Cybersecurity illustration of a shield blocking malicious domain threats from reaching a protected global network.

The Trouble With Counting Malicious Domains

If you follow domain security reports for long enough, you eventually notice that the numbers do not always match. One report may identify millions of malicious domains, while another looks at what appears to be the same problem and arrives at a very different result.

A recent Interisle Consulting Group report provides a good example. It found that approximately 8.5 million of the nearly 85 million gTLD domain names registered in 2025 had appeared on security blocklists. The same report estimated that the number of domains registered by malicious actors could be closer to 16.8 million after accounting for domains that may be blocklisted later and associated domains not detected by those lists.

The second figure is almost twice the first, but it is a broader estimate rather than an observed blocklist count.

ICANN addressed the report directly in a recent analysis of malicious domain registration data. It said it did not fully agree with some of the report’s scales and metrics. Its broader point was that a reported or blocklisted domain is not the same as a domain for which there is actionable evidence of DNS Abuse, and even evidence of abuse does not automatically tell us why the domain was registered.

A New Domain Is a Clue, Not a Verdict

We have written before about why newly registered domains are important for cybersecurity. Attackers can register them cheaply, put them online quickly, and replace them when blocked, making domain age a useful signal.

But every legitimate domain was once new. A creation date tells us when a domain was registered, not why somebody registered it.

Imagine opening a website that looks almost exactly like Microsoft, Amazon, or your bank. The design is convincing and HTTPS is working. Then you check the registration data and discover that the domain was created three days ago.

Any cybersecurity analyst would want to know that, but we would also want to know more. Who is the registrar? Which nameservers does it use? Is it already appearing in security feeds?

As we noted in Why Phishing Still Works in 2026, a three-day-old domain impersonating an established brand deserves attention, but the creation date alone is not proof of malicious intent. It becomes much more useful when other information points in the same direction.

Blocklisted Does Not Mean Maliciously Registered

Blocklists solve a practical problem. If a domain is distributing malware or hosting a phishing page, security products need to protect users quickly. The difficulty comes when the same data is used to answer a different question: was the domain originally registered for malicious purposes?

Consider a small business that has used the same domain for ten years. Its WordPress installation gets compromised and redirects visitors to malware, putting the domain on a blocklist. Nobody registered it ten years earlier with malicious intent; the business owner is another victim.

Now consider the opposite situation. Someone registers twenty domains for a phishing campaign, activates five, and keeps the rest unused until they are needed. Some may not yet appear on any blocklist, even though they were registered as part of a malicious operation.

A blocklisted domain may be a compromised legitimate website or part of a deliberately registered abuse campaign.

A blocklist may include domains that were never registered for abuse while missing domains that were. If all of them end up under the label “malicious domains,” an important part of the story disappears.

There Is No Single Field Called “Intent”

Different providers work with different data, definitions, and time periods. One may count domains found on blocklists, another may try to identify domains deliberately registered for abuse, and a third may include a broader range of harmful activity.

ICANN uses a specific contractual definition of DNS Abuse covering botnets, malware, pharming, phishing, and spam when it is used to deliver one of those forms of abuse. A commercial security company may use a broader definition, so the resulting numbers should not be compared as though they describe the same group of domains.

After working with domain data for many years, I keep coming back to the same limitation: there is no single field called “intent.”

A creation date tells us when a domain was registered. WHOIS or RDAP data may show the registrar, status, and nameservers, while DNS, certificate, and reputation data provide additional context. None can establish intent by itself.

We looked at this broader shift in 15 Years of Domain Data: From WHOIS to RDAP, but structured data still needs interpretation.

A long-established domain that suddenly changes infrastructure and appears in security feeds may have been compromised. A group of similarly structured domains registered and activated within a short period may be part of the same campaign. The useful conclusion comes from several facts pointing in the same direction.

One Abusive Domain May Point to Others

On August 18, 2026, ICANN’s Generic Names Supporting Organization opened public comment on an initial proposal involving associated domain checks. Under the proposal, if a registrar has actionable evidence that one domain is being used for DNS Abuse, it would be required to investigate other domains associated with the same customer account or registrant.

A phishing operation rarely depends on a single domain. Attackers can register groups of domains and rotate them as individual domains are detected and blocked.

The important part is that this would trigger an investigation, not an automatic suspension. Shared hosting, nameservers, or CDN infrastructure alone do not establish common control or malicious activity.

Conclusion

Large counts of malicious domains help show the scale of the problem, and blocklists remain essential tools for protecting users. But a blocklist count, a broader estimate, and evidence that a domain was maliciously registered are not interchangeable.

Was the domain reported for abuse, found on a blocklist, or directly observed being used for phishing or malware? Was it registered for that purpose, or was a legitimate website compromised later?

Once millions of domains are being counted, those distinctions can produce very different results.

So when two reports show very different numbers for malicious domains, I would not start by asking which one is wrong. I would first check what each one actually counted.

GoranDuskic

Goran Duskic has been the Founder and CEO of WhoAPI Inc. since 2011, a company that specializes in developing APIs, including the well-known Whois API. He started his career in internet entrepreneurship in 2006 and has co-founded several online businesses, including a web hosting company that he later sold. Goran's work primarily involves creating practical API solutions to meet technological needs.