https://www.unicode.org/Public/security/latest/confusables.txt, header “Version: 18.0.0” — checked 2026-09-25.Table of Contents
Domain abuse: squatting, parking, expired domains and dangling DNS
You are about to measure names that attract traffic or trust meant for someone else: a typo of a bank's domain, a brand name with -login appended, a domain that expired last month and still receives the old owner's email, a CNAME that points at a cloud bucket nobody owns any more. The measurement is the same four steps every time — generate or collect candidate names, find out which are registered or configured, decide what each one does, and (sometimes) register or claim a few to see what arrives — and each step has a decision that fixes what your number means:
- The generator is the population. Whatever permutation model, token list or record source you use decides which squats exist for you. Two squatting models over the same brands describe populations two orders of magnitude apart.
- The registration source decides what you can see. A daily zone snapshot, a Certificate Transparency stream and passive DNS each miss a different slice, and since 2018 WHOIS no longer tells you who registered the name.
- “Registered” is not “abused”. Most lookalike names are parked, for sale, unused, or registered by the brand itself. A count of lookalikes without a use label and a defensive-registration check measures the registration market, not abuse.
- Registering a name to see what it receives is an intervention. Nineteen papers in this population registered or took control of names, and seven of them logged the traffic, mail or queries that arrived for someone else. What they kept, and what they did with the name afterwards, differs from paper to paper — and Ethics does not yet answer the question.
This page is about the namespace itself as the measured object: which names exist, who holds them, what they do, and what trust they inherit. Three neighbours own the adjacent questions. DNS owns resolution measurement — which resolver answered what. Phishing owns what a lookalike is used for once it serves a phishing page; this page stops at “the squatted name serves a phish” and hands over. TLS certificates owns Certificate Transparency as a data source; this page uses CT only as one of several ways to find names. Squatting in namespaces that are not DNS — package registries, container images, app identifiers, voice skills, social handles, blockchain names — is counted as context, not population; the fourteen papers are listed on domain_abuse.
A count of lookalike or expired names is not a finding. Four measured facts a methods section has to survive:
- The generator is the population. Kintis et al. matched 268 trademarks against six years of passive and active DNS and found combosquatting domains — brand plus extra tokens — 100 times more prevalent than typosquatting domains [1Kintis, Panagiotis; Miramirkhani, Najmeh; Lever, Charles; Chen, Yizheng; Gómez, Rosa Romero; Pitropakis, Nikolaos; Nikiforakis, Nick; Antonakakis, Manos (2017): "Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. A study that generates only keyboard typos has measured the smaller of the two populations and cannot say so.
- Most registrations are not abuse, and some are the brand's own. Of 146,397,537 candidate names generated for the Fortune 500, 402,934 were registered and 19,523 (4.84%) of those were identified as defensive registrations by the companies themselves [2Adjibi, Boladji Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Bailey, Michael; Monrose, Fabian (2025): "The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]. Ten years earlier only 156 of the Alexa top 500 had any defensive registration of their five-model typos [3Agten, Pieter; Joosen, Wouter; Piessens, Frank; Nikiforakis, Nick (2015): "Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse", in: Proceedings of the Network and Distributed System Security Symposium. (Link)].
- Residual trust is cheap to buy and heavy. Re-registering 201 expired domains at an average of $7.29 each brought 650,737,621 requests from 5,540,379 IP addresses in four months [4So, Johnny; Miramirkhani, Najmeh; Ferdman, Michael; Nikiforakis, Nick (2022): "Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]. On the day they are deleted, 10% of all
.comdomains are re-registered [5Lauinger, Tobias; Chaabane, Abdelberi; Buyukkayhan, Ahmet Salih; Onarlioglu, Kaan; Robertson, William (2017): "Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers", in: Proceedings of the USENIX Security Symposium. (Link)]. - Dangling delegations are a registrar practice, not an accident. Registrars renaming nameservers to “sacrificial” hostnames exposed 512,715 domains over nine years, and 163,827 (31.95%) of those were actually taken over by someone registering the sacrificial name [6Akiwate, Gautam; Savage, Stefan; Voelker, Geoffrey M.; Claffy, Kimberly C. (2021): "Risky BIZness: risks derived from registrar name management", in: Proceedings of the ACM Internet Measurement Conference. (DOI)].
State your generator, your registration source and its date, how you told defensive registrations from squats, and what you registered yourself. “We found 40,000 typosquatting domains” states none of them.
What to read first
| Paper | Why now |
|---|---|
| Kintis et al., CCS 2017 [1Kintis, Panagiotis; Miramirkhani, Najmeh; Lever, Charles; Chen, Yizheng; Gómez, Rosa Romero; Pitropakis, Nikolaos; Nikiforakis, Nick; Antonakakis, Manos (2017): "Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] | Why the generator decides the population: combosquatting from passive and active DNS, 2.7 million domains, and how long abusive ones live. Read it before choosing a permutation model. |
| Adjibi et al., NDSS 2025 [2Adjibi, Boladji Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Bailey, Michael; Monrose, Fabian (2025): "The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] | Current lookalike design: every major permutation family over the Fortune 500, zone files plus WHOIS plus three years of ISP passive DNS, and a strict rule for what counts as a brand's own registration. The paper that makes “is this a squat or the owner?” a measured question. |
| Agten et al., NDSS 2015 [3Agten, Pieter; Joosen, Wouter; Piessens, Frank; Nikiforakis, Nick (2015): "Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] | The classic longitudinal typosquatting crawl — five typo models, Alexa top 500, daily for seven months, a 13-way use taxonomy, released data. Historical as a target list; still the template for labelling what a squat does. |
| Vissers et al., NDSS 2015 [7Vissers, Thomas; Joosen, Wouter; Nikiforakis, Nick (2015): "Parking Sensors: Analyzing and Detecting Parked Domains", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] | How to recognise a parked page, with a classifier and eight million parked domains. Parking is a common end state for squatted, speculative and expired names, so a parking detector belongs in any pipeline. |
| Lauinger et al., USENIX Security 2017 [5Lauinger, Tobias; Chaabane, Abdelberi; Buyukkayhan, Ahmet Salih; Onarlioglu, Kaan; Robertson, William (2017): "Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers", in: Proceedings of the USENIX Security Symposium. (Link)] and Miramirkhani et al., TheWebConf 2018 [8Miramirkhani, Najmeh; Barron, Timothy; Ferdman, Michael; Nikiforakis, Nick (2018): "Panning for gold.com: Understanding the Dynamics of Domain Dropcatching", in: Proceedings of the ACM Web Conference. (DOI)] | Expiry and drop-catching: who re-registers deleted names, how fast, and what they do with them. |
| So et al., IEEE S&P 2022 [4So, Johnny; Miramirkhani, Najmeh; Ferdman, Michael; Nikiforakis, Nick (2022): "Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] | Re-registering expired domains and logging what still arrives. The method, its cost, and an ethics section worth copying — and one outcome worth not repeating (see Registering names to measure them). |
| Squarcina et al., USENIX Security 2021 [9Squarcina, Marco; Tempesta, Mauro; Veronese, Lorenzo; Calzavara, Stefano; Maffei, Matteo (2021): "Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern Web", in: Proceedings of the USENIX Security Symposium. (Link)] | Subdomain takeover across the Tranco top 50k, and what a takeover grants inside the same site. The founding dangling-record paper, Liu et al. (CCS 2016) [10Liu, Daiping; Hao, Shuai; Wang, Haining (2016): "All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS Records", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], was selected for this corpus but its PDF was never retrieved, so it is cited here from the authors' copy and not counted. |
| Akiwate et al., IMC 2020 [11Akiwate, Gautam; Jonker, Mattijs; Sommese, Raffaele; Foster, Ian D.; Voelker, Geoffrey M.; Savage, Stefan; Claffy, K. C. (2020): "Unresolved Issues: Prevalence, Persistence, and Perils of Lame Delegations", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] and IMC 2021 [6Akiwate, Gautam; Savage, Stefan; Voelker, Geoffrey M.; Claffy, Kimberly C. (2021): "Risky BIZness: risks derived from registrar name management", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] | Delegations that point at nameserver domains anyone can register: nine years of zone files, lame delegations and sacrificial nameservers. |
