Phishing Activity in Top-level Domains (TLDs)
February 1, 2022 - April 30, 2022

We analyzed the phishing domains to see how they were distributed across the top-level domains. For our analysis, we extract the Top-level Domain (e.g., com, xyz, uk) from the hostnames we found in phishing reports. We then rank TLD operators based on the number of reported phishing domains and a metric, phishing score.

Most phishing continues to be concentrated in just a few TLDs: for the period, we identified 132 TLDs with a minimum of 30,000 delegated domains and at least 25 reported phishing domains.

- 36 TLDs had more than 500 domain names reported for phishing.

- 25 TLDs had more than 1000 domain names reported for phishing.

- 79 TLDs had more than 5000 domain names reported for phishing.

In the table below, we present the twenty TLDs that had the highest number of reported phishing domains.

Ranking of TLDs by Phishing Domains (February to April 2022)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains ▼ Phishing Domain Score
1 com 159,902,632 82,562 5.2
2 cn 8,980,611 29,204 32.5
3 tk 5,041,535 9,136 18.1
4 ml 5,344,979 8,656 16.2
5 xyz 4,130,573 7,462 18.1
6 buzz 513,201 6,923 134.9
7 shop 1,040,404 6,069 58.3
8 cf 5,383,367 4,676 8.7
9 net 13,170,783 4,496 3.4
10 ga 7,049,929 4,392 6.2
11 us 1,844,273 3,792 20.6
12 gq 4,307,508 3,590 8.3
13 live 596,948 3,468 58.1
14 org 10,614,272 3,444 3.2
15 info 3,653,720 3,145 8.6
16 online 1,847,551 3,039 16.5
17 ru 4,995,267 2,843 5.7
18 site 1,007,427 2,513 24.9
19 top 1,710,824 2,247 13.1
20 co 3,396,167 1,621 4.8

To allow comparison of large and small Top-level Domains, we also rank TLDs based on a metric, phishing domain score, which is calculated by dividing the number of domain names reported for phishing in a TLD by the number of domains delegated from that TLD.

TLD Phishing Score = (number of phishing domains/domains delegated from TLD) * 10,000

This score can highlight where high-volume phishers place multiple phish on one domain.

In the table below, we show the twenty TLDs that had the highest phishing domain score.

Ranking of TLDs by Phishing Domain Score (February to April 2022)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains Phishing Domain Score ▼
1 support 31,288 539 172.3
2 buzz 513,201 6,923 134.9
3 fyi 40,290 248 61.6
4 shop 1,040,404 6,069 58.3
5 live 596,948 3,468 58.1
6 sbs 34,030 185 54.4
7 finance 52,709 226 42.9
8 link 165,614 607 36.7
9 cn 8,980,611 29,204 32.5
10 pw 308,116 946 30.7
11 zone 39,977 118 29.5
12 cam 37,809 109 28.8
13 su 99,681 257 25.8
14 site 1,007,427 2,513 24.9
15 click 141,867 307 21.6
16 us 1,844,273 3,792 20.6
17 technology 34,340 67 19.5
18 cloud 221,924 415 18.7
19 tk 5,041,535 9,136 18.1
20 xyz 4,130,573 7,462 18.1

In the table below, we rank TLDs by malicious domain registrations. We identified 21 TLDs with more than 1000 malicious domain registrations; of these 6 had more than 5000 (BUZZ, COM, ML, SHOP, TK, and XYZ).

Ranking of TLDs by Malicious Phishing Domains (February to April 2022)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Malicious Phishing
Domain Registrations ▼
Malicious Phishing
Domain Score
1 com 159,902,632 56,175 3.5
2 tk 5,041,535 9,136 18.1
3 ml 5,344,979 8,656 16.2
4 buzz 513,201 6,865 133.8
5 xyz 4,130,573 6,288 15.2
6 shop 1,040,404 5,426 52.2
7 cf 5,383,367 4,676 8.7
8 cn 8,980,611 4,493 5.0
9 ga 7,049,929 4,392 6.2
10 gq 4,307,508 3,590 8.3
11 us 1,844,273 3,043 16.5
12 live 596,948 2,933 49.1
13 info 3,653,720 2,525 6.9
14 net 13,170,783 2,422 1.8
15 online 1,847,551 2,198 11.9
16 top 1,710,824 2,001 11.7
17 site 1,007,427 1,978 19.6
18 org 10,614,272 1,880 1.8
19 ru 4,995,267 1,754 3.5
20 icu 1,092,501 1,466 13.4