Of the roughly 85 million gTLD domains newly registered in 2025, 8.5 million had been added to blocklists by mid-May this year. That is one in ten. Interisle Consulting Group, which published the count in June, treats that observed figure as a floor rather than an estimate of the full scale, and projects that the number bought by malicious actors may be closer to 16.8 million, or one in five.
ICANN’s technical staff published a rebuttal on 10 August, disputing how the figures were arrived at and how large they are. The response does not specifically challenge the concentration tables, although its objections to how blocklist data are interpreted apply to the figures in them too. What those tables show is that the domains are not spread evenly across the industry.
Five registrars accounted for half of the blocklisted domains in the report’s registrar data, a slightly narrower set counted to an earlier date. And among the companies the report names, observed blocklisting rates run from about 3% to 88%, a spread of that size among companies operating in the same gTLD market.
Key facts
- Measured: 8.5 million of the 85 million gTLD domains created in 2025 were blocklisted by mid-May 2026, a rate of 10%.
- Projected: Interisle projects roughly 16.8 million, or 20%, after adding expected future listings and associated domains that blocklists missed.
- Concentration: in Interisle’s registrar tables, which run to 30 April 2026, five registrars accounted for 50% of the blocklisted 2025 registrations. Thirteen gTLDs saw more than half of their new registrations flagged.
- Bulk: of the 8.3 million blocklisted through 30 April, an estimated 88% were registered in batches, and twelve registrars handled more than 80% of those.
- Contested: ICANN says blocklist counts measure reports rather than confirmed abuse and “at best form an upper limit,” and that Interisle’s method departs from published methods without documenting how.
Five Names, and Two Very Different Reasons to Be on the List
The registrar and registry tables count domains blocklisted by 30 April 2026 that also met Interisle’s malicious-registration criteria, a narrower set than the 8.5 million above. Read by volume, five names carry half the total. Read by rate, limited to registrars with at least 10,000 blocklisted domains, the same market reorders and smaller companies come into view.
| Registrar | New registrations 2025 | Blocklisted | Rate |
|---|---|---|---|
| Most blocklisted domains | |||
| Dynadot | 4,900,809 | 1,029,018 | 21.0% |
| Gname | 2,481,620 | 997,771 | 40.2% |
| NameCheap | 10,204,514 | 816,805 | 8.0% |
| NameSilo | 3,028,042 | 621,268 | 20.5% |
| GoDaddy | 12,369,981 | 586,799 | 4.7% |
| Highest share of new registrations blocklisted | |||
| NICENIC | 180,404 | 157,970 | 87.6% |
| MainReg | 29,666 | 25,435 | 85.7% |
| Aceville | 119,896 | 99,072 | 82.6% |
| URL Solutions | 139,882 | 93,693 | 67.0% |
| Key-Systems | 745,084 | 435,136 | 58.4% |
| Ultahost | 31,034 | 17,759 | 57.2% |
Source: Interisle Consulting Group, blocklisting figures to 30 April 2026.
The two halves of that table describe different problems. GoDaddy and NameCheap appear at the top because they are very large, and their rates are among the lower figures in the report. Gname at 40.2% and Dynadot at 21.0% are a different matter, because those are shares of their own new business, and Dynadot alone accounted for 12.7% of the blocklisted-and-malicious domains in that dataset. At NICENIC, 87.6% of the new registrations Interisle counted were blocklisted and classified as malicious.
The registry side concentrates too, and by operator as well as by TLD: twelve of the twenty gTLDs with the highest blocklisting rates in 2025 were operated by Identity Digital. In that April dataset Verisign accounts for 26% of the blocklisted-and-malicious domains by volume, though only 4.9% of its own new .COM registrations were blocklisted; .TOP, run through 2025 by Jiangsu Bangning and transferred to Hong Kong Zhongze International in January 2026, accounts for 22% of the total at a rate of 34.6%.
The Wholesale Program Behind Cheap .COM
Interisle traces the price competition to specific mechanisms rather than to market forces in the abstract. Registries discount the wholesale price they charge for new registrations, or pay rebates when a registrar hits a sales or growth target. Registrars pass some of that through. Both commonly discount the first year only, betting that enough domains renew at full price to make the acquisition worthwhile.
After several flat years in .COM, the report says, Verisign “pursued growth in 2025 by offering a discount program, which saw some registrars sell .COM domains to customers at retail for less than half of .COM’s usual $10.26 wholesale price,” and observed “registrars shifting towards customer acquisition.” The report attributes to it a gain of 4.5 million .COM domains, the TLD’s strongest growth in several years.
That is the wholesale end of the market. At the retail end, in the same year, GoDaddy ran the discounted one-year .com offer over which it is now facing a securities claim, by our own reporting this week, after demand ran ahead of what the company expected. Neither document links the two directly. The report adds that open gTLDs have been available below $2.00 at retail, with some domains sold for as little as $0.49.
The economics of that customer are unusual. Cybercriminals rarely renew, Interisle says, which makes them close to the lowest-margin customers in the market. Renewal rates in some heavily affected gTLDs fall as low as 0.5%. They are also, as Interisle puts it, “a large and reliable source of repeat demand.” The report draws the inference plainly: “If those sales consistently produced losses, rational providers would adjust their pricing and sales strategy to limit their commercial exposure.”
