The setup, fast. Skip it if you don't give a fuck.
Every domain VirusTotal first saw from January to May 2026 that at least 5 separate scanners flagged as malicious. 1.52 million of them, joined to WHOIS, passive DNS, and the Tranco top 1M. The authors split the set first, because a hijacked real site and a purpose-built attack domain behave nothing alike: anything in the Tranco top 500K or registered 3-plus years before detection counts as compromised, everything else as attacker created. That attacker-created 89.3% is what the rest of this is about.
| Segment | Count | Share |
|---|---|---|
| Total flagged domains | 1,520,050 | 100% |
| Attacker created | 1,357,921 | 89.3% |
| Compromised | 162,129 | 10.7% |
| by age ≥ 3 years only | 157,707 | — |
| by Tranco rank only | 2,838 | — |
| by both conditions | 1,584 | — |
| Usable WHOIS creation date | ≈88.4% | — |
| Non empty passive DNS IP set | ≈88.1% | — |
The compromised class is almost entirely the age rule, which means old domains getting repurposed is the compromise story, not front page sites getting hijacked. The authors note 89.3% is a conservative floor, since any attacker domain aged past three years before use gets counted on the other side.
Half of all attack domains are caught within 60 days of registration
Age here is the gap between the WHOIS creation date and the first VirusTotal sighting, measured across 1,158,280 attack domains with usable dates.
| Registration to detection | Value |
|---|---|
| Median | 60 days |
| 90th percentile | 403 days |
| Detected within 1 day | 7.4% |
| Detected within 1 week | 29.9% |
Nearly a third get burned inside a week. Here is the part that stings. My 300 Google inboxes were 20 days old when they died. The 500 pre-warmed ones, nobody could even tell me how old they were. Anything under 30 days sits right in this bucket, and that is exactly where most of us are sending from.
Half are caught by day 60, then a wall of them lights up at one year
The full age curve from the released dataset: the share of attack domains detected by a given age, where age is the gap from WHOIS registration to first VirusTotal sighting.
The line goes near-vertical just before day 365: a large block of domains sit registered for about a year, then get detected almost together. That looks less like organic aging and more like aged or auto-renewed inventory switched on by the calendar. Read it as a caution about the age heuristic itself: the feature that splits compromised from attacker created has a seam right where a year of shelf-life lands.
Bulk registration is the biggest blunder you can make
The authors group attack domains by (registrar, WHOIS creation date) and call any group of five or more a batch. On that definition, 1,057,926 of 1,357,921 attack domains (77.9%) belong to a batch, across 22,977 distinct batches. Average batch size works out to about 46 domains†. Names inside batches follow programmatic patterns like 10jfr.top and 10jgr.top. This is not theory. Scan a fresh batch and bulk registration is the thing that lights up. I have watched it flag in VirusTotal with my own eyes. Buy your domains the same way the spammers do and you get sorted right in with them.
| # | Registrar | Date | Domains |
|---|---|---|---|
| 1 | Namesilo, LLC | 2026-02-06 | 2,168 |
| 2 | Namecheap Inc | 2025-01-06 | 2,017 |
| 3 | Namesilo, LLC | 2026-03-09 | 1,984 |
| 4 | Namecheap Inc | 2025-02-05 | 1,850 |
| 5 | Namecheap Inc | 2025-01-07 | 1,536 |
| 6 | Spaceship, Inc. | 2026-01-13 | 1,432 |
| 7 | Dynadot LLC | 2025-07-11 | 1,402 |
| 8 | Spaceship, Inc. | 2026-01-10 | 1,392 |
| 9 | Dynadot LLC | 2026-02-17 | 1,383 |
| 10 | GNAME.COM Pte Ltd | 2025-09-03 | 1,362 |
Bulk is not the tail of the distribution, it is the body
Grouping every dated attack domain by registrar and registration day, then counting how many domains land in each group-size bucket. Lone registrations are the exception, not the rule.
Domains by same-day batch size. Only about 10% are lone registrations. A third sit in batches of 100 to 499, and just 225 mega-batches of 500 or more hold 174,550 domains between them, the largest a single registrar-day of 2,168. In total 83% of dated attack domains live in a batch of five or more (the paper reports 78% on its attacker-only subset).