| So et al., USENIX Security 2025 [12So, Johnny; Sanchez-Rola, Iskander; Nikiforakis, Nick (2025): "Lost in the Mists of Time: Expirations in DNS Footprints of Mobile Apps", in: Proceedings of the USENIX Security Symposium. (Link)] and Hortea et al., PoPETs 2026 [13Hortea, Gabriel; Girish, Aniketh; Vallina-Rodriguez, Narseo; Tapiador, Juan (2026): "Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps", in: Proceedings on Privacy Enhancing Technologies. (DOI)] | Current residual-trust work: expired domains that apps still contact, tracked through their expiry — the app-side residual-trust work since 2025. |
| Sommese et al., IMC 2024 [14Sommese, Raffaele; Akiwate, Gautam; Affinito, Antonia; Müller, Moritz; Jonker, Mattijs; Claffy, K. C. (2024): "DarkDNS: Revisiting the Value of Rapid Zone Update", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] and Lu et al., NDSS 2021 [15Lu, Chaoyi; Liu, Baojun; Zhang, Yiming; Li, Zhou; Zhang, Fenglu; Duan, Haixin; Liu, Ying; Chen, Joann Qiongna; Liang, Jinjin; Zhang, Zaifeng; Hao, Shuang; Yang, Min (2021): "From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] | The two instruments papers: what daily zone snapshots miss, and what the GDPR did to WHOIS. Read both before you promise a registration count or a registrant. |
Four families, one pipeline
Every paper in this population measures names whose trust comes from somewhere other than their current holder. The four families differ in where the trust comes from, and that decides where you find instances:
| Family | Why the name attracts traffic or trust | Where instances come from | What you then verify |
|---|---|---|---|
| Lookalike | a person or machine makes an error against a live name: typo, bit flip, confusable character, brand plus keyword, a sentence parsed as a URL | a generator over a target list, matched against zone files, passive DNS or CT | registered? by whom? what does it serve? |
| Parking | the name is monetised rather than used; often the end state of the other three | parking-service nameservers in zone or DNS data | parked or not (a classifier), and where the ad or redirect chain leads |
| Residual | the name used to be something, or is referenced as if it were: expired, dropped, taken down and released, queried but never registered, embedded in an app or a link | drop lists, zone diffs, NXDOMAIN traffic, app traffic, link corpora | available? re-registered? what still arrives? |
| Dangling | a record or delegation points at something its owner no longer controls: a deprovisioned cloud resource, a released IP, an expired or typoed nameserver domain, a hosting zone anyone can create | zone files, subdomain enumeration, resolver and provider scans | claimable? claimed by someone already? |
Where the families stop. A lookalike that serves a credential form is a phish; the feed, cloaking and takedown questions are Phishing. A lookalike that sells a fake product is Online scams. A squat in the npm registry or an app store is the same idea in a different namespace, with its own registry rules; the papers are listed as context. Domain-generation-algorithm and generic malicious-domain detection are not here either — they classify names by behaviour, not by where their trust comes from — and no page on this wiki covers them yet; the eight such papers met here are counted as context.
Candidate generation: the generator is the population
A lookalike study starts from a target list (whose names are being imitated) and a generator (how imitations are produced). Both are sampling decisions, and a paper that states neither has an undefined population.
The models. Almost everything published uses some subset of these, often combined:
- Keyboard and edit-distance typos — omission, insertion, substitution by adjacent key, transposition, repetition, missing dot. The canonical set comes from Wang et al.'s Strider Typo-Patrol (SRUTI 2006, outside the corpus); 24 corpus papers mention Typo-Patrol by name, 14 of them in this population. Agten et al. used five models at Damerau–Levenshtein distance 1 and explicitly exclude wrong TLDs and multiple typos [3Agten, Pieter; Joosen, Wouter; Piessens, Frank; Nikiforakis, Nick (2015): "Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]; Szurdi et al. estimated that about 20% of the whole
.comzone are true typo domains, and that only 6.8% of registered typo domains target the 10,000 most popular.comnames — the long tail is where they are [16Szurdi, Janos; Kocso, Balazs; Cseh, Gabor; Spring, Jonathan; Felegyhazi, Mark; Kanich, Chris (2014): "The Long “Taile” of Typosquatting Domain Names", in: Proceedings of the USENIX Security Symposium. (Link)]. - Combosquatting — the trademark plus added tokens (
paypal-login). Not an edit-distance model at all, which is why typo generators miss it; Kintis et al. is the reference [1Kintis, Panagiotis; Miramirkhani, Najmeh; Lever, Charles; Chen, Yizheng; Gómez, Rosa Romero; Pitropakis, Nikolaos; Nikiforakis, Nick; Antonakakis, Manos (2017): "Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. - Bitsquatting — one flipped bit. Nikiforakis et al. found 5,366 bitsquatting domains targeting 491 of the Alexa top 500 over 270 days, 71.8% of which are not also typosquats [17Nikiforakis, Nick; Van Acker, Steven; Meert, Wannes; Desmet, Lieven; Piessens, Frank; Joosen, Wouter (2013): "Bitsquatting: exploiting bit-flips for fun, or profit?", in: Proceedings of the ACM Web Conference. (DOI)]. A real but small population.
- Homographs — confusable characters, mostly via IDN. ShamFinder combined Unicode's confusables list with its own automatically built homoglyph database, SimChar [18Suzuki, Hiroaki; Chiba, Daiki; Yoneya, Yoshiro; Mori, Tatsuya; Goto, Shigeki (2019): "ShamFinder: An Automated Framework for Detecting IDN Homographs", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]; Hu et al. found 1,855 homograph IDNs impersonating 674 popular names in
.com, of which Chrome showed Punycode for 64.1% and Safari and Firefox for 9.7% and 6.1% [19Hu, Hang; Jan, Steve T.K.; Wang, Yang; Wang, Gang (2021): "Assessing Browser-level Defense against IDN-based Phishing", in: Proceedings of the USENIX Security Symposium. (Link)]. The current confusables data is Unicode Technical Standard #39, version 18.0.0.1) Chromium's IDN policy compares the skeleton of a hostname against top domains and shows Punycode on a match2) — so a homograph count says nothing about what a Chrome user sees; a measurement of exposure has to test the browser, as Hu et al. did. - Soundsquatting (homophones) and user-error names that are not typos of any target — a missing space after a full stop turning
G-20. Ininto the linkg-20.in: Kaleli et al. collected 26,596 such unintended URLs from Twitter in seven months [20Kaleli, Beliz; Kondracki, Brian; Egele, Manuel; Nikiforakis, Nick; Stringhini, Gianluca (2021): "To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]. Soundsquatting's defining paper is outside the seven venues.3)
The target list. Nine of the fourteen lookalike papers used a top list or a company list as targets. Seven of the nine stopped at the Alexa top 10K or a few hundred brands — the Alexa top 500 [3Agten, Pieter; Joosen, Wouter; Piessens, Frank; Nikiforakis, Nick (2015): "Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] [17Nikiforakis, Nick; Van Acker, Steven; Meert, Wannes; Desmet, Lieven; Piessens, Frank; Joosen, Wouter (2013): "Bitsquatting: exploiting bit-flips for fun, or profit?", in: Proceedings of the ACM Web Conference. (DOI)], top 10K [18Suzuki, Hiroaki; Chiba, Daiki; Yoneya, Yoshiro; Mori, Tatsuya; Goto, Shigeki (2019): "ShamFinder: An Automated Framework for Detecting IDN Homographs", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] [19Hu, Hang; Jan, Steve T.K.; Wang, Yang; Wang, Gang (2021): "Assessing Browser-level Defense against IDN-based Phishing", in: Proceedings of the USENIX Security Symposium. (Link)], the Fortune 500 [2Adjibi, Boladji Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Bailey, Michael; Monrose, Fabian (2025): "The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] — while Szurdi et al. split the top million into head, middle and tail [16Szurdi, Janos; Kocso, Balazs; Cseh, Gabor; Spring, Jonathan; Felegyhazi, Mark; Kanich, Chris (2014): "The Long “Taile” of Typosquatting Domain Names", in: Proceedings of the USENIX Security Symposium. (Link)] and Roberts et al. went to the top 100K [21Roberts, Richard; Goldschlag, Yaelle; Walter, Rachel; Chung, Taejoong; Mislove, Alan; Levin, Dave (2019): "You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS Certificates", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. Alexa is gone; if you replace it, say with what and which day, because the long-tail result above means a head-only target list under-samples where most typo registrations are. See Website selection and Tranco.
