Phishing Activity in Top-level Domains (TLDs)
May 1, 2022 - July 31, 2022
We analyzed the phishing domains to see how they were distributed across the top-level domains. For our analysis, we extract the Top-level Domain (e.g., com, xyz, uk) from the hostnames we found in phishing reports. We then rank TLD operators based on the number of reported phishing domains and a metric, phishing score.
Most phishing continues to be concentrated in just a few TLDs: for the period, we identified 144 TLDs with a minimum of 30,000 delegated domains and at least 25 reported phishing domains.
- 83 TLDs had more than 100 domain names reported for phishing.
- 44 TLDs had more than 500 domain names reported for phishing.
- 27 TLDs had more than 1000 domain names reported for phishing.
- 1 TLDs had more than 5000 domain names reported for phishing.
In the table below, we present the twenty TLDs that had the highest number of reported phishing domains.
Ranking of TLDs by Phishing Domains (May to July 2022)
TLDs with a minimum of 30,000 domains and 25 phishing domains
Rank | TLD | Domains in TLD | Phishing Domains ▼ | Phishing Domain Score |
1 | com | 159,523,887 | 86,925 | 5.5 |
2 | cn | 8,125,667 | 20,554 | 25.3 |
3 | ml | 5,882,344 | 14,228 | 24.2 |
4 | tk | 5,503,716 | 11,499 | 20.9 |
5 | xyz | 4,187,298 | 7,054 | 16.9 |
6 | shop | 1,057,174 | 6,817 | 64.5 |
7 | ga | 8,030,092 | 6,807 | 8.5 |
8 | cf | 5,756,243 | 6,769 | 11.8 |
9 | top | 1,759,256 | 6,704 | 38.1 |
10 | gq | 4,666,405 | 6,075 | 13.0 |
11 | info | 3,623,437 | 5,833 | 16.1 |
12 | net | 13,075,489 | 4,778 | 3.7 |
13 | org | 10,605,066 | 4,028 | 3.8 |
14 | co | 3,506,347 | 4,018 | 11.5 |
15 | us | 1,883,017 | 3,889 | 20.7 |
16 | online | 1,886,710 | 3,648 | 19.3 |
17 | ru | 4,932,363 | 2,840 | 5.8 |
18 | live | 618,245 | 2,557 | 41.4 |
19 | pw | 310,504 | 2,273 | 73.2 |
20 | icu | 1,077,928 | 1,976 | 18.3 |
To allow comparison of large and small Top-level Domains, we also rank TLDs based on a metric, phishing domain score, which is calculated by dividing the number of domain names reported for phishing in a TLD by the number of domains delegated from that TLD.
TLD Phishing Score = (number of phishing domains/domains delegated from TLD) * 10,000
This score can highlight where high-volume phishers place multiple phish on one domain.
Table 2 presents the twenty TLDs that had the highest phishing domain score.
Ranking of TLDs by Phishing Domain Score (May to July 2022)
TLDs with a minimum of 30,000 domains and 25 phishing domains
Rank | TLD | Domains in TLD | Phishing Domains | Phishing Domain Score ▼ |
1 | support | 31,539 | 509 | 161.4 |
2 | pw | 310,504 | 2,273 | 73.2 |
3 | win | 77,224 | 512 | 66.3 |
4 | shop | 1,057,174 | 6,817 | 64.5 |
5 | click | 168,233 | 773 | 46.0 |
6 | live | 618,245 | 2,557 | 41.4 |
7 | top | 1,759,256 | 6,704 | 38.1 |
8 | fyi | 46,044 | 174 | 37.8 |
9 | finance | 49,460 | 176 | 35.6 |
10 | cfd | 104,688 | 359 | 34.3 |
11 | sbs | 45,910 | 147 | 32.0 |
12 | link | 181,360 | 494 | 27.2 |
13 | cn | 8,125,667 | 20,554 | 25.3 |
14 | cloud | 226,775 | 557 | 24.6 |
15 | ml | 5,882,344 | 14,228 | 24.2 |
16 | tk | 5,503,716 | 11,499 | 20.9 |
17 | us | 1,883,017 | 3,889 | 20.7 |
18 | host | 35,674 | 74 | 20.7 |
19 | id | 559,773 | 1,148 | 20.5 |
20 | monster | 94,320 | 183 | 19.4 |