Summary
- Interisle reports that 8,496,811 of 84,961,989 gTLD names created in 2025 had entered its selected blocklists by 18 May 2026. It calls 10% a floor and projects a possible 20% after future listings and associated-domain expansion.
- ICANN says reported or blocklisted domains differ from domains supported by actionable evidence, and that reported-abuse statistics are at best an upper limit on confirmed abuse. It also says suspension normally requires investigation or corroboration.
- The two labels refer to different target populations. An observed count can be below a proposed population of unseen malicious registrations and above the population that would survive a narrower definition and case-specific confirmation.
- A claim-state ledger should keep observation, classification, estimate, policy signal, case evidence and authorized action separate. Aggregate measurement can inform policy without becoming a per-domain verdict.
One cell, two vertical axes
Imagine a spreadsheet with one cell containing 8,496,811. Put Interisle's label above it: floor. Put ICANN's description of reported-abuse statistics below it: upper limit. At first glance, the labels appear mutually exclusive. A floor cannot also be a ceiling if both statements describe the same room.
They do not.
Interisle's June report studies gTLD names created during 2025. It gives the year's create count as 84,961,989 and says that 8,496,811 of those names had been added to the blocklists in its data by 18 May 2026. It treats that observed set, after applying its malicious-registration criteria, as evidence of a larger population that its feeds have not yet seen. Some abusive names never reach the selected lists; others may appear later; a malicious actor may register related names that remain unused or undetected. On that axis, the observed total sits below the proposed underlying population. It is a floor.
ICANN's 10 August response asks a different question. How many names reported or listed as suspicious have enough evidence to support a reasonable determination of DNS Abuse under the relevant contractual definition? Reports can include lower-confidence signals, predictive or heuristic entries, compromised legitimate sites, categories beyond ICANN's remit and items that need corroboration. On that axis, the reported population can be larger than the confirmed population. It is an upper limit.
The apparent contradiction is therefore an estimand problem. An estimand is the thing a method is trying to estimate. “Domains observed by these feeds under these rules,” “domains classified as maliciously registered,” “all malicious registrations that occurred,” “confirmed contractual DNS Abuse” and “domains for which suspension is proportionate” are not alternative names for one quantity. They are successive claims with different evidence and authority.
That difference is not statistical housekeeping. Statistics can influence a policy development process, the reputation of a registrar or registry, commercial negotiations, regulatory attention and the priority assigned to enforcement. A figure that loses its claim state can acquire more power as it becomes less precise.
What Interisle counted
Interisle does not describe its work as a simple download of one blacklist. Its methodology names multiple professional feeds, including sources specializing in phishing, malware and other harmful activity. It adds defined campaign lists drawn from law-enforcement, court and threat-research material. It collects updates several times a day and de-duplicates names within and across feeds. If one name is labelled for two abuse types, it may appear in both type columns but is counted once in the unique total.
The report also tries to separate names registered for a malicious purpose from legitimate names compromised later. That matters because an attacker who buys a disposable name presents a different operational problem from an attacker who exploits a real business's vulnerable site. Interisle says approximately 98% of the 8.5 million blocklisted 2025 creates appeared to be maliciously registered under its criteria.
Its floor has two further components. First, it projects that later blocklisting could raise the listed share from 10% to about 12% by the end of 2026. Second, it applies an associated-domain expansion derived from the relationship between known seeds and other names in registration batches. Combining those steps yields 16.8 million potentially purchased by bad actors, or 20% of 2025 creates. The report explicitly calls 20% a projection.
Those distinctions must remain visible. The 8.5 million figure is an observed-and-classified count under a dated source set. The move to 10.1 million adds a time projection. The move to 16.8 million adds an association projection. A public argument may defend each step, challenge each step or test alternative assumptions. It should not present all three as the same kind of fact.
Interisle's scope is also wider than ICANN's contract vocabulary. The report discusses phishing, malware and botnets, but also fraud, scams and broader forms of spam. Those categories can be entirely proper in a study of cybercriminal demand. A victim does not care whether a loss fits the jurisdictional vocabulary of one private coordinator. But a category's public importance does not by itself put it inside ICANN's enforcement remit.
What ICANN called reported
ICANN's answer does not reject blocklists as evidence. Its own Domain Metrica system relies on reputation feeds to show how reported DNS Abuse appears across parts of the domain market. The current FAQ says these data reflect the ecosystem through the lens of reported abuse, and that listed names do not necessarily become abuse incidents. Domain Metrica does not generate the original reports and does not claim to see all abuse.
