I find it interesting that within a couple of days of registering this domain name, nicos.tips, and changing the DNS records over to Cloudflare, Cloudflare was recording quite a bit of unexpected traffic.

The only entities that should know the name at this point were me, the domain registrar I used, Omnis, and Cloudflare. Anything else would be from observed network traffic, DNS requests, or something else.

What is going on here?
In my experience, it’s quite normal to see external hosts attempting to connect, port scan, or brute-force URLs after a server responds to network scanning across broad IP ranges. The interesting part here is that Cloudflare’s report means those connections originated from someone looking up the domain name. Why would anyone be doing a DNS lookup on nicos.tips at this point? Where would they have gotten the name?
A brand-new domain is also ripe for attack. People and businesses are just getting started, new software may not yet be locked down, and temporary credentials can be weak—or absent altogether.
My first guess was that Cloudflare’s own internal services were doing some kind of scanning or probing. Still, Cloudflare described some of the activity as a “prevented attack.”
I wasn’t aware of any facility that openly advertises new domain registrations. The owner of the .tips TLD is Identity Digital (previously Donuts Inc.), which manages a huge number of top-level domains.
The investigation continues in The lists are out there.