Suped

What is the most abused TLD (Top-Level Domain) for spam?

Published 21 Apr 2025
Updated 29 Jul 2026
9 min read
Summarize with
Editorial illustration of .com, .top, .xyz, and .us domain tiles used to explain TLD spam abuse.
Updated on 29 Jul 2026: We updated this guide with current TLD abuse figures, clearer measurement rules, and practical filtering guidance.
There is no single universal winner. In public domain reputation data covering October 2025 through March 2026, .com ranks first by raw malicious or suspicious domain count, with 506,482 listings. In the same dataset, .cfd ranks highest among the reported generic TLDs by concentration, with 17.54% of its zone listed. Other high-rate generic TLDs include .qpon, .icu, .bid, .xin, and .bond.
That distinction matters for email. A receiver does not usually reject mail because a domain ends in a specific TLD. It scores the message using domain age, sender reputation, authentication, URLs in the body, complaint history, and blocklist or blacklist signals. The TLD is a context clue, not a verdict.
  1. Raw volume: .com leads the current mixed-abuse dataset because it has a very large domain base.
  2. Abuse concentration: .cfd leads the reported generic TLD table when listed domains are divided by zone size.
  3. Dataset scope: A malicious or suspicious domain list includes more than unsolicited email.
  4. Email risk: The TLD should change scrutiny, not replace authentication and behavior checks.

The direct answer

Start with the metric. In the October 2025 through March 2026 snapshot, .com ranks first by number of malicious or suspicious domains, followed by .top. The dataset detected 2.15 million listed domains across all TLDs during the six-month period. It includes associations with spam, phishing, malware, ransomware, and other fraudulent activity, so it is broader than a spam-only count.
By rate, the reported generic TLD leader is .cfd in that snapshot. Its 93,940 listed domains make up 17.54% of its zone. .com has far more listed domains, but those listings are a much smaller share of its roughly 168 million-domain zone. Raw count measures total exposure, while the rate measures abuse concentration.

Metric

Current answer

Use

Raw listed-domain count
.com
Total exposure
Reported gTLD zone share
.cfd
Abuse concentration
Malicious email rate
Dataset-specific
Mail filtering
Phishing URLs or pages
Dataset-specific
Web threat review
Different ways to answer "most abused TLD"
Phishing rankings can still name a different TLD. One report can count unique registered domains, while another counts every URL, hosted subdomain, landing page, or email message. A TLD that leads one unit of measurement does not automatically lead the others.

What abuse datasets actually count

The unit of measurement can change the ranking before any security judgment is made. Check what the report counts, which abuse categories it includes, what time period it covers, and whether its sensors see email traffic, DNS activity, web pages, or several of these sources.
  1. Registered domains: Each second-level domain is counted once, even if it hosts many abusive URLs.
  2. Hostnames and subdomains: A shared hosting domain can create many counted hostnames under one registration.
  3. URLs and pages: One domain can produce many phishing pages or redirect URLs.
  4. Email messages: A high-volume campaign can dominate message counts while using few domains.
The cause matters too. A maliciously registered domain was acquired for abuse, while a compromised domain belongs to a legitimate owner whose site or account was taken over. Compromised sites and hosted subdomains can raise a TLD's count without showing that the namespace itself attracts disposable registrations. This is why a defensible filter keeps TLD reputation separate from domain reputation and URL reputation.

Why rankings disagree

Most disagreements come down to denominator choice. Counting bad domains answers one operational question: "Where is the most abuse appearing?" Dividing by the total number of registered domains answers another: "Which namespace has the highest concentration of abuse?" Both are useful, but they lead to different blocking and review decisions.
Raw count
  1. Best for: Estimating total volume hitting filters, traps, and URL feeds.
  2. Common winner: .com, because it has the largest installed base.
  3. Main risk: It can make large TLDs look uniquely bad when they are also uniquely common.
Abuse rate
  1. Best for: Finding TLDs where abuse is dense compared with legitimate use.
  2. Common winners: Low-cost, high-churn, lightly verified TLDs.
  3. Main risk: It can overstate small namespaces with limited legitimate mail use.
For email filtering, concentration deserves more weight when a domain is new, cheap, and sending unsolicited mail. For abuse response, raw volume matters because it shows where the greatest filter pressure originates.
Infographic comparing raw TLD abuse count with abuse rate, domain age, authentication, and blocklist hits.
Infographic comparing raw TLD abuse count with abuse rate, domain age, authentication, and blocklist hits.

