INFRA Signal 157
Interisle research estimates criminals may control 20% of new 2025 gTLD domains, drawing ICANN methodology pushback
Interisle researchers estimate 10-20% of new 2025 gTLD registrations may be malicious, and ICANN's Office of the CTO has replied that the figures depend on definitions and evidence standards.
The dispute is not about whether criminals use the registration channel but about what counts as confirmed DNS Abuse under ICANN's narrow contractual definition. Registries, registrars, and abuse-handling teams should expect policy pressure to widen what 'associated domains' and unreported fraud signal into registration-time decisions. Engineers who run blocklists or abuse pipelines may be asked to attribute risk to domains that never appear on a list.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Interisle's Greg Aaron and Karen Rose presented at ICANN 86 estimating that at least 10% of new 2025 gTLD names appeared on blocklists, with associated-domain analysis putting the malicious share closer to 20%.
ICANN's Office of the CTO argued the Interisle figures depend on the definition of 'abuse' and cautioned against treating every blocklisted domain as confirmed DNS Abuse under the botnet, malware, pharming, phishing, and facilitating-spam categories.
External harm data from the Global Anti-Scam Alliance (US$442 billion in 2025 scam losses) and Childlight's Into the Light index frame why the registration channel is being scrutinised even where abuse definitions do not directly apply.
THE READ
What the cluster adds up to.
The event centres on Interisle's measurement, presented at ICANN 86 by Greg Aaron and Karen Rose, that 10% of new gTLD names registered during 2025 had already appeared on security blocklists, and that applying an associated-domain heuristic pushes the estimated share of maliciously registered names toward 20%. The supporting ICANN-cited rule of thumb is that for every three blocklisted domains two further associated domains remain unlisted, which is what drives the upward adjustment. The number that an operator should treat as load-bearing is not the headline 20% but the gap between the directly observed 10% and the modelled figure, because that gap is where policy responses will either converge or diverge.
The counter-move came from ICANN's Office of the CTO in a blog post arguing that blocklist membership is not equivalent to confirmed DNS Abuse under ICANN's contractual definition, which is restricted to botnets, malware, pharming, phishing, and spam used to deliver those harms. The OCTO authors criticised Interisle for invoking methods associated with ICANN and COMAR without fully explaining departures from them, and pointed to ongoing policy work on associated-domain checks and high-volume-registration safeguards. For engineers, this is a reminder that contractually reportable abuse is a narrower set than what blocklists or fraud telemetry will flag, and that contractual obligations and empirical risk profiles are not the same surface.
The article extends the framing beyond confirmed DNS Abuse to technology-facilitated harms that may or may not be DNS-enabled, citing the Global Anti-Scam Alliance's US$442 billion 2025 scam-loss estimate and Childlight's Into the Light figures (roughly one in four children experiencing online sexual solicitation, with 9% facing online sexual extortion before 18). These numbers are explicitly not domain-attribution data, and the piece is careful to say so, but they are used to argue that the registration channel cannot be evaluated only through the narrow DNS Abuse lens. The operational implication is that registries asked to add fraud or sextortion categories to abuse handling will be arguing against an existing contractual definition, not extending an established one.
For someone who runs abuse intake, blocklists, or registrar risk scoring, the concrete change to watch is whether 'associated domain' and 'subsequently blocklisted' signals start being treated as registration-time red flags rather than post-hoc observations. The Interisle work implies that blocklists are a lower bound on malicious registration, and the OCTO response implies that ICANN's contractual framework is a different lower bound that excludes most fraud and many sextortion cases. Where the two diverge is exactly where a registry's abuse budget, KYC checks, or bulk-registration thresholds would have to absorb the difference, and where vendors selling abuse telemetry will face definitional pushback if they sell signals as 'DNS Abuse' under the contractual meaning.
What the material does not resolve is the precise share, and the article itself flags that the headline 20% figure is contested rather than settled. The available evidence supports saying that a non-trivial share of new 2025 gTLD names are blocklisted or associated with blocklisted names, that ICANN disputes treating those as confirmed DNS Abuse under its contract, and that the surrounding harm landscape gives the question political weight regardless of which definition wins. The article extract is truncated, so the piece's concluding recommendations are not visible in the material provided; the analysis above should not be read as endorsing the 20% number as confirmed fact.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