الرئيسية / English / Just One Malicious Domain, or a Phishing Campaign?
icann-logo-on-blue-536x302-13-08-2026-en-large

Just One Malicious Domain, or a Phishing Campaign?

About 8.5 million generic domain names registered in 2025 appeared on blocklists associated with malicious activity, while new research highlights how quickly phishing domains can turn over. Now, ICANN is considering a policy that could require registrars to investigate domains linked to a malicious actor rather than addressing abusive domains one at a time.

إقرأ القصة بالعربية

By: Abdulrahman Abotaleb
By: Abdulrahman Abotaleb

A message lands in your inbox or on your phone. The link looks familiar: your bank, an online retailer, a delivery company waiting to drop off a package. You click, and the page looks convincing. But it was designed to trick you into surrendering a password, payment details or other personal information.

Once the fake site is detected, its domain name can be blocked or suspended. But that does not necessarily end the campaign. In some operations, attackers may have already registered batches of domain names that can be rotated into use as others are detected.

That gap between how some attackers operate and how abuse is addressed is now at the center of a policy debate over the domain name system.

On August 18, 2026, a working group within the Internet Corporation for Assigned Names and Numbers, or ICANN, published eight preliminary recommendations that include a framework for what it calls Associated Domain Checks. Instead of necessarily ending an investigation with the domain already found to be abusive, a registrar could also be required, under specified conditions and safeguards, to investigate other domains that may be associated with the same actor.

The recommendations are not yet binding policy. The document is an initial report open to public comment and must pass through further stages of ICANN’s policy-development process.

For ordinary internet users, the debate may sound highly technical, but the stakes are straightforward: Can defenders move beyond blocking a phishing link that has already been detected and identify more of the infrastructure behind a campaign before its other domains are used?

8.5 million domains on blocklists

A June 2026 report from Interisle Consulting Group offers one indication of the scale of the problem.

The report analyzed domain names created during 2025 in generic top-level domains, or gTLDs — the part of the domain name system that includes extensions such as “.com”, rather than country-code domains.

A registrar, meanwhile, is the company through which a customer registers a domain name and which manages that registration.

Interisle found that 84,961,989 gTLD domain names were created in 2025. By May 18, 2026, 8,496,811 of them had appeared on reputation blocklists associated with malicious activity — roughly 10 percent of the new registrations covered by the analysis. The researchers say their analysis indicates that the overwhelming majority of those domains were maliciously registered rather than legitimate websites that were later compromised.

But the report estimates that the blocklisted domains capture only part of the problem.

After accounting for domains the researchers expect to be blocklisted later, as well as estimates of domains associated with known campaigns but not identified by blocklists, Interisle projects that malicious actors may have registered around 16.8 million domains, or roughly 20 percent of all gTLD domains created in 2025.

The distinction is crucial.

The 8.5 million figure reflects domains the researchers actually found on blocklists. The 16.8 million figure is a projection based on additional assumptions. It would therefore be misleading to state as an established fact that “one in five new domains was malicious.”

The more consequential finding may be less about the headline number than about how some of these domains are acquired.

Interisle found that bulk registration was widespread among the blocklisted domains it examined. In case studies, researchers started with known malicious domains and searched for others sharing indicators such as registrar, registration timing, naming patterns and name-server infrastructure. They found additional associated domains that blocklists had not identified.

That does not mean bulk domain registration is evidence of criminal activity. Legitimate businesses and service providers also register large numbers of domains. Nor does shared technical infrastructure, on its own, prove that two domains are controlled by the same actor.

But the findings raise a different question: If attackers operate portfolios of related domains, how effective is a system that responds to each malicious domain largely in isolation?

When the median active lifetime is one day

A separate academic study published in the Journal of Cybersecurity in 2026 provides a closer look at the life cycle of phishing domains.

Researchers Sharad Agarwal and Marie Vasek of University College London examined 15,126 newly registered domains used for phishing over an 11-month period. Their analysis focused on domains registered for malicious purposes, rather than legitimate websites that attackers subsequently compromised.

The domains had a mean active lifetime of 8.6 days. But that average masks a striking feature of the distribution: the median was just one day, and about 89 percent of the sample was active for less than two days.

The difference matters. A relatively small number of long-lived domains can push up the arithmetic mean, while the median better reflects the midpoint of the sample.

The findings illustrate why time matters in phishing defense. If many domains in the sample are short-lived, detecting and blocking one after it becomes active addresses only part of the problem. Another question is whether domains associated with the same operation can be identified before they are put to use.

The study should not, however, be treated as a snapshot of all phishing worldwide. Its data came from a single provider, and the researchers acknowledge that the sample was biased toward brands in English-speaking countries. Their method for estimating domain activity periods also has limitations.

The research therefore does not establish that a “typical phishing domain” survives for only a day. What it does show is rapid turnover among a substantial share of the malicious infrastructure in the dataset.

From one malicious domain to its associates

That is the problem ICANN’s ongoing policy process is attempting to address.

The initial report explains that existing requirements oblige registrars to respond to reports of Domain Name System abuse and investigate them. But when one domain is found to be malicious, there is currently no general contractual requirement for the registrar to investigate whether the same registrant or account has other domains associated with similar abuse.

The result can be a “one-at-a-time” approach: an attacker loses one domain while others in the campaign remain available until they are separately detected and reported.

The proposed Associated Domain Check is intended to change that.

When a registrar has actionable evidence sufficient to reasonably conclude that a domain is being used for DNS abuse, the preliminary recommendations would require a reasonable investigation into associated domains. Depending on the circumstances, an association could be established using information about an account or registrant, registration patterns, shared infrastructure or characteristics of a campaign.

The proposal is not simply to suspend every domain that has a technical connection to a malicious one. The recommendations include safeguards intended to ensure that investigations are reasonable and proportionate, protect data and limit false positives.

Those protections matter to end users just as much as the effort to combat phishing itself.

Protecting users — on both sides of the equation

Many legitimate websites can share the same hosting provider, name servers or other infrastructure. A company may legitimately operate hundreds of domain names. Define “association” too loosely, and an attempt to identify a criminal network could sweep legitimate domains into the investigation.

ICANN’s initial report explicitly recognizes those risks. It says investigations should be reasonable and proportionate and that the requirements should not be interpreted in ways that conflict with applicable law or globally recognized data-protection principles, including proportionality and data minimization.

That puts the end user on both sides of the equation.

Users could benefit if registrars are able to identify domains associated with a malicious campaign before each one becomes the subject of a separate abuse report. But users and legitimate domain owners also need safeguards against overly broad investigations that could disrupt legitimate websites and services.

And the size of any benefit remains unknown.

The available evidence does not show that Associated Domain Checks will reduce phishing attacks or fraud losses by any particular percentage. ICANN’s working group itself acknowledges that demonstrating a direct causal relationship between the policy and changes in overall levels of DNS abuse may be difficult.

The proposal, then, is not a proven solution to phishing. It represents an attempt to shift the point of intervention: from waiting for each malicious domain to surface individually to investigating, when sufficient evidence exists, the infrastructure that may connect it to others.

In an online ecosystem where some attackers can prepare multiple disposable domain names and replace them quickly, finding the first malicious link may need to become the beginning of the investigation, rather than the end of it.

شاهد أيضاً

قابلة في اليمن تقدم خدمات الرعاية الصحية للأم والوليد. مصدر الصورة: صندوق الأمم المتحدة للسكان.

Yemen study highlights infectious risk factors linked to recurrent pregnancy loss

A new study by researchers from Thamar University, Albaydha University, and Southern Medical University in …