Carlos Hernandez Ganan, Principal Security, Stability & Resiliency Scientist, SSR Research, Office of CTO (OCTO)
Reputation blocklists (RBLs) are fundamental for identifying and measuring Domain Name System (DNS) Abuse. Yet, beneath their surface lies a critical challenge: different blocklists have limited visibility, and we see little overlap between them, creating blind spots in abuse detection and measurement (see OCTO-037). This fragmentation has far-reaching implications for how we interpret DNS Abuse metrics and track global trends.
Not all blocklists see the same types of DNS Abuse. Open-source lists, maintained by volunteer communities or public projects, rely on user reports and open feeds. While transparent and broadly accessible, they often miss abuse that escapes their contributors' notice. In contrast, commercial blocklists, curated by security vendors, leverage proprietary data and advanced analytics for deeper, faster insights into emerging attacks. However, their visibility is shaped by collection infrastructure, customer networks, and intelligence partnerships, leading to unique blind spots of their own.
These differences directly affect DNS Abuse metrics. To mitigate this, for example, ICANN's Domain Metrica system aggregates data from multiple RBLs to assess abuse rates across registries and registrars. But the selection of RBLs can dramatically reshape the observed landscape. For instance, if abuse rankings rely mainly on open-source lists, a registrar targeted by sophisticated phishing – maybe detected only by commercial feeds – may appear to have a lower abuse profile than it actually does. Conversely, a registrar with a high number of domains associated with less sophisticated, opportunistic phishing may appear to have a greater issue, even though these cases often involve generic attacks or compromised sites rather than more targeted, high-impact phishing campaigns.
The impact is clear in the table below, which ranks the top 10 anonymized top-level domains (TLDs) by normalized abuse counts using ICANN Domain Metrica data from January to May 2025. TLD_1 and TLD_2 consistently top the list across all data sources, but other rankings diverge sharply. TLD_3, for instance, is third in both all feeds and commercial lists, but drops to tenth with just open source data, appearing far less problematic.
TLD Ranking based on normalized reported DNS abuse counts |
|||
|---|---|---|---|
| Feeds | |||
| All | Commercial | Open | |
| TLD_1 | 1 | 1 | 1 |
| TLD_2 | 2 | 2 | 2 |
| TLD_3 | 3 | 3 | 10 |
| TLD_4 | 4 | 4 | 14 |
| TLD_5 | 5 | 5 | 20 |
| TLD_6 | 6 | 6 | 4 |
| TLD_7 | 7 | 7 | 12 |
| TLD_8 | 8 | 8 | 51 |
| TLD_9 | 9 | 9 | 16 |
| TLD_10 | 10 | 10 | 7 |
| Source: ICANN Domain Metrica (Jan - May 2025) | |||
These discrepancies highlight how the perceived abuse landscape – and the reputation of specific TLDs – can shift dramatically depending on which blocklists are used. Notably, because of their greater volume and broader coverage, commercial RBLs tend to overshadow the contribution of open source lists, often dominating the overall picture.
This isn't just a technical issue. The reputation of registrars and registries, and the effectiveness of DNS Abuse policies, can hinge on which blocklists are chosen for measurement. A registry might show a sharp decline in abuse incidents in one report, while another, using different feeds, shows no change at all.
The problem can also reflect RBLs which have a geographic bias, and extends to trend analysis. Imagine a surge in malware domains tied to a botnet operating in Eastern Europe. An RBL with strong regional visibility will reflect the spike, while a blocklist focused on North America may show nothing.
In short, relying on a limited set of blocklists, especially open-source ones, can leave significant gaps in DNS Abuse coverage and skew interpretation. For researchers, policymakers, and industry stakeholders, the takeaway is clear: robust DNS Abuse measurement demands a multi-source approach, blending open and commercial RBLs. Only by acknowledging and addressing these blind spots can we build a more accurate, actionable view of the DNS Abuse landscape – and ensure that our metrics and responses truly reflect reality.
What are your thoughts and experiences you would like to share? We would love to hear from you! Contact us at: [email protected].

