Where spam and malware live: a TLD year in review

From .com to .beauty: The evolving threat landscape of unwanted email

Most phishing is a game of borrowed trust. Attackers impersonate brands, colleagues, or vendors, and one of the quickest signals a recipient can check is the top-level domain — the suffix after the dot in the sender's address. January-to-December 2023 data from Cloudflare's Cloud Email Security service offers a useful look at which TLDs carry the heaviest load of spam and malicious mail, and how those patterns shifted during the year.

The service processed a large sample: over 3.4 billion unwanted emails in 2023, about 26% of all messages it handled. On average, 9% of 2023 emails were flagged spam and 3% malicious, with the malicious share climbing toward 4% by year-end. Phishing is the umbrella term here — Cloudflare treats malicious email as equivalent to phishing attempts. The numbers include some reporting bias: measurements may occur after other filters have already stripped out obvious spam, meaning what remains is the harder, more damaging material.

The findings point clearly at newer generic TLDs (gTLDs) as the most unreliable senders. Names like .uno, .sbs, .beauty — all introduced since 2014 — had over 95% of their email flagged as spam or malicious. But raw volume tells a different story: .com alone accounts for 67% of all spam and malicious email.

A quick history lesson on domain names

Email predates most of the internet you know — Ray Tomlinson sent the first networked email over ARPANET in 1971, and the @ sign has been the address separator ever since. The rise of email standardization in the 1980s brought interoperability across academia and the military, and that same interoperability is now what makes phishing scale.

ICANN oversees the domain name system, which spans the classic .com (from 1985), hundreds of newer generic gTLDs, and country-code TLDs (ccTLDs) where IANA designates a trustee per country. ICANN's big 2014 expansion aimed to increase choice and competition in the domain space — a goal that also created fertile ground for abuse. New TLDs are cheap, can allow anonymous registration, and security tools are slow to learn which new suffixes are spam magnets.

What the volume looks like

BLOG-2291 Embedded Image - McsShc

Cloudflare's email security service blocked 2.4 billion unwanted emails in 2022, jumping to over 3.4 billion in 2023 — that's 26% of all messages processed. In per-second terms: 9.3 million a day, 6,500 per minute, 108 per second. Part of the increase is just growth — new customers drove a 42% rise in unwanted email year over year — but the scale still signals how central email-borne attacks remain. CISA notes that 90% of cyber attacks begin with phishing.

Which TLDs look worst

Looking at 2023 across more than 350 TLDs (with tiny ones under 20,000 emails excluded), a few patterns emerge:

  • Highest threat rates: Newer gTLDs, especially beauty-industry suffixes like .beauty, and others including .uno and .sbs, had the highest proportions of spam and malicious mail relative to their total email.
  • Highest threat volumes: .com sits at 67% of all spam and malicious email, joined by .net at 4%. Together, .com and .net make up 68% of all malicious and 71% of all spam email.
  • Newer gTLDs overall: All gTLDs introduced since 2014 account for 13.4% of spam and malicious email, and over 14% of malicious-only email.
  • ccTLDs: Country-code domains still contribute more than 12% of both unwanted categories, though newer gTLDs have overtaken them in malicious email.

Type of TLDs

Spam

Malicious 

Spam + malicious

ccTLDs

13%

12%

12%

.com and .net only

71%

68%

71%

new gTLDs 

13%

14%

13.4%

One standout is .shop — available since 2016, it ranks #2 by volume of spam and malicious email with 5% of the total, holding that same 5% share in both separate spam and malicious categories. Its influence is rising over time.

The full 2023 top 50

Beyond the top 10, more recent gTLDs rank high: .autos tops the spam-only list, with .today, .bid, and .cam also near the top. Leisure and entertainment-themed suffixes — .fun and similar — appear throughout the top 50 as well.

How patterns shifted mid-year

Comparing the first half of 2023 to the second half shows movement. Some TLDs climbed noticeably in the percentage of their email that was spam or malicious between July and December, with .uno, .makeup, and .directory appearing in the top rankings for the first time in the latter half of the year. Attackers also rotate through TLDs and methods, which keeps the landscape in flux — the top-10 lists in both halves are entirely recent, generic TLDs, several of which only became available since 2021.

The Freenom effect

BLOG-2291 Embedded Image - zKkLsg

One notable shift in 2023 followed Meta's lawsuit against Freenom, filed in December 2022 and refiled in March 2023. Freenom was a registry offering free domains across five ccTLDs — .cf, .ga, .gq, .ml, and .tk — which became infamous as phishing havens. Freenom stopped new registrations during the lawsuit and announced in February 2024 that it would exit the domain business entirely.

These Freenom TLDs appeared in the top 50 only during the first half of 2023. By October, their email volume — across all categories — had nearly vanished. In February 2023, they accounted for 0.17% of all malicious email tracked; that share has since effectively dropped to zero. The legal pressure appears to have reshaped at least one corner of the abuse ecosystem.