TLDs that deserve extra scrutiny

No TLD is automatically bad, but some TLDs need extra evidence of legitimacy. That includes TLDs that repeatedly appear in abuse reports, TLDs with heavy new-domain churn, and TLDs that attackers can buy cheaply in bulk. The specific list changes over time, so the right workflow is monitoring, not a static wall chart.
Listed-domain volume by TLD
Malicious or suspicious domain counts detected from October 2025 through March 2026.
.com
506,482 domains
.top
270,121 domains
.cn
252,852 domains
.cc
94,415 domains
.cfd
93,940 domains
.bond
59,271 domains
.xyz
47,547 domains
.sbs
42,115 domains
Country-code TLDs are not automatic trust signals. .us ranked 15th among country-code TLDs in the current snapshot, with 2,981 listed domains. That volume is far below .cn and .cc, but it still shows why a country label should not replace sender-level checks.
If you are choosing a domain for email, use a credible TLD, avoid bargain registrations for production sending, and give the domain time to build reputation. The practical tradeoffs are covered in TLD choices and deliverability.

How to use TLD data without overblocking

The worst operational mistake is blocking a whole TLD from mail or web access without checking the business impact. Some TLDs deserve aggressive treatment in consumer inbox filtering, but enterprise mail, support desks, and security teams still need exceptions for real customers, partners, and abuse reports.
Do not block on TLD alone
A TLD should increase scrutiny when it appears with other signals. It should not be the only reason a legitimate message disappears.
  1. Strong signal: New domain, poor authentication, suspicious URLs, and prior blocklist or blacklist hits.
  2. Weak signal: A familiar sender using an unusual TLD with clean authentication and normal engagement.
  3. Review signal: A new sender on a high-risk TLD that links to more new domains in the message body.
A good review flow checks the sending domain, return-path domain, DKIM signing domain, and every linked domain in the message. Suped's blocklist monitoring supports that workflow by tracking domain and IP listings alongside the identities found in authenticated mail.
Blocklist checker
Check your domain or IP against 144 blocklists.
www.spamhaus.org logoSpamhaus0spam.org logo0Spam
Blocklist icon
Abusix
Blocklist icon
Barracuda Networks
www.spamcop.net logoCisco
Blocklist icon
Mailspike
www.nosolicitado.org logoNoSolicitado
Blocklist icon
SURBL
Blocklist icon
UCEPROTECT
uribl.com logoURIBL
Blocklist icon
8086 Consultancy
abuse.ro logoabuse.rowiki.alphanet.ch logoALPHANETanonmails.de logoAnonmailsascams.com logoAscamswww.blockedservers.com logoBLOCKEDSERVERS
Blocklist icon
Brukalai.lt
dnsbl.calivent.com.pe logoCalivent Networks
Blocklist icon
dan.me.uk
Blocklist icon
DrMx
Blocklist icon
DroneBL
rbl.efnetrbl.org logoEFnet
Blocklist icon
Fabel
Blocklist icon
GBUdb
Blocklist icon
ImproWare
Blocklist icon
JIPPG Technologies
Blocklist icon
Junk Email Filter
www.justspam.org logoJustSpamwww.kempt.net logoKempt.net
Blocklist icon
Mail Baby
www.nordspam.com logoNordSpam
Blocklist icon
nsZones
Blocklist icon
Polspam
rv-soft.info logoRV-SOFT Technology
Blocklist icon
Schulte
www.scientificspam.net logoScientific Spam
Blocklist icon
Spam Eating Monkey
psbl.org logoSpamikazewww.spamrats.com logoSpamRATSspfbl.net logoSPFBLsuomispam.net logoSuomispamwww.usenix.org.uk logoSystem 5 Hosting
Blocklist icon
