Skip to content
Tech News
← Back to articles

DNS abuse and criminal infrastructure

read original more articles
Why This Matters

The significant presence of malicious actors controlling a notable portion of new gTLD registrations highlights ongoing challenges in DNS security and abuse mitigation. This issue underscores the need for the tech industry and domain registries to reevaluate their measures and policies to better prevent misuse and protect consumers. Addressing DNS abuse is crucial for maintaining trust and security in the evolving internet infrastructure.

Key Takeaways

Evidence suggests that criminals may control a substantial share of new gTLD registrations. Although the precise scale remains contested, the article asks whether current DNS Abuse measures adequately address wider misuse of domain names.

The scale of malicious registrations

According to research published by Interisle Consulting Group, cybercriminals registered a significant share of new domain names in 2025, representing a substantial portion of the generic top-level domain (gTLD) market.

The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis. It estimated that, taking account of subsequent blocklisting and associated domains not themselves blocklisted, the share of names registered by malicious actors may be closer to 20%.

In a follow-up presentation at the ICANN 86 Policy Forum, Greg Aaron and Karen Rose of Interisle stated that malicious actors may have registered approximately 20% of gTLD names created in 2025. They further reported that 10% of domains registered during 2025 had already appeared on blocklists and estimated that later blocklisting could raise the directly observed proportion to around 12%. In support of that projection, they cited ICANN research indicating that, for every three domains appearing on blocklists, two additional associated domains may remain unlisted.

Any industry confronted with evidence that a material share of its output may be controlled by bad actors should be seriously concerned. It should examine whether its commercial incentives, operational practices, and contractual arrangements inadvertently enable criminals to acquire, use and profit from its products or services at scale.

Definitions and methodologies

ICANN org has since published a blog post by members of its Office of the CTO (OCTO). The post argues, reasonably, that estimates of malicious registrations depend on the definition of "abuse", the standard of evidence applied, and the analytical method used. In particular, it cautions against treating every reported or blocklisted domain as automatically constituting confirmed DNS Abuse.

The post also emphasises that ICANN's contractual definition of DNS Abuse is deliberately limited to botnets, malware, pharming, phishing, and spam when spam serves as a delivery mechanism for one of the preceding harms. It argues that broader categories (including fraud, scams, and spam that does not facilitate these enumerated harms) should be identified separately in analysis. The authors further criticise the Interisle report for referring to methods associated with ICANN and COMAR without sufficiently explaining departures from those methods. They also point to ongoing policy development work concerning associated domain checks and safeguards for high-volume registrations.

Those methodological and definitional questions are important. They affect what can properly be claimed about the scale of confirmed DNS Abuse and the comparability of different studies. However, they do not by themselves resolve the broader concern raised by the Interisle findings: that a substantial proportion of newly registered gTLD names may be under the control of actors engaged in, or supporting, malicious activity.

... continue reading