NordVPN Promotion

Home / Blogs

DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists

Evidence that malicious actors may control a substantial share of new gTLD registrations is testing ICANN’s definitions, safeguards and capacity to curb abuse at scale.

The Scale of Malicious Registrations

Research published by Interisle Consulting Group1 found that cybercriminals registered a significant share of new domain names in 2025, representing a substantial portion of the generic top-level domain (gTLD) market. The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis. It estimated that, taking account of subsequent blocklisting and associated domains not themselves blocklisted, the share of names registered by malicious actors may be closer to 20%.

In a follow-up presentation at the ICANN 86 Policy Forum,2 Greg Aaron and Karen Rose of Interisle stated that malicious actors may have registered approximately 20% of gTLD names created in 2025. They further reported that 10% of domains registered during 2025 had already appeared on blocklists and estimated that later blocklisting could raise the directly observed proportion to around 12%. In support of that projection, they cited ICANN research indicating that, for every three domains appearing on blocklists, two additional associated domains may remain unlisted.

Any industry confronted with evidence that a material share of its output may be controlled by bad actors should be seriously concerned. It should examine whether its commercial incentives, operational practices, and contractual arrangements inadvertently enable criminals to acquire, use and profit from its products or services at scale.

Definitions and Methodologies

ICANN org has since published a blog post by members of its Office of the CTO (OCTO)3. The post argues, reasonably, that estimates of malicious registrations depend on the definition of “abuse”, the standard of evidence applied, and the analytical method used. In particular, it cautions against treating every reported or blocklisted domain as automatically constituting confirmed DNS Abuse.

The post also emphasises that ICANN’s contractual definition of DNS Abuse is deliberately limited to botnets, malware, pharming, phishing, and spam when spam serves as a delivery mechanism for one of the preceding harms. It argues that broader categories (including fraud, scams, and spam that does not facilitate these enumerated harms) should be identified separately in analysis. The authors further criticise the Interisle report for referring to methods associated with ICANN4 and COMAR5 without sufficiently explaining departures from those methods. They also point to ongoing policy development work concerning associated domain checks and safeguards for high-volume registrations.

Those methodological and definitional questions are important. They affect what can properly be claimed about the scale of confirmed DNS Abuse and the comparability of different studies. However, they do not by themselves resolve the broader concern raised by the Interisle findings: that a substantial proportion of newly registered gTLD names may be under the control of actors engaged in, or supporting, malicious activity.

The Scale of Technology-Facilitated Harm

A domain need not yet appear on a blocklist, or satisfy ICANN’s narrow contractual definition of DNS Abuse, to present a meaningful risk. Domains controlled by criminal actors may be retained for later deployment, used in campaigns not yet detected by reporting systems, or used in technology-facilitated harms falling outside ICANN’s current contractual definition, including fraud, scams, sextortion, and other forms of online deception.

The wider scale of technology-facilitated harm should inform the urgency of this discussion, while not being confused with a claim that every such harm is DNS-enabled. The Global Anti-Scam Alliance estimates that scams caused US$442 billion in global losses during 2025, and reports that the “likelihood of financial loss is notably higher in developing countries”6.

Childlight’s “Into the Light index” also illustrates the scale of online child sexual abuse and exploitation. Its 2026 update reports that approximately one in four children experience online sexual solicitation (including 6.7% during 2025 alone) and that 9% experience online sexual extortion before the age of 18 (2.5% during 2025).7

The above figures from the Global Anti-Scam Alliance and Childlight do not measure the role of domain names in each incident, but they do demonstrate why all relevant parts of the Internet ecosystem should consider whether their systems are being used to enable, sustain, or scale serious harm.

Is This In-Hand?

The existence of legitimate methodological debate must not become a reason for institutional complacency or inaction. Even if the precise proportion of malicious registrations remains uncertain, evidence that criminal actors may control a substantial share of new gTLD registrations warrants a commensurate response.

The ICANN community should therefore examine whether current contractual definitions, preventive obligations, data-sharing arrangements, and enforcement mechanisms can reduce this risk at the necessary scale and speed. That assessment should include the effectiveness of measures before registration, at the point of registration, and after credible evidence of harmful use emerges. It should also consider whether high-volume and otherwise anomalous registration patterns receive appropriate scrutiny, consistent with due process, proportionality, and the legitimate needs of registrants.