Tools, and their state today. Most papers wrote their own generator. The named tools:
| Tool | What it generates | Checks registration? | State on 2026-09-25 |
|---|---|---|---|
| dnstwist | 16 fuzzers: addition, bitsquatting, cyrillic, homoglyph, hyphenation, insertion, omission, plural, repetition, replacement, subdomain, transposition, vowel-swap, dictionary, tld-swap, various | DNS (NS/A/AAAA/MX), WHOIS, GeoIP, HTTP/SMTP banners, fuzzy page hashes (ssdeep, TLSH), screenshot perceptual hash | maintained; latest release 20250130, last commit 2025-04-15; Apache-2.0 |
| URLCrazy | 17 variant types incl. homophones, bit flips, homoglyphs, wrong TLD | DNS only; its README: “This tool does not check if a domain has been registered” | latest release v0.8.2 (2025-07-28); bespoke licence, not open-source |
| twistrs | a Rust port of dnstwist's permutation engine | library | active (pushed 2026-09-25); moved to haveibeensquatted/twistrs |
| ail-typo-squatting (CIRCL) | permutation library feeding AIL | — | last release v2.7.4 (2023-12-01), commits to 2025-04-30 |
dnstwist is named in 5 corpus papers (3 in this population, 2018–2025), URLCrazy in 3. Tian et al. used both, plus their own squatting rules, to scan 224 million DNS records [22Tian, Ke; Jan, Steve T. K.; Hu, Hang; Yao, Danfeng; Wang, Gang (2018): "Needle in a Haystack: Tracking Down Elite Phishing Domains in the Wild", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. If you use a tool, pin the release and publish the fuzzer list you enabled: the fuzzer set is your population definition. Repository states are re-checked by external_checks_domain_abuse.sh on domain_abuse.
LLMs. No paper in this population uses an LLM to classify or generate names (0 of 48 in the extraction's classification records; one 2026 paper uses GPT-4o only to clean addresses in dispute records [23Adjibi, Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Dainotti, Alberto; Bailey, Michael; Monrose, Fabian (2026): "Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century’s Worth of Squabbles", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]). Corpus-wide, papers with an LLM classification step went from 2 of 719 in 2023 to 77 of 770 in 2025. Outside the seven venues, DomainLynx uses an LLM pipeline for squatting detection (IEEE Access 2025).4) A related new residual-trust vector — names that code-generating models hallucinate and attackers then register — has, in peer-reviewed work, so far been measured for package names, not domains, and the one corpus-venue paper on it was screened out of this corpus.
Where registrations come from, and what each source misses
Once you have candidates you need to know which exist. Every source is a partial view, and the part it misses is systematic:
| Source | What it sees | What it misses | Papers here (of 48) |
|---|---|---|---|
TLD zone files — ICANN CZDS for gTLDs, including .com/.net | every delegated second-level name in the TLD, daily | names with no nameservers, and names in serverHold, clientHold, pendingDelete or redemptionPeriod 5); names created and removed between two snapshots; almost all ccTLDs; subdomains | 20 (hand-coded) |
| Certificate Transparency | names (and subdomains) that got a publicly logged certificate | names that never got one; see TLS certificates for the log-list and static-CT change | 6 |
| Passive DNS (Farsight/DNSDB, ISP resolvers) | names someone actually looked up, with first/last-seen dates | names nobody queried at the vendor's sensors; coverage is the vendor's customer base | 11 |
| Active DNS datasets (Active DNS Project, OpenINTEL) or your own resolution | resolution of a seeded list | only what is seeded | 11 |
| Drop and pending-delete lists | names about to be deleted | what happens at private auctions and registrar-internal transfers | 5 |
| Traffic you can see (ISP, enterprise proxy, root-server query captures, an email provider's bounces) | real demand for a name, including names that do not exist | only your vantage's users | 4 |
| App code and app traffic | names software will contact, even years later | apps you did not run | 4 (all 2023–2026) |
Short-lived names are invisible to daily snapshots. Sommese et al. found that “the daily snapshots miss at least 1% of newly registered and short-lived domains, which are frequently registered with likely malicious intent”, and against a ccTLD registry's ground truth detected only a third of transient domains with the best public data [14Sommese, Raffaele; Akiwate, Gautam; Affinito, Antonia; Müller, Moritz; Jonker, Mattijs; Claffy, K. C. (2024): "DarkDNS: Revisiting the Value of Rapid Zone Update", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. If your question involves abuse, the snapshot's blind spot is correlated with your label.
ccTLDs are mostly dark. A handful publish their full zone: .se and .nu (hourly, from zonedata.iis.se), .ee (AXFR, CC BY 4.0), and .ch/.li through SWITCH's open-data portal.6) Elsewhere you are inferring from CT, passive DNS or crawls, and the coverage of that inference is itself unknown. Akiwate et al.'s lame-delegation study leans on exactly such open ccTLD zones alongside the gTLD ones [11Akiwate, Gautam; Jonker, Mattijs; Sommese, Raffaele; Foster, Ian D.; Voelker, Geoffrey M.; Savage, Stefan; Claffy, K. C. (2020): "Unresolved Issues: Prevalence, Persistence, and Perils of Lame Delegations", in: Proceedings of the ACM Internet Measurement Conference. (DOI)].
The DNS-side instruments — CZDS, OpenINTEL, passive DNS — and their paper counts across the whole corpus are also tabulated on Pick the instrument; this page counts only the 48.
Newly registered domain feeds are commercial derivatives of zone diffs and passive DNS; WhoisXML API advertises “around 450,000 newly registered or newly discovered domains” a day.7) They inherit the snapshot gap above. For research access, Farsight (now DomainTools) runs a grant programme covering DNSDB and its newly-observed-domains feed, and OpenINTEL's open data is CC BY-NC-SA 4.0 with a required attribution.8)
In the extraction's own source fields, 21 corpus papers name CZDS — 16 of them since 2023 — and 3 name RDAP. Zone data went from a registry favour to routine infrastructure; registration data went the other way.
WHOIS after the GDPR, and RDAP
The registration record used to answer three questions: when was the name created and when does it expire, who is the registrar, and who is the registrant. Since 2018 only the first two are reliably public for gTLDs.
- May 2018: registrars and registries began redacting registrant data under the GDPR. Lu et al. analysed 1.2 billion WHOIS records and found “over 85% surveyed large WHOIS providers redacting EEA records at scale” and “over 60% large WHOIS data providers also redact non-EEA records” [15Lu, Chaoyi; Liu, Baojun; Zhang, Yiming; Li, Zhou; Zhang, Fenglu; Duan, Haixin; Liu, Ying; Chen, Joann Qiongna; Liang, Jinjin; Zhang, Zaifeng; Hao, Shuang; Yang, Min (2021): "From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR", in: Proceedings of the Network and Distributed System Security Symposium. (Link)].
- 28 January 2025: for ICANN-contracted gTLDs, “the Registration Data Access Protocol (RDAP) will be the definitive source … in place of sunsetted WHOIS services”.9) Port-43 WHOIS is no longer a contractual obligation; a WHOIS client in your pipeline is now a compatibility layer over whatever each operator still runs.
- 21 August 2025: ICANN's Registration Data Policy took effect, replacing the interim policy; where it applies, registrant name, street, postal code, phone and fax, and registrant and tech email are redacted from public output.10) Non-public data is requested through ICANN's Registration Data Request Service (RDRS), launched in November 2023 as a pilot and extended in November 2025 “for up to two years past the project's initial pilot period”.11) It is meant for “law enforcement, intellectual property professionals, consumer protection advocates, cybersecurity professionals, and government officials”, not for bulk research.12)
- EU: NIS2 Article 28 requires TLD registries and registrars to keep accurate registration data and to “make publicly available … the domain name registration data which are not personal data”; transposition was due by 17 October 2024.13)
What this does to a measurement:
- Lifecycle studies are fine. Creation, expiry and update dates, status codes and registrar are still published, and RDAP returns them as JSON instead of per-registrar free text — the parsing problem that needed a learned parser at
.comscale in 2015 [24Liu, Suqi; Foster, Ian D.; Savage, Stefan; Voelker, Geoffrey M.; Saul, Lawrence K. (2015): "Who is .com?: Learning to Parse WHOIS Records", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] largely goes away. Only one paper in this population used RDAP, in 2018, against Verisign's test deployment, falling back to WHOIS when a registrar's RDAP returned HTTP 500 [25Lauinger, Tobias; Buyukkayhan, Ahmet Salih; Chaabane, Abdelberi; Robertson, William K.; Kirda, Engin (2018): "From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. - Registrant clustering is broken for new data. “Who owns these 500 squats?” and “is this the brand's own registration?” used to be a WHOIS join. Now it needs other evidence: nameservers, registrar, redirect to the brand, a certificate shared with the brand, or a historical WHOIS product for pre-2018 records. Adjibi et al.'s defensive-registration rule combines several of these [2Adjibi, Boladji Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Bailey, Michael; Monrose, Fabian (2025): "The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]; Ownership resolution covers what a registrant field was ever worth.
