These charts are available in an interactive format on our website:
Chart 1: Aggregate Trends
- Phishing: is an attempt to trick people into sharing important or sensitive information – for example logins, passwords, credit card numbers or banking information – in either a personal or business context.
- Malware: is malicious software designed to compromise a device on which it is installed.
Chart 2: Mitigation
The methodology includes a process to determine whether any mitigation has been observed. This involves taking an initial measurement of various factors related to the URL and repeating these measurements for one month. Further details are set out in the methodology.
Our methodology includes four labels:
- Mitigated: We detected that a mitigating action has occurred. This action could have been taken by a registrar, registry, a hosting provider, or another relevant actor, including the registrant.
- Not Mitigated: We did not detect any indication of mitigation.
- Uncategorized: We were unable to determine whether or not mitigation occurred.
- Unprocessed: The domains were not processed due to network connectivity, server problems, or other similar issues.
Chart 3: Registrar Median Mitigation Time
After an initial measurement, KOR Labs repeats measurements for one month to determine if mitigation has occurred. The intervals used are (starting at the time of acquiring the URL from the blocklist): 5m, 15m, 30m, 1hr, 2hr, 3hr, 4hr, 5hr, 6hr, 12hr, and then once every 12 hours for one month.
While we are describing this information as a “median registrar mitigation time,” it should be noted that we do not know definitively that it was the registrar that took action. This data could include mitigation taken by the registry, the host, or any other relevant party. The reference to a registrar is indicative that the domain is under their management. The number of unique domains has been ascertained by counting the number of unique domains per registrar credential, and then proportioning that number into the time bucket reflecting the median mitigation time of the registrar credential.
Chart 4: Malicious vs. Compromised
Our methodology includes three labels:
- Malicious: a domain registered for malicious purposes (i.e., to carry out DNS Abuse).
- Compromised: A benign domain name that has been compromised at the website, hosting, or DNS level.
- Uncategorized: A domain that our methodology was unable to categorize for a number of reasons, including problems in collecting the metadata necessary to categorize domain names accurately.
About Specific Reporting
Specific Reporting is intended to show the spectrum of how malicious phishing and malware is concentrated across the DNS registration ecosystem. To demonstrate this, we are identifying registrars and TLDs with higher and lower relative volumes of malicious domain registrations in their Domains Under Management (DUM), or new registrations.
The metrics we have chosen in this section of reporting were selected to provide a straightforward mechanism to understand DNS Abuse using the data points observed by our methodology. In the future, we may add additional metrics or combine various data points.
To the best of our ability in accordance with our methodology, all metrics are compiled using only observed maliciously registered domains, and exclude observed as compromised. We also provide registrars and registries with data relating to compromised domain names within their DUM on a one-to-one basis.
It is important to recognise the limitations of this work. We are faced with the universal challenge of understanding malicious activity in society; we can only measure the harms that are identified. In our case, we identify phishing and malware through the source lists we use for NetBeacon MAP. Identified phishing and malware will always be a subset of all existing phishing and malware. There will also be “false positives,” that is, domain names categorized as phishing and malware that actually aren’t due to both classification errors and differences in standards. There is also the potential that identified DNS Abuse is biased to particular geographic regions or activities that are more likely to be subject to reporting.
Another challenge we encounter is accurately enumerating the number of DUM for each registrar and TLD (which can impact “per 100K DUM” density metrics). Generally, our observed DUM is lower than officially reported DUM for all TLDs and registrars. For additional information on the limitations of this work, please refer to our methodology.
With these metrics, we want to provide the industry with evidence and information on how phishing and malware is distributed across the ecosystem. We have made several exclusions from each table to reduce the risk of including false positives and to increase the focus on credentials that account for the bulk of domain registrations exhibiting generalizable practices and policies.
Registrars: DUM (Tables 1-3)
This metric is intended to show the prevalence of observed maliciously registered domains in each registrar. We use observed maliciously registered domains per 100,000 DUM to allow comparison across registrars. Focusing only on absolute numbers of observed maliciously registered domains would typically result in the largest registrars having the largest number of malicious domain registrations. The observed maliciously registered domains is a count of the number of unique domain names, not URLs.
Our reporting is indifferent to registrar corporate families as we report on the registrar IANA ID (i.e., at the credential level). This means that some corporate entities will have more than one IANA ID, and they may choose to operate these credentials differently; for example, by using one credential for all new registrations. We chose not to manually combine credentials to minimize the risk that we could unintentionally attribute data to the incorrect registrar family as a result of missing a credential sale or corporate acquisition.
