What is the most abused TLD (Top-Level Domain) for spam?

Updated on 29 Jul 2026: We updated this guide with current TLD abuse figures, clearer measurement rules, and practical filtering guidance.
There is no single universal winner. In public domain reputation data covering October 2025 through March 2026, .com ranks first by raw malicious or suspicious domain count, with 506,482 listings. In the same dataset, .cfd ranks highest among the reported generic TLDs by concentration, with 17.54% of its zone listed. Other high-rate generic TLDs include .qpon, .icu, .bid, .xin, and .bond.
That distinction matters for email. A receiver does not usually reject mail because a domain ends in a specific TLD. It scores the message using domain age, sender reputation, authentication, URLs in the body, complaint history, and blocklist or blacklist signals. The TLD is a context clue, not a verdict.
- Raw volume: .com leads the current mixed-abuse dataset because it has a very large domain base.
- Abuse concentration: .cfd leads the reported generic TLD table when listed domains are divided by zone size.
- Dataset scope: A malicious or suspicious domain list includes more than unsolicited email.
- Email risk: The TLD should change scrutiny, not replace authentication and behavior checks.
The direct answer
Start with the metric. In the October 2025 through March 2026 snapshot, .com ranks first by number of malicious or suspicious domains, followed by .top. The dataset detected 2.15 million listed domains across all TLDs during the six-month period. It includes associations with spam, phishing, malware, ransomware, and other fraudulent activity, so it is broader than a spam-only count.
By rate, the reported generic TLD leader is .cfd in that snapshot. Its 93,940 listed domains make up 17.54% of its zone. .com has far more listed domains, but those listings are a much smaller share of its roughly 168 million-domain zone. Raw count measures total exposure, while the rate measures abuse concentration.
|
|
|
|---|---|---|
Raw listed-domain count | .com | Total exposure |
Reported gTLD zone share | .cfd | Abuse concentration |
Malicious email rate | Dataset-specific | Mail filtering |
Phishing URLs or pages | Dataset-specific | Web threat review |
Different ways to answer "most abused TLD"
Phishing rankings can still name a different TLD. One report can count unique registered domains, while another counts every URL, hosted subdomain, landing page, or email message. A TLD that leads one unit of measurement does not automatically lead the others.
What abuse datasets actually count
The unit of measurement can change the ranking before any security judgment is made. Check what the report counts, which abuse categories it includes, what time period it covers, and whether its sensors see email traffic, DNS activity, web pages, or several of these sources.
- Registered domains: Each second-level domain is counted once, even if it hosts many abusive URLs.
- Hostnames and subdomains: A shared hosting domain can create many counted hostnames under one registration.
- URLs and pages: One domain can produce many phishing pages or redirect URLs.
- Email messages: A high-volume campaign can dominate message counts while using few domains.
The cause matters too. A maliciously registered domain was acquired for abuse, while a compromised domain belongs to a legitimate owner whose site or account was taken over. Compromised sites and hosted subdomains can raise a TLD's count without showing that the namespace itself attracts disposable registrations. This is why a defensible filter keeps TLD reputation separate from domain reputation and URL reputation.
Why rankings disagree
Most disagreements come down to denominator choice. Counting bad domains answers one operational question: "Where is the most abuse appearing?" Dividing by the total number of registered domains answers another: "Which namespace has the highest concentration of abuse?" Both are useful, but they lead to different blocking and review decisions.
Raw count
- Best for: Estimating total volume hitting filters, traps, and URL feeds.
- Common winner: .com, because it has the largest installed base.
- Main risk: It can make large TLDs look uniquely bad when they are also uniquely common.
Abuse rate
- Best for: Finding TLDs where abuse is dense compared with legitimate use.
- Common winners: Low-cost, high-churn, lightly verified TLDs.
- Main risk: It can overstate small namespaces with limited legitimate mail use.
For email filtering, concentration deserves more weight when a domain is new, cheap, and sending unsolicited mail. For abuse response, raw volume matters because it shows where the greatest filter pressure originates.

