New study suggests 10% to 20% of domains are registered for bad purposes, but it might be even higher.

Every month, roughly eight to ten million domain names are created. A significant portion of those registrations is used for malicious activity such as phishing, malware distribution, spam, or fraud. Estimates vary, but researchers and industry analysts consistently warn that the problem is widespread and growing.
Interisle’s recent report found that around 10% of generic top-level domains (gTLDs) registered in 2025 were later placed on blocklists. The organization notes that most of these additions reflect domains that were intentionally registered for abuse rather than legitimate sites that were compromised after registration. Based on patterns and other signals, Interisle estimates the true share of registrations by bad actors may be closer to 20%.
Independent measurements point to potentially higher rates. WhoisXML API, which monitors roughly 8–10 million new registrations each month, has estimated that about one in four new domain registrations overall is created with malicious intent. These differing estimates highlight the challenge of measuring abuse precisely, but both sources agree that abuse is a major portion of new registrations.
New and low-cost top-level domains attract more abuse than established ones. Interisle reports that only 4.9% of .com and 4.0% of .org domains registered last year were later added to blocklists, while some newer gTLDs show far higher rates. For example, approximately 35% of .top domains registered in the same period ended up on blocklists. Even more striking, Interisle found that 63% of .mobi registrations from last year were flagged and placed on blocklists.
Smaller and niche TLDs can show even higher abuse proportions, often driven by low registration costs and limited registry oversight. Research published last year found a strong correlation between price and abuse: for every dollar decrease in registration fees, malicious registrations increased by an estimated 49%. This economic incentive helps explain why attackers gravitate to cheap, easily obtained domains.
Registrars also differ widely in how many of their new registrations are later associated with abuse. Interisle’s analysis highlights that a notable share of registrations at certain registrars ended up on blocklists. For example, around a third of registrations at Gname from last year were flagged, while other registrars showed substantially higher rates—NiceNic at 88%, MainReg Inc at 86%, and Aceville at 83%.
By contrast, several large, well-known registrars tend to have much lower proportions of their new registrations added to blocklists. GoDaddy, GMO, Newfold Digital, and Tucows were among those with rates below 5%, reflecting stronger abuse mitigation practices, higher prices, and stricter verification or policy enforcement in many cases.
Taken together, these findings underline persistent structural drivers of domain abuse: low-cost registrations, emerging or lightly regulated TLDs, and registrars that do not aggressively police abuse. Addressing the problem will require better data sharing, stronger verification and vetting at registration, price and policy adjustments for vulnerable TLDs, and continued monitoring to identify and take down domains used for harmful purposes.
While precise figures vary by methodology, the consensus is clear: a notable fraction of new domain registrations are tied to criminal or abusive activity, and targeted measures are needed across registries and registrars to reduce that share.