Latest news of the domain name industry

Recent Posts

.tk registrar gets ICANN breach notice

Kevin Murphy, March 19, 2015, Domain Registrars

OpenTLD, the registrar owned by .tk registry Freenon, has received an odd contract-breach notice from ICANN.
The company apparently forgot to send ICANN a Compliance Certificate for 2014, despite repeated pestering by ICANN staff.
It’s the first time I’ve seen ICANN issue a breach notice (pdf) for this reason.
A Compliance Certificate, judging by the 2013 Registrar Accreditation Agreement, seems to be a simple form letter that the CEO must fill in, sign and submit once a year.
Coming back into compliance would be, one imagines, five minutes’ work.
As well as being an ICANN-accredited registrar, OpenTLD is part of Freenom. That’s the registry that repurposes under-used ccTLDs with a “freemium” model that allows free registrations.
Its flagship, .tk, is the biggest ccTLD in world, with over 30 million active names.

.tk passes 25 million domains

The .tk registry has become only the second TLD to pass 25 million domain names.
Netherlands-based Dot TK passed the milestone at the weekend, according to statistics posted on its web site, and today has 25,068,128 domains under management.
It’s grown by a whopping 837,703 names in the last 30 days alone.
That means Tokelau, the tiny island nation the ccTLD represents, has a nominal 17,900 domains per citizen.
The reason for the huge numbers is that .tk names are usually free to register anywhere in the world, with Dot TK using a freemium model through which it only makes money from add-on services.
.tk became the largest ccTLD last year, hitting 16.7 million names in April 2013 and passing Germany’s .de, which today has about 15.7 million domains under management.
Being free, you’d expect there to be a disproportionate amount of nefarious activity in .tk, but that does not appear to be the case any more.
The TLD doesn’t show up in the top 10 most abused TLDs in the most recent report of the Anti-Phishing Working Group (pdf).
Architelos says (pdf) it’s the 47th-safest out of 72 TLDs, scoring it better than .com, .net, .co and many other popular TLDs.

Tiny Tokelau now has the biggest ccTLD in the world

The .tk domain is now the biggest ccTLD in the world, according to the latest stats from Centr.
In its just-published biannual Domainwire Stat Report, Centr says that .tk had 16.7 million registered domains in April, taking the #1 spot in the league table for the first time.
It now out-ranks Germany’s .de (15.4 million), the United Kingdom’s .uk (10.5 million), China’s .cn (7.5 million) and the Netherland’s .nl (5.2 million), despite Tokelau having a population of less than 1,500.
The reason for its success, of course, is that .tk domains are free to register. The ccTLD frequently pops up towards the top of abuse lists for that very reason.
At 54.7%, .tk wasn’t the fastest-growing ccTLD over the six months covered by Centr’s report, however. That honor belongs to .cn, which bounced back from previous declines with an 82.7% growth rate.

ICANN accredits .tk registry as registrar

Kevin Murphy, March 12, 2013, Domain Registrars

Freedom Registry, the company behind the oft-criticized .tk domain registry, seems to have been accredited as an ICANN registrar.
The new registrar business goes by the name OpenTLD. Its domain name currently bounces visitors to Freedom’s home page.
Freedom manages .tk, the ccTLD for tiny Tokelau. It’s the fastest-growing TLD — currently the second-largest ccTLD after Germany’s .de — because it’s free to register .tk domains.
As a result, it’s also regularly recognized by the Anti-Phishing Working Group as one of the most-abused TLDs out there, though the company says its business model allows it turn off abusive domains at will.

Only 2% of phishing attacks use cybersquatted domain names

Kevin Murphy, October 25, 2012, Domain Registries

The number of cybersquatted domain names being used for phishing is falling sharply and currently stands at just 2% of attacks, according to the Anti-Phishing Working Group.
The APWG’s first-half 2012 report (pdf) identified 64,204 phishing domains in total.
Of those, the group believes that only 7,712 (12%) were actually registered by the phishers themselves. The rest belonged to innocent third parties and had been compromised.
That’s a steep drop from 12,895 domains in the second half of 2011 and 14,650 in the first half of 2011.
Of the 7,712 phisher-owned domains, about 66% were being use to phish Chinese targets, according to the APWG.
The group’s research found only 1,350 that contained a brand name or a misspelling of a brand name.
That’s down from 2,232 domains in the second-half of 2011, representing just 2% of all phishing domains and 17% of phisher-owned domains.
The report states:

Most maliciously registered domain strings offered nothing to confuse a potential victim. Placing brand names or variations thereof in the domain name itself is not a favored tactic, since brand owners are proactively scanning Internet zone files for such names.
As we have observed in the past, the domain name itself usually does not matter to phishers, and a domain name of any meaning, or no meaning at all, in any TLD, will usually do.
Instead, phishers almost always place brand names in subdomains or subdirectories. This puts the misleading string somewhere in the URL, where potential victims may see it and be fooled. Internet users are rarely knowledgeable enough to be able to pick out the “base” or true domain name being used in a URL.

Taken as a percentage of attacks, brand-jacking is clearly a pretty low-occurrence offence, according to the APWG’s numbers.
In absolute numbers, it works out to about 7.5 domain names per day that are being use to phish and contain a variation of the brand name being targeted.
Unsurprisingly, the APWG found that Freedom Registry’s .tk — which offers free registration — is the TLD being abused most often to register domains for phishing attacks.
More than half of the phisher-owned domains were in .tk, according to the report.