Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Abuse & Phishing ICANN

Malicious gTLD registrations may reach 20% of new domains

ICANN data suggests criminals control a significant share of new gTLDs

Malicious gTLD registrations may reach 20% of new domains
Clint Patterson · Unsplash

New data on domain registrations has raised concerns about the scale of criminal activity within the generic top-level domain (gTLD) market. Evidence compiled by Interisle Consulting Group and presented at ICANN forums suggests that malicious actors may have secured a substantial portion of newly created gTLD names in 2025, with estimates ranging between 10% and 20% of all registrations for that year.

Scale of the problem

Interisle’s analysis found that at least 10% of new gTLD domains registered in 2025 had already appeared on security blocklists by mid-2026. The firm’s researchers, Greg Aaron and Karen Rose, later projected that the figure could rise to 12% once delayed blocklist additions were accounted for. Their methodology also factored in associated domains—those linked to confirmed malicious registrations but not yet flagged—leading to an upper estimate of 20% of new gTLDs potentially under criminal control.

ICANN’s Office of the Chief Technology Officer (OCTO) has since challenged aspects of Interisle’s approach, particularly the definition of "DNS Abuse" and the treatment of blocklisted domains as confirmed abuse. ICANN’s contractual framework currently limits DNS Abuse to five specific harms: botnets, malware, pharming, phishing, and spam used as a delivery mechanism for these threats. Broader categories, such as fraud or scams, fall outside this definition, complicating efforts to quantify the full scope of misuse.

Background

Background: Generic top-level domains (gTLDs) are domain extensions like .com, .org, and newer options such as .app or .online, managed under ICANN’s global coordination framework. Unlike country-code TLDs (ccTLDs), which are tied to specific jurisdictions, gTLDs operate under standardized contracts with ICANN, creating a uniform but often slower policy response to abuse.

Broader risks beyond blocklists

Even domains not yet flagged on blocklists pose risks. Criminals may register domains for future use, deploy them in undetected campaigns, or exploit them for harms not covered by ICANN’s narrow definition, such as sextortion or ransomware. The financial and social impact of such activity is substantial: the Global Anti-Scam Alliance reported $442 billion in global losses to scams in 2025, while Childlight’s 2026 Into the Light index found that 6.7% of children experienced online sexual solicitation that year.

These figures do not isolate the role of domain names, but they underscore the urgency for the DNS ecosystem to address how its infrastructure enables large-scale harm. Registries and registrars face growing pressure to implement preventive measures, such as risk-based know-your-customer (KYC) checks, to identify suspicious registration patterns—particularly high-volume accounts or those linked to known abuse.

Policy and operational gaps

ICANN’s current contractual obligations focus on post-registration enforcement rather than proactive prevention. While the organization has initiated policy work on associated domain checks and safeguards for bulk registrations, critics argue these efforts lack the speed and scope needed to curb industrial-scale abuse. ccTLD operators, by contrast, often have clearer legal mandates to act against broader categories of illegal activity, potentially creating disparities in trust across the DNS market.

For professionals

For professionals: Registrars and registries should review their KYC and monitoring processes for high-volume registrations, particularly those exhibiting patterns linked to past abuse. Contractual compliance with ICANN’s existing abuse definitions remains mandatory, but operators may also need to assess risks beyond these categories to mitigate reputational and legal exposure.

The debate over definitions has not diminished the core concern: criminals appear to be exploiting gTLD infrastructure at scale. ICANN’s community is now being urged to evaluate whether its contractual frameworks, data-sharing practices, and enforcement mechanisms are sufficient to address the problem. Proposed reforms include clearer coordination with law enforcement and national authorities, while preserving ICANN’s role as a technical coordinator rather than a content regulator.

What’s next

The ICANN community is expected to discuss potential policy changes in upcoming forums, including whether to expand the definition of DNS Abuse to encompass a wider range of technology-facilitated harms. Any reforms will need to balance effectiveness with the principles of openness, privacy, and interoperability that underpin the DNS. Meanwhile, registrars and registries are likely to face increasing scrutiny over their ability to detect and prevent malicious registrations before they are weaponized.

Companies mentioned

ICANN Childlight Global Anti-Scam Alliance Interisle Consulting Group

Discussion · coming soon

Be the first to join the thread when community discussion launches.