This produces a two-sided limitation. A domain absent from the feeds is not guaranteed to be benign; coverage is incomplete. A domain present in a feed is not automatically a confirmed incident; reporting and confirmation are different states. The same dataset can miss real abuse and still contain entries that do not satisfy a later action threshold.
ICANN's July 2025 analysis of blocklist choice makes the coverage problem concrete. Rankings changed when the input was limited to open sources, commercial feeds or the combined set. Some anonymized TLDs remained near the top; others moved substantially. The visible concentration was partly a property of which sensors were selected.
OCTO-037 explains why. An RBL has a focus, collection mechanism, identifier type, timing, overlap and churn. Volume can be measured directly. Liveliness, purity and metadata accuracy may require sampling or surrogate tests. Catchment, retesting practice and operational reliability may be unavailable from the entries themselves. A source that is useful for protecting one network can be unsuitable for a study where every false positive imposes a large investigation cost.
ICANN's 2026 response applies that use-case principle to consequence. An RBL can be useful for pattern analysis while a suspension requires investigation or corroboration. This is not a demand to ignore urgent evidence. It is a demand that the authority and evidentiary standard increase as the consequence becomes more specific and harder to reverse.
A citation is not a method diff
The dispute becomes sharpest where both sides refer to related research. Interisle says its associated-domain work shares similarities with an ICANN OCTO batch-registration method and that its malicious-registration classification resembles COMAR. ICANN responds that the differences from those published methods are not explained in enough detail. Merely naming a method does not expose what was changed.
The ICANN batch paper is useful precisely because it states exclusions. It groups time-bound registrations using registrar, authoritative nameserver and creation-time features, then tests how known RBL seeds sit inside those batches. It excludes clusters smaller than ten because co-occurrence was less reliable. It excludes clusters larger than 1,000 from detailed analysis because some were heterogeneous and could reflect reseller processing effects. Its validation used ground truth from one cooperating registrar, while broader account-holder truth remains with registrars and registries.
The paper reports an 80% expansion in newly registered RBL domains through batch inference. It also says association does not itself supply new attribution, attackers can evade the grouping assumptions, and operational deployment needs refinement and a minimum evidence threshold. A later report can reasonably adapt that method. But if it changes cluster boundaries, source windows, filters, denominators or treatment of excluded cases, a citation alone does not tell readers whether the published result is comparable.
COMAR has the same virtue. The 2020 paper reports 97% accuracy with a 2.5% false-positive rate on its labelled phishing and malware datasets, using 38 public-data features to distinguish maliciously registered names from compromised ones. Those are strong reported test results, not a perpetual certificate for every later classification. The paper documents manual labelling, content-fetch failures, evasion, domain dropcatching and cases where benign history or a defaced homepage can mislead features.
A method name is therefore a branch point, not a provenance chain. Reproducibility requires a versioned statement of what was retained, omitted, tuned or reinterpreted. Without the diff, the reader cannot tell whether disagreement comes from data, definition, implementation or inference.
The six claim states
The smallest common layer is not a universal abuse detector. It is a public grammar for the claim's state.
| State | What the record may establish | What it must not silently become |
|---|---|---|
| Observation | A name or URL appeared in a named source at a stated time | Proof of malicious intent |
| Classification | A versioned rule or model assigned a category, association or confidence | An infallible label |
| Population estimate | Observations and inferences produced a numerator, denominator, range or projection | A count of adjudicated cases |
| Policy signal | The aggregate is relevant to a stated policy question | Authority to act against one domain |
| Case evidence | A particular name was investigated or corroborated under the applicable definition | A decision by an unidentified actor |
| Authorized action | A responsible party applied a valid instrument and proportionate response | Erasure of notice, review or correction history |
These states may connect. They must not collapse. A policy body can use aggregate evidence to decide that a problem deserves attention. A registrar can use a feed entry to prioritize investigation. A registry may receive different evidence under its contract and role. None of those transitions needs the fiction that the first observation already contained the last decision.
A receipt for the number
For the measurement layer, each important figure should carry a compact receipt. It should identify the target estimand and unit; the observation window and cutoff; the feed set and visibility limits; the abuse definition; inclusion, exclusion and de-duplication rules; the classifier and version; any association or expansion method; the numerator and denominator; and which components are observed, inferred or projected.
The receipt should also record uncertainty direction and sensitivity. If a feed misses activity, the count may be low relative to one target. If reports include unconfirmed or out-of-remit items, the count may be high relative to another. Both can be true. A range without a target is not uncertainty disclosure; it is decoration.
