TLD Reputation, Phishing & Spamhaus Abuse Radar

Independent analysis of security threat vectors, malicious domain concentrations, and email deliverability penalties across top-level domain extensions. Integrates data from Spamhaus, SURBL, and ICANN Domain Abuse Activity Reporting (DAAR) feeds.

Audited Extensions 15 Cross-category sample
Critical Abuse Alert 3 TLDs >40% malicious ratio
Pristine Security 4 TLDs Vetted institutional
Economic Barrier >$50 Floor Suppresses disposable spam

Startup Advisory: How TLD Neighborhood Affects Email Deliverability

Major email security gateways (Proofpoint, Mimecast, Cisco IronPort, Microsoft Defender) maintain automated reputation scores that evaluate the overall health of the parent top-level domain. When a new gTLD suffers from elevated phishing and malware concentration (often driven by unmoderated penny promotions), mail filters routinely downrank or quarantine inbound correspondence originating from those extensions regardless of DKIM/SPF alignment.

Key Takeaway: If deploying mission-critical transactional email or B2B sales outreach, favor established legacy gTLDs (.com, .org) or extensions with rigorous vetting (.bank, .gov, .edu) to avoid systemic firewall suppression.
TLD Abuse Score (0-100) Risk Rating Spamhaus Badness Primary Threat Vector Email Deliverability Outlook Registry Operator
.bank Restricted / Institutional 0.2 Pristine Vetted 0.0% None (Strict Identity Vetted) Optimal (Pre-vetted Financial Trust) fTLD Registry Services
.gov Restricted / Institutional 0.1 Pristine Vetted 0.0% None (US CISA Governed) Optimal (Institutional White-listing) Cybersecurity and Infrastructure Security Agency (CISA)
.edu Restricted / Institutional 0.8 Pristine Vetted 0.1% Compromised Student Accounts (Rare) Optimal (Accredited Higher Education) Educause
.insurance Restricted / Institutional 0.3 Pristine Vetted 0.0% None (Vetted Insurers) Optimal (Regulated Financial) fTLD Registry Services
.com Legacy gTLD 18.5 Low Risk 3.2% Brand Impersonation & Typosquatting Standard Baseline (Gold Standard) Verisign, Inc.
.net Legacy gTLD 19.2 Low Risk 3.5% Infrastructure & Phishing Standard Baseline Verisign, Inc.
.org Legacy gTLD 14.8 Low Risk 2.8% Charity & Donation Impersonation Standard Baseline Public Interest Registry (PIR)
.ai ccTLD 12.0 Low Risk 1.9% Tech Startup Phishing (Low Volume) Favorable (High Economic Barrier) Government of Anguilla / Data Solutions Inc.
.io ccTLD 15.5 Low Risk 2.6% Developer Token Phishing Favorable (Developer Trusted) Identity Digital (Internet Computer Bureau)
.xyz New gTLD 42.0 Moderate 8.5% Wallet Drainers & Malvertising Caution (Some Firewalls Flag $0.99 Cohorts) Generation.XYZ LLC
.online New gTLD 54.0 High Risk 14.2% Bulk Phishing Campaigns Elevated Risk of Spam Folder Placement Radix
.click New gTLD 84.5 Critical Risk 41.0% SMS Phishing (Smishing) & Malicious Redirects High Risk (Often Blanket Blocked by Firewalls) GoDaddy Registry
.surf New gTLD 88.0 Critical Risk 48.5% Phishing Relays & Botnet C2 Severe Risk (Corporate Firewalls Block Inbound) Minds + Machines Group / Registry Services
.top New gTLD 92.5 Critical Risk 56.0% High-Volume Bulletproof Spam & Malware Severe Risk (Routinely Blacklisted) Jiangsu Bangning Science & Technology
.work New gTLD 78.0 High Risk 32.5% Job Offer Fraud & Identity Harvesting Elevated Risk (Mail Gateways Penalize Score) Minds + Machines Group