- Bulk lookups have terms. Registry and registrar WHOIS and RDAP services limit automated high-volume querying in their terms of use; the constraint and a registry's wording are on Terms of service and acceptable-use policies. Plan a lookup budget per day before you plan a population.
- Historical WHOIS is a commercial product with unknown sampling. Ten papers here used one, four of them in 2025–2026. Lauinger et al. rejected such archives for a systematic study because “the companies do not disclose when and how they collect the data” [26Lauinger, Tobias; Onarlioglu, Kaan; Chaabane, Abdelberi; Robertson, William; Kirda, Engin (2016): "WHOIS Lost in Translation: (Mis)Understanding Domain Name Expiration and Re-Registration", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. If you use one, say which, and treat its gaps as missing data rather than as absence.
- ICANN's “DNS abuse” does not include squatting. The 2024 contract amendments define DNS Abuse as “malware, botnets, phishing, pharming, and spam (when spam serves as a delivery mechanism for the other forms of DNS Abuse …)”.14) A typosquat that parks ads is a trademark matter, handled through UDRP disputes — WIPO managed “over 6,200 domain name cases” in 2025, its highest on record.15) Adjibi et al. analysed 90,153 English-language UDRP proceedings and found that “2,751 malicious domains remained under malicious actors' control for up to four months after a panel ordered their transfer” [23Adjibi, Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Dainotti, Alberto; Bailey, Michael; Monrose, Fabian (2026): "Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century’s Worth of Squabbles", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]. Do not describe your squats as “DNS abuse” in a paper a registrar will read; they will reply that it is not.
What does a squatted or re-registered name do?
Thirty of the 48 papers classify what the names they found actually do. This page codes their labels into a dozen classes — parked with ads, for sale, redirect to the target, redirect elsewhere, affiliate abuse, malicious, phishing, own content, error, unused — although the papers' own taxonomies differ. Across all 48, the labelling step, whatever it labels, is mostly rules plus a manual pass: rules in 36, manual review in 32, a trained classifier in 7.
What the papers found the names doing, with their own denominators:
| Paper | Population | What the names did |
|---|---|---|
| [3Agten, Pieter; Joosen, Wouter; Piessens, Frank; Nikiforakis, Nick (2015): "Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] | 28,179 generated typo domains of the Alexa top 500, 17,172 of which ever resolved | 477 of the 500 targets had at least one malicious typosquatting domain; 344 (68.8%) had no defensive registration at all |
| [27Halvorson, Tristan; Der, Matthew F.; Foster, Ian D.; Savage, Stefan; Saul, Lawrence K.; Voelker, Geoffrey M. (2015): "From .academy to .zone: An Analysis of the New TLD Land Rush", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] | 3,638,209 domains in the new gTLD zones (2015) | 31.9% parked; only 15% “consistent with primary registrations”; the rest promotional, speculative or defensive |
| [7Vissers, Thomas; Joosen, Wouter; Nikiforakis, Nick (2015): "Parking Sensors: Analyzing and Detecting Parked Domains", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] | more than 8 million parked domains at 15 parking services | 60% at three services; 131,673 (1.63%) of them typosquatting |
| [28Alrwais, Sumayah; Yuan, Kan; Alowaisheq, Eihal; Li, Zhou; Wang, XiaoFeng (2014): "Understanding the Dark Side of Domain Parking", in: Proceedings of the USENIX Security Symposium. (Link)] | 24M visits to over 100K parked domains | 1.2M (5%) of visits produced redirection chains rather than a plain ad page; illicit monetisation was at least 0.8% of one reputable service's revenue and 40.3% of another's |
| [8Miramirkhani, Najmeh; Barron, Timothy; Ferdman, Michael; Nikiforakis, Nick (2018): "Panning for gold.com: Understanding the Dynamics of Domain Dropcatching", in: Proceedings of the ACM Web Conference. (DOI)] | re-registered dropped domains (1,059,050 caught in 80 days), a crawled subset labelled | less than 11% hosted web content; the rest were used by speculators or malicious actors |
| [22Tian, Ke; Jan, Steve T. K.; Hu, Hang; Yao, Danfeng; Wang, Gang (2018): "Needle in a Haystack: Tracking Down Elite Phishing Domains in the Wild", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] | 657,663 squatting domains of 702 brands | 1,175 confirmed phishing pages; more than 90% evaded popular blacklists for at least a month |
| [29Khan, Mohammad Taha; Huo, Xiang; Li, Zhou; Kanich, Chris (2015): "Every Second Counts: Quantifying the Negative Externalities of Cybercrime via Typosquatting", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] | 11.1K adversarial typo domains seen in enterprise and ISP traffic | 33 listed on VirusTotal (3 or more detections), 9 on Google Safe Browsing |
Three things follow for your design:
- Parking is a common outcome, so a parking detector is part of any squatting pipeline — 31.9% of all new-gTLD registrations in 2015 were parked [27Halvorson, Tristan; Der, Matthew F.; Foster, Ian D.; Savage, Stefan; Saul, Lawrence K.; Voelker, Geoffrey M. (2015): "From .academy to .zone: An Analysis of the New TLD Land Rush", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. Vissers et al.'s Random Forest over HTML, HAR, frame and domain features is the published baseline [7Vissers, Thomas; Joosen, Wouter; Nikiforakis, Nick (2015): "Parking Sensors: Analyzing and Detecting Parked Domains", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]; nuclei's takeover template set includes a parked-page signature (GoDaddy's) alongside its takeover fingerprints.16) No paper in these venues has made parking its subject since 2015.
- Blocklists see a sliver. The coverage figures above (and the phishing-feed ones on What a blocklist hit proves) mean a blocklist can label a squat malicious but cannot tell you a squat is benign. VirusTotal as a label is VirusTotal.
- A use label is a snapshot. Over seven months Agten et al. counted on average 2.84 category transitions per typosquatting domain [3Agten, Pieter; Joosen, Wouter; Piessens, Frank; Nikiforakis, Nick (2015): "Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]. One crawl gives you the label on that day; say which day, or re-crawl.
- Separate defensive registrations explicitly, or say you did not. Only 8 of the 30 classifying papers have a defensive class. A redirect to the brand is not proof of ownership — Kintis et al. and Agten et al. both found affiliate abusers who redirect to the target with their affiliate ID appended [1Kintis, Panagiotis; Miramirkhani, Najmeh; Lever, Charles; Chen, Yizheng; Gómez, Rosa Romero; Pitropakis, Nikolaos; Nikiforakis, Nick; Antonakakis, Manos (2017): "Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] [3Agten, Pieter; Joosen, Wouter; Piessens, Frank; Nikiforakis, Nick (2015): "Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]. Check the redirect for affiliate parameters and the registration for the brand's nameservers or registrar before calling it defensive.
Parked pages reach other people's crawls, too. Among the 1,120 corpus papers that crawled, 50 mention parked domains at least once (a full-text mention, not read per paper), and 38 of those are not in this population — among them censorship-list and dead-link studies, privacy-policy corpora and notification campaigns, several of which filter parked pages as a cleaning step. That is the point: a parked page answers 200 and looks like a site, and a list-driven crawl that does not filter it counts ad-network templates as websites.
