Interisle Report Reveals Massive DNS Abuse Rates
A new Interisle report reveals that at least 10 percent of new generic top-level domains are immediately blacklisted, exposing a massive security crisis for internet infrastructure.
A newly highlighted report from research firm Interisle has exposed the staggering scale of malicious activity within the global Domain Name System (DNS). According to data analyzed by technology researcher Terence Eden, the internet's domain registration system is facing an unprecedented crisis of criminal exploitation. The report reveals that out of 85 million new generic Top-Level Domain (gTLD) registrations created in 2025, a shocking 8.5 million were flagged and added to blocklists by May 2025.
This means that at least 10 percent of all newly registered domains are actively used for malicious purposes, representing a conservative floor for DNS abuse. Eden suggests the actual figure is likely closer to 20 percent, meaning that as many as one in five newly registered gTLDs are being deployed as scams. Describing the situation as a "bloody crisis," Eden argued that the primary utility of the modern DNS increasingly appears to be serving as a tool for bad actors to launch fraudulent campaigns at an alarming scale.
The Internet Corporation for Assigned Names and Numbers (ICANN) has reportedly been discussing this systemic vulnerability for years, yet effective mitigation remains elusive. For technology practitioners, network administrators, and cybersecurity professionals, these statistics underscore the extreme risk of trusting newly registered domains. Automated security systems and threat intelligence pipelines must adapt to this reality by treating new gTLD registrations with immediate suspicion.
With up to a fifth of new domains operating as malicious vectors, practitioners can no longer rely on traditional reactive blocklists alone. Instead, defensive strategies must shift toward proactive zero-trust models for newly observed domains. As automated systems and AI agents increasingly navigate the web independently, securing DNS pathways and filtering out these millions of fraudulent endpoints will be critical to maintaining enterprise security and data integrity.
This is our own summary of reporting by Simon Willison



