.
> 
> A DGA is used to dynamically generate a large number of seemingly random domain names and then selecting a small subset of these domains for C2 communication. The generated domains are computed based on a given seed, which can consist of numeric constants, the current date, or even the Twitter trend of the day. Based on this same seed, each infected device will produce the same domain. The rapid change of C2 domains in use allows attackers to create a large network of servers, that is resilient to sinkholing, takedowns, and blacklisting. If you sinkhole one domain, another pops up the next day or the next minute. This technique is commonly used by multiple malware families and actors. For example, Ramnit, Gozi, and Quakbot use generated domains in the malware."

**A fairly simple and effective way would be to use** `Creation Date` **of a domain from a simple** `whois` **lookup. If the domain was registered less than a specified period of time ago, it would be pi-holed.  
I think it happens rarely that you visit a newly created domain, but it should be opt in anyway.**

```auto
whois pi-hole.net
   Domain Name: PI-HOLE.NET
..
   Creation Date: 2015-03-20T18:00:23Z
...

```

* * *

Related:

> [@Integrated optional WHOIS lookup](https://discourse.pi-hole.net/t/integrated-optional-whois-lookup/3038):
>
> I've searched the site but can't find a similar request, so apologies if this has been raised before... My 'Top Domains' often includes some very weird looking domains - usually Apple related due to the number of iOS devices on my local network. But the purpose of the DNS request is not always obvious from the domain name. Would it be possible to integrate a WHOIS domain lookup function into the Top Domains or elsewhere in the Pi Hole Web GUI? Personally, I don't think this would need to be an…

> [@Link to detailed information about domain in query log](https://discourse.pi-hole.net/t/link-to-detailed-information-about-domain-in-query-log/2970):
>
> Would it be possible to wrap the domain name in the query log with a simple HTML tag to link to a site with more information about the domain? For example from [https://ipinf.ru](https://ipinf.ru) but i guess the domain experts know better domain info sites to be used for this. That way it's (a few mouseclicks) easier to know if i should black-/white-list the domain or not.

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [June 12, 2019, 3:39am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/2 "2019-06-12T03:39:42Z")

</div>

I think this is outside the scope of Pi-Hole; it is not intended to be a one-stop internet security program. It is a DNS resolver.

If you foresee potential interest in an enhancement that would do this, write a script that would find domains recently queried in the query log, perform the whois search you mention, and then add to blacklist as desired. Put the script on GitHub for others to use.

---

<div class="post-metadata">

**Author:** ![slawa](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/slawa/32/19727_2.png) [@slawa](https://discourse.pi-hole.net/u/slawa)\
**Post date:** [June 12, 2019, 3:58am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/3 "2019-06-12T03:58:52Z")

</div>

I agree that this request is an edge case for the scope of pi-hole.

You do not want to slow down resolving DNS requests by a whois lookup. This has to happen afterwards. But adding it to the blacklist permanently is not something I suggest to do.  
As an example: Domains that are less than a week old should be pi-holed. After that period of time the domain should be accessible.

A script that will blacklist domains can not serve this purpose. Maybe that solution can be considered when we get an option to blacklist domains for a certain period of time and not permanently.

Theoretically the script can be made to remember and remove those domains from the blacklist after a period of time. This would make the script more complicated.

I already have seen scripts that blacklist domains and remove them after a period of time for the purpose of parental control.

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [June 12, 2019, 4:06am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/4 "2019-06-12T04:06:07Z")

</div>

> [@slawa](#):
>
> A script that will blacklist domains can not serve this purpose.

Why not? The same script that can put a domain on a blacklist based on the age of the domain registration can easily remove it from the blacklist based on the same criteria. Run the script once a day and check everything in the blacklist, or have a separate table that the script creates and when the time is up on an item, remove it from the blacklist the next time the script runs.

---

<div class="post-metadata">

**Author:** ![slawa](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/slawa/32/19727_2.png) [@slawa](https://discourse.pi-hole.net/u/slawa)\
**Post date:** [June 12, 2019, 4:19am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/5 "2019-06-12T04:19:39Z")

</div>

It should be more responsive than once a day, more like right after a non cached request. And that criteria will apply to domains that were blocked manually.

