Interisle report finds one in five new gTLD domains are scams
Simon Willison's link blog on 6 September 2026 points readers to a post by Terence Eden, who shares statistics from an Interisle report that reached him via Andrew Campling. The report counted 85 million new gTLD domain registrations made in 2025, of which 8.5 million had already been added to abuse blocklists by May 2025. Eden reports that the study treats a 10% abuse rate as the likely floor for these numbers, and reckons the true rate is probably closer to 20%, meaning roughly one in five newly registered gTLD domains are scams. Eden calls that "a bloody crisis" and argues that the Domain Name System functions, in effect, as a vector letting criminals run scams on people at a terrifyingly high rate. Willison adds that he had no idea the problem was this large, and notes that ICANN has apparently been discussing it for years without the figures he saw here.
Key facts
- Interisle's report counted 85 million new gTLD domain registrations in 2025.
- 8.5 million of those registrations were added to blocklists by May 2025.
- The report treats a 10% abuse rate as the likely floor and estimates it is probably closer to 20%.
- Terence Eden restates the finding as roughly one in five newly registered gTLD domains being scams.
- The report reached Eden via Andrew Campling and was surfaced to a wider audience by Simon Willison's link blog.
Why it matters
The figures describe abuse at the scale of the domain name system itself rather than any single platform or company: tens of millions of new gTLD domains are registered every year, and the report's estimate puts a fifth of them in the scam category within months of registration. That reframes DNS abuse from an occasional nuisance into a structural feature of how new domains get used.
Who it affects
Anyone who clicks a link to an unfamiliar domain is exposed, since the abuse is concentrated in newly registered names rather than established ones. It also concerns registrars, blocklist operators, and ICANN, which Willison says has been discussing the problem for years, and security teams who rely on domain age and reputation signals to filter traffic.
How to use it
The post is commentary rather than a tool or product, so the practical takeaway is caution: treat a domain's newness as a risk signal, and be skeptical of unsolicited links to gTLD domains registered within the past months, since the report puts the odds of abuse in that pool at roughly one in five to one in ten.
How solid is it
The numbers come from Eden's summary of the Interisle report, which he learned of via Andrew Campling; Willison's post relays Eden's account rather than the report directly. The report itself is not named, dated, or linked in the source beyond the 2025 and May 2025 figures cited, and the methodology behind the 10 percent to 20 percent abuse-rate estimate is not described.
Risks and caveats
No specific gTLDs, registrars, or scam types are named, so the abuse cannot be traced to particular actors from this post alone. What ICANN's multi-year discussion of the problem has concluded or produced is also not stated, leaving the scale of any response unclear.
“the Domain Name System's purpose seems to be a vector for criminals to run scams on people at a terrifyingly high rate”
— Terence Eden