The uncomfortable diagnosis that DNS spreads scams
Following the measurement that more than 10 percent of new gTLDs look like scams, a walk through the abuse structure and what engineers should watch.
Read the original paper
Patrick Rho · AI Research
I am covering Simon Willison's short post from September 6, 2026, The purpose of DNS is to spread scams, which cites Terence Eden and Interisle report data. The original is linked under the title. The claim fits in one sentence. DNS now works as a distribution channel for crime, with roughly one in five newly registered gTLD domains looking like scams or malicious registrations.
I stopped for a moment when I first read it. DNS belongs to the oldest and most solid infrastructure on the internet. The textbook story calls it a phone book that turns names into numbers. Then someone says the purpose of that phone book is to spread scams. It sounds like provocation. It stops sounding like provocation once you see the numbers. What interests me more is not the sharp phrasing but the measurement behind it. Citing Interisle, the post says 85 million new gTLD registrations were made in 2025, and 8.5 million of them had reached blocklists by May 2025. That is not an impression. It is two records, registrations and blocks, placed side by side.
Where the phone book story stops working
The phone book analogy was comfortable for a long time. It painted DNS as polite infrastructure that maps a name to a number. What the analogy hides is registration. The phone book starts the moment someone lists a name. What is happening on the gTLD side right now is that names go up too fast and too cheaply. Eighty five million new registrations in one year shows the speed. I think the more important result is the structure behind the number. Registration is automated, the cost is low, and failure costs almost nothing. For an attacker, a domain is not an asset to protect. It is closer to a disposable supply.
For general readers, a short note on gTLDs helps. The term covers com, net, and org plus the hundreds of newer endings added after them. Some look familiar, like shop or xyz. Some are strings most people have never seen. More choice is convenient for users. It also gives attackers more raw material to pack phishing phrases directly into a domain. A near replica of a bank name, a phrase that looks like a delivery lookup, a phrase that looks like a payment error, all of it fits in one line. Anyone who does not study the address bar closely can find it convincing enough.
What 8.5 million blocked out of 85 million really means
Let me take the numbers apart slowly. The cited Interisle figures say 85 million new gTLD registrations in 2025, with 8.5 million added to blocklists by May 2025. Since May is the cutoff, the year end total could only grow. Eight point five divided by eighty five is 10 percent. That is why the report treats 10 percent as the floor. What is already confirmed is 10 percent.
This is where I would be careful not to over-read the experiment, or in this case the count. A blocklist is a record written after the fact. A name lands there after someone was hurt, after a detection system tripped, or after a report came in. If detection is imperfect, real abuse has to be larger than the list. That is the step that connects to the report saying the true figure may sit closer to 20 percent. One in five is an estimate that allows for that measurement gap. It reads as judgment laid over observation rather than a settled fact. Ten percent is observed. Twenty percent is assessed. The two should not sit on the same shelf.

From a systems perspective, the next question is obvious. How long does a domain live before it reaches a list, and how many people visit in between. If a domain lives only a few days, blocking is closer to cleaning up traces than catching the offender. The attacker has already moved to the next domain. In that structure, a rising block count is not a sign that defense is winning. It is closer to a sign that intake is enormous.
Why calling 10 percent the floor feels alarming
Floor is a familiar word for engineers. It marks a lower bound. Saying 10 percent is the floor means reality cannot sit below it. The posture of the report is plain. Even counting only what is visible gives 10 percent, and allowing for what stays hidden points to around 20 percent. I think the more important result is what that high floor implies about character. It points to routine rather than accident. It looks like a production line that runs every day.
Try the one in five phrase on an everyday scene. Picture a new shopping arcade with five units, one of them a scam shop. Passersby cannot tell which unit is normal. The sign looks fine and the display looks plausible. People notice something wrong only after they walk in and type payment details. Online, even that discovery comes late. A page vanishes within hours and the same content reappears at another address. Victims do not memorize addresses. Attackers do not need to. Automated tooling stamps out fresh addresses for them.
A common reply at this point says the whole DNS and new gTLDs must be separated. That is fair. Adding long lived domains pulls the ratio down. But the character of the problem changes once you see that attackers mostly spend new registrations. It is not that the entire old town is bad. It is that scam shops keep pouring out of the newly built district. When parcels sell fast and screening stays loose, the reputation of that district sinks quickly. Users do not memorize each ending. They just tap the link.
Why counting through blocklists always looks small
Blocklist measurement is close to standard in DNS abuse discussion. Feeds get combined, duplicates get removed, and entries get matched against registration time. The method is transparent. The limits are plain too. It counts only what made a list. What went undetected, unreported, pre-use, or used briefly and thrown away slips through. So the count leans toward undercounting by construction. That is also why the report can call 10 percent the floor.
When my team looks at a new AI architecture, we do not look at benchmark numbers alone. We ask what actually changed and what cost structure that change creates in a system. DNS abuse numbers deserve the same treatment. The count of 8.5 million matters less than how it gets made. Who lists a name, by what criteria, and how fast the entry links back to registration data, those details set the meaning of the result. Each feed leans a different way. One is strong on phishing, another on malware delivery. Merging them creates duplicates and gaps. No merge is perfect. Still the direction stays consistent. Wherever it bends, it bends toward undercount.