The only way to do it with a script would be to save the blacklisted domains and the time they need to be unblocked again. Basically implementing blacklisting for a period of time that IMHO should also be a feature.

I am not saying solving it with a script is not possible. Just doing it within pi-hole will be more efficient.

Anyway this probably has to wait as other features are more pressing. I just wanted to throw in the idea.

---

<div class="post-metadata">

**Author:** ![pe0mot](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/pe0mot/32/4901_2.png) [@pe0mot](https://discourse.pi-hole.net/u/pe0mot)\
**Post date:** [June 13, 2019, 6:39am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/7 "2019-06-13T06:39:44Z")

</div>

I support your request slawa.  
Funny DNS names are getting a serious problem, not just for malicious but also for add sites.  
The last month I checked a few new ones, they were not blocked by using upstream OpenDNS or Quad9.  
Upstream filtering is only done if half the world starts complaining 🙂 .  
So yes, I believe it's a great optional feature for PiHole.

---

<div class="post-metadata">

**Author:** ![slawa](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/slawa/32/19727_2.png) [@slawa](https://discourse.pi-hole.net/u/slawa)\
**Post date:** [June 20, 2019, 2:50am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/8 "2019-06-20T02:50:22Z")

</div>

Another example where this feature will help and is in scope of Pi-Hole.

There are some websites that use aggressive ads tactics.  
They serve their **ads from a new domain they create every few days**.

I block the ad domain and few days later the ads pop up again.  
I can effectively block it on Desktop with addons.  
But some mobile phones can not use uBlock.

Here are the sites:  
**[WARNING!] Ads are NSFW**

> **Ads are NSFW**
>
> [https://m.zhuishubang.com/83201/31435645.html](https://m.zhuishubang.com/83201/31435645.html)
> 
> [https://m.biquge.com.cn/book/32715/366984\_2.html](https://m.biquge.com.cn/book/32715/366984_2.html)

---

<div class="post-metadata">

**Author:** ![DanSchaper](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/danschaper/32/91_2.png) [@DanSchaper](https://discourse.pi-hole.net/u/DanSchaper)\
**Post date:** [June 20, 2019, 3:11am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/9 "2019-06-20T03:11:02Z")

</div>

And why would regex blocking not work in these cases?

---

<div class="post-metadata">

**Author:** ![slawa](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/slawa/32/19727_2.png) [@slawa](https://discourse.pi-hole.net/u/slawa)\
**Post date:** [June 20, 2019, 3:20am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/10 "2019-06-20T03:20:12Z")

</div>

It works for a few days. Ads come from new domains after a while. And the circle begins.

I have a dozen domains blocked that were used for ads. And new domains keep coming.  
Usually they use a script that tries 3-4 domains to display ads.

---

<div class="post-metadata">

**Author:** ![jpgpi250](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jpgpi250/32/286_2.png) [@jpgpi250](https://discourse.pi-hole.net/u/jpgpi250)\
**Post date:** [June 21, 2019, 2:37pm UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/11 "2019-06-21T14:37:39Z")

</div>

Not sure this will help,

Found [this](https://dnpedia.com/tlds/daily.php) site. If somebody is capable of generating lists from this site, you could add them to your blocklists, on a daily base.

---

<div class="post-metadata">

**Author:** ![slawa](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/slawa/32/19727_2.png) [@slawa](https://discourse.pi-hole.net/u/slawa)\
**Post date:** [July 1, 2019, 5:50am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/12 "2019-07-01T05:50:23Z")

</div>

There a so many new domains created. This would be overkill.  
And then it should not block them permanently, just for specified amount of time.

Here are some specifics what I am thinking about:

- There should be a cache of already checked domains. This can use the cache the pi-hole already has and add a flag [creation\_date\_checked:true/false]. This will save whois calls on frequently used domains.

