Zero-Click Scams Persist, Exploiting Wildcard .ph Domains

Domains using zero-click monetization continue to forward to scam sites.

Image of a scam site for apple support
A zero-click redirect went to this fake Apple Support site.

Tech support scams continue to exploit zero-click monetization networks, including large wildcarded namespaces such as the .ph country-code domain. These scams present a persistent threat to users who type or mistype domains and are automatically forwarded to malicious pages without clicking any advertisements.

Zero-click monetization is a traffic delivery model that routes visitors directly to landing pages based on domain requests rather than relying on user clicks on traditional ads. After Google closed its AdSense for Domains program, the ecosystem shifted and third-party monetization providers filled the gap. That shift has increased the importance of zero-click traffic in the domain parking and monetization market.

Reports and research differ on how much of this redirected traffic reaches scam or malware-hosting pages, but there is broad agreement that a significant portion of zero-click traffic ends up on risky or deceptive sites. The issue has persisted for years and remains difficult to eradicate because of how these networks and redirects operate.

My own observations over recent days reinforce the ongoing problem: several domains forwarded through zero-click services resolved to fake tech support pages that claim a visitor’s computer is infected. In some cases a user’s browser froze as these pages attempted to coerce immediate action. The problematic domains were handled by various monetization name servers, including some operated by major providers.

One especially concerning factor is wildcarding. When an entire namespace is wildcarded, any unregistered domain in that space can be automatically monetized. The .ph namespace is one such example where unregistered names appear to be monetized by default, and an increasing number of those resulting destinations lead to scam pages.

Part of the difficulty in policing these networks stems from multi-stage redirects. A monetization provider may vet an initial advertiser or landing page, but after approval the advertiser can change redirect chains downstream. Each additional redirect introduces another opportunity for the traffic to be routed to deceptive or harmful content, and tracing responsibility across multiple intermediaries becomes complex.

Another complication arises when companies split-test traffic across multiple parking or monetization platforms. A parking service that receives forwarded traffic may itself use zero-click monetization for some of its inventory, effectively passing traffic through multiple monetizers. That layering makes it harder for any single company to guarantee the final destination is safe.

The scam illustrated in the image above used a free subdomain hosted through a service that provides temporary or convenience subdomains to customers. Using free subdomains of well-known host domains to run scams has been observed more frequently; attackers leverage that credibility to make fraudulent pages appear legitimate.

In several encounters the landing URL indicated traffic was flowing through a known advertising network, yet other domains resolved to different scam infrastructure. For example, I found a registered domain where the root returned a 404 error but a specially configured subdomain served a scam page. That domain was registered through a registrar that has been criticized by security researchers in the past, which highlights how registrars, monetization platforms, and hosting providers are all part of the broader ecosystem where abuse can occur.

Mitigating zero-click abuse requires coordinated action among registrars, monetization providers, hosting platforms, and security researchers. Practical steps include stricter vetting of landing pages, continuous monitoring of redirect chains, rapid takedown procedures when abuse is detected, and better communications between providers when traffic is passed between multiple networks. For end users, exercising caution when visiting unfamiliar domains, keeping browsers and security software up to date, and avoiding providing personal information to unsolicited tech support pages reduces risk.

Zero-click monetization is a useful tool for legitimate traffic management and domain monetization, but without stronger controls and transparency, it will remain an attractive vector for tech support scams and other malicious activities. Industry stakeholders must continue to improve detection and response capabilities to reduce the number of victims exposed through these automatic redirects.