Photo by Samuel Regan-Asante on Unsplash
If you have spent any time looking at DNS traffic logs, you know the internet is a noisy, often unfriendly place, but the latest numbers on new domain registrations are still enough to make a veteran sysadmin wince.
A recent deep dive into 2025 registration data shows that out of 85 million new gTLD registrations, a staggering 8.5 million were flagged on blocklists by the following spring. That is a ten percent failure rate for the entire industry. According to reporting on the Interisle Consulting Group study, the bulk of this malicious activity isn't spread evenly across the thousands of accredited registrars; instead, it is heavily concentrated within just five major players. We are looking at a scenario where a handful of companies are effectively acting as the primary gateways for the web's phishing and malware infrastructure.
The Economics of Apathy
This matters because it highlights a fundamental rift in how we value the domain ecosystem. For a large registrar, a registration is a unit of revenue. If that unit is used to host a phishing site for 48 hours before being burned, the registrar still keeps the fee. There is a clear financial incentive to keep the doors wide open and the friction low, even if it means the neighborhood goes to hell. When five companies account for half of the world's blocklisted domains, it ceases to be an accidental byproduct of scale and starts looking like a business model.
For the rest of us—the hosting providers, the security teams, and the end users—this creates a massive "hidden" tax. We spend millions on filtering, blacklisting, and cleanup efforts just to stay level with the tide of garbage flowing out of these high-volume outlets. If the industry doesn't find a way to make hosting malicious actors more expensive for the registrar than it is for the victim, this ratio is only going to get worse.
It is almost impressive, in a dark way, that we have managed to industrialize the production of digital landfill to the point where every tenth domain is essentially a weaponized asset.
Looking Ahead
We need to move past the era of "disputing the count" and start addressing the concentration of risk. If a registrar cannot maintain a clean portfolio, they shouldn't be allowed to hide behind the sheer volume of their transactions. Growth is great, but not when it is fueled by the systematic exploitation of the global DNS. We either clean it up now, or we wait for regulators who don't understand the technology to do it for us, and nobody in this industry wants that.