- Add a new table to the local database that handles a temporary block list. This can be a useful feature for the whole project. e.g. you can block Facebook for a week without the need to manually unblock.

- Add a function that will run separately after domain resolution:

1. Check if domain in cache and has true flag
2. Check WHOIS Creation Date on cache miss
3. If new domain, add to temporary block list with the desired duration (Creation Date + new domain block length from the settings)
4. Domain will be automatically unblocked after temporary block expiry

In the Setting you should be able to specify for how long domains will be blocked after their registration.

This will help block DGA domains. Ad domains can circumvent it buy buying random old domains for cheap, instead of registering new ones.

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [July 2, 2019, 4:47pm UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/13 "2019-07-02T16:47:08Z")

</div>

> [@slawa](#):
>
> Domains that are less than a week old should be pi-holed. After that period of time the domain should be accessible.

This sounds more like a request for a new list than a feature for Pi-hole.

> [@slawa](#):
>
> A script that will blacklist domains can not serve this purpose. Maybe that solution can be considered when we get an option to blacklist domains for a certain period of time and not permanently.

You could write a script that does this by itself. In the current `development` version of Pi-hole (and the next v5.0 release), we store the creation date of blacklist values.

You may also want to read this discussion:

> <https://github.com/pi-hole/FTL/issues/596>
>
> \*\*In raising this issue, I confirm the following (please check boxes, eg \[X\]) Fa…ilure to fill the template will close your issue:\*\*
> 
> \- \[X\] I have read and understood the \[contributors guide\](https://github.com/pi-hole/pi-hole/blob/master/CONTRIBUTING.md).
> \- \[X\] The issue I am reporting can be \*replicated\*
> \- \[X\] The issue I am reporting isn't a duplicate 
> 
> \*\*How familiar are you with the codebase?:\*\*
> 
> \_{7}\_
> 
> \---
> 
> \*\*\[BUG | ISSUE\] Expected Behaviour:\*\*
> N/A
> 
> \*\*\[BUG | ISSUE\] Actual Behaviour:\*\*
> N/A
> 
> \*\*\[BUG | ISSUE\] Steps to reproduce:\*\*
> N/A
> \-
> \-
> \-
> \-
> 
> \*\*Log file output \[if available\]\*\*
> 
> N/A
> 
> \*\*Device specifics\*\*
> 
> Hardware Type: rPi, VPS, etc
> OS: N/A
> 
> 
> \_This template was created based on the work of \[\`udemy-dl\`\](https://github.com/nishad/udemy-dl/blob/master/LICENSE).\_
> 
> Reaching out to see if there is any interest in adding support to help stop malware. The code I am referring to can be found here. This idea is something I started working on 4 years ago and thanks to krisives, have a demo of the idea.
> https://github.com/krisives/dnsmasq-sqlite
> 
> Pi-hole obviously supports blacklists, but it does not support massive whitelists. Right now, if a DNS request is made to any of the potentially malicious domains found here, https://phishstats.info/phish\_score.txt, it will only be blocked if the domain is on a blacklist. The way https://github.com/krisives/dnsmasq-sqlite works is it imports the 10 million domains from here: https://www.domcop.com/top-10-million-domains or a much larger 400 million set from here: http://commoncrawl.org/connect/blog/ (searchable here http://wwwranking.webdatacommons.org/ )
> 
> As an example, if you select any domain from the top of this list: https://phishstats.info/phish\_score.txt , pi-hole will only block it if the domain is found on a recently updated blacklist. Since krisives's code requires the domain to have some amount of popularity in order to resolved, it likely wouldn't resolve the domain because it doesn't trust domains with a extremely low harmonic page rank score.
> 
> Note because blocking a domain could create a serious problem for someone using pi-hole in a business network, I am leaning more toward alerting and not blocking until edge cases are more thoroughly tested. Let me know if this is something that anyone would want added to pi-hole.

Also in the current `development` version, we now support massive whitelists. The idea of above's discussion is that they want to permit the, say, top 10 million domains with sufficient "reputation" (however you measure that) and block everything else.