Taughannock Networks
www.team-cymru.com logoTeam Cymru
Blocklist icon
Tornevall Networks
senderscore.org logoValiditywww.blocklist.de logowww.blocklist.de Fail2Ban-Reporting Servicezapbl.net logoZapBL2stepback.dk logo2stepback.dkfaynticrbl.org logoFayntic Servicesorbz.gst-group.co.uk logoORB UK
Blocklist icon
RedHawk
dnsbl.technoirc.org logotechnoirc.orgwww.techtheft.info logoTechTheftwww.spamhaus.org logoSpamhaus0spam.org logo0Spam
Blocklist icon
Abusix
Blocklist icon
Barracuda Networks
www.spamcop.net logoCisco
Blocklist icon
Mailspike
www.nosolicitado.org logoNoSolicitado
Blocklist icon
SURBL
Blocklist icon
UCEPROTECT
uribl.com logoURIBL
Blocklist icon
8086 Consultancy
abuse.ro logoabuse.rowiki.alphanet.ch logoALPHANETanonmails.de logoAnonmailsascams.com logoAscamswww.blockedservers.com logoBLOCKEDSERVERS
Blocklist icon
Brukalai.lt
dnsbl.calivent.com.pe logoCalivent Networks
Blocklist icon
dan.me.uk
Blocklist icon
DrMx
Blocklist icon
DroneBL
rbl.efnetrbl.org logoEFnet
Blocklist icon
Fabel
Blocklist icon
GBUdb
Blocklist icon
ImproWare
Blocklist icon
JIPPG Technologies
Blocklist icon
Junk Email Filter
www.justspam.org logoJustSpamwww.kempt.net logoKempt.net
Blocklist icon
Mail Baby
www.nordspam.com logoNordSpam
Blocklist icon
nsZones
Blocklist icon
Polspam
rv-soft.info logoRV-SOFT Technology
Blocklist icon
Schulte
www.scientificspam.net logoScientific Spam
Blocklist icon
Spam Eating Monkey
psbl.org logoSpamikazewww.spamrats.com logoSpamRATSspfbl.net logoSPFBLsuomispam.net logoSuomispamwww.usenix.org.uk logoSystem 5 Hosting
Blocklist icon
Taughannock Networks
www.team-cymru.com logoTeam Cymru
Blocklist icon
Tornevall Networks
senderscore.org logoValiditywww.blocklist.de logowww.blocklist.de Fail2Ban-Reporting Servicezapbl.net logoZapBL2stepback.dk logo2stepback.dkfaynticrbl.org logoFayntic Servicesorbz.gst-group.co.uk logoORB UK
Blocklist icon
RedHawk
dnsbl.technoirc.org logotechnoirc.orgwww.techtheft.info logoTechTheftwww.spamhaus.org logoSpamhaus0spam.org logo0Spam
Blocklist icon
Abusix
Blocklist icon
Barracuda Networks
www.spamcop.net logoCisco
Blocklist icon
Mailspike
www.nosolicitado.org logoNoSolicitado
Blocklist icon
SURBL
Blocklist icon
UCEPROTECT
uribl.com logoURIBL
Blocklist icon
8086 Consultancy
abuse.ro logoabuse.rowiki.alphanet.ch logoALPHANETanonmails.de logoAnonmailsascams.com logoAscamswww.blockedservers.com logoBLOCKEDSERVERS
Blocklist icon
Brukalai.lt
dnsbl.calivent.com.pe logoCalivent Networks
Blocklist icon
dan.me.uk
Blocklist icon
DrMx
Blocklist icon
DroneBL
rbl.efnetrbl.org logoEFnet
Blocklist icon
Fabel
Blocklist icon
GBUdb
Blocklist icon
ImproWare
Blocklist icon
JIPPG Technologies
Blocklist icon
Junk Email Filter
www.justspam.org logoJustSpamwww.kempt.net logoKempt.net
Blocklist icon
Mail Baby
www.nordspam.com logoNordSpam
Blocklist icon
nsZones
Blocklist icon
Polspam
rv-soft.info logoRV-SOFT Technology
Blocklist icon
Schulte
www.scientificspam.net logoScientific Spam
Blocklist icon
Spam Eating Monkey
psbl.org logoSpamikazewww.spamrats.com logoSpamRATSspfbl.net logoSPFBLsuomispam.net logoSuomispamwww.usenix.org.uk logoSystem 5 Hosting
Blocklist icon
Taughannock Networks
www.team-cymru.com logoTeam Cymru
Blocklist icon
Tornevall Networks
senderscore.org logoValiditywww.blocklist.de logowww.blocklist.de Fail2Ban-Reporting Servicezapbl.net logoZapBL2stepback.dk logo2stepback.dkfaynticrbl.org logoFayntic Servicesorbz.gst-group.co.uk logoORB UK
Blocklist icon
RedHawk
