DNS Infrastructure Becomes a Fraud Hotbed: Nearly 20% of New Domains Abused

Nearly 20% of new domains are used for fraud, turning DNS into cheap criminal infrastructure while regulators stall.
According to Interisle's latest report, approximately 8.5 million of 85 million newly registered domains were blacklisted within five months, putting the real abuse rate near 20%. DNS has become cheap infrastructure for fraud operations due to ultra-low registration costs, lax identity verification, and slow malicious detection. Despite years of discussion, ICANN has failed to produce substantive solutions, hampered by registrar incentives, openness concerns, and cross-border enforcement difficulties. Until systemic governance improves, users should protect themselves by enabling DNS filtering, verifying official domains, and checking WHOIS registration dates.
Alarming Statistics on DNS Abuse
According to the latest research report from Interisle, 85 million new generic top-level domain (gTLD) registrations were recorded globally, of which 8.5 million were blacklisted within just five months. That means one in every ten newly registered domains has been identified as malicious — and the actual abuse rate may be closer to 20%, with one in five new domains being used for fraudulent purposes.

Tech blogger Terence Eden, after analyzing the report, reached a deeply troubling conclusion: the Domain Name System (DNS) has effectively become the infrastructure that criminals exploit to carry out large-scale fraud operations. This is not merely a technical problem — it represents a crisis threatening the very trust upon which the internet is built.
Why DNS Has Become a Hotbed for Fraud
DNS is a foundational component of the internet, responsible for translating human-readable domain names into machine-readable IP addresses. However, its openness and low barrier to entry are being systematically exploited by malicious actors.
Extremely Low Registration Costs
Some top-level domains can be registered for under one dollar. Fraud operations can bulk-register large numbers of domains to host phishing sites, fake storefronts, and other malicious platforms. Once a domain is flagged, they simply abandon it and register new ones — the cost of doing so is essentially zero.
Identity Verification That Exists Only on Paper
Most domain registrars perform only cursory checks on registrant information, allowing false identities to proliferate. Even when a domain is reported and suspended, criminals can easily assume new identities and continue registering fresh domains.
Severely Lagging Malicious Domain Detection
From the time a domain is registered to when it is identified as malicious and added to a blacklist, weeks or even months can pass. This window is more than sufficient for fraud operations to complete a full attack cycle and walk away with their proceeds.
Years of ICANN Discussions with Little Substantive Progress
ICANN (Internet Corporation for Assigned Names and Numbers), as the global steward of the domain name system, has been discussing DNS abuse for years — yet meaningful progress remains extremely limited. The issue involves a complex web of competing interests:
- Registrars lack incentive: Domain registrars profit from high-volume registrations and have little economic motivation to proactively remove malicious domains.
- Concerns about openness: The technical community worries that heavy-handed regulation could undermine the open nature of the internet.
- Cross-border enforcement challenges: Differences in national jurisdictions make cross-border enforcement against domain fraud exceedingly difficult.
In an article published on RIPE Labs, Andrew Campling pointed out that the industry still lacks consensus on the definition of "DNS abuse," which prevents stakeholders from agreeing on a coherent response. When definitions are unclear and accountability is diffuse, problems only continue to worsen.
How Ordinary Users Can Protect Themselves from DNS Fraud
Until systemic solutions are in place, individual users need to raise their security awareness and take proactive protective measures:
- Be wary of links from unfamiliar domains: Do not trust links from unknown domains, especially websites that appear to be newly created.
- Enable DNS security filtering: Use your browser's safe browsing features and DNS filtering services (such as Cloudflare 1.1.1.1's malware-blocking variant).
- Verify official domain names: For any site asking you to enter sensitive information such as passwords or banking details, always confirm whether the domain is the official address.
- Check domain registration dates: Use WHOIS lookup tools to check when a domain was registered, and be especially cautious with recently registered domains.
DNS Abuse Threatens the Foundation of Internet Trust
This crisis exposes the vulnerability of internet infrastructure when confronted with malicious activity at scale. A 20% abuse rate is not just a statistic — it means millions of users face potential fraud risk every single day. If the DNS system continues to be abused at its current rate while regulators fail to produce effective countermeasures, the foundational trust on which the internet operates faces a fundamental threat.
Related articles

Vercel AI SDK Releases Vue 3.0.282 Patch Update
Vercel AI SDK releases @ai-sdk/vue@3.0.282 patch update, syncing with core package ai@6.0.282. Learn about the changes, release cadence, and upgrade recommendations.

Vercel AI SDK Sandbox Component Receives Patch Update
Vercel AI SDK releases sandbox-vercel@1.0.109 patch update, syncing the harness dependency to the same version. A look at this maintenance release and what it means for AI app developers.

Vercel AI SDK Vue 4.0.99 Released: Dependency Update Overview
The @ai-sdk/vue 4.0.99 patch release syncs the underlying ai@7.0.99 dependency. Learn what this means for Vue developers building AI apps with Vercel AI SDK.