---

<div class="post-metadata">

**Author:** ![Metta\_Crawler](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/metta_crawler/32/1959_2.png) [@Metta\_Crawler](https://discourse.pi-hole.net/u/Metta_Crawler)\
**Post date:** [August 21, 2019, 9:18pm UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/14 "2019-08-21T21:18:00Z")

</div>

It's naive to think WHOIS will always output "Creation Date". Try running WHOIS on yandex.ru for example and it says "created" instead of "Creation Date". There is no standard WHOIS output format. I could not find any way to specify the creation date as an attribute but it might be possible.

The issue with newly-created domains is getting more attention:  
[https://unit42.paloaltonetworks.com/newly-registered-domains-malicious-abuse-by-bad-actors/](https://unit42.paloaltonetworks.com/newly-registered-domains-malicious-abuse-by-bad-actors/)

---

<div class="post-metadata">

**Author:** ![drego85](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/drego85/32/5830_2.png) [@drego85](https://discourse.pi-hole.net/u/drego85)\
**Post date:** [February 18, 2020, 10:17am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/15 "2020-02-18T10:17:32Z")

</div>

[Nextdns.io](https://Nextdns.io) has introduced a very useful function to fight Phishing and Malware: the blocking of domains registered for less than 30 days.

New domains are often used to spread Phishing or Malware in Ad Hoc campaigns.

I think this function is very useful, I would also like to see it on Pi-Hole.

Thanks

---

<div class="post-metadata">

**Author:** ![Bucking\_Horn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/bucking_horn/32/18719_2.png) [@Bucking\_Horn](https://discourse.pi-hole.net/u/Bucking_Horn)\
**Post date:** [February 18, 2020, 10:30am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/16 "2020-02-18T10:30:10Z")

</div>

Pi-hole provides just the means to filter DNS traffic, not the filters themselves.

You are free to configure Pi-hole to use any blocklist of your choice, so you can implement this straight away by employing a corresponding blocklist.

With regards to the idea itself, I am skeptical whether this is a viable approach.  
AFAIA, there are no binding standards guiding how a registrar should store and alter registration information, nor which parts of that information is made accessible, nor how that is done.

In addition, it leaves to consider what defines a newly registered domain, as e.g. change of ownership from a trustworthy to a malevolent site content provider does not necessarily change that site's _registered on_ date.

---

<div class="post-metadata">

**Author:** ![DanSchaper](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/danschaper/32/91_2.png) [@DanSchaper](https://discourse.pi-hole.net/u/DanSchaper)\
**Post date:** [February 18, 2020, 6:43pm UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/17 "2020-02-18T18:43:35Z")

</div>

> [@drego85](#):
>
> I think this function is very useful, I would also like to see it on Pi-Hole.

Great news then, you've always been able to do that with Pi-hole. Just add the list of the domains and they will be blocked. Starting with version 5 they will even be blocked when they appear as CNAMEs.

---

<div class="post-metadata">

**Author:** ![slawa](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/slawa/32/19727_2.png) [@slawa](https://discourse.pi-hole.net/u/slawa)\
**Post date:** [February 19, 2020, 12:36am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/18 "2020-02-19T00:36:57Z")

</div>

The point of the feature is that such a list is automatically generated from the domains the users of pi-hole visit and domains that are out of age threshold are automatically removed from being blocked.

Suggestion to 'manually' create such a list has issues:

- creating a list of all newly registered domains worldwide is difficult (cooperation from registrars is required?)
- such a list including all new domains would be large and overkill for this task ([11+ million new domains every 90 days](https://unit42.paloaltonetworks.com/newly-registered-domains-malicious-abuse-by-bad-actors/) some only active for a few hours)
- there would be one point of failure if the host of such list goes down since that list needs to be constantly updated (like every hour) to be effective
- pi-hole updates lists automatically only once a week!
- a list can only have domains with one age threshold (non variable)

I see the problem that WHOIS responses do not always include creation date or name it differently. Over long term registrars would be inclined to provide it to prevent abuse.

