The “bad” domains have something in common.

Update: DomainTools has temporarily removed its report from publication to address and verify certain calculations. Their official statement reads:
We are investigating a possible error in one of the data inputs we use for this seasonal Domain Report and until we can remediate our concern we are choosing to suspend the previously published version.
The potential impact of this revision on the reported rankings and overall conclusions remains uncertain. This article will be updated promptly once DomainTools officially republishes its revised report.
Unmasking the Culprits: DomainTools Report Shines Light on Abused TLDs
In the relentless battle against cybercrime, understanding the patterns of abuse is paramount. Cybersecurity firm DomainTools recently released its Spring 2022 Report, a critical analysis that identifies and highlights Top-Level Domains (TLDs) disproportionately utilized for malicious activities. This comprehensive report, initially published and now under review, provides invaluable insights into the landscape of domain abuse, specifically targeting TLDs that are overrepresented in the realm of “badness.”
Beyond Raw Numbers: A Deeper Look at Domain Abuse Methodology
Unlike traditional reports that might simply count the sheer volume of malware, phishing, or spam domains, DomainTools employs a more nuanced and insightful methodology. Their analysis focuses on the prevalence of malicious usage compared to the total number of domains registered within a particular TLD. This approach offers a clearer picture of how susceptible a TLD is to abuse, rather than just highlighting those with the largest overall domain count. A TLD with millions of registrations might have a high absolute number of bad domains, but if its prevalence of abuse is low, it suggests better overall health compared to a smaller TLD where a significant percentage of its domains are malicious. This “signal strength” metric allows for a more equitable comparison across diverse TLDs, revealing true hotspots of cybercriminal activity.
The Unmistakable Pattern: Free and Cheap Domains Fuel Cybercrime
The core finding of the DomainTools report is both stark and consistent: TLDs that offer domains for free or at exceptionally low prices are overwhelmingly the most abused. This isn’t a new phenomenon; it’s a trend that has persisted for years and shows no signs of abating. Cybercriminals, driven by the desire for low cost, anonymity, and ease of access, flock to these budget-friendly options to establish their malicious infrastructure. The economics of cybercrime dictate that minimizing operational costs for setting up phishing sites, distributing malware, or sending spam maximizes potential illicit gains. Therefore, registries that make domain registration incredibly affordable inadvertently create an attractive environment for malicious actors.
This pattern extends beyond just domain registrations. Similar trends can be observed in other internet resources. For instance, services that offer free SSL certificates, such as Let’s Encrypt, sometimes appear in DomainTools’ “badness” reports related to SSL usage. It’s crucial to understand that this is not an indictment of these services, which provide immense value to legitimate users and help secure the web. Instead, it underscores a broader principle: any widely available, free, or low-cost internet resource can become a target for exploitation by those with malicious intent, seeking to leverage legitimate services for illegitimate purposes.
The Vicious Cycle: Damage Done Before Cleanup
While some TLDs listed in these reports actively work to combat abuse, their efforts often face an uphill battle. Many registries invest in sophisticated systems and collaborate with security researchers to identify and suspend malicious domains. However, the sheer speed and scale of cyberattacks mean that by the time a domain is flagged and added to a phishing or malware blocklist, a significant amount of damage may have already been inflicted. Victims might have had their credentials stolen, their systems infected, or their inboxes inundated with spam. This highlights the reactive nature of many current abuse mitigation strategies, underscoring the need for more proactive measures.
Case Study: The Persistent Challenge of .xyz
Consider the example of the .xyz TLD. Despite employing proactive strategies, including extensive blocklists and an internal system for monitoring abuse, and being known for quickly suspending misused domains, .xyz consistently ranks high on DomainTools’ lists for malicious activity. The report specifically noted concerning statistics for .xyz:
Sorry, .xyz, but your reputation in the infosec community is what it is for a reason. In the Malware category, we observed over 323,000 domains in .xyz, a significant uptick from its previous showing of a still-substantial ~207,000. Couple this with the signal strength of 108.60, and it becomes especially clear why this TLD has the reputation it does.
For context, a “signal strength” of 1.0 in the DomainTools report is considered neutral. Anything below 1.0 indicates a positive reputation, while anything above it signifies a negative one. A signal strength of 108.60 is exceptionally high, indicating a severe prevalence of malware activity within the .xyz namespace. In response to these findings, XYZ publicly stated to Domain Name Wire, “We have reached out to DomainTools to discuss their report. We dispute their findings, and would love to cooperatively work together to clear up any misconceptions.” This exchange highlights the ongoing dialogue and challenges in accurately assessing and addressing domain abuse.