Expired domains and residual trust
A gTLD domain that is not renewed passes through an optional auto-renew grace period of 1–45 days, a 30-day Redemption Grace Period, and five days of pending delete before it is released.17) Then it is caught or it is not:
- Drop-catching is fast and concentrated. “10 % of all com domains are re-registered on the same day as their old registration is deleted”; drop-catch services “control over 75 % of accredited domain registrars and cause more than 80 % of domain creation attempts, but represent at most 9.5 % of successful domain creations” [5Lauinger, Tobias; Chaabane, Abdelberi; Buyukkayhan, Ahmet Salih; Onarlioglu, Kaan; Robertson, William (2017): "Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers", in: Proceedings of the USENIX Security Symposium. (Link)]. On average only about 10% of dropped domains are caught [8Miramirkhani, Najmeh; Barron, Timothy; Ferdman, Michael; Nikiforakis, Nick (2018): "Panning for gold.com: Understanding the Dynamics of Domain Dropcatching", in: Proceedings of the ACM Web Conference. (DOI)]. The
.comDrop starts at 19:00 UTC and many names are re-registered with zero delay [25Lauinger, Tobias; Buyukkayhan, Ahmet Salih; Chaabane, Abdelberi; Robertson, William K.; Kirda, Engin (2018): "From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], so any re-registration timing needs second-level resolution and the registry's own drop data, not daily WHOIS. - What the new holder inherits. Lever et al. found 27,758 blacklisted and 238,279 malware-resolved domains that had expired and been maliciously re-registered [30Lever, Chaz; Walls, Robert J.; Nadji, Yacin; Dagon, David; McDaniel, Patrick D.; Antonakakis, Manos (2016): "Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in Domains", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]. Alowaisheq et al. found that 350K (56.46%) of six years of taken-down domains had been released, and that expired sinkhole nameserver domains had handed about 30K seized domains to new owners [31Alowaisheq, Eihal; Wang, Peng; Alrwais, Sumayah; Liao, Xiaojing; Wang, XiaoFeng; Alowaisheq, Tasneem; Mi, Xianghang; Tang, Siyuan; Liu, Baojun (2019): "Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downs", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]. Ma et al. found valid TLS certificates held by a domain's previous owner — “over 9 million instances of abusable third-party stale certificates from 2016-2023 across 4.5 million effective second-level domains” [32Ma, Zane; Faulkenberry, Aaron; Papastergiou, Thomas; Durumeric, Zakir; Bailey, Michael D.; Keromytis, Angelos D.; Monrose, Fabian; Antonakakis, Manos (2023): "Stale TLS Certificates: Investigating Precarious Third-Party Access to Valid TLS Keys", in: Proceedings of the ACM Internet Measurement Conference. (DOI)].
- Names that were never registered have residual demand too. NXDOMAIN traffic: Liu et al. identified 146,363,745,785 NXDomains queried in passive DNS from 2014–2022 and registered 19 that had kept receiving queries while non-existent for at least six months [33Liu, Guannan; Jin, Lin; Hao, Shuai; Zhang, Yubao; Liu, Daiping; Stavrou, Angelos; Wang, Haining (2023): "Dial "N" for NXDomain: The Scale, Origin, and Security Implications of DNS Queries to Non-Existent Domains", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. Name collisions: leaked internal queries for strings that later became new gTLDs — 65.7% of the new gTLDs delegated by August 2015 had leaked WPAD queries at two root servers before delegation [34Chen, Qi Alfred; Osterweil, Eric; Thomas, Matthew; Mao, Zhuoqing Morley (2016): "MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]. Links: Saric et al. found active links to “more than 572 000 dot-com domains that have never been registered” in Common Crawl [35Saric, Kevin; Savins, Felix; Ramachandran, Gowri Sankar; Jurdak, Raja; Nepal, Surya (2024): "Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains", in: Proceedings of the ACM Web Conference. (DOI)].
- Software keeps calling dead names. So et al.: 309 versions of 149 apps relied on 41 first-order domains that were immediately registrable [12So, Johnny; Sanchez-Rola, Iskander; Nikiforakis, Nick (2025): "Lost in the Mists of Time: Expirations in DNS Footprints of Mobile Apps", in: Proceedings of the USENIX Security Symposium. (Link)]; Hortea et al. tracked 3,420 domains used by 11,131 apps through their expiry and found 218 dangling CNAMEs susceptible to hijacking [13Hortea, Gabriel; Girish, Aniketh; Vallina-Rodriguez, Narseo; Tapiador, Juan (2026): "Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps", in: Proceedings on Privacy Enhancing Technologies. (DOI)]. The same check appears as one section of papers on IoT companion apps [36Schmidt, David; Tagliaro, Carlotta; Borgolte, Kevin; Lindorfer, Martina (2023): "IoTFlow: Inferring IoT Device Behavior at Scale through Static Mobile Companion App Analysis", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], Deno packages [37AlHamdan, Abdullah; Staicu, Cristian-Alexandru (2025): "Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its Ecosystem", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] and email auto-configuration [38Wen, Shushang; Zhang, Yiming; Shen, Yuxiang; Li, Bingyu; Duan, Haixin; Lin, Jingqiang (2025): "Automatic Insecurity: Exploring Email Auto-configuration in the Wild", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] — five of the population's eight section-level papers are residual-trust sections from 2023–2025. On this corpus's thin 2025–2026 years, this is where the residual-trust family shows new work.
Measuring residual traffic without registering. Randall et al.'s Trufflehunter estimates how many users look up rare names — typosquats among its case studies — by cache-snooping large public resolvers [39Randall, Audrey; Liu, Enze; Akiwate, Gautam; Padmanabhan, Ramakrishna; Voelker, Geoffrey M.; Savage, Stefan; Schulman, Aaron (2020): "Trufflehunter: Cache Snooping Rare Domains at Large Public DNS Resolvers", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. It gives a lower bound on demand without ever receiving anyone's traffic. If your question is “how much demand does this name have”, try this before buying the name.
Dangling DNS and subdomain takeover
A dangling record points at a resource its owner released: a CNAME to a deleted cloud app or bucket, an A record to a released cloud IP, an NS record to a nameserver domain that expired or was renamed. Whoever claims the resource next answers for the name.18) The literature has moved up the delegation chain:
| Level | Papers | Measured |
|---|---|---|
| Subdomain → third-party service | [10Liu, Daiping; Hao, Shuai; Wang, Haining (2016): "All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS Records", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] (not in the extraction), [9Squarcina, Marco; Tempesta, Mauro; Veronese, Lorenzo; Calzavara, Stefano; Maffei, Matteo (2021): "Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern Web", in: Proceedings of the USENIX Security Symposium. (Link)] | Squarcina et al.: 1,520 subdomains exposed to takeover on 887 of the Tranco top 50k domains, 83% from discontinued third-party services and 17% from expired domains; plus 13,532 potentially vulnerable domains through deprovisioned cloud instances |
| Record → released cloud IP | [40Pauley, Eric; Sheatsley, Ryan; Hoak, Blaine; Burke, Quinn; Beugin, Yohan; McDaniel, Patrick D. (2022): "Measuring and Mitigating the Risk of IP Reuse on Public Clouds", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] | allocated 1.5 million unique AWS IPs (about 56% of the pool) over 101 days for $2,089.76; 14 top-million domains had dangling records at the second level |
| Delegation → registrable nameserver domain | [41Kalafut, Andrew J.; Gupta, Minaxi; Cole, Christopher A.; Chen, Lei; Myers, Nathan E. (2010): "An empirical study of orphan DNS servers in the internet", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], [11Akiwate, Gautam; Jonker, Mattijs; Sommese, Raffaele; Foster, Ian D.; Voelker, Geoffrey M.; Savage, Stefan; Claffy, K. C. (2020): "Unresolved Issues: Prevalence, Persistence, and Perils of Lame Delegations", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], [6Akiwate, Gautam; Savage, Stefan; Voelker, Geoffrey M.; Claffy, Kimberly C. (2021): "Risky BIZness: risks derived from registrar name management", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], [42Vissers, Thomas; Barron, Timothy; Van Goethem, Tom; Joosen, Wouter; Nikiforakis, Nick (2017): "The Wolf of Name Street: Hijacking Domains Through Their Nameservers", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] (not in the extraction) | about 14% of 49 million actively measured domains had at least one lame delegation; of the 48,185 unresolvable nameserver domains behind 151,422 lame-delegated domains, 42,579 (88%) were available for purchase [11Akiwate, Gautam; Jonker, Mattijs; Sommese, Raffaele; Foster, Ian D.; Voelker, Geoffrey M.; Savage, Stefan; Claffy, K. C. (2020): "Unresolved Issues: Prevalence, Persistence, and Perils of Lame Delegations", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] |
