New gTLD trust and spam risk: Which domain extension gets flagged
A new gTLD can arrive at a reader’s inbox, spam filter, and resale buyer already carrying a reputation, and the cheap ones carry the worst one.
The buyer guides that rank for this query tell you which extensions are cheap. Almost none tell you which ones are flagged for abuse, why, and what that reputation costs a domain a buyer acquires.
That gap is what this page closes, using the anti-abuse data the registrar blogs leave out.
The numbers are blunt. Interisle found that 42 percent of phishing domains now sit in new gTLDs, up from 25 percent the year before, and that 7 of the 10 worst extensions had over 10 percent of their domains reported for cybercrime.
So this page gives you three things the listicles skip:
- A searchable, risk-band-filterable reference of 32 extensions, each carrying a categorical spam-risk band drawn from Spamhaus and Interisle data, not an invented score.
- The mechanism behind the band: why cheap new gTLDs get abused, and how that reputation taxes deliverability and trust.
- The investor read the buyer guides omit: how a low-trust extension drags on a domain’s resale liquidity, and why a screened catalogue avoids it.
The extension is one signal. A flagged extension is a tax on top of the domain, and reading that tax before acquiring is what this page is built to support.
This guide is general SEO and domain-market education about top-level domains, abuse reputation, and the aged-domain market. It is not financial, investment, or legal advice, and it does not value or endorse any specific domain or extension.
The risk bands in the reference tool are categorical readings of published Spamhaus and Interisle abuse data, not numeric scores we invented. Where the data is mixed or thin, the band reflects that, and no per-domain verdict is implied.
What new gTLD spam risk means and how the band is read
New gTLD spam risk is the abuse reputation an extension carries because of how its domains are registered and used, measured by anti-abuse trackers like Spamhaus and Interisle as a share of the zone tied to spam, phishing, or malware. The risk attaches to the string, not to any one site on it.
A new gTLD is a generic extension added from ICANN’s 2012 program onward, like .xyz, .top, or .shop. A second application round opened in 2026, widening the namespace.
The band each extension carries here is categorical, not numeric. It reads four levels off the published data:
- High: extensions repeatedly named in the worst-10 abuse rankings, with double-digit shares of their zone reported for cybercrime.
- Elevated: cheap, high-churn strings with a heavy abuse association but below the worst-of-the-worst tier.
- Moderate: extensions with mixed reputations, where abuse is present but not dominant.
- Low: established or restricted extensions with little abuse association and a long good-reputation history.
The band is a categorical read of published data, never an invented score.
The discipline this page holds is that no number is made up. Spamhaus and Interisle publish the abuse figures; this page sorts them into four plain bands a buyer can act on.
Spamhaus defines a bad domain as one its systems profile as spamming, botnet, or malware abuse, then measures that against all domains it sees on the extension. The badness score multiplies that percentage by the logarithm of the bad-domain count, and feeds the blocklists that downstream filters consult.
Interisle’s phishing landscape report measures phishing per capita, so a small extension with concentrated malicious registrations can score far above a large clean one. Its .xin ranked 10,810 against a .com score of 30.
Where the two sources disagree or the data is thin, the band reflects the uncertainty instead of overstating it. The point is a usable read, not a false precision.
Searchable spam-risk reference: every extension, by risk band
The reference below holds 32 domain extensions, each with a categorical spam-risk band, a sourced abuse note, and a buyer takeaway, searchable by extension and filterable by risk band. Type an extension in the search box, or filter to high, elevated, moderate, or low risk.
Every band is a read of published Spamhaus or Interisle data. No numeric scores are invented, and the source for each note is named in the column.
The tool runs entirely in your browser over embedded data. With scripting off, the full table still renders as static HTML below.
The most abused TLDs in the Spamhaus and Interisle data
The heaviest-abuse TLDs in the 2025 anti-abuse data are a recurring short list of cheap new gTLDs, led by .top, .xyz, .shop, .bond, and .cc, each carrying a double-digit share of its zone reported for cybercrime. The names repeat across independent trackers.
Two sources anchor the read. Spamhaus tracks listed domains; Interisle tracks phishing per capita. They converge on the same extensions.
The same extensions surface across independent trackers, which is the signal.
The reliability of the read comes from the overlap. .top, .xyz, .shop, .cc, and .vip appear in both Spamhaus listings and Interisle's phishing worst-10, measured by different methods.
When two trackers using unrelated methodologies name the same strings, the reputation is structural, not a sampling quirk. That is the basis for a high band instead of a moderate one.
Interisle's headline finding sharpens it: 7 of the worst 10 extensions had over 10 percent of their domains reported for cybercrime. A one-in-ten abuse share is the reputation a buyer inherits with the string.