One more distinction matters. Blocklists count domains. They do not count harm. One scam domain can send thousands of texts and collect money from dozens of people. A registered but unused domain can also land on a list. Counts and losses sit on different axes. Ten percent of names does not mean ten percent of losses. Harm can concentrate or scatter. That is why the unit has to be read alongside the number.
When domains are cheap and fast, the business stays profitable
The math from the attacker side is simple. A domain costs a few dollars, registration takes minutes, and bulk buying needs only a payment method. Buy ten, lose nine to blocks, and one hit can still pay for the batch. A single phishing success often exceeds the price of hundreds of domains. In that environment, attack traffic does not stop even when defense succeeds 90 percent of the time. The remaining 10 percent still pays.
The math on the registrar and registry side deserves a look too. A sold domain is revenue. Even when an abusive domain is suspended later, the fee already paid often does not return. Faster suspension collides more directly with sales. Responsible operators keep abuse teams, and that should be said. But the incentive points the wrong way. The more you sell, the more you earn, so response tends to lag. Every hour of lag is business hours for attackers. That gap is their opening.
I keep thinking of this while watching AI infrastructure. As inference cost falls, abuse gets cheaper too. Writing spam copy, stamping out fake storefronts, and polishing phrases per language all fall together. Domains are the addresses pasted onto that output. When generation cost and distribution cost fall at the same time, scam output can jump in steps. Domain counts alone do not show that link. Generation and distribution have to be read together.
What happens each time a new ending opens
The gTLD expansion widened choice. Groups, regions, and brands could claim their own strings. The intent was good. The side effects are plain. Each new ending adds another normal pattern for users to memorize. Years ago, knowing com plus a few country endings was enough. Now hundreds exist. A strange ending no longer feels strange. Attackers use that gap. They pair an innocent looking word with an unfamiliar ending.

Bulk registration is also hard to stop at the gate. Automation serves normal business too. A company protecting a brand can buy hundreds at once. That looks like an attacker stocking up. Telling the two apart at registration time is harder than it sounds. Stolen payment, fake registrant details, or odd usage patterns tend to surface later. That is why post hoc action stays the default. Tighter screening up front would burden normal users. That balance has stayed unsolved for years.
What I would watch next is per ending disclosure. Which endings concentrate abuse, how the blocked share of new registrations moves, and how long takedown takes. Once those splits appear, the discussion changes. Right now a large aggregate shocks people and then fades. Split numbers allow responsibility to stick. When registry and registrar figures become visible, incentives shift. Reputation turns into numbers.
What years of ICANN discussion really mean
The bitter passage in the post is that ICANN has apparently been discussing this problem for years. ICANN holds policy and contract structure. Registries and registrars move under contracts with ICANN. That is where abuse duties, wording, and penalties get set. A long discussion usually signals tangled interests rather than hard technology.
There are structural reasons policy moves slowly. ICANN gathers many sides. Registries, registrars, corporate users, civil society, and governments each speak. The side urging stronger abuse duties meets the side worried about registration freedom and business burden. Without agreement, output stays at guidance level. Guidance binds weakly. Good actors comply and weak actors stay as they are. Attackers gather at the weak spots. It is the balloon effect.
A measurement dispute sits on top. The abuse share shifts with the lists chosen, with new versus total denominators, and with cutoff dates. When numbers wobble, responsibility blurs. That is why a floor figure like 10 percent matters. Even on generous settings, 10 percent remains. Such a number narrows room for argument. Past that point the topic should move from talk to action. Targets for suspension speed, screening for bulk buys, and clearer victim recovery paths belong in that conversation.