| Delegation → shared DNS hosting | [43Alowaisheq, Eihal; Tang, Siyuan; Wang, Zhihao; Alharbi, Fatemah; Liao, Xiaojing; Wang, XiaoFeng (2020): "Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting Referral", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], [44Zhang, Fenglu; Zhang, Yunyi; Liu, Baojun; Alowaisheq, Eihal; Ying, Lingyun; Li, Xiang; Zhang, Zaifeng; Liu, Ying; Duan, Haixin; Zhang, Min (2023): "Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], [45Zhang, Yunyi; Zhang, Mingming; Liu, Baojun; Liu, Zhan; Zhang, Jia; Duan, Haixin; Zhang, Min; Shi, Fan; Xu, Chengxi (2024): "Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure", in: Proceedings of the USENIX Security Symposium. (Link)] | 125,124 domains vulnerable across 12 hosting providers, 10 of which did nothing to stop customers claiming unauthorised zones [45Zhang, Yunyi; Zhang, Mingming; Liu, Baojun; Liu, Zhan; Zhang, Jia; Duan, Haixin; Zhang, Min; Shi, Fan; Xu, Chengxi (2024): "Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure", in: Proceedings of the USENIX Security Symposium. (Link)] |
| Registry → stale glue and deleted domains still delegated | [46Zhang, Yunyi; Liu, Baojun; Duan, Haixin; Zhang, Min; Li, Xiang; Shi, Fan; Xu, Chengxi; Alowaisheq, Eihal (2024): "Rethinking the Security Threats of Stale DNS Glue Records", in: Proceedings of the USENIX Security Symposium. (Link)], [47Zhang, Mingming; Zhang, Yunyi; Liu, Baojun; Duan, Haixin; Zhang, Min; Shi, Fan; Xu, Chengxi (2025): "Misty Registry: An Empirical Study of Flawed Domain Registry Operation", in: Proceedings of the USENIX Security Symposium. (Link)] | 23.18% of glue records stale; 193,558 directly exploitable, affecting 6,687,000 domains [46Zhang, Yunyi; Liu, Baojun; Duan, Haixin; Zhang, Min; Li, Xiang; Shi, Fan; Xu, Chengxi; Alowaisheq, Eihal (2024): "Rethinking the Security Threats of Stale DNS Glue Records", in: Proceedings of the USENIX Security Symposium. (Link)]; 3.4K “relic” domains across registry back ends serving 812 TLDs [47Zhang, Mingming; Zhang, Yunyi; Liu, Baojun; Duan, Haixin; Zhang, Min; Shi, Fan; Xu, Chengxi (2025): "Misty Registry: An Empirical Study of Flawed Domain Registry Operation", in: Proceedings of the USENIX Security Symposium. (Link)] |
Two measurement problems are specific to this family:
- You cannot confirm a takeover without taking over. A fingerprint (“the bucket does not exist”, “no such app”) is a candidate; only claiming the resource proves it. Squarcina et al. created accounts on each service and tested bindings against their own domain, and “did not create any virtual machine or registered any service at cloud providers” for the cloud case [9Squarcina, Marco; Tempesta, Mauro; Veronese, Lorenzo; Calzavara, Stefano; Maffei, Matteo (2021): "Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern Web", in: Proceedings of the USENIX Security Symposium. (Link)]; Hortea et al. did not claim anything [13Hortea, Gabriel; Girish, Aniketh; Vallina-Rodriguez, Narseo; Tapiador, Juan (2026): "Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps", in: Proceedings on Privacy Enhancing Technologies. (DOI)]. Report fingerprint matches and confirmed claims as different numbers.
- Fingerprint lists age. Services change their error pages and add ownership verification. The community list
can-i-take-over-xyzwas last pushed 2025-02-08; the last commit touching nuclei's takeover templates (2026-07-20) only re-signed them, so it says nothing about new coverage; dnsReaper's latest release is 2.0.3 (2025-10-06); subjack's v3.0.0 (2026-03-16) README now claims NS-delegation and stale-A detection as well asCNAMEfingerprints.19) Name the list and its date, and re-verify fingerprints on a sample.
Registering names to measure them
Open question for Ethics: that page covers crawling, scanning and notification, but not the practice this section describes — registering or claiming a name in order to receive the traffic, mail or queries meant for someone else. Nineteen papers here registered or claimed names; seven of them — the traffic-logging rows of the table below — did it to see what arrived. The decisions below are what a review board will ask about, and the papers answer them differently. A section on Ethics that states a default for each would close this.
15 of the 48 papers registered domains themselves — 535 domains across the 13 that state an exact count, from one (a lab testbed) to 201; the other two give only a lower bound — and 6 took control of third-party resources: a seized domain's nameserver slot, 1.5 million cloud IPs, other people's zones on DNS-hosting services. Of these 19, 2 report IRB approval, 2 an IRB exemption, 2 approval by a non-IRB body (university counsel; an industry partner's network department), 10 an ethics section with no review body, and 3 nothing.
| Paper | Registered or claimed | What they collected, and what they did with it | Review, as stated |
|---|---|---|---|
| [48Szurdi, Janos; Christin, Nicolas (2017): "Email Typosquatting", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] | 76 typo domains of email providers, over seven months | millions of emails; sensitive strings removed by regular expression before storage, encrypted with a key kept elsewhere | IRB approved (the authors' and their sponsor's) |
| [20Kaleli, Beliz; Kondracki, Brian; Egele, Manuel; Nikiforakis, Nick; Stringhini, Gianluca (2021): "To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] | 45 unintended-URL domains, registered within hours of the tweet | visit counts only; “we do not interact in any way with the users” | IRB: not human-subjects research |
| [4So, Johnny; Miramirkhani, Najmeh; Ferdman, Michael; Nikiforakis, Nick (2022): "Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] | 201 expired domains | 650,737,621 requests; a 404 page carrying bot traps and fingerprinting JavaScript; never engaged clients; the domains expired back into the pool afterwards | ethics section, no review body |
| [33Liu, Guannan; Jin, Lin; Hao, Shuai; Zhang, Yubao; Liu, Daiping; Stavrou, Angelos; Wang, Haining (2023): "Dial "N" for NXDomain: The Scale, Origin, and Security Implications of DNS Queries to Non-Existent Domains", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] | 19 NXDomains, six months | 5,925,311 queries, passive only; personal data anonymised, then deleted before publication; the authors will keep renewing the domains | ethics appendix, no review body |
| [35Saric, Kevin; Savins, Felix; Ramachandran, Gowri Sankar; Jurdak, Raja; Nepal, Surya (2024): "Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains", in: Proceedings of the ACM Web Conference. (DOI)] | 51 phantom domains plus a control | web-server logs of a blank page; chose not to serve tracking JavaScript | “ethics approval” |
| [49Li, Ruixuan; Xiao, Shaodong; Liu, Baojun; Lin, Yanzhong; Duan, Haixin; Pan, Qingfeng; Chen, Jianjun; Zhang, Jia; Liu, Ximeng; Lu, Xiuqi; Shao, Jun (2024): "Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service Provider", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] | 30 unregistered recipient domains | nothing deployed; the names were offered free of charge to the brand owner | no IRB at the institution; authorised by the partner |
| [6Akiwate, Gautam; Savage, Stefan; Voelker, Geoffrey M.; Claffy, Kimberly C. (2021): "Risky BIZness: risks derived from registrar name management", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] | 5 sacrificial-nameserver domains | observed incoming queries “while being careful to never respond”; logs deleted; one defensive registration | IRB declined jurisdiction; university general counsel approved |
| [40Pauley, Eric; Sheatsley, Ryan; Hoak, Blaine; Burke, Quinn; Beugin, Yohan; McDaniel, Patrick D. (2022): "Measuring and Mitigating the Risk of IP Reuse on Public Clouds", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] | 1.5 million cloud IPs, 101 days | unsolicited traffic, stored encrypted; disclosure through Amazon, then to affected organisations | IRB exemption |
| [44Zhang, Fenglu; Zhang, Yunyi; Liu, Baojun; Alowaisheq, Eihal; Ying, Lingyun; Li, Xiang; Zhang, Zaifeng; Liu, Ying; Duan, Haixin; Zhang, Min (2023): "Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] | undelegated records for 30 domains on hosting providers, including top-100 sites | A → 127.0.0.1 and a TXT record naming the researchers; removed afterwards | ethics discussed |
| [45Zhang, Yunyi; Zhang, Mingming; Liu, Baojun; Liu, Zhan; Zhang, Jia; Duan, Haixin; Zhang, Min; Shi, Fan; Xu, Chengxi (2024): "Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure", in: Proceedings of the USENIX Security Symposium. (Link)] | inactive real domains claimed on hosting providers | a TXT record for under two minutes, then released; query logs checked for real users | Menlo Report cited, no review body |
And the explicit refusals, which are as instructive: Akiwate et al. would not defensively register thousands of at-risk nameserver domains because it “would raise its own ethical issues if we could” [11Akiwate, Gautam; Jonker, Mattijs; Sommese, Raffaele; Foster, Ian D.; Voelker, Geoffrey M.; Savage, Stefan; Claffy, K. C. (2020): "Unresolved Issues: Prevalence, Persistence, and Perils of Lame Delegations", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]; So et al. (2025) and Hortea et al. registered none of the expired domains they found [12So, Johnny; Sanchez-Rola, Iskander; Nikiforakis, Nick (2025): "Lost in the Mists of Time: Expirations in DNS Footprints of Mobile Apps", in: Proceedings of the USENIX Security Symposium. (Link)] [13Hortea, Gabriel; Girish, Aniketh; Vallina-Rodriguez, Narseo; Tapiador, Juan (2026): "Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps", in: Proceedings on Privacy Enhancing Technologies. (DOI)].