Volume vs. Risk: Reordering the TLD Rankings

Filtering purely by share can obscure what matters to operators: which TLDs actually deliver the most unwanted mail in absolute terms. Ordering the data by volume of spam and malicious messages brings familiar, long-established TLDs back to the fore, led by .com. But within that high-volume group, a separate risk signal emerges when you look at the percentage of email per TLD that is spam or malicious. TLDs including .shop, .no, .click, .beauty, .top, .monster, .autos, and .today all show elevated shares of unwanted mail — and of pure malicious email specifically.

Among country-code TLDs, Norway’s .no leads the spam ranking, followed by China’s .cn, Russia’s .ru, Ukraine’s .ua, and Anguilla’s .ai — the last now seeing more use for AI-related domains than for its territorial origin. In the table, TLDs where the combined spam and malicious share exceeds 20% of all email are marked in bold red; we consider that a high bar for domains carrying substantial mail volume.

Why .gov Appears on the Malicious List

Ranking by raw volume of blocked malicious messages surfaces a less obvious entry: .gov, the TLD restricted to US government use and administered by CISA.

TLDs ordered by malicious email volume

% of all malicious emails

.com

63%

.net

5%

.shop

5%

.org

3%

.gov

2%

.ru

2%

.jp

2%

.click

1%

.best

0.9%

.beauty

0.8%

The top two domains here, .com (63%) and .net (5%), mirror the overall volume rankings. .shop also appears at 5%, and .org — open-registration despite its non-profit reputation — takes fourth place. The presence of .gov in fifth is explained not by compromised government systems but by spoofing: attackers forge the sender address to look like a legitimate .gov origin. These spoofed messages typically fail SPF, DKIM, and DMARC validation, signaling that the sender is using an unauthorized IP or domain. Content inspection is often unnecessary; the authentication failures themselves provide a straightforward blocking signal.

High-Risk Lists by Category

Separating malicious from spam mail produces two distinct risk rankings. For malicious email, the top three slots all belong to generic TLDs: .bar leads with 70% of its mail classified as malicious, followed by .makeup and .cyou. The list also includes ccTLDs frequently repurposed beyond their country codes, such as .ml (Mali), .om (Oman), and .pw (Palau), alongside .ir, .kg, and .lk.

The spam-only ranking is topped by .autos at 93%, with .today and .directory close behind, all exceeding 90% spam share.

New Entrants in 2024

January 2024 brought fresh TLDs into the high-risk category that had not appeared in the 2023 top 50. Samoa’s .ws, Indonesia’s .id, and the Cocos Islands’ .cc all joined, each showing a significant malicious share. The range is stark: from 20% of all .cc email up to 95% for .ws. These ccTLDs, like others on the list, are marketed and used for purposes far removed from their geographic origins.

January 2024: Newer TLDs in the top 50 list

TLD

Spam %

Malicious %

Spam + mal %

.ws

3%

95%

98%

.company

96%

0%

96%

.digital

72%

2%

74%

.pro

66%

6%

73%

.tz

62%

4%

65%

.id

13%

39%

51%

.cc

25%

21%

46%

.space

32%

8%

40%

.enterprises

2%

37%

40%

.lv

30%

1%

30%

.cn

26%

3%

29%

.jo

27%

1%

28%

.info

21%

5%

26%

.su

20%

5%

25%

.ua

23%

1%

24%

.museum

0%

24%

24%

.biz

16%

7%

24%

.se

23%

0%

23%

.ai

21%

0%

21%

A Year of Unwanted Email in Numbers

Cloudflare’s Cloud Email Security telemetry offers a broader view of the mail landscape. Over 2023, spam accounted for 8.58% of all emails seen, and nearly 3% were flagged as malicious. These percentages reflect mail that reaches Cloudflare’s filters after upstream providers have already removed some volume.

Malicious mail was not evenly distributed across the year. Q4 saw the highest shares, with notable spikes in the weeks before Christmas and the first week of 2024, when malicious email averaged 7% and 8% of weekly volume respectively. Christmas week itself dropped to 3%. Other peaks aligned with the week before Valentine’s Day, the first week of September as work and school resumed in the Northern Hemisphere, and late October.

BLOG-2291 Embedded Image - pQ070I
BLOG-2291 Embedded Image - LyiWgs

Threat Mix and Attachment Habits

Breaking down 2023 threats by type, links appeared in 49% of all threats. Extortion accounted for 36%, identity deception for 27%, credential harvesting for 23%, and brand impersonation for 18% — categories defined in Cloudflare’s 2023 phishing threats report. Extortion was the fastest-growing category, climbing from 7% of threats in Q1 to 38% by November and December.

BLOG-2291 Embedded Image - cLfhvw

Attachment habits remained steady: 20% of all emails carried attachments, while 82% included links in the body. Plain-text messages made up 31% of volume, HTML-formatted mail 18%, and 39% of emails used remote content.

BLOG-2291 Embedded Image - FXF96r

Practical Takeaways

The unwanted-email landscape shifts with technology adoption, user behavior, and attacker tactics. The 2023–2024 data shows new generic TLDs becoming preferred channels for malicious campaigns, reinforcing the case for caution with mail from unfamiliar domains. Email remains a primary business tool and a primary attack vector; authentication failures like SPF, DKIM, and DMARC breaks remain reliable indicators of spoofed senders, and spikes around holidays and seasonal transitions suggest predictable windows of elevated risk.