For criminals, DNS looks less like a directory and more like a factory
The Terence Eden line bites because it redefines what DNS does. On paper it resolves names. In practice it reads like a channel that mass produces scams. I read that less as exaggeration and more as a functional description. Design intent and current throughput can differ. Throughput gives the answer. When a large share of new registrations heads straight to blocklists, the line looks like a scam line. That is a statement about flow, not about original intent.
Push the factory comparison a little further. Raw material is cheap domains. Equipment is automated registration, hosting, and text delivery. Products are phishing pages, fake shops, and payment prompts. Distribution runs through texts, messengers, and email. There are no returns. When a defective unit gets caught, the factory does not close. It changes the sign. The same equipment ships the next product. Blocklists read like defective unit logs. A large pickup volume means large output.
Response looks different through that lens. Taking down single domains removes single defective units. Stopping the factory means touching material intake and machine time. Identity checks on bulk buys, anomaly detection on payments, blocks on burst creation patterns, and linked action across hosting and messaging layers all belong here. Fast single takedowns still matter. At the same time, treating the next few hundred names from the same hands as one cluster matters too. Single unit action cannot match that speed.
Reading the same problem as an engineer
From a systems perspective, DNS abuse is not a single layer problem. Registration, resolution, hosting, distribution, and payment tangle together. DNS handles address assignment in that chain. Cutting the address cuts intake, which is why DNS action matters. It still does not end with DNS. When a domain dies, traffic shifts to bare IP addresses, messenger accounts, or in app browsers. The balloon keeps moving. Even so, DNS sits near a choke point. It lives on trust. When the address bar shows a lock and the name looks plausible, people relax.
Work an engineer can do now splits into three strands. First is detection speed. Domain age is a useful signal. A domain registered hours ago that serves a payment page deserves a higher risk score. Checking the age of domains inside email or text links alone filters a large share. Second is cluster thinking. Domains from the same payment method, the same registrant pattern, the same name servers, or the same hosting batch get judged together. Decide on the cluster, not the unit. Third is user side warning. Browsers, messengers, and mail clients should speak plainly about fresh domains and lookalike spellings. Show the full address and say briefly why it looks risky.

I want to keep the measurement point explicit. Merging blocklists carries an undercount bias. Each list has its own scope and criteria. Dedup choices move totals. Registration time versus detection time framing moves them too. Even with those limits, this method sits at the center because it can be reproduced. Anyone can rerun the same lists against the same registration data. Imperfect but hard to game, that is its strength. A 10 percent floor carries weight for the same reason. It is the number that survives generous counting.
What to remember the next time one domain appears
Time to gather the threads. Eighty five million new gTLDs in 2025, 8.5 million blocklisted by May 2025, a 10 percent floor with estimates near 20 percent, the one in five reading, the Eden diagnosis, the long ICANN discussion, and the undercount lean of list based measurement. Those seven factual points carry the piece. The rest is interpretation. Mine is this. Whatever DNS was designed for, it currently serves as a choke point and a mass channel for scam distribution.
What I would watch next is threefold. First, split figures by ending and by operator. Action follows once concentration becomes visible. Second, the distribution of time to suspension. Averages hide the shape. What matters for harm is how long the longest lived slice survives. Third, records of cluster action. Not counts of single takedowns but cases where one batch from one actor was handled together. Evidence of stopped lines needs to accumulate.

One closing note for engineers and planners. Every new service touches external links, payments, and logins. Each of those touch points can carry one small signal like domain age. Copy for unfamiliar endings and lookalike combinations deserves careful wording too. No grand security product is required. A little friction that makes people reread the address bar is enough. In an era when DNS reads like a scam channel, the side offering trust has to prove it first. This uncomfortable post marks a good place to start that proof.