Phishing Activity in Top-level Domains (TLDs)
February 1, 2021 - April 30, 2021

We analyzed the phishing domains to see how they were distributed across the top-level domains. For our analysis, we extract the Top-level Domain (e.g., com, xyz, uk) from the hostnames we found in phishing reports. We then rank TLD operators based on the number of reported phishing domains and a metric, phishing score.

Most phishing continues to be concentrated in just a few TLDs: for the February 1, 2021 - April 30, 2021, we identified 135 TLDs with a minimum of 30,000 delegated domains and at least 25 reported phishing domains.

- 80 TLDs had more than 100 domain names reported for phishing.

- 34 TLDs had more than 500 domain names reported for phishing.

- 25 TLDs had more than 1000 domain names reported for phishing.

- 6 TLDs had more than 5000 domain names reported for phishing.

In the table below, we present the twenty TLDs that had the highest number of reported phishing domains. Four TLDs are legacy TLDs (com, net, info, org). Eight are country ccTLDs (tk, ml, ga, cf, gq, cn, ru, cc). Eight are new TLDs (xyz, top, bar, icu, live, buzz, online, club).

Ranking of TLDs by Phishing Domains
(February to April 2021)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains ▼ Phishing Domain Score
1 com 154,155,492 59,226 3.8
2 tk 4,797,006 12,336 25.7
3 xyz 3,033,793 7,953 26.2
4 ml 4,009,918 7,586 18.9
5 ga 4,968,228 5,802 11.7
6 cf 4,352,161 5,086 11.7
7 gq 3,496,937 4,954 14.2
8 top 1,100,090 4,485 40.8
9 cn 9,518,054 3,368 3.5
10 net 13,349,104 3,351 2.5
11 bar 151,081 2,949 195.2
12 info 3,950,811 2,788 7.1
13 ru 4,899,116 2,739 5.6
14 icu 626,924 2,411 38.5
15 org 10,436,774 2,358 2.3
16 live 444,572 2,251 50.6
17 buzz 251,787 2,166 86.0
18 online 1,790,351 1,782 10.0
19 club 1,048,604 1,532 14.6
20 cc 780,067 1,370 17.6

To allow comparison of large and small Top-level Domains, we also rank TLDs based on a metric, phishing domain score, which is calculated by dividing the number of domain names reported for phishing in a TLD by the number of domains delegated from that TLD.

TLD Phishing Score = (number of phishing domains/domains delegated from TLD) * 10,000

This score can highlight where high-volume phishers place multiple phish on one domain.

Table 2 presents the twenty TLDs that had the highest phishing domain score.

Ranking of TLDs by Phishing Domain Score (February to April 2021)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains Phishing Domain Score ▼
1 bar 151,081 2,949 195.2
2 buzz 251,787 2,166 86.0
3 cyou 93,684 627 66.9
4 casa 50,719 334 65.9
5 tokyo 158,957 996 62.7
6 live 444,572 2,251 50.6
7 link 121,120 503 41.5
8 top 1,100,090 4,485 40.8
9 icu 626,924 2,411 38.5
10 center 40,074 131 32.7
11 services 55,378 177 32.0
12 xyz 3,033,793 7,953 26.2
13 tk 4,797,006 12,336 25.7
14 click 56,951 146 25.6
15 zone 32,041 77 24.0
16 digital 93,862 224 23.9
17 cam 53,030 116 21.9
18 best 75,200 158 21.0
19 ink 40,973 83 20.3
20 ke 84,411 165 19.6