Finally, the record needs intended and prohibited uses. “Suitable for aggregate trend analysis” is not the same authorization as “suitable for initiating case review,” and neither means “sufficient for suspension.” A method-change log and correction identity should let a later version supersede a result without pretending that the earlier result never existed.
This receipt need not expose licensed feeds, personal data or detection thresholds that would help attackers. Reproducibility is not synonymous with publishing every secret. Where inputs cannot be shared, the record can still disclose their class, coverage, selection logic, hashes or escrowed audit path, and show how sensitive the conclusion is to their inclusion.
A separate receipt for action
The domain-specific action record begins where the aggregate receipt ends. It identifies the case, applicable contractual category, responsible contracted party, source evidence, corroboration state and whether the name appears maliciously registered, compromised or unresolved. It names the investigator and decision owner, records the scope and proportionality of the response, and preserves notification, escalation, review, correction and reinstatement.
ICANN's 2024 amendments matter at this layer. They define DNS Abuse for the relevant agreements as malware, botnets, phishing, pharming and spam when spam delivers the other listed harms. The compliance advisory explains duties for registrars and registries when actionable evidence reaches them within their roles. It does not convert every broader social harm into the same contractual category or give ICANN one undifferentiated suspension switch.
The join between the two receipts should contain a plain sentence: an aggregate listing, association or population estimate does not become domain-specific actionable evidence merely because it informed policy. If a particular report also contains case evidence, that evidence should enter the case record on its own terms.
This boundary protects action as well as restraint. A clearly corroborated phishing case should not be delayed because an analyst is arguing over a market-wide percentage. Conversely, a market-wide concentration should not be dismissed because not every listed name has reached a case verdict. The two systems answer different questions and can operate at different speeds.
Evidence does not appoint itself
Heng Lu's critique of multistakeholder mandate offers the governing distinction. Participation can supply evidence, expertise, warning and technical discipline. It does not turn the participant into the principal authorized to bind everyone affected. Measurement has the same temptation. A large dataset can look like a constituency; a model can look like a decision-maker; a dashboard can look like an order.
None is one.
Interisle has authority over its own research method and claims. ICANN OCTO has authority over its own measurement systems and technical publications. The GNSO community can develop policy through its assigned process. Contractual Compliance can assess obligations within adopted instruments. Registrars and registries hold operational information and particular contractual responsibilities. Courts and public authorities operate under separate law. Their evidence may travel; their authority does not merge merely because they cite the same domain.
The thin common layer is the join among those actors. It makes the state of a claim portable while leaving lawful investigation and operational judgment local. This is running-code discipline applied to governance: standardize what must survive a handoff, not every method used on either side of it.
The useful disagreement
The 2026 exchange should not end with a winner declared by adjective. Interisle's report raises a serious claim about the scale and market concentration of malicious registrations. ICANN's response raises a serious claim about definition, method disclosure and the evidentiary threshold for consequences. Those claims can be tested together.
A useful next publication would show the 8.5 million observed set as a reproducible measurement chain: feed contribution, overlap, campaign additions, exclusions, malicious-versus-compromised classification, denominator and cutoffs. The 20% projection should expose separate contributions from later listing and associated-domain expansion, along with sensitivity cases. ICANN, in turn, should state which comparisons would change its view of scale and which parts of its disagreement concern remit rather than empirical prevalence.
The result may still be disagreement. That is acceptable. A governance system does not become accountable by forcing every observer to produce one number. It becomes accountable by making clear what each number can prove, what it cannot prove, who may use it and what additional record is needed before harm is imposed.
The floor and the ceiling can remain. The missing structure is the room between them.
Sources
- ICANN, “Looking Beyond the Numbers: Understanding Malicious Domain Registration Data”
- Interisle Consulting Group, “Malicious Registrations in the Domain Market”
- ICANN, Domain Metrica FAQs
- ICANN, “How Choice of Reputation Blocklists Affects DNS Abuse Metrics”
- ICANN OCTO-037v2, “RBL Evaluation Methodology”
- ICANN OCTO SSR, “Detecting Malicious Domain Registration Batches: Patterns, Prevalence, and Security Implications”
- Maroofi et al., “COMAR: Classification of Compromised versus Maliciously Registered Domains”
- ICANN advisory on compliance with DNS Abuse obligations
- ICANN, 2024 Global Amendments
- ICANN, DNS Abuse Mitigation Program
- Lu Heng, “The Multi-Stakeholder Mirage—How the Multi-Stakeholder Model Turned Attendance Into Mandate”
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
