Verisign: Interisle Study Finds Malicious Actors Registered 10-20% of New Domain Names in 2025, Accounted for ‘Significant Share’ of Market

Published on Jun 05, 2026

A new study by Interisle Consulting Group suggests that cybercriminal demand represents “a significant share of the domain name market”—the digital ecosystem where domain registrars and registry operators facilitate the buying, selling, and management of web addresses. The report, which notes that domains are an “essential resource” for committing cybercrimes like phishing attacks, malware, and […]

A new study by Interisle Consulting Group suggests that cybercriminal demand represents “a significant share of the domain name market”—the digital ecosystem where domain registrars and registry operators facilitate the buying, selling, and management of web addresses.

The report, which notes that domains are an “essential resource” for committing cybercrimes like phishing attacks, malware, and scam campaigns, found that malicious actors purchased between 10% and 20% of all generic top-level domain (gTLD) names created in 2025.

While widespread in the market, abuse appeared to be highly concentrated at specific gTLDs, registrars, and corporate families in domain name industry. Five registrars were responsible for about 50% of all blocklisted gTLD domains created in 2025 and multiple open gTLDs saw more than half of their new registrations used for malicious purposes.

More than 90% of domains created in 2025 that were subsequently blocklisted—meaning they were flagged for hosting known phishing pages, malware, and other unwanted content—were operated by just eight companies. Verisign (VRSN), which operates the registries for the popular .com and .net gTLDs, had the most blocklisted domains of any registry family at more than 2.1 million, comprising 26% of new blocklisted domains.

The report relied on publicly and commercially available data to reveal that nearly 8.5 million or 10% of the 85 million domains created in 2025 have been blocklisted as of May 18, 2026. However, authors cautioned that as many 20% of new domains may have been maliciously registered, given that blocklists do not cover all abusive domain registrations and domains created in 2025 will continue to be blocklisted through the rest of the year.

“That is a substantial share,” Karen Rose, Interisle partner and study co-author, said. “Imagine if one out of every five products in another industry were being purchased by bad actors to commit damaging criminal acts.”

The authors also pointed to a recent study of malicious batch registrations by the Internet Corporation for Assigned Names and Numbers’ (ICANN) Office of the CTO, which indicated that “for every three domains appearing on blocklists, two additional domains appear to have been registered within the same registration batches.”

A 2025 analysis of 100.8 million newly observed domains by threat intelligence company Infoblox found over a quarter to be malicious or suspicious, suggesting an even higher ceiling.

“The latest report by Interisle confirms the organization’s previous findings that malicious registrations make up a comparatively low percentage of new .com registrations,” a Verisign spokesperson said in an email. “The report likely overcounts malicious registrations by relying on data from public blocklists, which include a significant number of domain names that are blocked for reasons other than malicious activity, but even by the report’s own methodology, .com had among the lowest percentages of blocklisted registrations.”

“The report calls out 20 top-level domains with abuse rates ranging from 42 percent to 72.9 percent of new registrations,” they added. “The rate Interisle reported for .com was less than 5 percent, one of the lowest percentages for any domain identified in the report. The report also notes that low renewal rates are an indicator of abuse. The renewal rate for .com as of Q1 2026 was 76 percent, which was one of the highest rates among TLDs for which such data is available.”

ICANN did not respond to a request for comment.

Market incentives lead to high-volume, low-margin sales preferred by cybercriminals. In recent years the gTLD market had been relatively stagnant, experiencing just 6.2% growth from 2021 through 2024. Verisign’s .com registrations shrank most quarters in 2023 and 2024, according to Domain Name Industry Brief (DNIB) reports.

Last year Verisign initiated a discount program that resulted in some registrars reportedly selling .com domains to customers for less than half of the usual $10.26 wholesale price. While Verisign’s .com and .net TLDs had a combined decrease of 3.7 million registrations in 2024, their numbers grew by about 4.5 million in 2025.

The Interisle report noted that volume-based discount programs and high-volume, low-margin sales strategies create strong incentives for registrars to sell domains in bulk. Past studies have demonstrated that cybercriminals are heavily dependent on bulk registrations to provide a continuous flow of new domains to exploit.