Why cheap new gTLDs get flagged for abuse
Cheap new gTLDs get flagged because near-zero registration prices, weak verification, and a short reputation history let bad actors register disposable domains in bulk faster than registry anti-abuse can react. Spamhaus names the cause directly.
The price correlation is the clearest single signal, and it is why phishers gravitate to whichever string is cheapest. Interisle's updated 2025 figures found 9 of the worst extensions priced under $1 and nearly two dozen under $2, while the cheapest .com it identified was $5.91.
Spamhaus attributes the pattern to three conditions that stack:
The reputation rotates with price, so the worst list is a moving target.
The practical consequence is that no single list stays current for long. When a registry runs a promotion, the abuse migrates toward whatever is cheapest, which is why .bond and .sbs surged as older targets cooled.
This is also why the band, not a frozen ranking, is the durable read. An extension priced near zero with light verification will attract abuse regardless of which one held the crown last quarter.
For a buyer, the lesson is to read the structural conditions, price, verification, and registry investment, instead of memorising a list that turns over every six months.
How a TLD's reputation taxes deliverability and trust
A TLD's abuse reputation taxes deliverability and trust by acting as one negative signal in the scoring filters apply, so a clean domain on a flagged extension starts from a colder position than the same domain on a trusted one. The extension is a context signal, not an automatic block.
The mechanism matters because the listicles overstate how the extension affects sending in both directions. The honest read sits between auto-block and no effect, and it explains why a risky extension warrants extra screening before trusted use.
Deliverability weighs the TLD alongside authentication, age, and history.
Email filters score a sender on four inputs at once. Domain age, SPF and DKIM authentication, the URLs in the body, and prior blocklist history all weigh in, with the extension as one contextual factor.
The deliverability research is consistent: receivers rarely reject mail on the TLD alone. They treat an abuse-heavy extension as a reason to scrutinise harder, which raises spam-folder placement for legitimate senders who share the string with the abusers.
Deliverability data shows .xyz, .top, .click, and .work needing extra validation before trusted production sending, precisely because the shared reputation precedes the individual sender.
The extension never determines the outcome on its own. It sets the starting position, and a flagged extension starts every trust contest a step behind.
The broader evidence on how the extension does and does not move SEO outcomes runs through the sibling guide Does your domain extension affect SEO? The data, the myths, and the aged-domain nuance.
The credible new gTLDs the abuse reputation does not touch
The credible new gTLDs are the restricted and security-enforced extensions where the registry gate suppresses the cheap-throwaway abuse pattern, led by .app, .dev, and .bank. The abuse tax is extension-specific, not a penalty on the whole new-gTLD category.
This is the correction the worst-of lists invite. Heavy abuse on ten cheap strings gets generalised to every post-2012 extension, which is wrong.
Three design choices separate the credible new gTLDs from the flagged ones:
- Enforced HTTPS: .app and .dev (Google Registry) are HSTS-preloaded, so every site must use HTTPS. The requirement deters the register-abuse-discard pattern that thrives on disposable HTTP sites.
- Registrant verification: .bank (fTLD) verifies every registrant and enforces security requirements, which keeps its abuse share near zero.
- Validated eligibility: restricted strings like .ngo validate the registrant, so the gate, not the price, sets who registers.
The gate, not the launch year, sets the reputation band.
The variable that predicts the band is the barrier to registration. A high gate, verification or enforced security, keeps abuse out and the reputation clean. An absent gate plus a sub-dollar price invites the abuse that defines the high-risk strings.
So a credible new gTLD can fit a trust-sensitive build when the audience reads it as a deliberate, on-topic choice. The .app extension reads as a developer signal, not a bargain.
What a credible new gTLD does not match is the resale depth of an established gTLD, which is the read the value section develops next.
How spam risk drags on a domain extension's resale value
A high spam-risk band drags on resale value because an abuse reputation thins the buyer pool, lowers renewal rates, and forces every future owner to overcome the same shared reputation, so the extension trades at a discount independent of the name itself. Reputation is priced into liquidity.
