Originally published at https://monstadomains.com/blog/domain-security-measures/
Between January and May 2026, attackers registered roughly 1.5 million malicious domains. Not stolen, not repurposed, but created from scratch and in bulk through ordinary registrar checkouts. That single number should settle any argument about whether domain security measures deserve attention this year, because the infrastructure behind modern phishing is not exotic. It is a domain name, a DNS record and a certificate, bought the same way you bought yours.
The Assembly Line Behind 1.5 Million Attack Domains
The research, reported by Help Net Security in June 2026, counted only domains flagged by at least five independent scanning engines on VirusTotal, so the figure is conservative rather than inflated. Around 89 percent of those 1.5 million domains were purpose built by attackers. Only about 11 percent were hijacked legitimate sites. That ratio reframes the entire conversation. The dominant threat is not someone taking your domain away from you, it is someone manufacturing thousands of their own, cheaply and at speed.
January recorded the highest volume of the five month window. Activity at that scale is not individuals experimenting. It is production, and production systems have supply chains. That matters for anyone deciding where to spend effort, because domain security measures aimed at a supply chain look very different from ones aimed at a lone opportunist. Supply chains have chokepoints, and chokepoints can be watched.
Four Registrars Handled A Third Of The Attack Domains
Concentration is the most actionable finding in the dataset. The top four registrars accounted for more than a third of attack domains where registrar information was recoverable, and the top ten covered roughly 60 percent. Hosting was tighter still. Cloudflare fronted eight of the top ten IP addresses in the set, and two individual addresses each carried more than 230,000 attack domains. The TLD picture matched that pattern, with .com taking about a third of the total and the top ten extensions covering around two thirds.
That concentration cuts both ways. It means a small number of intermediaries could disrupt a large share of this activity if they chose to. It also means the domain security measures you rely on are only ever as strong as the neighbourhood your records happen to live in, and most domain owners have never checked what that neighbourhood looks like.
Bulk registration leaves a signature
More than three quarters of attack domains with usable WHOIS records were registered as part of a batch, and the largest single batch held over 2,000 domains created at one registrar simultaneously. That is a script with a funded payment method, not a person choosing a name. Domain security measures built around a human adversary picking one convincing lookalike will miss this pattern entirely, which is part of why lookalike domain attacks keep landing on well resourced targets.
How Quickly These Domains Are Weaponised
The median attack domain was around two months old at first detection. Some were caught within a day of registration, and close to a third within a week. Two months sounds slow until you understand what the waiting period buys. The domain sits registered and dormant, ageing quietly past the reputation filters that treat newly registered domains as inherently suspicious, then activates once it looks sufficiently established to pass.
This is the detail that should change how you think about detection windows, and about which domain security measures earn their keep. A defence tuned to spot brand new domains is watching the wrong end of the timeline. By the time most of these domains do anything visible, they have already earned the benefit of the doubt from the very systems designed to stop them.
Why age based filtering underperforms
Plenty of domain security measures still lean on registration age as a proxy for trust. The 2026 data shows why that proxy is weak. Attackers have industrialised patience, and ageing a domain costs them a renewal fee and nothing else. Filters tuned to block anything registered in the last thirty days will catch the impatient minority and wave the median straight through. Domain security measures that assume speed is an attacker constraint are calibrated against an adversary that no longer exists.
The Domain Security Measures Enterprises Never Switched On
The defensive picture is not encouraging. CSC’s Domain Security Report 2026, released on 20 January and now in its sixth year, found that 67 percent of Global 2000 companies had implemented fewer than half of its recommended domain security measures. DNSSEC and CAA record adoption sat at just 11 percent across the Global 2000, rising to 17 percent among the world’s top 100 unicorns. DNS redundancy reached 1 percent of unicorns. APAC trailed EMEA and the Americas by more than 15 points overall.
Read those two datasets together and the asymmetry is stark. One side has automated its operations to the point of registering domains 2,000 at a time. The other side has not enabled a free DNS setting that has been production ready for over a decade. The domain security measures in question are not waiting on budget approval or a vendor evaluation. They are checkboxes nobody got round to.
What DNSSEC and CAA actually stop
DNSSEC signs your DNS responses so a resolver can detect tampering. CAA records tell certificate authorities which of them are permitted to issue certificates for your domain, closing the door on quietly minted certificates for lookalike infrastructure. Neither is exotic, neither costs meaningful money, and both sit among the domain security measures that directly frustrate the redirect and impersonation techniques this research documents. An 11 percent adoption rate after six annual reports is not a technical problem. It is an attention problem.
ICANN Enforcement Is Moving, Slowly
Registrar accountability is tightening in parallel. On 17 July 2026, Domain Incite reported that Trustname.com had received its third ICANN contract breach notice in five weeks, with a compliance deadline of 6 August. ICANN cited Section 3.18.1 of the Registrar Accreditation Agreement over a domain hosting phishing, payment card harvesting and malicious client side code. The notice stated plainly that “the actions the Registrar took were not prompt” after the domain stayed live for three days following confirmed abuse.
Three days is a long window when the median attack domain has already spent two months building credibility. ICANN publishes its compliance notices openly, and reading them is a genuinely useful way to judge how seriously a registrar treats abuse before you hand it your portfolio. We looked at the sharper end of this enforcement trend in our coverage of registry level takedowns.
It is worth being honest about the limits here. Enforcement is retrospective and slow, and it applies to a tiny fraction of the registrars in the dataset. Treating it as a substitute for your own domain security measures would be a mistake. It is a signal about provider quality, nothing more.
What The 2026 Data Reveals About Domain Security Measures
Put both findings side by side and the shape of the problem is clear. Attackers have automated registration, batched thousands of domains through a handful of providers, and learned to age them past naive filters. Defenders have not switched on the domain security measures that were already sitting in their control panels. The gap is not sophistication on either side. It is operational follow through.
The concentration finding also undercuts a comfortable assumption. If 60 percent of attack domains route through ten registrars, then registrar choice is itself one of the domain security measures that matters, both for the abuse landscape you sit next to and for how fast your provider moves when something goes wrong with your own name.
Domain Security Measures Worth Acting On This Week
Start with what the research actually points at. Enable DNSSEC and publish CAA records, because those are the domain security measures with the clearest line to the attack patterns described above. Add registry lock on any domain that would genuinely hurt to lose. Then audit which nameservers and IP ranges your records currently resolve to with a DNS lookup tool and confirm nothing has quietly drifted since you last looked.
Judge your registrar, not just your config
After that, check your registrar’s public record. Has ICANN issued it breach notices? How quickly does it act on reported abuse? At MonstaDomains we treat abuse response and account hardening as part of the product rather than a paid tier, but the principle holds whoever you use. The domain security measures at your provider are as much a part of your posture as the ones you configure yourself, and no amount of local hardening compensates for a registrar that takes three days to answer.
The Takeaway
Three things are worth carrying away from the 2026 data. Attack domain creation is industrial, concentrated and patient, so any defence built on catching brand new registrations is already outflanked. The domain security measures that would blunt these campaigns, DNSSEC and CAA in particular, remain unused by 89 percent of the Global 2000. And your registrar’s abuse posture is a live variable in your own risk, not a footnote in a contract you never read.
None of the domain security measures above require a budget cycle, which is precisely what makes the adoption numbers so uncomfortable. If you want to shrink what your records give away while you tighten everything else, begin with proper WHOIS privacy protection on every domain you hold.

Top comments (0)