Our methodology identified a substantial number of registrar credentials that have zero observed maliciously registered domains in the current month of reporting. There are several reasons for why a registrar credential may have zero observed malicious domain names. For example, the credential may be:
- used for corporate purposes,
- operate a business model of brand protection (offering defensive registrations for existing brands),
- register low numbers or no new domain names, or
- used predominantly for registering expiring domain names for the purposes of resale (“drop catching”).
A specific business model or operational practice (rather than a generalizable policy or practice that other registrars could adopt) may cause registrar credentials to be identified as having zero observed maliciously registered domains. Zero observed maliciously registered domains is likely not feasible for typical credentials held by most registrars, particularly large retail registrars who sponsor the overwhelming majority of domains. Nevertheless, zero observed maliciously registered domains is still a laudable achievement. Accordingly, we have listed these registrar credentials in Appendix A: Registrar Credentials With Zero Observed Maliciously Registered Domains.
While every effort has been made to reduce the chance of false positives, it is impossible to eliminate this risk. To minimize the impact of false positives, we have required a minimum number of observed maliciously registered domains per registrar ID. With this requirement we are aiming to avoid where tables are largely composed of registrar credentials that would—other than for the existence of a few false positives—be listed in Appendix A. However, as very low numbers of observed malicious domain names is also a laudable result, we have included a list of these registrars in Appendix B: Registrar Credentials With One to Five Observed Maliciously Registered. We also exclude Brand Protection registrars in Appendix H. We determined this list based on a research paper focusing on exclusions to improve accuracy. Finally, the registrar data excludes ccTLD domains due to challenges in mapping domains to registrars in ccTLD ecosystems.
To account for the diversity of registrar credential sizes, we have reported low numbers of observed maliciously registered domains for both smaller (1-999,999 gTLD DUM) registrars (Table 1) and larger (1 million + gTLD DUM) registrars (Table 2). We note that this threshold of 1 million is somewhat arbitrary and slightly different rankings would result from a different threshold.
For higher numbers of observed maliciously registered domains, we have used one table (Table 3) and introduced a concept of consistency: a registrar credential will only be listed if they appear in this table of ten registrars for 4 or more of the last 6 months, otherwise they will be redacted. We attempt to contact all registrars in advance of publications, regardless of redaction. To further reduce the possibility of false positives, we also require a higher threshold of minimum malicious domain names for inclusion: more than 10 observed malicious domain names per month.
Data for this metric is presented in the following tables:
Table 1: Smaller registrars: lowest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 5 per month
- Observed DUM: 1 – 999,999
Table 2: Larger registrars: lowest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 5 per month
- Observed DUM: Equal to or greater than 1 million
Table 3: Highest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 10 per month
- Consistency: If a registrar does not appear in the list of 10 registrars with the highest observed maliciously registered domains per 100,000 DUM for 4 or more of the last 6 months, its data has been redacted.
For excluded data in the following Appendices, please visit our website.
- Appendix A: Registrar Credentials With Zero Observed Maliciously Registered Domains
- Appendix B: Registrar Credentials With One to Five Observed Maliciously Registered Domains
- Appendix H: Brand Protection Registrars
Registrars: New registrations (Tables 4-6)
This metric is intended to show the relationship between new registrations and observed malicious registration abuse. If the number of observed malicious domain names is a significant proportion of newly registered domain names, it may be an indication that a registrar should consider mechanisms to prevent incoming maliciously registered domains such as utilizing improved fraud prevention techniques.
As with our previous registrar metric, we have excluded registrar credentials with zero observed maliciously registered domains, and those with low numbers (1-5) of observed maliciously registered domains to reduce the risk of false positives. Instead we have focused on registrar credentials that account for the bulk of domain registrations that may exhibit generalizable practices and policies.
As our reporting is based on registrar IANA ID (credential), not registrar corporate family, there may be some unexpected results in the data. It should be noted that a registrar may use one ID for new registrations, and another ID for holding registrations. We have minimized the risk of this type of discrepancy by introducing an inclusion requirement for registrar credentials to have a substantial amount of new registrations per month: 300 per month or approximately 10 new gTLD domain registrations per day.
To account for the diversity of registrar credential sizes, we have reported low numbers of observed maliciously registered domains for both smaller (300-20,000 Newly Registered gTLD Domains) registrars (Table 4) and larger (20,000+ Newly Registered gTLD Domains) registrars (Table 5). We note that this threshold of 20,000 is somewhat arbitrary and slightly different rankings would result from a different threshold.