Other Notorious TLDs in the Crosshairs
While .xyz frequently appears across multiple categories, other TLDs claim the top spots in specific areas of abuse. According to the DomainTools report, .buzz emerged as the worst offender for phishing attacks, indicating its preferred status among those seeking to deceive internet users. For spam, .cam unfortunately topped the list. It might surprise some that .cam isn’t higher in the phishing category given its visual similarity to the highly trusted .com domain. However, the report’s methodology emphasizes prevalence and cost-effectiveness over mere visual deception. Phishers, in their pursuit of scale, often prioritize the cheapest available domains rather than those most likely to visually “dupe” people, especially when operating on a mass scale.
Furthermore, several free domain offerings from Freenom also consistently feature on these lists. These include .ml, .ga, .cf, and .gq, all notorious for their high rates of abuse. Interestingly, .tk, another popular free domain from Freenom and arguably its most-registered TLD, might escape the very top of these specific “badness” lists due to DomainTools’ unique methodology. The sheer volume of legitimate registrations on .tk, while still hosting numerous malicious domains, could dilute its “prevalence” score compared to smaller TLDs that have a higher percentage of bad domains relative to their total registrations.
The Broader Impact: Erosion of Trust and Security Risks
The widespread abuse of certain TLDs carries significant consequences, extending far beyond the immediate victims of cyberattacks. For internet users, it translates into a heightened risk of encountering phishing scams, malware infections, and relentless spam, leading to financial losses, data breaches, and compromised online security. For legitimate businesses, the problem is multifaceted: their brand reputation can suffer if their genuine communications are confused with malicious activity originating from similar-sounding domains on abused TLDs. Moreover, domains on such TLDs often face lower email deliverability rates, as spam filters become more aggressive, and trigger more frequent security warnings in browsers and security software. This ultimately makes these TLDs less desirable and less trustworthy for all registrants, even the innocent ones.
Ultimately, the continuous presence of high-abuse TLDs erodes overall trust in the internet’s infrastructure. When users become overly cautious or suspicious of certain domain extensions, it disrupts the seamless flow of information and commerce that is fundamental to the digital economy. This erosion of trust necessitates proactive measures from all stakeholders to maintain a secure and reliable online environment.
Incentives and Solutions: A Path Towards Cleaner Domains
Given the long-term repercussions, TLD operators have strong incentives to address and mitigate abuse. TLDs that consistently appear on “badness” lists risk diminished appeal for legitimate registrants, decreased trust from security vendors, and potentially lower overall market value. To counter this, operators have several strategic options:
- Investment in Proactive Suspension Systems: Moving beyond reactive cleanups, TLD operators can invest heavily in advanced, AI-driven monitoring and analytics systems capable of identifying suspicious registration patterns and domain behavior in real-time. These systems could flag potential abuse *before* it becomes widespread, allowing for quicker suspensions and disruption of malicious campaigns at their inception. This includes leveraging machine learning to predict and prevent abuse based on historical data and emerging threat intelligence.
- Strategic Price Adjustments: A seemingly simple yet potentially effective measure is to strategically raise first-year registration prices by a few dollars. While this might seem counterintuitive for “cheap” TLDs, even a modest price increase can significantly deter cybercriminals who rely on registering thousands of domains at minimal cost. This slight barrier to entry can make large-scale abuse campaigns less economically viable for malicious actors, without making domains prohibitively expensive for legitimate small businesses or individuals.
- Enhanced Collaboration: Effective abuse mitigation requires robust collaboration. TLD registries must work closely with registrars, cybersecurity firms (like DomainTools), law enforcement agencies, and other industry bodies. Sharing threat intelligence, implementing standardized abuse reporting mechanisms, and coordinating rapid responses are crucial for creating a safer domain ecosystem.
The Path Forward: Building a Safer Digital Landscape
The findings from reports like DomainTools’ Spring 2022 edition serve as a critical reminder of the ongoing challenges in maintaining a secure and trustworthy internet. While the internet offers unprecedented opportunities, it also provides fertile ground for malicious activities, often leveraging the very mechanisms designed for accessibility and growth. By understanding which TLDs are most abused and why, and by implementing proactive and collaborative strategies, TLD operators, registrars, and the cybersecurity community can collectively work towards a cleaner, safer, and more reliable online experience for everyone. The journey to mitigate domain abuse is continuous, requiring vigilance, innovation, and a shared commitment to digital security.
Top 5 Abused TLDs by Category (According to DomainTools)
Here are the TLDs identified as the top 5 worst in each category, based on DomainTools’ analysis, reflecting their prevalence of malicious activity:
Phishing
- .buzz
- .gq
- .ga
- .rest
- .ml
Malware
- .xyz
- .cc
- .buzz
- .cfd
- .cyou
Spam
- .cam
- .bar
- .surf
- .xyz
- .click