dnsbl.technoirc.org logotechnoirc.orgwww.techtheft.info logoTechTheftwww.spamhaus.org logoSpamhaus0spam.org logo0Spam
Blocklist icon
Abusix
Blocklist icon
Barracuda Networks
www.spamcop.net logoCisco
Blocklist icon
Mailspike
www.nosolicitado.org logoNoSolicitado
Blocklist icon
SURBL
Blocklist icon
UCEPROTECT
uribl.com logoURIBL
Blocklist icon
8086 Consultancy
abuse.ro logoabuse.rowiki.alphanet.ch logoALPHANETanonmails.de logoAnonmailsascams.com logoAscamswww.blockedservers.com logoBLOCKEDSERVERS
Blocklist icon
Brukalai.lt
dnsbl.calivent.com.pe logoCalivent Networks
Blocklist icon
dan.me.uk
Blocklist icon
DrMx
Blocklist icon
DroneBL
rbl.efnetrbl.org logoEFnet
Blocklist icon
Fabel
Blocklist icon
GBUdb
Blocklist icon
ImproWare
Blocklist icon
JIPPG Technologies
Blocklist icon
Junk Email Filter
www.justspam.org logoJustSpamwww.kempt.net logoKempt.net
Blocklist icon
Mail Baby
www.nordspam.com logoNordSpam
Blocklist icon
nsZones
Blocklist icon
Polspam
rv-soft.info logoRV-SOFT Technology
Blocklist icon
Schulte
www.scientificspam.net logoScientific Spam
Blocklist icon
Spam Eating Monkey
psbl.org logoSpamikazewww.spamrats.com logoSpamRATSspfbl.net logoSPFBLsuomispam.net logoSuomispamwww.usenix.org.uk logoSystem 5 Hosting
Blocklist icon
Taughannock Networks
www.team-cymru.com logoTeam Cymru
Blocklist icon
Tornevall Networks
senderscore.org logoValiditywww.blocklist.de logowww.blocklist.de Fail2Ban-Reporting Servicezapbl.net logoZapBL2stepback.dk logo2stepback.dkfaynticrbl.org logoFayntic Servicesorbz.gst-group.co.uk logoORB UK
Blocklist icon
RedHawk
dnsbl.technoirc.org logotechnoirc.orgwww.techtheft.info logoTechTheftwww.spamhaus.org logoSpamhaus0spam.org logo0Spam
Blocklist icon
Abusix
Blocklist icon
Barracuda Networks
www.spamcop.net logoCisco
Blocklist icon
Mailspike
www.nosolicitado.org logoNoSolicitado
Blocklist icon
SURBL
Blocklist icon
UCEPROTECT
uribl.com logoURIBL
Blocklist icon
8086 Consultancy
abuse.ro logoabuse.rowiki.alphanet.ch logoALPHANETanonmails.de logoAnonmailsascams.com logoAscamswww.blockedservers.com logoBLOCKEDSERVERS
Blocklist icon
Brukalai.lt
dnsbl.calivent.com.pe logoCalivent Networks
Blocklist icon
dan.me.uk
Blocklist icon
DrMx
Blocklist icon
DroneBL
rbl.efnetrbl.org logoEFnet
Blocklist icon
Fabel
Blocklist icon
GBUdb
Blocklist icon
ImproWare
Blocklist icon
JIPPG Technologies
Blocklist icon
Junk Email Filter
www.justspam.org logoJustSpamwww.kempt.net logoKempt.net
Blocklist icon
Mail Baby
www.nordspam.com logoNordSpam
Blocklist icon
nsZones
Blocklist icon
Polspam
rv-soft.info logoRV-SOFT Technology
Blocklist icon
Schulte
www.scientificspam.net logoScientific Spam
Blocklist icon
Spam Eating Monkey
psbl.org logoSpamikazewww.spamrats.com logoSpamRATSspfbl.net logoSPFBLsuomispam.net logoSuomispamwww.usenix.org.uk logoSystem 5 Hosting
Blocklist icon
Taughannock Networks
www.team-cymru.com logoTeam Cymru
Blocklist icon
Tornevall Networks
senderscore.org logoValiditywww.blocklist.de logowww.blocklist.de Fail2Ban-Reporting Servicezapbl.net logoZapBL2stepback.dk logo2stepback.dkfaynticrbl.org logoFayntic Servicesorbz.gst-group.co.uk logoORB UK
Blocklist icon
RedHawk
dnsbl.technoirc.org logotechnoirc.orgwww.techtheft.info logoTechTheft
When a domain appears in mail you did not expect, check whether the exact domain or IP is on known blocklists. If you control the sending domain, run a broader domain health check as well, because TLD reputation is only one part of the sender identity.