The investor read inverts the sender's question. A sender asks whether mail lands; a buyer asks whether the name resells. A flagged extension answers both poorly.
| Mechanism | How a high-risk extension behaves | How a low-risk extension behaves |
|---|---|---|
| Buyer pool depth | An abuse reputation scares off buyers regardless of how strong the name reads, so the name sits illiquid and can wait years for a sale | An established gTLD or premium vanity generic draws a deep buyer pool, so a clean name clears faster at a known floor |
| Renewal signal | Cheap abuse-heavy strings show low renewal, the market signalling weak long-term value and thin demand | Renewal near 75 percent on .com and .net signals durable legitimate use and underwrites resale confidence |
| Inherited reputation | Every future owner inherits the same shared abuse reputation, so the discount persists across resales rather than resetting per name | A clean extension carries no reputational drag, so the name's own history and metrics set the price |
| Deliverability risk transfer | A buyer planning email or outreach inherits the flagged extension's spam-folder tax, which suppresses willingness to pay | A trusted extension transfers a clean sending reputation, removing a discount the buyer would otherwise demand |
The extension prices the reputation, and the history prices the equity.
On an acquisition, two values sit side by side. The inherited backlink profile and topical history decide the SEO equity; the extension's reputation band decides how deep and how warm the resale pool around it runs.
An aged domain on a low-risk extension combines both: a clean inherited profile and a trusted string with a deep aftermarket. A strong name on a high-risk extension carries the same on-page equity and a thinner, colder exit.
The condition on inherited equity is relevance and cleanness, not the extension. An engineered backlink profile discounts a name on .com as readily as on .xyz, which is why the history is screened first.
How a name's inherited authority is read and scored across the decision runs through the metric guides What is a good Domain Authority score and Trust Flow to Citation Flow ratio, and how the extension tier itself holds or sheds value is mapped in TLD value and resale tiers: which domain extension holds value.
7 frequently asked questions about new gTLD spam risk
The 7 questions readers raise about new gTLD spam risk concern which extensions carry the heaviest abuse, why they get flagged, whether new gTLDs are bad, the deliverability impact, whether .xyz is a safe choice, which extensions to avoid, and whether spam risk lowers resale value.
The answers are general SEO and market education, not financial, investment, or legal advice, and not a verdict on any specific domain or extension.
Q1Which TLDs carry the heaviest abuse for spam?
The heaviest-abuse extensions in 2025 anti-abuse data are cheap new gTLDs, led by .top, .xyz, .shop, .bond, .cc, and .vip.
Interisle named 7 of these in its worst 10, each with over 10 percent of domains reported for cybercrime, and Spamhaus logged a 50 percent rise in .top abuse with 211,406 detections in the six months to March 2025.
.xin held the highest per-capita phishing score at 10,810 against a .com baseline of 30. This is a sourced read, not a per-domain claim.
Q2Why do .top and .xyz get flagged as spam?
They get flagged because near-zero registration prices, light verification, and a short reputation history let bad actors register disposable domains in bulk.
Spamhaus names three causes: no legacy good reputation, anti-abuse systems still maturing, and cheap or free promotional pricing that attracts throwaway bulk registration. Interisle found bulk registration drives 27 percent of phishing domains.
XYZ Registry runs an active anti-abuse program that has reduced but not erased the reputation, which is why .xyz still reads as elevated to high risk.
Q3Are all new gTLDs bad for trust?
No. The abuse tax is extension-specific, not a penalty on the whole new-gTLD category.
Restricted and security-enforced new gTLDs sit at low risk: .app and .dev (Google Registry) enforce HTTPS, and .bank (fTLD) verifies every registrant, which keeps abuse near zero.
A verified .bank and a bulk-registered .top share a launch era and nothing else. The gate and the price, not the new-gTLD label, set the reputation band. This is general SEO education, not a ranking claim.
Q4Does the domain extension affect email deliverability?
Yes, as one contextual signal, not as an automatic block. Receivers rarely reject mail on the TLD alone.
Filters weigh the extension alongside domain age, SPF and DKIM authentication, the URLs in the message, and blocklist history. An abuse-heavy extension raises scrutiny, so legitimate senders on it see higher spam-folder placement.
Deliverability data flags .xyz, .top, .click, and .work as needing extra validation before trusted production sending. A clean .com starts from a warmer position. This is general education, not a sending guarantee.
Q5Is a .xyz domain a safe choice?
.xyz is usable but starts from a reputational deficit, so it carries an avoidable tax for trust-sensitive or email-led builds.
It was named among the top phishing offenders by Krebs and Interisle, with abuse concentration estimated at 10 to 15 percent of the zone. The registry's anti-abuse program has helped, but filters and buyers still discount it.
For a low-stakes project it works. For a broad-audience, trust-led, or outreach-heavy build, an established gTLD starts from a cleaner position. This is general SEO education, not a verdict on any name.
Q6Which domain extensions are best avoided for trust-sensitive use?
The high-risk band lists the extensions to avoid for trust-sensitive use: .top, .xyz, .shop, .bond, .cc, .vip, .xin, .cfd, .sbs, and .icu.