8 registrars carry 59%, and Dynadot is actually number 1
Normalized here. Dynadot was split across Dynadot LLC and Dynadot Inc, and Namecheap across two spellings, so the paper double-counted both. Merged, Dynadot is really number 1 at 164,416† and Namecheap number 3 at 133,511†. The paper never does this, which is why its own top-four ranking is wrong. The rest is 4,464 registrars sharing 491,565 domains.
10 TLDs carry 68%, and the cheap ones we use are all in there
Look at that list again. .info, .cc, .shop, .xyz, .click, the exact cheap TLDs cold email buys by the hundred, all sitting near the top. Strip .com out and the 9 cheap ones below it are 37.1%† of all attack volume. And this is not just one paper. SURBL keeps a live most-abused-TLD list, and .info sits at number 2, right under .com, with 726,137 flagged domains (surbl.org/tld). The dollar TLD is a dollar for a reason.
The attackers are on Cloudflare. Just like you and me.
At the IP level it is even starker. 8 of the top 10 hosting addresses are Cloudflare, spread across the 188.114.0.0/16, 172.64.0.0/16 and 2a06:98c1::/32 ranges. The two busiest IPv4 addresses front 231,685 and 231,618 distinct attack domains each. That is reverse proxying used as origin masking at industrial scale. Worth knowing, because if you send cold email you are almost certainly on Cloudflare name servers too. Same neighborhood as the study. A name server two doors down goes bad and it becomes your problem, which is exactly how my 111,000-domain footprint took me down.
AS398823 hosts 523,395 attack domains, second only to Cloudflare, and the paper leaves it blank. One reverse lookup says it is PEG TECH INC, a US hosting outfit (ARIN, allocated 2020). The single most actionable unknown in the study, and it was hiding one query away.
2 Cloudflare IPs front 231,000 attack domains each. That's insane.
8 of the 10 are Cloudflare edge ranges (188.114.0.0/16, 172.64.0.0/16, 2a06:98c1::/32, 2606:4700::/32). One of them, 2606:4700:130:436c:6f75:6466:6c61:7265, spells Cloudflare in ASCII (43 6c → Cl, 6f 75 → ou, 64 66 → df, 6c 61 → la, 72 65 → re). The two that are not Cloudflare, 172.234 and 172.239, are Akamai and Linode space.
The two busiest addresses each front over 231,000 distinct attack domains. That is reverse proxying used as origin masking at industrial scale: the real host hides behind the CDN, so a takedown has to go through the proxy, not the box.
Spam domains share your IPs. Share the IP, share the punishment.
Here is what this mess of lines actually means. A pile of throwaway spam domains all sit on the same handful of IPs on the left, and each domain touches several of them at once. So the IP your provider put you on is shared with total strangers. If one of them is spammy, and on shared infra one of them always is, the whole block gets treated as dirty and you go down with it. That is the entire game with cheap infra: you inherit your neighbors' reputation whether you like it or not. (Node labels are real, from the paper's figure.)
A tiny slice of domains does almost all the damage
Passive DNS query count is a rough stand-in for how much a domain is actually used. Across 1,172,386 attack domains with real traffic:
Log scale. The busiest slice is thousands of times bigger than the middle. Counting bad domains tells you almost nothing about who is actually doing damage. A handful of them carry the whole thing.
1% of the domains carry 91% of the queries
Passive-DNS query volume is the paper’s stand-in for real-world exposure. Summed across the released dataset it comes to 56.1 billion queries, and almost all of it sits in a sliver of domains. Cumulative share of all queries held by the busiest domains:
133 domains out of 1.5 million move 42% of all the traffic. That is the whole point. The count of bad domains means nothing on its own, a few of them do everything. One honest catch: the very top of that list is real infrastructure that got swept into the flagged set, bitbucket.org (3.5B queries), mandrillapp.com (1.2B) and the like. Legit services caught in the net, not attackers.
The WhatsApp landmine: never put a brand in a cold email
Brand tokens were pulled from Tranco's top 10,000, filtered to four characters or more and screened against an English word list, leaving 7,154 tokens matched as substrings inside attack domain names. In total 114,034 attack domains (8.4%) contain a brand token, across 2,569 distinct brands.
Half this chart is noise and the paper does not say so. It reads logi as Logitech, but that substring hits login, logistics, technologies and logic. Four more entries are ordinary words that survived the filter. Treat 8.4% as a ceiling, not a measurement. The signal that does hold: messaging apps, crypto exchanges and gambling are the credential harvesting bullseye. For you the lesson is copy-side. Substring matchers watch exactly these tokens, so putting whatsapp, paypal, coinbase or a client's brand inside a sending domain, or heavy in the body, volunteers you for the same bucket. Your domain is not where you get clever with a brand name.
The spike is in new registrations, not detections
The paper counts domains by the month they were detected. Counting instead by the month they were registered exposes the supply side: a steep ramp into 2026.
Monthly registrations among flagged domains, in thousands. From about 30,000 a month through 2025 to 152,000 in January 2026 alone. Roughly 592,000 of the 1.52 million flagged domains, about 39%, were registered in the same January-to-May 2026 window in which they were caught. Register, weaponise, burn, often inside one quarter. (A long tail of pre-2020 registrations, the aged and compromised set, sits off the left edge of this chart.)
Stop hand-drawing the scammer fingerprint
Here is the uncomfortable part. The setup most cold email runs on is the exact shape this study flags as malicious. Not similar. Identical. I learned that the 800-inbox way, you get it for free. What to change:
- Stop buying 30 domains in one afternoon. 78% of the malicious domains here sit in a same-day batch at one registrar. Buy 20 to 40 at Namecheap in one sitting and you just drew the same fingerprint. Spread registrations across days + 2 or 3 registrars. Boring, and it is the number 1 signal in the whole study.
- Spintax your fingerprint. You already spintax your copy so it looks unpredictable. Your infrastructure should be just as unpredictable. Everyone runs the identical playbook, one registrar, one day, brand-variant names, .info, then wonders why inboxes treat them like a bot. Do not follow the pattern. Be the exception.
- Stop combosquatting your domains. tryapple, getapple, applehq all pointing at apple.com. Sticking a brand name inside your domain is called combosquatting, and it is exactly what the reputation tools hunt for. Same deal if you drop a brand like WhatsApp or PayPal in the body. Ease off the client's brand in the domain, and never put someone else's brand in there at all.
- A fresh domain is guilty until proven innocent. Median malicious domain here gets caught at 60 days old. Under 60 and you sit in the exact same age band. Spamhaus DBL says it flat: “an unknown reputation has a much higher risk of emitting spam than known-good domains, so unknown reputations begin as poor by default.” New equals suspicious. Warm in weeks, not days.
- You are racing a 7-day clock. 30% of these domains get torched inside a week of registration. Buy fresh, blast on day 2, and you can be flagged before you have sent 100 real emails. Ramp slow, watch placement from email 1.
- Check the name servers. Providers hide them for a reason. They set your name servers and sometimes put you on blacklisted ones, then never show you, or hand you a clean decoy. Mine were serving 111,000 domains on a negative Spamhaus DBL score. That is the paper's shared-footprint finding in real life. EmailGuard runs the forensic check and tells you if your name servers are burned + whether to demand a replacement. I run it on every batch.
- Pre-warmed or pre-wound? Nobody knows how a “pre-warmed” inbox was warmed, or for how long. People send day 1 on pure faith because the invoice said ready. I had 500 pre-warmed inboxes torched. Provider said he appealed, I canceled. And where do the burned ones go? Straight into a dirty pool on some cheap sequencer, resold to the next guy as pre-warmed. Trust the warmup score, not the label.
- Warmup is not the villain. Dirty shared pools are. Cheap sequencers let providers dump marked domains into the shared pool to launder reputation on top of yours. That is the real problem. Isolation is the whole game. It is why Email Bison is not cheap, and why a bad warmup score there is never a false alarm. Clean pool, the score is the truth.
- .info is cheap for a reason. .info, .top, .xyz, .shop, .sbs together are 37% of all attack volume in this study. .info is a cold email favorite because it costs a dollar. It is also sitting in the abuse pool. Stay on .com.
None of this is warmup-tool advice. It is don't-look-like-the-1.5-million-domains-that-just-got-flagged advice. I paid for it in inboxes. You get the receipt for free. Have a good week.