Depending on jurisdictional requirements, ccTLD operators may have a clearer mandate and more direct legal basis to act against wider categories of illegal or harmful conduct. If approaches to technology-facilitated harm materially diverge, the community should consider the potential consequences for trust in the gTLD market. For example, this may lead some stakeholders, including governments, registrants and users, to perceive that parts of the DNS ecosystem are offering weaker safeguards against criminal misuse.

A Call to Action

I encourage all parts of the ICANN community to consider whether current contractual obligations, operational measures, and policy proposals are adequate in both scope and pace to address DNS Abuse, and to identify additional actions where necessary. The community should also consider whether the current definition of DNS Abuse is sufficiently broad to support effective action against domain names used to facilitate serious technology-facilitated harms, including fraud, scams, ransomware, and child sexual abuse and exploitation.

Any additional measures should not require ICANN to assume the role of a global content regulator or criminal-law authority. The broader challenge is to respond meaningfully to serious harms without unnecessarily sacrificing openness, privacy, security, interoperability, or user agency. As Heather Flanagan observed in reflecting on IETF 126, technical communities cannot disregard policy concerns, but nor should they incorporate every political demand into technical architecture without considering the consequences.8

The community should instead consider whether contractual and operational arrangements adequately enable registries and registrars to prevent and mitigate misuse of domain-name infrastructure, and to cooperate, where appropriate, lawfully, transparently, and proportionately with competent national authorities addressing wider domain-name-related harms.

Effective, proportionate know-your-customer processes, going beyond superficial telephone-number or email-address validation, are likely to be part of the solution to reducing criminal misuse of domain names. Risk-based KYC checks by registrars could help identify suspicious customers and registration patterns, particularly where accounts register names at high volume or display other indicators of misuse. These measures should protect legitimate registrants while helping registrars prevent repeat abuse and, where justified by credible evidence, act earlier against criminal activity.

Any reform should preserve the distinction between ICANN’s global technical-coordination role and the primary responsibility of national legal and regulatory systems to define and enforce wider categories of illegality. However, that distinction should not prevent the ICANN community from addressing clear evidence that criminals can acquire and deploy domain-name infrastructure at industrial scale.

Finally, the community should state clearly which technology-facilitated harms it considers outside ICANN’s remit, and why. This clarity would support timely coordination between ICANN, governments, regulators, law-enforcement bodies, and other competent authorities, enabling complementary action across the wider Internet ecosystem while respecting each actor’s independent powers, responsibilities, and legal mandates.

  1. “Malicious Registrations in the Domain Name Market: An Analysis of 2025 gTLD Registrations and Cybercriminal Demand”, Interisle Consulting Group, June 2026. 
  2. Greg Aaron and Karen Rose, “Malicious Registrations in the Domain Name Market”, presentation at the ICANN 86 Policy Forum, June 2026. 
  3. Sam Cheadle, Carlos Hernandez Gañán and Siôn Lloyd, “Looking Beyond the Numbers: Understanding Malicious Domain Registration Data”, ICANN, 10 August 2026. 
  4. Sam Cheadle, Carlos Hernandez Gañán, Siôn Lloyd and Samaneh Tajalizadehkhoob, “Detecting Malicious Domain Registration Batches”, ICANN Office of the Chief Technology Officer, 13 February 2026. 
  5. Sourena Maroofi, Maciej Korczyński, Cristian Hesselman, Benoît Ampeau and Andrzej Duda, “COMAR: Classification of Malicious Registrations”, IEEE Symposium on Security and Privacy Workshops, 2020. 
  6. Global Anti-Scam Alliance, “Global State of Scams 2025”, 2025. 
  7. Childlight, “Into the Light Index 2026”, 2026. 
  8. Heather Flanagan, “Staying Useful in a Geopolitical Internet: Reflections from IETF 126”, 18 August 2026. 

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By Andrew Campling, Director at 419 Consulting Ltd

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Cybersecurity

Sponsored byVerisign

DNS Security

Sponsored byWhoisXML API

Domain Names

Sponsored byVerisign

New TLDs

Sponsored byRadix

DNS

Sponsored byDNIB.com

IPv4 Markets

Sponsored byIPv4.Global

Brand Protection

Sponsored byCSC

NordVPN Promotion