Finally, the registrar data excludes ccTLD domains due to challenges in mapping domains to registrars in ccTLD ecosystems.
To account for the diversity of registrar credential sizes, we have reported low numbers of observed maliciously registered domains for both smaller (1-999,999 gTLD DUM) registrars (Table 1) and larger (1 million + gTLD DUM) registrars (Table 2). We note that this threshold of 1 million is somewhat arbitrary and slightly different rankings would result from a different threshold.
For higher numbers of highest observed maliciously registered domains per new domain registration, we have used one table (Table 6) and introduced a concept of consistency: a registrar credential will only be listed if they appear in this table of ten registrars for 4 or more of the last 6 months, otherwise they will be redacted. We attempt to contact all registrars in advance of publications, regardless of redaction. To further reduce the possibility of false positives, we also require a higher threshold of minimum malicious domain names for inclusion: more than 10 observed malicious domain names per month.
Data for this metric is presented in the following tables:
Table 4: Smaller volume: lowest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 5 per month
- Observed Newly Registered Domains: 300 – 20,000
Table 5: Higher volume lowest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 5 per month
- Observed Newly Registered Domains: Equal to or greater than 20,000
Table 6: Highest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 10 per month
- Observed Newly Registered Domains: Equal to or greater than 300
- Consistency: If a registrar does not appear in the list of 10 registrars with the highest percentage of new registrations observed as malicious 4 or more of the last 6 months, its data has been redacted.
For excluded data in the following Appendices, please visit our website.
- Appendix A: Registrar Credentials With Zero Observed Maliciously Registered Domains
- Appendix B: Registrar Credentials With One to Five Observed Maliciously Registered
- Appendix C: Registrars With Registrars with Less Than 300 New Registrations per Month
- Appendix H: Brand Protection Registrars
Generic Top Level Domains (Tables 7-9)
This metric is intended to show the prevalence of observed maliciously registered domains in each gTLD.
When reported in raw numbers, the TLDs with the largest DUM will typically have the most observed maliciously registered domains. To create a benchmark which takes into account the different sizes of TLDs, we have reported the number of observed maliciously registered domains per 100,000 DUM. The observed abuse is a count of the number of unique domain names, not URLs.
We report on gTLDs and ccTLDs separately to reflect the fact that gTLDs have a consistent contractual framework, are bound by consensus policies produced through the ICANN multistakeholder process, while ccTLDs are largely unique in their policies, processes, and governance models (e.g., nexus requirements, three-party contracts that include the ccTLD registry, only names for accredited businesses).
However, there is considerable policy, process, and business model diversity within gTLDs, any of which can influence abuse rates. For example, some gTLDs are brand-operated, closed for public registration, and have dozens of registrations, while others are operated by publicly traded companies, open for public registration, and have millions of registrations.
Our methodology observed a substantial number of gTLDs that have zero observed maliciously registered domains in the current month of reporting. There are several reasons for why a gTLD may have zero observed malicious domain names. Some TLD operators have specific and unique business models that may not translate to open gTLDs. For example, operating at very small volumes, maintaining a closed and exclusive number of customers, or applying human verification to every single domain name registration. This can result in very low concentrations of abuse, but is less helpful for generalizable information and not scalable to the wider ecosystem. Zero observed maliciously registered domains is likely not feasible for most gTLDs. Nevertheless, zero observed maliciously registered domains is still a laudable achievement. Accordingly, we have listed these TLDs in Appendix D: gTLDs with Zero Observed Maliciously Registered Domains.
While every effort has been made to reduce the chance of false positives (reports of malware or phishing that prove to be mistaken), it is impossible to entirely eliminate this risk. To minimize the impact of false positives, we have required a minimum number of observed maliciously registered domains per TLD. As very low numbers of observed malicious domain names is also a laudable result, we have included a list of these TLDs in Appendix E: gTLDs with One to Five Observed Maliciously Registered Domains.
To account for the diversity of gTLD registry sizes, we have reported low numbers of observed maliciously registered domains for both smaller (1 – 199,999 DUM) gTLDs (Table 7) and larger (200,000+ DUM) gTLDs (Table 8). We note that this threshold of 200,000 is somewhat arbitrary and slightly different rankings would result from a different threshold.
For higher numbers of observed maliciously registered domains, we have used one table (Table 9) and introduced a concept of consistency: a TLD will only be listed if they appear in this table of ten TLDs for 4 or more of the last 6 months, otherwise they will be redacted. We attempt to contact all TLDs in advance of publications, regardless of redaction. To further reduce the possibility of false positives, we also require a higher threshold of minimum malicious domain names for inclusion: more than 10 observed malicious domain names per month.
