# DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists

DevFeed: [DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists](<https://devfeed.tech/articles/dns-abuse-and-criminal-infrastructure-beyond-definitions-and-blocklists-11441.md>)

Original publisher: [Read original article](<https://labs.ripe.net/author/andrew_campling/dns-abuse-and-criminal-infrastructure-beyond-definitions-and-blocklists/>)

Author: Andrew Campling

Published: 2026-08-24T11:30:19Z

Content type: article

Language: en

Sources: [RIPE Labs](<https://devfeed.tech/sources/ripe-labs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [article](<https://devfeed.tech/tags/article.md>), [competition](<https://devfeed.tech/tags/competition.md>), [dns](<https://devfeed.tech/tags/dns.md>), [governance](<https://devfeed.tech/tags/governance.md>), [malware](<https://devfeed.tech/tags/malware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article examines evidence that malicious actors may control a substantial share of new generic top-level domain registrations. It discusses estimates that at least 10% of domains registered in 2025 appeared on security blocklists, while the share associated with malicious actors may be closer to 20%. It also evaluates how definitions of DNS Abuse, evidentiary standards, and analytical methods affect these estimates, emphasizing that ICANN's contractual definition is limited to botnets, malware, pharming, phishing, and qualifying spam.

## Source excerpt

Evidence suggests that criminals may control a substantial share of new gTLD registrations. Although the precise scale remains contested, the article asks whether current DNS Abuse measures adequately address wider misuse of domain names.