After the customer adds a new custom domain to be monitored it will take effect only on newly observed data starting from the next day.
The Suspicious lookalikes RPZ feed is filled with the findings of the domains monitored.
Infoblox monitor 123+ “common” domains (e.g. Apple, Microsoft, etc. i.e. the most obvious ones)
Infoblox monitor whatever the customer tells us to in “custom RPZ”. Any suspicious results get put into the global suspicious feed.
Infoblox monitor other feeds as well but don't publish the full list.
infoblox.shop
Lookalike
Poor TLD
Aged domain
Abused registrar