Infographic comparing raw TLD abuse count with abuse rate, domain age, authentication, and blocklist hits.
TLDs that deserve extra scrutiny
No TLD is automatically bad, but some TLDs need extra evidence of legitimacy. That includes TLDs that repeatedly appear in abuse reports, TLDs with heavy new-domain churn, and TLDs that attackers can buy cheaply in bulk. The specific list changes over time, so the right workflow is monitoring, not a static wall chart.
Listed-domain volume by TLD
Malicious or suspicious domain counts detected from October 2025 through March 2026.
.com
506,482 domains.top
270,121 domains.cn
252,852 domains.cc
94,415 domains.cfd
93,940 domains.bond
59,271 domains.xyz
47,547 domains.sbs
42,115 domainsCountry-code TLDs are not automatic trust signals. .us ranked 15th among country-code TLDs in the current snapshot, with 2,981 listed domains. That volume is far below .cn and .cc, but it still shows why a country label should not replace sender-level checks.
If you are choosing a domain for email, use a credible TLD, avoid bargain registrations for production sending, and give the domain time to build reputation. The practical tradeoffs are covered in TLD choices and deliverability.
How to use TLD data without overblocking
The worst operational mistake is blocking a whole TLD from mail or web access without checking the business impact. Some TLDs deserve aggressive treatment in consumer inbox filtering, but enterprise mail, support desks, and security teams still need exceptions for real customers, partners, and abuse reports.
Do not block on TLD alone
A TLD should increase scrutiny when it appears with other signals. It should not be the only reason a legitimate message disappears.
- Strong signal: New domain, poor authentication, suspicious URLs, and prior blocklist or blacklist hits.
- Weak signal: A familiar sender using an unusual TLD with clean authentication and normal engagement.
- Review signal: A new sender on a high-risk TLD that links to more new domains in the message body.
A good review flow checks the sending domain, return-path domain, DKIM signing domain, and every linked domain in the message. Suped's blocklist monitoring supports that workflow by tracking domain and IP listings alongside the identities found in authenticated mail.
Blocklist checker
Check your domain or IP against 144 blocklists.















When a domain appears in mail you did not expect, check whether the exact domain or IP is on known blocklists. If you control the sending domain, run a broader domain health check as well, because TLD reputation is only one part of the sender identity.
What this means for email senders
If you send legitimate email, do not pick a sending domain only because the TLD is cheap or available. Pick a domain that a recipient can trust, authenticate it properly, warm it carefully, and avoid sending patterns that look disposable. A polished domain on a risky TLD still has to earn reputation.
Suped's product supports this workflow by showing which services send for your domain, whether SPF and DKIM align for DMARC, and whether a sending domain or IP develops a blocklist or blacklist problem. TLD reputation can set the level of scrutiny, while the authentication and monitoring data shows what needs fixing.

Blocklist monitoring page showing domain and IP checks across blocklists with importance and status
For a real sending test, send a message through your normal mail path and inspect the headers, authentication alignment, URL reputation, and content signals. A quick email tester run tells you more than judging the domain by its final label.
TLD risk scoring exampleYAML
domain: sender.example sender_tld: .top domain_age_days: 3 spf_alignment: pass dkim_alignment: fail dmarc_policy: none url_tld: .cfd blocklist_hit: true action: quarantine and review
A risky TLD alone does not force rejection. A risky TLD plus a new domain, failed DKIM alignment, no DMARC enforcement, and a listed URL domain is a different case. That combination deserves quarantine or manual review.
Views from the trenches
Best practices
Separate raw volume rankings from abuse-rate rankings before choosing a blocking rule.
Treat TLD reputation as one signal beside age, authentication, traffic, and complaints.
Monitor domains and URLs in mail content, not only the visible sending domain and From.
Common pitfalls
Blocking a whole TLD catches some spam but also creates false positives for support.
Assuming .com is low risk ignores its large raw share of reported abusive domains.
Buying a cheap TLD for outbound mail saves little when reputation problems follow fast.
Expert tips
Use short-lived domain age and failed authentication to raise the score before filtering.
Review URL blocklist hits separately because spam often points away from the sender.
Keep abuse and postmaster inboxes monitored so complaints reach someone accountable.
Marketer from Email Geeks says .com often leads raw abuse rankings because its installed base is so large, even when its abuse rate is small.
2023-09-16 - Email Geeks
Marketer from Email Geeks says .us surprised people in cold email contexts because a country-code domain can still carry abuse signals.
2023-09-16 - Email Geeks
The practical answer
The most abused TLD is .com when the metric is raw malicious or suspicious domain count in the current six-month dataset. The highest reported concentration among generic TLDs is .cfd, while smaller TLDs such as .qpon, .icu, .bid, and .xin also have high listed shares.
- For filtering: Use TLD reputation with domain age, authentication, URLs, and complaint data.
- For sending: Use a credible domain, authenticate it, and build reputation before volume.
- For monitoring: Track DMARC, SPF, DKIM, blocklist or blacklist status, and URL reputation together.
A TLD can tell you where to look harder, but the domain's behavior tells you what to do.