10,848 Domains in Just Over Five Hours
Of the 8.3 million 2025 domains blocklisted through 30 April, an estimated 88% were registered in bulk, which Interisle defines as ten or more domains through one registrar with no more than ten minutes between consecutive registrations, usually sharing string patterns and nameservers. The report notes that this method under-counts, because it captures only domains that were later blocklisted.
The largest single batch it found was 10,848 blocklisted domains created through GMO Internet Group between 18:02 and 23:20 UTC on 25 November 2025, all algorithmically generated strings in .BOND. Interisle describes that as 106 domains a minute, although the count and the timestamps it gives work out at about 34 a minute across the five hours and eighteen minutes. Twelve registrars handled more than 80% of the bulk-registered domains.
Interisle’s case studies include FUNNULL, which the report calls a criminal organization and which was placed under United States government sanctions in May 2025. The report says it carried on acquiring domain names afterwards. Across those case studies, only small percentages of the blocklisted domains were suspended by registrars and registries.
One detail cuts against the assumption that this is a fraud-losses problem for registrars. Interisle argues that bad actors appear to be paying with acceptable payment instruments rather than stolen cards, on the reasoning that chargebacks would otherwise have forced registrars to change their practices already.
Interisle Puts Two Large Registrar Families at 3.0% and 3.9%
None of which makes the outcome inevitable. Interisle points to other large registrar families operating in the same broad market that recorded far lower blocklisting rates. These are family-level figures rather than the individual-registrar numbers used above.
Newfold Digital, the parent of 582 accredited registrars including Network Solutions, Register.com and SnapNames, is described as having “achieved high annual renewal rates of 74% to 80%, and has relatively low domain abuse,” at a rate of 3.9%. Tucows is described as having “managed its businesses, which include both reseller-oriented and public-facing registrars (Tucows/OpenSRS, eNom, EPAG, and Ascio) in a manner that has controlled abuse numbers,” at 3.0%.
The report finds the same on the registry side. .XYZ grew from 4.4 million to 8.7 million domains in 2025 despite a renewal rate of just 18.7%, recording about 7.2 million new registrations during the year, of which 275,896 were blocklisted. Interisle calls that “a relatively low percentage of its overall new registrations” and concludes that XYZ.COM “was somehow able to replace its losses and grow the TLD without attracting outsized abuse.”
These are not like-for-like comparisons: registrar portfolios, pricing and customer channels differ, so the rates cannot be read as controlled comparisons. That is part of the point. The report puts the conclusion this way: “Abuse is not inevitable, however. Some registries and registrars grew without attracting outsized levels of abuse. Pricing strategies, provider practices, and abuse mitigation choices can materially affect whether growth is driven by legitimate demand or by cybercriminal registrations.”
ICANN Disputes the Scale, the Definition and the Reproducibility
The rebuttal published on 10 August by ICANN’s Siôn Lloyd and Carlos Hernández Gañán, both principal security, stability and resiliency scientists, with machine learning engineer Sam Cheadle, opens by saying the organization does “not fully agree with some of the scales and metrics portrayed by this specific report,” while crediting it with advancing the discussion. Three objections follow.
- Evidence. A domain reported as suspicious is not a domain with actionable evidence against it, and blocklist statistics “at best form an upper limit to the amount of confirmed abuse.” Interisle, for its part, says about 98% of the domains it counted appear to have been registered maliciously rather than compromised after the fact.
- Definition. ICANN’s contractual definition covers botnets, malware, pharming, phishing and spam only when spam carries one of those. Broader definitions pull in fraud and scams outside its remit, and wide spam categories can capture advertising that “may or may not be real, and which may or may not be legal.”
- Reproducibility. For finding associated domains, ICANN says the report’s approach resembles its own published method, but “the analysis described in the report differs from the published ICANN method, and those differences are not explained.” It says the same of the academic COMAR approach for classifying a registration as malicious.
ICANN also points to work already under way. The community is running a policy development process on associated domain checks, to be followed by one seeking “safeguards for new account holders’ abilities to register domains at scale.” Both address behavior closely related to what the report documents. ICANN does not dispute that malicious registration and registration at scale are policy concerns; it disputes how the report measures and classifies them.
About the Data
The Interisle report was read in full from the published PDF and the ICANN response from the organization’s blog, both on 25 August. The report uses two cutoffs and they are not interchangeable: the headline count of 8,496,811 blocklisted domains runs to 18 May 2026, while the registrar and registry tables run to 30 April 2026 and apply a further malicious-registration test. The observed 10% and Interisle’s projected 20% are kept apart throughout, since ICANN disputes both the interpretation and the method. Interisle names its sponsors as the Anti-Phishing Working Group, the Coalition for Online Accountability, DomainTools, Meta, Spamhaus and SURBL, and states that its methodology and analysis were independent of them.
Sources
- Malicious Registrations in the Domain Name Market: An Analysis of 2025 gTLD Registrations and Cybercriminal Demand - Interisle Consulting Group (full report)
- Malicious Registrations in the Domain Name Market - Interisle Consulting Group (summary)
- Looking Beyond the Numbers: Understanding Malicious Domain Registration Data - ICANN (Office of the Chief Technology Officer)
- DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists - RIPE Labs (community contribution)