---

<div class="post-metadata">

**Author:** ![DanSchaper](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/danschaper/32/91_2.png) [@DanSchaper](https://discourse.pi-hole.net/u/DanSchaper)\
**Post date:** [February 19, 2020, 1:26am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/19 "2020-02-19T01:26:31Z")

</div>

If we had to do a WHOIS check and evaluation for every client DNS name query then latency would be on the order of seconds per query.

---

<div class="post-metadata">

**Author:** ![slawa](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/slawa/32/19727_2.png) [@slawa](https://discourse.pi-hole.net/u/slawa)\
**Post date:** [February 19, 2020, 2:51am UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/20 "2020-02-19T02:51:31Z")

</div>

> [@slawa](#):
>
> - There should be a cache of already checked domains. This can use the cache the pi-hole already has and add a flag [creation\_date\_checked:true/false]. This will save whois calls on frequently used domains.
> - Add a new table to the local database that handles a temporary block list. This can be a useful feature for the whole project. e.g. you can block Facebook for a week without the need to manually unblock.
> - Add a function that will run separately after domain resolution:
> 
> 1. Check if domain in cache and has true flag
> 2. Check WHOIS Creation Date on cache miss
> 3. If new domain, add to temporary block list with the desired duration (Creation Date + new domain block length from the settings)
> 4. Domain will be automatically unblocked after temporary block expiry
> 
> In the Setting you should be able to specify for how long domains will be blocked after their registration.

I mentioned before that for performance this should run separately after DNS request. But it will result in the very first domain request not being blocked. This is not ideal as malware might only request the DNS resolution from cnc servers once, but for other use cases it is enough.

---

<div class="post-metadata">

**Author:** ![Bucking\_Horn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/bucking_horn/32/18719_2.png) [@Bucking\_Horn](https://discourse.pi-hole.net/u/Bucking_Horn)\
**Post date:** [February 19, 2020, 12:23pm UTC](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/21 "2020-02-19T12:23:57Z")

</div>

I try to elaborate on my previous post:

The whole WHOIS protocol lacks proper standardisation, e.g. it does not guide encoding at all -neither for queries nor for the requested content- which would be a prerequisite for internationalisation, many of the data are not required to be well-formed (e.g. data might be labeled differently by different providers or not have the same semantics tied to it), there is no standard for determining the authoritative WHOIS server for a given domain name, possibly leaving you with no or incomplete information, etc.  
(Just do a whois on `google.com` and `heise.de` to get an idea of what I am talking about, and mind that output would also differ by the whois binary in use.)

Worse still, to my knowledge, access to the data you wish to scrutinize here is currently not standardized at all, nor are registrars obliged to offer programmatical access to that data for free (afaik, only mailing and email address as well as phone number are required to be publically available - but subject to be adopted to latest GDPR requirements).

They also commonly enforce rate limits on the amount of queries they would allow from an IP address, or may offer to lift such limits for a fee.

As accessing and correctly extracting or interpreting that data is tricky, numerous service providers have established a business around this by offering access to well-formed proprietary APIs.  
So rather than wasting resources on redeveloping something that is already available, Pi-hole offering integration with one of those APIs could be an option.

However, employing such a service would require you to enter a contract with the provider of your choice (e.g. [50 bucks for requesting max 24k domains](https://whoapi.com/documentation/api/whois#api-function-pricing) - per month, that is).  
And then there may be additional contractual obligations, e.g. no permission to store requested data locally, which would restrict you from caching data over a prolongued period, that in return would have to be honored by Pi-hole in order to not make you transgress those obligations.

All of this to block you from accessing the website your friend has just started when opening her new cafe?

Why just block new domains? And why suddenly allow them after some 30 days? I doubt that 'new' domains are any more or less trustworthy than existing ones (avoiding having to define the exact meaning of 'new') or -if they are malevolent- that they would cease being so after an arbitrary period of time.

When operating at that level of confidence or mistrust, maybe employing a deny all strategy would be worth considering, and certainly easier to implement.

[Next page](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700.md?page=2)
