Approximately 8 to 10 million new domain names are registered in the world every month. And if they all turned out to be Long-livers in the DNS system, their number would have reached billions on billions. Still, many domain names exist for just several days and even hours because they are registered by malicious users for specific immediate needs: spreading spam, malware, fraudulent transactions, phishing attacks, etc.
What share of new registrations is really malicious? This question was posed by Domain Name Wire, which refers to information from various surveys. For instance, Interisle Consulting Group of the United States, engaged in cybersecurity and network strategies, published a report, which said that at least 10 percent of all names registered in the generic top-level domains in 2025 were eventually entered in the blocklists, i.e. were associated with unlawful activity. And their overwhelming majority have not been compromised but were initially registered for improper purposes. The authors of the report say that the real percentage of malicious new registrations is closer to 20.
And WhoisXML API, which monthly analyses 8-10 million of new domain names’ registrations, provides an even higher estimate. According to its information, about a quarter of all new domain names are initially registered for illegal purposes. Meanwhile, the priorities of cybercriminals remain the same: new generic top-level domains and low registration costs. While only 4.9 percent of new registrations are malicious in the .COM domain and just 4 percent in .ORG, this indicator reaches 63 percent in .MOBIЕ. As for the prices, the recent research by the Université Grenoble Alpes has shown: reducing the registration price by one dollar increases malicious registrations by 49 percent.
Malicious users also have favorite registrars. Last year, a third of the new names registered by Gname ended up on blicklists. Actually, this is far from being a record: NiceNic shows 88 percent, MainReg Inc 86 percent, and Aceville – 83. GoDaddy, GMO, Newfold Digital and Tucows do much better against such a background: none of them has the share of malicious registrations above five percent.