Phishing Activity in Top-level Domains (TLDs)
August 1, 2021 - October 31, 2021

We analyzed the phishing domains to see how they were distributed across the top-level domains. For our analysis, we extract the Top-level Domain (e.g., com, xyz, uk) from the hostnames we found in phishing reports. We then rank TLD operators based on the number of reported phishing domains and a metric, phishing score.

Most phishing continues to be concentrated in just a few TLDs: for the period, we identified 125 TLDs with a minimum of 30,000 delegated domains and at least 25 reported phishing domains.

- 76 TLDs had more than 100 domain names reported for phishing.

- 34 TLDs had more than 500 domain names reported for phishing.

- 26 TLDs had more than 1000 domain names reported for phishing.

- 7 TLDs had more than 5000 domain names reported for phishing.

In the table below, we present the twenty TLDs that had the highest number of reported phishing domains.

Ranking of TLDs by Phishing Domains
(August to October 2021)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains ▼ Phishing Domain Score
1 com 157,659,393 75,736 4.8
2 cn 9,851,501 32,786 33.3
3 shop 922,927 29,243 316.9
4 xyz 3,376,847 11,083 32.8
5 tk 5,757,727 6,283 10.9
6 top 1,362,594 5,524 40.5
7 ml 4,630,221 5,143 11.1
8 ga 6,284,674 4,974 7.9
9 info 3,832,511 4,053 10.6
10 net 13,310,711 4,016 3.0
11 live 531,086 3,437 64.7
12 bar 376,099 3,326 88.4
13 cf 4,914,247 3,048 6.2
14 org 10,501,832 2,710 2.6
15 gq 3,880,956 2,429 6.3
16 ru 4,932,438 2,367 4.8
17 cyou 137,358 1,894 137.9
18 online 1,859,805 1,801 9.7
19 co 3,111,187 1,725 5.5
20 br 4,254,130 1,537 3.6

To allow comparison of large and small Top-level Domains, we also rank TLDs based on a metric, phishing domain score, which is calculated by dividing the number of domain names reported for phishing in a TLD by the number of domains delegated from that TLD.

TLD Phishing Score = (number of phishing domains/domains delegated from TLD) * 10,000

This score can highlight where high-volume phishers place multiple phish on one domain.

Table 2 presents the twenty TLDs that had the highest phishing domain score.

Ranking of TLDs by Phishing Domain Score
(August to October 2021)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains Phishing Domain Score ▼
1 shop 922,927 29,243 316.9
2 support 30,074 598 198.8
3 cyou 137,358 1,894 137.9
4 bar 376,099 3,326 88.4
5 live 531,086 3,437 64.7
6 email 112,835 722 64.0
7 ge 47,216 297 62.9
8 tokyo 233,469 1,362 58.3
9 casa 43,201 221 51.2
10 finance 41,507 183 44.1
11 top 1,362,594 5,524 40.5
12 link 143,599 528 36.8
13 cn 9,851,501 32,786 33.3
14 xyz 3,376,847 11,083 32.8
15 rest 63,556 192 30.2
16 fyi 32,742 98 29.9
17 digital 107,434 298 27.7
18 buzz 314,256 801 25.5
19 cam 42,251 102 24.1
20 services 57,537 100 17.4