The decisions, as the papers expose them:
- Do you need the traffic at all? Several questions — is the name registrable, is it referenced, how much demand does it have — are answerable without receiving anything: registrability checks, passive DNS volumes, cache snooping [39Randall, Audrey; Liu, Enze; Akiwate, Gautam; Padmanabhan, Ramakrishna; Voelker, Geoffrey M.; Savage, Stefan; Schulman, Aaron (2020): "Trufflehunter: Cache Snooping Rare Domains at Large Public DNS Resolvers", in: Proceedings of the ACM Internet Measurement Conference. (DOI)].
- What do you keep? From counts only, through headers and URLs, to full email bodies. The content you receive belongs to people who made a mistake; minimise at collection, not at analysis.
- Do you answer? Answering a query or an HTTP request can change what the sender does next (deliver mail, send credentials, cache a record). Most papers here answered nothing, or a blank page.
- What happens to the name afterwards? The papers disagree here, and the residual-trust literature itself says why it matters: a domain you let lapse goes back to a market where about a tenth of dropped names are caught, often by the actors this page measures. Renewing indefinitely [33Liu, Guannan; Jin, Lin; Hao, Shuai; Zhang, Yubao; Liu, Daiping; Stavrou, Angelos; Wang, Haining (2023): "Dial "N" for NXDomain: The Scale, Origin, and Security Implications of DNS Queries to Non-Existent Domains", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], handing the name to the brand [49Li, Ruixuan; Xiao, Shaodong; Liu, Baojun; Lin, Yanzhong; Duan, Haixin; Pan, Qingfeng; Chen, Jianjun; Zhang, Jia; Liu, Ximeng; Lu, Xiuqi; Shao, Jun (2024): "Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service Provider", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], leaving the affected project to register it after disclosure [37AlHamdan, Abdullah; Staicu, Cristian-Alexandru (2025): "Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its Ecosystem", in: Proceedings of the Network and Distributed System Security Symposium. (Link)], and letting it expire [4So, Johnny; Miramirkhani, Najmeh; Ferdman, Michael; Nikiforakis, Nick (2022): "Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] are all on record. State which you chose and why.
- Who reviewed it? An IRB can say this is not human-subjects research — and then nobody reviews it (two exemptions and one declined jurisdiction among the 19). The counsel route [6Akiwate, Gautam; Savage, Stefan; Voelker, Geoffrey M.; Claffy, Kimberly C. (2021): "Risky BIZness: risks derived from registrar name management", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] is a model when that happens.
Which methods are current
The corpus runs to 2026, but 2025–2026 are its thinnest and provisional years (CCS and IMC 2026 have not been held; IEEE S&P and TheWebConf 2026 are incompletely indexed). The population has 7 papers from 2025 and 2 from 2026. “Current” below means used by a 2022–2026 paper in these seven venues; a judgement about whether you should use a method is marked as one.
| Method | Years in this population | Status | On what evidence |
|---|---|---|---|
| Keyboard-typo generation over a head-of-list target set | 2014–2019, 2025 | current, but judgement: never alone | [2Adjibi, Boladji Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Bailey, Michael; Monrose, Fabian (2025): "The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] combines it with combo, bit, homoglyph and homophone models; typo-only misses the combosquatting population [1Kintis, Panagiotis; Miramirkhani, Najmeh; Lever, Charles; Chen, Yizheng; Gómez, Rosa Romero; Pitropakis, Nikolaos; Nikiforakis, Nick; Antonakakis, Manos (2017): "Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] and the long tail [16Szurdi, Janos; Kocso, Balazs; Cseh, Gabor; Spring, Jonathan; Felegyhazi, Mark; Kanich, Chris (2014): "The Long “Taile” of Typosquatting Domain Names", in: Proceedings of the USENIX Security Symposium. (Link)] |
| Combosquatting by trademark-token matching in DNS data | 2017–2019, 2025 | current | [1Kintis, Panagiotis; Miramirkhani, Najmeh; Lever, Charles; Chen, Yizheng; Gómez, Rosa Romero; Pitropakis, Nikolaos; Nikiforakis, Nick; Antonakakis, Manos (2017): "Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], [2Adjibi, Boladji Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Bailey, Michael; Monrose, Fabian (2025): "The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] |
| Homograph detection via confusables / homoglyph databases | 2018–2021, 2025 | current; confusables data now UTS #39 v18.0.0 | [18Suzuki, Hiroaki; Chiba, Daiki; Yoneya, Yoshiro; Mori, Tatsuya; Goto, Shigeki (2019): "ShamFinder: An Automated Framework for Detecting IDN Homographs", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], [19Hu, Hang; Jan, Steve T.K.; Wang, Yang; Wang, Gang (2021): "Assessing Browser-level Defense against IDN-based Phishing", in: Proceedings of the USENIX Security Symposium. (Link)] |
| Bitsquatting | 2013, 2018, 2025 | current by the rule; judgement: niche, one component of combined generators | [17Nikiforakis, Nick; Van Acker, Steven; Meert, Wannes; Desmet, Lieven; Piessens, Frank; Joosen, Wouter (2013): "Bitsquatting: exploiting bit-flips for fun, or profit?", in: Proceedings of the ACM Web Conference. (DOI)] |
| Parking detection as a research subject | 2014–2015 | historical as a subject; the classifiers survive as a pipeline step | no parking-focused paper since 2015 |
| Live WHOIS for registrant identity | 2014–2026 | current by the rule; superseded on external evidence for post-2018 registrant data (GDPR redaction); port-43 WHOIS no longer required for gTLDs since 2025-01-28 | [15Lu, Chaoyi; Liu, Baojun; Zhang, Yiming; Li, Zhou; Zhang, Fenglu; Duan, Haixin; Liu, Ying; Chen, Joann Qiongna; Liang, Jinjin; Zhang, Zaifeng; Hao, Shuang; Yang, Min (2021): "From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]; use RDAP for dates, status and registrar |
| RDAP | 2018 | judgement: the current instrument; 1 of 48 papers used it | [25Lauinger, Tobias; Buyukkayhan, Ahmet Salih; Chaabane, Abdelberi; Robertson, William K.; Kirda, Engin (2018): "From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] |
| Historical WHOIS products | 2016–2025 | current, for pre-2018 history; sampling undisclosed | 4 of the 9 papers from 2025–2026 |
| Daily zone snapshots (CZDS) | 2010–2026 | current, with the transient-domain gap | [14Sommese, Raffaele; Akiwate, Gautam; Affinito, Antonia; Müller, Moritz; Jonker, Mattijs; Claffy, K. C. (2024): "DarkDNS: Revisiting the Value of Rapid Zone Update", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] |
| Drop / pending-delete lists | 2016–2022 | current for lifecycle work | [5Lauinger, Tobias; Chaabane, Abdelberi; Buyukkayhan, Ahmet Salih; Onarlioglu, Kaan; Robertson, William (2017): "Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers", in: Proceedings of the USENIX Security Symposium. (Link)], [4So, Johnny; Miramirkhani, Najmeh; Ferdman, Michael; Nikiforakis, Nick (2022): "Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] |
| Registering or claiming names and logging what arrives | 2017–2024 | current, and the most ethically exposed method here | [48Szurdi, Janos; Christin, Nicolas (2017): "Email Typosquatting", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], [20Kaleli, Beliz; Kondracki, Brian; Egele, Manuel; Nikiforakis, Nick; Stringhini, Gianluca (2021): "To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media", in: Proceedings of the Network and Distributed System Security Symposium. (Link)], [4So, Johnny; Miramirkhani, Najmeh; Ferdman, Michael; Nikiforakis, Nick (2022): "Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)], [33Liu, Guannan; Jin, Lin; Hao, Shuai; Zhang, Yubao; Liu, Daiping; Stavrou, Angelos; Wang, Haining (2023): "Dial "N" for NXDomain: The Scale, Origin, and Security Implications of DNS Queries to Non-Existent Domains", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], [35Saric, Kevin; Savins, Felix; Ramachandran, Gowri Sankar; Jurdak, Raja; Nepal, Surya (2024): "Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains", in: Proceedings of the ACM Web Conference. (DOI)] |