What this means for email senders

If you send legitimate email, do not pick a sending domain only because the TLD is cheap or available. Pick a domain that a recipient can trust, authenticate it properly, warm it carefully, and avoid sending patterns that look disposable. A polished domain on a risky TLD still has to earn reputation.
Suped's product supports this workflow by showing which services send for your domain, whether SPF and DKIM align for DMARC, and whether a sending domain or IP develops a blocklist or blacklist problem. TLD reputation can set the level of scrutiny, while the authentication and monitoring data shows what needs fixing.
Blocklist monitoring page showing domain and IP checks across blocklists with importance and status
Blocklist monitoring page showing domain and IP checks across blocklists with importance and status
For a real sending test, send a message through your normal mail path and inspect the headers, authentication alignment, URL reputation, and content signals. A quick email tester run tells you more than judging the domain by its final label.
TLD risk scoring exampleYAML
domain: sender.example sender_tld: .top domain_age_days: 3 spf_alignment: pass dkim_alignment: fail dmarc_policy: none url_tld: .cfd blocklist_hit: true action: quarantine and review
A risky TLD alone does not force rejection. A risky TLD plus a new domain, failed DKIM alignment, no DMARC enforcement, and a listed URL domain is a different case. That combination deserves quarantine or manual review.

Views from the trenches

Best practices
Separate raw volume rankings from abuse-rate rankings before choosing a blocking rule.
Treat TLD reputation as one signal beside age, authentication, traffic, and complaints.
Monitor domains and URLs in mail content, not only the visible sending domain and From.
Common pitfalls
Blocking a whole TLD catches some spam but also creates false positives for support.
Assuming .com is low risk ignores its large raw share of reported abusive domains.
Buying a cheap TLD for outbound mail saves little when reputation problems follow fast.
Expert tips
Use short-lived domain age and failed authentication to raise the score before filtering.
Review URL blocklist hits separately because spam often points away from the sender.
Keep abuse and postmaster inboxes monitored so complaints reach someone accountable.
Marketer from Email Geeks says .com often leads raw abuse rankings because its installed base is so large, even when its abuse rate is small.
2023-09-16 - Email Geeks
Marketer from Email Geeks says .us surprised people in cold email contexts because a country-code domain can still carry abuse signals.
2023-09-16 - Email Geeks

The practical answer

The most abused TLD is .com when the metric is raw malicious or suspicious domain count in the current six-month dataset. The highest reported concentration among generic TLDs is .cfd, while smaller TLDs such as .qpon, .icu, .bid, and .xin also have high listed shares.
  1. For filtering: Use TLD reputation with domain age, authentication, URLs, and complaint data.
  2. For sending: Use a credible domain, authenticate it, and build reputation before volume.
  3. For monitoring: Track DMARC, SPF, DKIM, blocklist or blacklist status, and URL reputation together.
A TLD can tell you where to look harder, but the domain's behavior tells you what to do.

Frequently asked questions

DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing