Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Incidents & Breaches

India’s .bank.in registry leaked data of 5,576 bank staff

Unauthenticated API exposed credentials and personal details for months

India’s .bank.in registry leaked data of 5,576 bank staff
Pixabay · Pexels

In 2025, India’s central bank mandated that all local banks adopt a .bank.in domain to reduce phishing risks. The Institute for Development and Research in Banking Technology (IDRBT) was appointed as the sole registrar for the namespace. However, the system designed to enhance trust in banking infrastructure instead became a security liability when its registration portal exposed sensitive data for over a year.

What was exposed

A security researcher, identified as Srikanth L, reported that the IDRBT Domain Registration Portal (registrar.idrbt.ac.in) left 33 REST API endpoints unauthenticated. These endpoints allowed anyone with basic tools like curl to retrieve bcrypt password hashes, mobile numbers, email addresses, login IP addresses, and device fingerprints of all 5,576 bank employees authorized to manage .bank.in domains. The researcher also discovered that some Indian banks host their websites on shared servers located in the United States, Singapore, and Lithuania, raising concerns about data sovereignty and infrastructure resilience.

Key facts
  • 5,576 bank employees’ credentials and personal data exposed
  • 33+ unauthenticated API endpoints accessible via curl
  • 80% of .bank.in domains lacked DNSSEC
  • 40% of domains did not use DMARC
  • Flaw persisted for 13 months before being fixed in June 2026

The researcher published findings on a GitHub repository, making some of the exposed data publicly accessible. While the intent was to aid security research, the disclosure also highlighted the risk that malicious actors could have exploited the same data for phishing, DNS spoofing, or other attacks. Many of the exposed domains relied on free Let’s Encrypt certificates, which, while secure, may not meet the higher assurance standards expected for financial institutions.

Response and implications

Srikanth L disclosed the vulnerability to IDRBT in early June 2026, and the organization subsequently secured the API endpoints. However, as of 30 June 2026, neither IDRBT, the Reserve Bank of India, nor the Indian government had issued a public statement addressing the incident. The lack of transparency leaves unanswered questions about whether the exposed data was accessed by unauthorized parties during the 13-month window.

The incident undermines the original goal of the .bank.in mandate: to create a trusted, phishing-resistant namespace for Indian banks. Instead, the registry’s poor security practices introduced new risks, including the potential for attackers to impersonate bank employees or manipulate DNS records. The fact that 80% of registered domains lacked DNSSEC and 40% did not use DMARC further weakens the security posture of India’s banking sector, despite the central bank’s efforts to standardize protections.

For professionals

For professionals: Operators of critical infrastructure registries should audit API security, enforce authentication on all endpoints, and conduct regular penetration testing. Banks using .bank.in domains should review their DNS and email security configurations, particularly DNSSEC and DMARC, to mitigate risks from potential credential misuse.

What to watch

The incident raises broader questions about the oversight of specialized TLD registries, particularly those handling sensitive sectors like finance. If IDRBT’s portal lacked basic security controls, similar vulnerabilities may exist in other country-code or industry-specific registries. Regulators and industry groups may push for stricter security standards for registries, including mandatory audits and breach disclosure requirements. Meanwhile, Indian banks will need to assess whether the exposed credentials were compromised and take steps to rotate them, even if no evidence of misuse has emerged.

Discussion · coming soon

Be the first to join the thread when community discussion launches.