Email Deliverability State of the Union 2026
State of the Union Cold email deliverability 2026 Independent, unsponsored

Domain abuse is a registration game

I lost 800 inboxes in one week. Then I read the study that explains exactly why. 1.52 million malicious domains taken apart, and the way most cold email is set up, probably yours too, looks statistically identical to theirs. Here is all of it, so you don't repeat my week.

Built on: Mashood, F. and Nabeel, M. “A Longitudinal Study of Recently Observed Malicious Domains.” 9 June 2026, CC BY 4.0. Plus the released 1.52M-domain dataset and the Spamhaus DBL FAQ.

Youssef Hesham
Youssef Hesham
Aug 2, 2026 · 5:25 AM
Why this exists · not sponsored

Last week I watched 800 inboxes die.

July 26, 500 pre-warmed inboxes, gone. July 29, a different provider with a totally different setup, 300 fresh Google inboxes torched 20 days into warmup. I had not sent a single email from them.

We had to pause sending. We were waiting on the batch to be ready, and instead it flatlined. Turned out that provider's name servers were serving 111,000 domains, all sitting on a negative Spamhaus DBL score. So it was never just me. One shared footprint goes bad and everyone on it drowns together. I only caught it because EmailGuard ran the forensic check on the name servers.

So I spent 4 hours tearing apart the study below, 1.52 million malicious domains, plus the Spamhaus FAQs, to work out what actually went wrong. The short version: the way most cold email is set up is the exact fingerprint this research flags as malicious. Here is the whole thing, with the fixes at the end.

Nobody paid me and I am not affiliated with anything named here. No affiliate links, no discounts. I pay full price: $600/mo for Email Bison, $200/mo for EmailGuard. I am recommending the tools I bleed money on because they are the ones that saved me. That is the only reason they are in here.

1.52M
Domains flagged
Jan to May 2026
89.3%
Registered by attackers,
not compromised
60d
Median age at
first detection
77.9%
Sit in a same day
bulk batch
What was measured

The setup, fast. Skip it if you don't give a fuck.

Every domain VirusTotal first saw from January to May 2026 that at least 5 separate scanners flagged as malicious. 1.52 million of them, joined to WHOIS, passive DNS, and the Tranco top 1M. The authors split the set first, because a hijacked real site and a purpose-built attack domain behave nothing alike: anything in the Tranco top 500K or registered 3-plus years before detection counts as compromised, everything else as attacker created. That attacker-created 89.3% is what the rest of this is about.

SegmentCountShare
Total flagged domains1,520,050100%
Attacker created1,357,92189.3%
Compromised162,12910.7%
 by age ≥ 3 years only157,707
 by Tranco rank only2,838
 by both conditions1,584
Usable WHOIS creation date≈88.4%
Non empty passive DNS IP set≈88.1%

The compromised class is almost entirely the age rule, which means old domains getting repurposed is the compromise story, not front page sites getting hijacked. The authors note 89.3% is a conservative floor, since any attacker domain aged past three years before use gets counted on the other side.

Lifecycle

The average scam domain lives 60 days. Your fresh one isn't special.

Age here is the gap between the WHOIS creation date and the first VirusTotal sighting, measured across 1,158,280 attack domains with usable dates.

Registration to detectionValue
Median60 days
90th percentile403 days
Detected within 1 day7.4%
Detected within 1 week29.9%

Nearly a third get burned inside a week. Here is the part that stings. My 300 Google inboxes were 20 days old when they died. The 500 pre-warmed ones, nobody could even tell me how old they were. Anything under 30 days sits right in this bucket, and that is exactly where most of us are sending from.

Lifecycle · repo figure

Most die young. Then a whole graveyard wakes up at exactly 365 days and nobody can explain it.

The full age curve from the released dataset: the share of attack domains detected by a given age, where age is the gap from WHOIS registration to first VirusTotal sighting.

1.0 0.75 0.50 0.25 0 0 200 400 600 800 1000 Domain age at first detection (days) Median 60d P90 403d ≈1-year wall →

The line goes near-vertical just before day 365: a large block of domains sit registered for about a year, then get detected almost together. That looks less like organic aging and more like aged or auto-renewed inventory switched on by the calendar. Read it as a caution about the age heuristic itself: the feature that splits compromised from attacker created has a seam right where a year of shelf-life lands.

Coordination

Bulk registration is the biggest blunder you can make

The authors group attack domains by (registrar, WHOIS creation date) and call any group of five or more a batch. On that definition, 1,057,926 of 1,357,921 attack domains (77.9%) belong to a batch, across 22,977 distinct batches. Average batch size works out to about 46 domains. Names inside batches follow programmatic patterns like 10jfr.top and 10jgr.top. This is not theory. Scan a fresh batch and bulk registration is the thing that lights up. I have watched it flag in VirusTotal with my own eyes. Buy your domains the same way the spammers do and you get sorted right in with them.

#RegistrarDateDomains
1Namesilo2026-02-062,168
2Namecheap2025-01-062,017
3Namesilo2026-03-091,984
4Namecheap2025-02-051,850
5Namecheap2025-01-071,536
6Spaceship2026-01-131,432
7Dynadot2025-07-111,402
8Spaceship2026-01-101,392
9Dynadot2026-02-171,383
10GNAME.COM2025-09-031,362

Each row is one registrar on one day. This is the 10 biggest single-day batches, not a registrar ranking, so the same name repeats when it ran more than one of them (different dates, check the column). The merged registrar totals are in the Registrars section below.

Coordination · derived from the dataset

Bulk buying isn't a growth hack. It's a signed confession, and they file it the same day.

Grouping every dated attack domain by registrar and registration day, then counting how many domains land in each group-size bucket. Lone registrations are the exception, not the rule.

1 · lone reg
134,171
2
43,778
3–4
52,344
5–9
79,185
10–49
243,134
50–99
175,607
100–499
449,307
500 or more
174,550

Domains by same-day batch size. Only about 10% are lone registrations. A third sit in batches of 100 to 499, and just 225 mega-batches of 500 or more hold 174,550 domains between them, the largest a single registrar-day of 2,168. In total 83% of dated attack domains live in a batch of five or more (the paper reports 78% on its attacker-only subset).

Concentration

8 registrars run 59% of the sewer. And the paper crowned the wrong king, it's Dynadot.

Dynadotmerged
164,416
GNAME.COM
147,425
Namecheapmerged
133,511
Namesilo
114,088
GoDaddy
56,880
Spaceship, Inc.
52,086
NiceNIC
22,659
PublicDomainRegistry
22,130
All other (4,464)
491,565

Normalized here. Dynadot was split across Dynadot LLC and Dynadot Inc, and Namecheap across two spellings, so the paper double-counted both. Merged, Dynadot is really number 1 at 164,416 and Namecheap number 3 at 133,511. The paper never does this, which is why its own top-four ranking is wrong. The rest is 4,464 registrars sharing 491,565 domains.

Concentration

10 TLDs, 68% of the abuse. That horrible dollar TLD you just bought 40 of is right there.

.com
420,579
.top
96,405
.cc
70,128
.xyz
68,786
.cn
53,997
.shop
52,902
.sbs
49,130
.info
46,799
.click
34,792
.cfd
31,156
All other (741)
433,247

Look at that list again. .info, .cc, .shop, .xyz, .click, the exact cheap TLDs cold email buys by the hundred, all sitting near the top. Strip .com out and the 9 cheap ones below it are 37.1% of all attack volume. And this is not just one paper. SURBL keeps a live most-abused-TLD list, and .info sits at number 2, right under .com, with 726,137 flagged domains (surbl.org/tld). The dollar TLD is a dollar for a reason.

Same picture, two independent sources
This studyattacker domains, Jan to May 2026
1.com420,579
2.top96,405
3.cc70,128
4.xyz68,786
5.cn53,997
6.shop52,902
7.sbs49,130
8.info46,799
9.click34,792
10.cfd31,156
SURBLlive most-abused list
1.com1,121,010
2.info726,137
3.top585,017
4.cn135,520
5.co117,854
6.cc101,778
7.vip91,734
8.pro86,265
9.shop84,110
10.help76,858
Infrastructure

The attackers are on Cloudflare. Just like you and me.

AS13335 Cloudflare
587,784
AS398823 PEG TECH INCnamed here
523,395
AS16509 Amazon AWS
218,808
AS4837 China Unicom
191,959
AS63949 Akamai (Linode)
146,480
AS20940 Akamai
134,432
AS396982 Google Cloud
89,342
AS45102 Alibaba Cloud
81,274
AS22612 Namecheap
74,589
AS47846 Sedo
62,562

At the IP level it is even starker. 8 of the top 10 hosting addresses are Cloudflare, spread across the 188.114.0.0/16, 172.64.0.0/16 and 2a06:98c1::/32 ranges. The two busiest IPv4 addresses front 231,685 and 231,618 distinct attack domains each. That is reverse proxying used as origin masking at industrial scale. Worth knowing, because if you send cold email you are almost certainly on Cloudflare name servers too. Same neighborhood as the study. A name server two doors down goes bad and it becomes your problem, which is exactly how my 111,000-domain footprint took me down.

AS398823 hosts 523,395 attack domains, second only to Cloudflare, and the paper leaves it blank. One reverse lookup says it is PEG TECH INC, a US hosting outfit (ARIN, allocated 2020). The single most actionable unknown in the study, and it was hiding one query away.

Infrastructure · repo figure

2 Cloudflare IPs front 231,000 attack domains each. These numbers are bananas.

188.114.96.3 (v4)
231,685
188.114.97.3 (v4)
231,618
188.114.96.4 (v4)
173,325
188.114.97.4 (v4)
173,262
2a06:98c1:3120::3 (v6)
136,233
2a06:98c1:3121::3 (v6)
136,128
172.64.80.1 (v4)
119,195
2606:4700:130:436c:6f75:6466:6c61:7265 (v6)spells “Cloudflare”
112,955
172.234.24.211 (v4)
83,138
172.239.57.117 (v4)
83,129

8 of the 10 are Cloudflare edge ranges (188.114.0.0/16, 172.64.0.0/16, 2a06:98c1::/32, 2606:4700::/32). One of them, 2606:4700:130:436c:6f75:6466:6c61:7265, spells Cloudflare in ASCII (43 6c → Cl, 6f 75 → ou, 64 66 → df, 6c 61 → la, 72 65 → re). The two that are not Cloudflare, 172.234 and 172.239, are Akamai and Linode space.

The two busiest addresses each front over 231,000 distinct attack domains. That is reverse proxying used as origin masking at industrial scale: the real host hides behind the CDN, so a takedown has to go through the proxy, not the box.

Infrastructure · repo figure

You don't pick your neighbors, and some of them are terrible fuckin neighbors.

TOP 5 EDGE IPS SAMPLE DOMAINS 188.114.96.3 188.114.97.3 188.114.96.4 188.114.97.4 2a06:98c1:3120::3 y.gy in.sv id.sv th.gg xs.pe 74.sb 2m.is yt.vu me.sv 3s.cm xm.lk i8.ae

Here is what this mess of lines actually means. A pile of throwaway spam domains all sit on the same handful of IPs on the left, and each domain touches several of them at once. So the IP your provider put you on is shared with total strangers. If one of them is spammy, and on shared infra one of them always is, the whole block gets treated as dirty and you go down with it. That is the entire game with cheap infra: you inherit your neighbors' reputation whether you like it or not. (Node labels are real, from the paper's figure.)

Damage proxy

Counting bad domains is useless. A rounding error does all the damage.

Passive DNS query count is a rough stand-in for how much a domain is actually used. Across 1,172,386 attack domains with real traffic:

Log scale. The busiest slice is thousands of times bigger than the middle. Counting bad domains tells you almost nothing about who is actually doing damage. A handful of them carry the whole thing.

Damage proxy · derived from the dataset

1% of the domains do 91% of the volume. The other 99% is landfill.

Passive-DNS query volume is the paper’s stand-in for real-world exposure. Summed across the released dataset it comes to 56.1 billion queries, and almost all of it sits in a sliver of domains. Cumulative share of all queries held by the busiest domains:

Top 0.01%~133 domains
42.2%
Top 0.1%
69.2%
Top 1%~13,332
91.0%
Top 5%
96.5%
Top 10%
97.8%
Top 50%
99.7%

133 domains out of 1.5 million move 42% of all the traffic. That is the whole point. The count of bad domains means nothing on its own, a few of them do everything. One honest catch: the very top of that list is real infrastructure that got swept into the flagged set, bitbucket.org (3.5B queries), mandrillapp.com (1.2B) and the like. Legit services caught in the net, not attackers.

Impersonation

The WhatsApp landmine: never put a brand in a cold email

Brand tokens were pulled from Tranco's top 10,000, filtered to four characters or more and screened against an English word list, leaving 7,154 tokens matched as substrings inside attack domain names. In total 114,034 attack domains (8.4%) contain a brand token, across 2,569 distinct brands.

whatsapp
19,511
logiFalse positive
5,900
google
2,302
coinbase
2,028
labsGeneric
1,803
promGeneric
1,702
telegra
1,652
appsGeneric
1,596
bet365
1,547
cryptoGeneric
1,360

Half this chart is noise and the paper does not say so. It reads logi as Logitech, but that substring hits login, logistics, technologies and logic. Four more entries are ordinary words that survived the filter. Treat 8.4% as a ceiling, not a measurement. The signal that does hold: messaging apps, crypto exchanges and gambling are the credential harvesting bullseye. For you the lesson is copy-side. Substring matchers watch exactly these tokens, so putting whatsapp, paypal, coinbase or a client's brand inside a sending domain, or heavy in the body, volunteers you for the same bucket. Your domain is not where you get clever with a brand name.

Timing · derived from the dataset

These aren't investments. Buy, blast, burn, repeat. Domains are disposable now.

The paper counts domains by the month they were detected. Counting instead by the month they were registered exposes the supply side: a steep ramp into 2026.

Jan 2025Jul 2025Jan 2026May 2026

Monthly registrations among flagged domains, in thousands. From about 30,000 a month through 2025 to 152,000 in January 2026 alone. Roughly 592,000 of the 1.52 million flagged domains, about 39%, were registered in the same January-to-May 2026 window in which they were caught. Register, weaponise, burn, often inside one quarter. (A long tail of pre-2020 registrations, the aged and compromised set, sits off the left edge of this chart.)

Deliverability recommendations · the fixes

Stop drawing the scammer fingerprint with your own hands.

Here is the uncomfortable part. The setup most cold email runs on is the exact shape this study flags as malicious. Not similar. Identical. I learned that the 800-inbox way, you get it for free. What to change:

  1. Stop buying 30 domains in one afternoon. 78% of the malicious domains here sit in a same-day batch at one registrar. Buy 20 to 40 at Namecheap in one sitting and you just drew the same fingerprint. Spread registrations across days + 2 or 3 registrars. Boring, and it is the number 1 signal in the whole study.
  2. Spintax your fingerprint. You already spintax your copy so it looks unpredictable. Your infrastructure should be just as unpredictable. Everyone runs the identical playbook, one registrar, one day, brand-variant names, .info, then wonders why inboxes treat them like a bot. Do not follow the pattern. Be the exception.
  3. Stop combosquatting your domains. tryapple, getapple, applehq all pointing at apple.com. Sticking a brand name inside your domain is called combosquatting, and it is exactly what the reputation tools hunt for. Same deal if you drop a brand like WhatsApp or PayPal in the body. Ease off the client's brand in the domain, and never put someone else's brand in there at all.
  4. A fresh domain is guilty until proven innocent. Median malicious domain here gets caught at 60 days old. Under 60 and you sit in the exact same age band. Spamhaus DBL says it flat: “an unknown reputation has a much higher risk of emitting spam than known-good domains, so unknown reputations begin as poor by default.” New equals suspicious. Warm in weeks, not days.
  5. You are racing a 7-day clock. 30% of these domains get torched inside a week of registration. Buy fresh, blast on day 2, and you can be flagged before you have sent 100 real emails. Ramp slow, watch placement from email 1.
  6. Check the name servers. Providers hide them for a reason. They set your name servers and sometimes put you on blacklisted ones, then never show you, or hand you a clean decoy. Mine were serving 111,000 domains on a negative Spamhaus DBL score. That is the paper's shared-footprint finding in real life. EmailGuard runs the forensic check and tells you if your name servers are burned + whether to demand a replacement. I run it on every batch.
  7. Pre-warmed or pre-wound? Nobody knows how a “pre-warmed” inbox was warmed, or for how long. People send day 1 on pure faith because the invoice said ready. I had 500 pre-warmed inboxes torched. Provider said he appealed, I canceled. And where do the burned ones go? Straight into a dirty pool on some cheap sequencer, resold to the next guy as pre-warmed. Trust the warmup score, not the label.
  8. Warmup is not the villain. Dirty shared pools are. Cheap sequencers let providers dump marked domains into the shared pool to launder reputation on top of yours. That is the real problem. Isolation is the whole game. It is why Email Bison is not cheap, and why a bad warmup score there is never a false alarm. Clean pool, the score is the truth.
  9. .info is cheap for a reason. .info, .top, .xyz, .shop, .sbs together are 37% of all attack volume in this study. .info is a cold email favorite because it costs a dollar. It is also sitting in the abuse pool. Stay on .com.

None of this is warmup-tool advice. It is don't-look-like-the-1.5-million-domains-that-just-got-flagged advice. I paid for it in inboxes. You get the receipt for free. Have a good week.