Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Abuse & Phishing U.S. Department of Justice

DOJ seizes deepfake porn domains under TAKE IT DOWN Act

U.S. authorities shut down two websites distributing AI-generated nonconsensual nude images in the first public domain seizure under the 2025 law.

Federal law enforcement has taken offline two websites accused of distributing nonconsensual AI-generated nude images, signaling the first public enforcement action under a 2025 law targeting deepfake pornography. The seizure of CFAKE.com and SOCFAKE.com follows a multinational investigation involving U.S., Italian, and French authorities, highlighting the cross-border challenges of policing digital abuse enabled by artificial intelligence.

The U.S. Department of Justice announced the domain seizures on Friday, confirming that a federal judge found probable cause the sites violated the TAKE IT DOWN Act. The law, signed in May 2025, makes it a federal crime to publish sexually explicit altered images of identifiable individuals without their consent. Both domains now display a seizure banner citing violations of 47 U.S.C. § 223, the statute underpinning the legislation. The banner notes the operation involved Homeland Security Investigations, French National Police, Italy’s Postal and Cybersecurity Police, and U.S. prosecutors.

What happened

The investigation began in October 2025 after Italy’s Postal and Cybersecurity Police received complaints about AI-generated sexually explicit images depicting women in politics, sports, entertainment, and journalism. Italian authorities obtained a court order blocking access to the websites within Italy while continuing their probe. Evidence gathered by U.S. law enforcement was later shared with French counterparts, leading to the arrest of a suspect in Nice on June 10 and the seizure of cryptocurrency allegedly linked to the operation.

According to the DOJ, the sites hosted deepfake images and videos of politicians, celebrities, athletes, musicians, and royalty from multiple countries. Deepfakes—AI-generated or manipulated media—are often created using existing photos, videos, or audio recordings. While the technology has legitimate applications, it is frequently weaponized for nonconsensual pornography, impersonation scams, and fraud.

Background

Background: The TAKE IT DOWN Act, championed by First Lady Melania Trump as part of her "Be Best" initiative, expanded federal prohibitions on nonconsensual intimate imagery to explicitly include AI-generated deepfakes. The law also imposes a 48-hour removal requirement on online platforms after receiving a valid complaint from a victim. Prior to the act, enforcement relied on a patchwork of state laws and civil remedies, which proved ineffective against cross-border distribution.

Why it matters

The seizure of CFAKE.com and SOCFAKE.com demonstrates the TAKE IT DOWN Act’s potential to disrupt large-scale distribution of deepfake pornography. The law’s requirement for platforms to remove reported content within 48 hours could pressure hosting providers, registrars, and CDNs to adopt stricter content moderation policies. However, the global nature of the internet means enforcement will likely remain reactive, targeting high-profile cases while smaller-scale abuse persists.

For domain industry professionals, the case underscores the legal risks associated with hosting or enabling access to sites engaged in illegal content distribution. Registrars and hosting providers may face increased scrutiny from law enforcement, particularly when domains are linked to jurisdictions with weak enforcement mechanisms. The involvement of multiple countries in the investigation also signals growing international cooperation on digital crimes, which could lead to more frequent cross-border domain seizures or content takedowns.

For professionals

For professionals: Registrars and hosting providers should review their abuse policies to ensure compliance with the TAKE IT DOWN Act’s 48-hour removal requirement for nonconsensual intimate imagery. Proactive monitoring for deepfake-related abuse—such as unusual traffic patterns or complaints—could mitigate legal exposure. Providers operating in the U.S. or serving U.S. users may also need to update terms of service to reflect the law’s provisions.

What to watch

The DOJ’s use of the TAKE IT DOWN Act in this case may encourage more victims to report deepfake abuse, potentially leading to additional domain seizures or criminal charges. However, the law’s effectiveness will depend on enforcement resources and the willingness of platforms to comply with removal requests. Future cases could also test the boundaries of the statute, particularly around issues of jurisdiction, free speech, and the definition of "identifiable individuals."

The arrest in France and the seizure of cryptocurrency suggest law enforcement is targeting not just the distribution but also the financial infrastructure behind deepfake operations. This could prompt operators to adopt more sophisticated evasion tactics, such as decentralized hosting or privacy-focused payment methods, complicating future investigations.

Companies mentioned

U.S. Department of Justice French National Police Homeland Security Investigations Italy's Postal and Cybersecurity Police

Discussion · coming soon

Be the first to join the thread when community discussion launches.