Phishing Activity in Top-level Domains (TLDs)
May 1, 2022 - July 31, 2022

We analyzed the phishing domains to see how they were distributed across the top-level domains. For our analysis, we extract the Top-level Domain (e.g., com, xyz, uk) from the hostnames we found in phishing reports. We then rank TLD operators based on the number of reported phishing domains and a metric, phishing score.

Most phishing continues to be concentrated in just a few TLDs: for the period, we identified 144 TLDs with a minimum of 30,000 delegated domains and at least 25 reported phishing domains.

- 83 TLDs had more than 100 domain names reported for phishing.

- 44 TLDs had more than 500 domain names reported for phishing.

- 27 TLDs had more than 1000 domain names reported for phishing.

- 1 TLDs had more than 5000 domain names reported for phishing.

In the table below, we present the twenty TLDs that had the highest number of reported phishing domains.

Ranking of TLDs by Phishing Domains (May to July 2022)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains ▼ Phishing Domain Score
1 com 159,523,887 86,925 5.5
2 cn 8,125,667 20,554 25.3
3 ml 5,882,344 14,228 24.2
4 tk 5,503,716 11,499 20.9
5 xyz 4,187,298 7,054 16.9
6 shop 1,057,174 6,817 64.5
7 ga 8,030,092 6,807 8.5
8 cf 5,756,243 6,769 11.8
9 top 1,759,256 6,704 38.1
10 gq 4,666,405 6,075 13.0
11 info 3,623,437 5,833 16.1
12 net 13,075,489 4,778 3.7
13 org 10,605,066 4,028 3.8
14 co 3,506,347 4,018 11.5
15 us 1,883,017 3,889 20.7
16 online 1,886,710 3,648 19.3
17 ru 4,932,363 2,840 5.8
18 live 618,245 2,557 41.4
19 pw 310,504 2,273 73.2
20 icu 1,077,928 1,976 18.3

To allow comparison of large and small Top-level Domains, we also rank TLDs based on a metric, phishing domain score, which is calculated by dividing the number of domain names reported for phishing in a TLD by the number of domains delegated from that TLD.

TLD Phishing Score = (number of phishing domains/domains delegated from TLD) * 10,000

This score can highlight where high-volume phishers place multiple phish on one domain.

Table 2 presents the twenty TLDs that had the highest phishing domain score.

Ranking of TLDs by Phishing Domain Score (May to July 2022)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains Phishing Domain Score ▼
1 support 31,539 509 161.4
2 pw 310,504 2,273 73.2
3 win 77,224 512 66.3
4 shop 1,057,174 6,817 64.5
5 click 168,233 773 46.0
6 live 618,245 2,557 41.4
7 top 1,759,256 6,704 38.1
8 fyi 46,044 174 37.8
9 finance 49,460 176 35.6
10 cfd 104,688 359 34.3
11 sbs 45,910 147 32.0
12 link 181,360 494 27.2
13 cn 8,125,667 20,554 25.3
14 cloud 226,775 557 24.6
15 ml 5,882,344 14,228 24.2
16 tk 5,503,716 11,499 20.9
17 us 1,883,017 3,889 20.7
18 host 35,674 74 20.7
19 id 559,773 1,148 20.5
20 monster 94,320 183 19.4