These recur across Spamhaus and Interisle data with double-digit abuse shares, near-total churn, or both. The cheap ShortDot strings (.cfd, .sbs, .icu) and finance-themed strings (.loan, .bond) cluster the worst figures.
The avoidance rule is structural: skip extensions priced near zero with light verification, because that is the condition abuse concentrates around. Use the reference tool above to check any specific string.
Q7Does a TLD's spam reputation lower a domain's resale value?
Yes. A high spam-risk band thins the buyer pool, lowers renewal, and forces every future owner to overcome the same shared reputation, so the extension trades at a discount.
An abuse reputation scares off buyers regardless of how strong the name reads, so a flagged name can sit illiquid for years. Renewal near 75 percent on .com and .net signals the trust that underwrites a deep aftermarket.
The extension prices the liquidity; the domain's inherited history prices the SEO equity. This is general market education, not investment advice or a sale guarantee.
How a screened catalogue reads the extension's reputation
The whole page resolves to one operational point: a flagged extension is a reputation tax on top of the domain, and the inherited history, the abuse exposure, and the resale liquidity are what a screened catalogue reads first. The bands, the data, the deliverability tax, and the value drag all point the same way.
SEO Domains reads the extension exactly that way at intake. The curated catalogue screens each aged domain in a fixed order:
- Its inherited backlink profile, read for relevance and cleanness.
- Its topical history, read against the buyer's intended use.
- Its abuse and trademark exposure, including the extension's reputation band, surfaced before acquisition.
- The extension and its tier last, read as a trust-and-liquidity modifier on top of that screen.
Domain Authority, Domain Rating, Trust Flow, and Citation Flow are reported alongside the inheritance read, so a buyer sources a name selected on the history that decides the SEO and an extension whose reputation is read, not assumed.
| Spam-risk trap in an unscreened pool | How a raw list leaves it | What the SEO Domains catalogue screens for instead |
|---|---|---|
| Cheap new gTLD sold as equal to a trusted string | A flagged extension is listed at a low price with its abuse reputation and deliverability tax unread | The screen reads the extension's reputation band and surfaces the abuse exposure before acquisition, not after the first bounced campaign |
| Abuse history of the specific domain ignored | A name with prior spam or blocklist history reaches a buyer unflagged because the pool never checked | The screen reads the inherited link profile and abuse exposure first, so a tainted history is visible before the name is matched to a use |
| Resale liquidity assumed from the name alone | A strong-reading name on a high-risk extension is priced as if the extension carried no drag | The screen reads resale depth so a thin, reputation-taxed exit is known up front, not discovered at sale |
| New-gTLD label treated as one reputation | A clean .app and a bulk-registered .top are lumped together or both dismissed | The screen reads the specific extension's gate and abuse data, separating credible restricted strings from flagged cheap ones |
| History ignored in favour of the suffix | The inherited topic and standing go unread while the extension drives the price | The screen prices the inherited equity that decides the SEO and treats the extension's band as the modifier it is |
The catalogue reads the reputation before the extension, which is the order the data demands.
The discipline SEO Domains applies is to read the abuse exposure as part of the screen, not as an afterthought. A raw list prices a name on its extension and leaves the reputation unread.
The catalogue reverses that. It reads the inherited backlink profile for relevance and cleanness, reads the topical history against the buyer's intended use, reads the abuse and trademark exposure including the extension's band, and only then reads the extension and its tier as the trust-and-liquidity modifier they are.
An aged domain on a low-risk extension combines the inherited SEO equity that carries the ranking with the deep, warm resale pool the extension prices. ICANN-accredited transfer applies to every acquisition regardless of extension, and the underlying diligence runs on RDAP after the WHOIS sunset of 28 January 2025.
A buyer who reads the extension's reputation, not the price alone, is the buyer best served by inventory screened on the history that is the larger lever.
A screened catalogue raises confidence in the history, and it guarantees no outcome.
The honest takeaway is two-sided. A cheap flagged extension sold as equal to a trusted one, a tainted abuse history left unread, a thin resale exit assumed away, and a history ignored in favour of the suffix are real ways an extension-led purchase goes wrong.
They concentrate in unscreened pools where a name reaches a buyer priced on its extension with its reputation and history unread.
A screened catalogue does not write the content, earn the new links, or run the conversion the inherited equity rewards. It does not provide financial, investment, or legal advice, and it promises no ranking or sale outcome on any name or extension.
What it does is read the inherited equity, the topical history, the abuse exposure, and the resale liquidity that decide the outcome, and place the extension's reputation band where this page places it, as one tax on top of the asset.
A reader who finishes this page is equipped to stop reading the price in isolation and start reading the reputation.
