The Dark Side of the DNS: Why 1 in 5 New Domains Might Be Dangerous

The Dark Side of the DNS: Why 1 in 5 New Domains Might Be Dangerous

Sep 07, 2026 dns security domain fraud web hosting phishing cybersecurity ssl certificates domain registrar internet safety malware startup security

The Dark Side of the DNS: Why 1 in 5 New Domains Might Be Dangerous

Every second, dozens of domains are registered somewhere in the world. Someone launches a startup. A developer spins up a portfolio. A scammer sets up another phishing page designed to steal credentials. The process is identical for all of them—a few clicks, a payment, and suddenly there's a new address on the internet.

The speed and accessibility of domain registration is genuinely remarkable. It's one of the things that makes the modern web so dynamic. But that same accessibility has a shadow side that the industry has struggled to address.

The Numbers Are Staggering

A recent analysis by Interisle Consulting Group examined generic top-level domains (gTLDs)—the .coms, .websites, and .funs of the world—and found something alarming. Of the 85 million new domain registrations in 2025, approximately 8.5 million appeared on security blocklists by May. That's 10% flagged as malicious. But researchers believe the actual figure is closer to 20% when accounting for domains not yet detected or associated with flagged sites.

Let that sink in. One in five newly registered domains with a gTLD is likely involved in scams, malware distribution, or other criminal activity.

Some TLDs are worse than others. Thirteen top-level domains had over half of their registrations appear on blocklists. Predictably, domains like .bid and .loan—often used for fake banking and payment scams—showed extremely high abuse rates. But the presence of TLDs like .mobi on that list suggests the problem isn't limited to obviously suspicious extensions.

Why Registrars Struggle to Keep Up

At NameOcean, we take domain security seriously. We implement safeguards, monitor for abuse patterns, and work to ensure our platform isn't used for harmful purposes. But here's the uncomfortable truth: no registrar can catch everything, and the economics of the situation favor attackers.

When a malicious actor registers a domain for a phishing campaign, they often use it for just 24-48 hours. They send out millions of spam emails, harvest credentials from unsuspecting victims, and abandon the domain before most blocklists can react. By the time our abuse team or external security services flag the domain, the damage is done.

This is what DNS abuse looks like in practice:

  • Phishing domains that impersonate banks, government services, or popular brands
  • Malware distribution sites disguised as software downloads or updates
  • Command-and-control domains used by botnets
  • Typosquatting domains that exploit common misspellings (think "g00gle.com" or "paypa1.com")

The internet moves at the speed of light. Abuse moves faster.

What Actually Works?

The research highlights that suspension rates for blocklisted domains range from just 7.4% to 16.3%—meaning most malicious domains remain active even after being flagged. This suggests the current reactive approach isn't working.

So what could change the equation?

Better registrar policies would be a start. Several major registrars have been criticized for having weak abuse handling or even knowingly hosting scam domains. Registrars who invest in proactive monitoring, faster response times, and stricter terms of service can meaningfully reduce abuse on their platforms.

Domain reputation systems similar to email sender scores could help. If a newly registered domain has no history, no hosting footprint, and appears only in DNS records with suspicious patterns, browsers and email providers could treat it with appropriate suspicion.

Extended validation (EV) SSL certificates remain underutilized. While they won't stop all abuse, they add a layer of verification that makes impersonation harder. Businesses serious about security should consider EV certs for their domains.

For website owners and developers, vigilance is essential:

  • Monitor your brand — Set up alerts for domains suspiciously similar to yours
  • Use domain locking — Prevent unauthorized transfers
  • Enable two-factor authentication — Protect your registrar account
  • Check your DNS regularly — Ensure no unauthorized records have been added

The Bigger Picture

DNS was designed for connectivity, not security. It was created in an era when the internet was a small community of trusted institutions. The fact that it's become a primary attack vector isn't a design flaw—it's a consequence of success. DNS works so well that criminals naturally gravitate toward it.

But the solution isn't to make domain registration harder for legitimate users. Startups need to launch quickly. Developers need to experiment. Activists and journalists in repressive regimes need access to anonymous registration for their safety.

The balance between openness and security is genuinely difficult. Registrars, registries, browsers, and security researchers all have roles to play. At NameOcean, we're committed to doing our part—investing in abuse detection, supporting industry initiatives, and educating our customers about security best practices.

The internet's address system is a remarkable achievement. It deserves a security model that matches its ambition.


The bottom line? When you're browsing the web and encounter a suspicious domain, trust your instincts. When you're building your own web presence, treat your domain like the valuable asset—and potential attack surface—it is. The DNS might be the internet's phone book, but it's also, unfortunately, a scammer's playground. Stay alert out there.

Read in other languages:

RU BG EL UZ CS TR FI RO SV PT HU NB PL NL IT FR DA ES ZH-HANS DE