Phishing Activity in Top-level Domains (TLDs)
November 1, 2021 - January 31, 2022

We analyzed the phishing domains to see how they were distributed across the top-level domains. For our analysis, we extract the Top-level Domain (e.g., com, xyz, uk) from the hostnames we found in phishing reports. We then rank TLD operators based on the number of reported phishing domains and a metric, phishing score.

Most phishing continues to be concentrated in just a few TLDs: for the period, we identified 127 TLDs with a minimum of 30,000 delegated domains and at least 25 reported phishing domains.

- 79 TLDs had more than 100 domain names reported for phishing.

- 39 TLDs had more than 500 domain names reported for phishing.

- 26 TLDs had more than 1000 domain names reported for phishing.

- 9 TLDs had more than 5000 domain names reported for phishing.

In the table below, we present the twenty TLDs that had the highest number of reported phishing domains.

Ranking of TLDs by Phishing Domains (November 2021 to January 2022)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains ▼ Phishing Domain Score
1 com 159,001,848 79,341 5.0
2 cn 9,692,024 26,033 26.9
3 tk 5,586,719 10,941 19.6
4 xyz 3,645,935 8,929 24.5
5 ml 5,004,676 8,520 17.0
6 ga 6,721,278 7,064 10.5
7 bar 408,610 6,220 152.2
8 cf 5,163,898 5,465 10.6
9 gq 4,154,606 5,425 13.1
10 net 13,243,353 4,372 3.3
11 info 3,784,123 3,595 9.5
12 live 568,840 3,582 63.0
13 org 10,571,742 3,057 2.9
14 online 1,849,526 2,889 15.6
15 store 710,582 2,790 39.3
16 shop 976,348 2,780 28.5
17 top 1,489,263 2,538 17.0
18 co 3,288,801 2,153 6.6
19 ru 4,966,202 2,079 4.2
20 us 1,761,332 1,733 9.8

To allow comparison of large and small Top-level Domains, we also rank TLDs based on a metric, phishing domain score, which is calculated by dividing the number of domain names reported for phishing in a TLD by the number of domains delegated from that TLD.

TLD Phishing Score = (number of phishing domains/domains delegated from TLD) * 10,000

This score can highlight where high-volume phishers place multiple phish on one domain.

In the table below, we show the twenty TLDs that had the highest phishing domain score.

Ranking of TLDs by Phishing Domain Score (November 2021 to January 2022)

TLDs with a minimum of 30,000 domains and 25 phishing domains

Rank TLD Domains in TLD Phishing Domains Phishing Domain Score ▼
1 support 30,871 578 187.2
2 bar 408,610 6,220 152.2
3 finance 48,891 450 92.0
4 live 568,840 3,582 63.0
5 fyi 36,636 186 50.8
6 email 111,637 516 46.2
7 store 710,582 2,790 39.3
8 rest 70,884 277 39.1
9 fun 265,918 1,036 39.0
10 pw 323,386 1,149 35.5
11 link 156,074 532 34.1
12 click 122,252 396 32.4
13 shop 976,348 2,780 28.5
14 space 352,307 992 28.2
15 cn 9,692,024 26,033 26.9
16 digital 113,619 281 24.7
17 xyz 3,645,935 8,929 24.5
18 services 58,786 142 24.2
19 to 30,921 74 23.9
20 casa 38,163 91 23.9