An increased supply of domains thanks to the planned introduction of more open new gTLDs by ICANN may further drive down prices to the potential benefit of bad actors, according to the study. With more domains available, operators will have to compete by offering cheaper prices to establish a market share.

The authors cautioned that “the relationship between low pricing and abuse is well documented” and cited another recent ICANN-supported study, found that “each dollar reduction in registration fees corresponds to a 49% increase in malicious domains.”

“Verisign’s marketing program costs have been consistent for the past several years, and do not come close to offering the sub $2.00 price point identified by Interisle in its discussion of ultra-low-cost domains,” the Verisign spokesperson said. “A 2019 Interisle report identifies domains with retail prices lower than $2 or in some cases lower than $1 as being attractively priced for malicious actors.”

To be sure, only 4.9% of the new .com domains created in 2025 appeared to be blocklisted and malicious, a relatively low percentage compared with the other gTLDs with the highest numbers of malicious registrations. Still, the overall volume of maliciously registered .com domains—nearly 2 million—could present a significant threat to consumers down the road.

A lawsuit filed in November 2025 by Google (GOOG) against a Chinese-based phishing operation alleged that over a 20-day period approximately 200,000 fraudulent websites were used to attract over 1 million potential victims in at least 121 countries. Google’s motion for a temporary restraining order dismantling the defendants’ phishing infrastructure was granted by U.S. District Judge Victor Marrero in November and the case remains active.

“Two millions domain names is a lot of potential harm,” Rose said. “[.com] is still the single highest source of malicious domains in the market—representing 26% of all gTLD acquisitions by bad actors. On sheer volume, they’re still at the top, and that’s significant.”

A breakdown of the corporate families operating the most blocklisted new domains. Source: Interisle

Even if .com domains might cost more relative to other gTLDs that are abused at higher rates, one appeal of .com to cybercriminals may be the domain’s legitimacy in the eyes of consumers. Domain defender services might also be more reticent to block .com domains, according to Damon McCoy, a professor of computer science and engineering and co-director of New York University’s Center for Cybersecurity.

“Defenders have reputation lists of kind of bad neighborhoods of these top-level domains,” McCoy said. “They’ll be quicker to block those, whereas .com presumably has a better reputation, it’s better neighborhood, and they’ll be slower and more reluctant to probably block .com domains.”

Some registrars and registry operators may commercially benefit from sales to bad actors amid surge in cybercrime. The Interisle study argued that the existing market potentially incentives registrars and registry operators to take or tolerate abusive registrations “when deterrence is more costly or risks losing higher-margin legitimate customers” and that some of these companies “appear to derive commercial benefits from selling large numbers of domains to bad actors.”

Both ICANN and the registrars and registry operators like Verisign that it contracts with generaterevenue from domain name renewals and registrations, including potentially malicious ones.

“If you can potentially profit from some activity, and there’s relatively low risk of consequences, then you’re incentivized to do that activity,” McCoy said. “In this case, ICANN and Verisign basically have money printing machines. They can collect relatively high overheads for just allocating new domain names.”

“Obviously there’s a limited demand to that, or else they’d be the most valuable companies in the world,” McCoy added. “If cybercriminals present kind of a demand business opportunity, then I could see how, again from a business incentives perspective, how they might try and grow their margins.”

Interisle authors wrote that domain abuse is not inevitable, and that “[p]ricing strategies, provider practices, and abuse mitigation choices can materially affect” whether registration growth is legitimate or not. Requiring registrants to undergo identity verification and maintaining validated registration data have been shown to be effective  at mitigating abuse.

But without industry or policymaker intervention, Rose said cybercriminal demand is likely to continue underpinning the market as cybercrime grows globally. A previous Interisle study found that malware, phishing, and spam attacks increased by 60% between 2024 and 2025.

“It is far too easy for criminals to register a web domain and use it for fraudulent purposes,” Ken Westbrook, founder and CEO of the nonprofit Stop Scams Alliance, said in an email. “Fraud enabled by malicious domains crosses borders and is increasingly perpetrated by transnational organized criminal networks. The domain name industry’s response must match the increased scale of the attack.”