ICANN Blogs

Read ICANN Blogs to stay informed of the latest policymaking activities, regional events, and more.

ICANN Examines Parked Domains and Zero-Click Redirection

9 March 2026
By

Authors:
Siôn Lloyd, Principal Security, Stability, and Resiliency Scientist
Sam Cheadle, Machine Learning Engineer
Samaneh Tajalizadehkhoob, Director, Security, Stability, and Resiliency Research
Carlos Hernandez Gañán, Principal Security, Stability, Resiliency Scientist

Several years ago, the ICANN Security, Stability, and Resiliency research team investigated whether we could classify domains that appear to have no real content, often referred to as parked pages. According to our definition, parked pages can present in several ways, from traditional pages with a few advertisements, to pages showing that the domain is for sale, to pages indicating that the domain has been suspended. This project has been presented and published, and we have recently spent some time extending the work, which will be presented as part of the Office of the Chief Technology Officer's (OCTO) publication series.

Parked Pages Revisited – "Zero-Click" Redirection

As we revisited the topic, we noticed that the ecosystem has evolved. Some of the markers we had used to identify parked pages have become less common, while new ones have appeared. This is to be expected as businesses merge and models adapt to changing pressures. We also observed an increase in a behavior known as "zero-click" redirection, or "direct search" advertising, where users can, under certain conditions, be redirected to different domains without any interaction on their part. These redirections are mediated by one or more advertising brokers in a chain. The final destination will depend on, for example, the apparent country that the user visits from, the browser or device used, or a combination of multiple factors.

The detail of what we see in this space will be part of an upcoming OCTO publication based on this work. Until that is published, we have written a blog post that covers some initial measurements and findings.

Observations and Next Steps

We can see that zero-click redirection is currently common among parked domains. The most interesting examples are those that show mixed behaviors of sometimes staying in-domain and sometimes not. It seems clear to us that, with these domains, decisions are being made based on where the visitor appears to be coming from. We also believe those decisions are based on maximizing the financial return on the traffic.

In our experiment on a random sample, most of the redirections seen are relatively constrained and appear unlikely to be malicious. This cannot be said of all cases, though, with 5.5 percent of our sample showing some potential for harm.

We are also aware of certain ecosystems where the risks are much higher, in that they are either deliberately, or through negligence, redirecting to malicious or suspicious pages.

This area requires additional investigation. We will continue to conduct measurements and look for patterns, which can be used to make the web a safer place. For now, our advice remains: "Be careful what you click on; be careful what you type; and using bookmarks, a password safe that links your account details to a specific site, and multifactor authentication can help keep you safe."

Authors

Siôn Lloyd

Principal Security, Stability & Resiliency Scientist