Data for this metric is presented in the following tables:
Table 7: Smaller gTLDs: lowest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 5 per month
- Observed DUM: 1 – 200,000
Table 8: Larger gTLDs: lowest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 5 per month
- Observed DUM: Equal to or more than 200,000
Table 9: gTLDs highest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 10 per month 27
- Consistency: If a TLD does not appear in the list of 10 TLDs with the highest observed maliciously registered domains per 100,000 DUM for 4 or more of the last 6 months, its data has been redacted
For excluded data in the following Appendices, please visit our website.
- Appendix D: gTLDs with Zero Observed Maliciously Registered Domains
- Appendix E: gTLDs with One to Five Observed Maliciously Registered Domains
Country Code Top Level Domains (Table 10-12)
This metric is intended to show the prevalence of observed maliciously registered domains in each ccTLD.
When reported in raw numbers, the largest TLDs will typically have the most observed maliciously registered domains. To create a benchmark which takes into account the different sizes of TLDs we have reported the number of observed maliciously registered domains per 100,000 DUM. The observed abuse is a count of the number of unique domain names, not URLs.
We report on gTLDs and ccTLDs separately to reflect the fact that gTLDs have a consistent contractual framework[8], are bound by consensus policies produced through the ICANN multistakeholder process, while ccTLDs are largely unique in their policies, processes, and governance models (e.g., nexus requirements, three-party contracts that include the ccTLD registry, only names for accredited businesses).
This allows ccTLDs to create policies that are relevant and appropriate for their distinct local circumstances and population. This can still involve the use of multi-stakeholder processes, but is conducted by each individual country in line with its local regulations, values, languages, and expectations of the communities it serves. There is considerable diversity within the ccTLD community, so caution should be applied in comparing these TLDs.
Our methodology observed a substantial number of ccTLDs that have zero observed maliciously registered domains in the current month of reporting. There are several reasons for why a ccTLD may have zero observed malicious domain names. Some TLD operators have specific, unique, and typically untranslatable business models when applied to other ccTLDs or gTLDs. For example, operating at very small volumes, having a geographical nexus requirement, requiring a government identity number, restricting the number of domains available to each individual or business, or applying human or electronic identity verification to every domain name registration. This can result in very low concentrations of abuse, but is less helpful for generalizable information and not scalable to the wider ecosystem. Zero observed maliciously registered domains is likely not feasible for most TLDs. Nevertheless, zero observed maliciously registered domains is still a laudable achievement. Accordingly, we have listed these TLDs in Appendix F: ccTLDs with Zero Observed Maliciously Registered Domains.
While every effort has been made to reduce the chance of false positives, it is impossible to entirely eliminate this risk. To minimize the impact of false positives we have required a minimum number of observed maliciously registered domains per TLD. As very low numbers of observed malicious domain names is also a laudable result, we have included a list of these TLDs in Appendix G: ccTLDs with One to Five Observed Maliciously Registered Domains.
To account for the diversity of ccTLD registry sizes, we have reported low numbers of observed maliciously registered domains for both smaller 1 – 999,999 DUM ccTLDs (Table 10) and larger 1,000,000+ DUM ccTLDs (Table 11). We note that this threshold of 1 million is somewhat arbitrary and slightly different rankings would result from a different threshold.
For higher numbers of observed maliciously registered domains, we have used one table (Table 9) and introduced a concept of consistency: a TLD will only be listed if they appear in this table of ten TLDs for 4 or more of the last 6 months, otherwise they will be redacted. We attempt to contact all TLDs in advance of publications, regardless of redaction. To further reduce the possibility of false positives, we also require a higher threshold of minimum malicious domain names for inclusion: more than 10 observed malicious domain names per month.
Data for this metric is presented in the following tables:
Table 10: Smaller ccTLDs: lowest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 5 per month
- Observed DUM: 1 – 999,999
Table 11: Larger ccTLDs: lowest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 5 per month
- Observed DUM: Equal to or more than 1 million
Table 12: ccTLDs: highest observed rates of abuse
Inclusion criteria:
- Observed Maliciously Registered Domains: More than 10 per month
- Consistency: If a TLD does not appear in the list of 10 TLDs with the highest observed maliciously registered domains per 100,000 DUM for 4 or more of the last 6 months, its data has been redacted
For excluded data in the following Appendices, please visit our website.
- Appendix F: ccTLDs with Zero Observed Maliciously Registered Domains
- Appendix G: ccTLDs with One to Five Observed Maliciously Registered Domains