| Subdomain-takeover fingerprint scanning | 2016 (outside the extraction), 2021, 2025–2026 | current; fingerprint lists need dating | [9Squarcina, Marco; Tempesta, Mauro; Veronese, Lorenzo; Calzavara, Stefano; Maffei, Matteo (2021): "Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern Web", in: Proceedings of the USENIX Security Symposium. (Link)], [13Hortea, Gabriel; Girish, Aniketh; Vallina-Rodriguez, Narseo; Tapiador, Juan (2026): "Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps", in: Proceedings on Privacy Enhancing Technologies. (DOI)] |
| Delegation-level hijack measurement (lame, sacrificial, stale glue, relic, hosting) | 2010, 2020–2025 | current; 7 papers since 2020 | [6Akiwate, Gautam; Savage, Stefan; Voelker, Geoffrey M.; Claffy, Kimberly C. (2021): "Risky BIZness: risks derived from registrar name management", in: Proceedings of the ACM Internet Measurement Conference. (DOI)], [46Zhang, Yunyi; Liu, Baojun; Duan, Haixin; Zhang, Min; Li, Xiang; Shi, Fan; Xu, Chengxi; Alowaisheq, Eihal (2024): "Rethinking the Security Threats of Stale DNS Glue Records", in: Proceedings of the USENIX Security Symposium. (Link)], [47Zhang, Mingming; Zhang, Yunyi; Liu, Baojun; Duan, Haixin; Zhang, Min; Shi, Fan; Xu, Chengxi (2025): "Misty Registry: An Empirical Study of Flawed Domain Registry Operation", in: Proceedings of the USENIX Security Symposium. (Link)] |
| Expired dependencies in apps and code | 2023–2026 | current and growing, often as one section of another paper | [12So, Johnny; Sanchez-Rola, Iskander; Nikiforakis, Nick (2025): "Lost in the Mists of Time: Expirations in DNS Footprints of Mobile Apps", in: Proceedings of the USENIX Security Symposium. (Link)], [13Hortea, Gabriel; Girish, Aniketh; Vallina-Rodriguez, Narseo; Tapiador, Juan (2026): "Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps", in: Proceedings on Privacy Enhancing Technologies. (DOI)] |
| LLM-based squatting detection | none here | emerging outside these venues | 0 of 48; DomainLynx (IEEE Access 2025) |
The lookalike family has no primary paper in these venues from 2022–2024, and two since — defensive registration (2025) and UDRP disputes (2026) — while 14 context papers from 2018–2025 study squatting in packages, containers, apps, voice skills, social handles and blockchain names. The squatting idea is current. The two lookalike papers since 2021 both take the defender's side — defensive registration and disputes — and both sit in the provisional years; what that says about typosquatting of DNS names as a research subject, this corpus cannot tell (see Open questions).
Use in publications
Everything below is a claim about seven venues — CCS, IMC, NDSS, PETS, USENIX Security, TheWebConf and IEEE S&P, 2010–2026, 5,859 extracted papers. DNS-OARC workshops, the APWG eCrime symposium, PAM, TMA, DIMVA, EuroS&P, ACSAC, RAID and AsiaCCS are absent, so a domain-abuse paper missing from these counts may simply be outside the corpus. See Corpus. 2025–2026 are provisional.
The inclusion rule, and its measured precision
Six probes — the 2026-09-22 gap-pass regex, a squatting-vocabulary probe, a lifecycle-and-delegation probe, a parking probe, a registration-data probe at a high threshold, and the extraction's own free-text fields — produce a 149-paper candidate set. Each candidate was read against a rule written before the verdicts were counted:
- IN — the measured objects include DNS names (registered domains, subdomains, or the records and delegations behind them) whose abuse comes from the name or its lifecycle, and the paper counts instances in the wild. A paper about something else is IN when one measured section reports such a count (section); a paper that only mentions the risk is not.
- CONTEXT — squatting in a namespace that is not DNS; a lookalike only as the vehicle of phishing or scams; the registration system itself as the instrument; malicious-domain and DGA detection; hijacking through resolver or registrar-account attacks; search poisoning on misspellings; user studies of lookalike URLs.
- OUT — homonyms (a dangling pointer, homography in computer vision, re-registering an account) or passing mentions.
- Two scope decisions. Email typosquatting is IN: the object is a registered DNS name, only the protocol carrying the mistaken traffic differs [48Szurdi, Janos; Christin, Nicolas (2017): "Email Typosquatting", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. Container-registry and package typosquatting [50Liu, Guannan; Gao, Xing; Wang, Haining; Sun, Kun (2022): "Exploring the Unchartered Space of Container Registry Typosquatting", in: Proceedings of the USENIX Security Symposium. (Link)] [51Neupane, Shradha; Holmes, Grant; Wyss, Elizabeth; Davidson, Drew; De Carli, Lorenzo (2023): "Beyond Typosquatting: An In-depth Look at Package Confusion", in: Proceedings of the USENIX Security Symposium. (Link)] and ENS drop-catching [52Muzammil, Muhammad; Wu, Zhengyu; Balasubramanian, Aruna; Nikiforakis, Nick (2024): "Panning for gold.eth: Understanding and Analyzing ENS Domain Dropcatching", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] are CONTEXT: different registries, with their own naming and expiry rules. A reader could reasonably move ENS in.
| Verdict | Papers of 149 |
|---|---|
| IN — this page's population | 48 (32.2%): 40 primary, 8 section |
| CONTEXT — other namespace 14, malicious-domain detection 8, lookalike as a vehicle 5, registration data 4, DNS attacks 4, a check without a count 3, search poisoning 2, user study 1 | 41 |
| OUT — passing mention 52, homonym 8 | 60 |
How well each probe finds the population:
| Probe | Hits | IN | Precision | Recall of the 48 |
|---|---|---|---|---|
| gap-pass regex, 5 or more hits | 90 | 38 | 42.2% | 79.2% |
| squatting vocabulary, 5 or more | 68 | 22 | 32.4% | 45.8% |
| lifecycle and delegation, 5 or more | 51 | 29 | 56.9% | 60.4% |
| parking, 5 or more | 21 | 10 | 47.6% | 20.8% |
| registration data, 30 or more | 45 | 20 | 44.4% | 41.7% |
| extraction free text | 67 | 36 | 53.7% | 75.0% |
The gap pass chose this page on 85 papers (47 web, 25 from 2024–2026). The regex re-runs to exactly those numbers on paper.norm.txt; over whitespace-collapsed paper.cols.txt it hits 90. It misses 10 of the 48 — the name-collision and delegation-hijack papers, which use its terms fewer than five times, and half of the section-level papers. Of its 27 hits from 2024–2026, 11 are in the population; 8 mention the terms in passing, 4 are squatting in other namespaces and 4 are other context.
Three on-topic papers were selected for the corpus but never retrieved — their full-text directories are empty — and so are not counted anywhere on this page: All Your DNS Records Point to Us (CCS 2016) [10Liu, Daiping; Hao, Shuai; Wang, Haining (2016): "All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS Records", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], The Wolf of Name Street (CCS 2017) [42Vissers, Thomas; Barron, Timothy; Van Goethem, Tom; Joosen, Wouter; Nikiforakis, Nick (2017): "The Wolf of Name Street: Hijacking Domains Through Their Nameservers", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], and Alias Equals Zone? (USENIX Security 2026). The first two are cited above from the authors' copies.
When, where, and which family
| Years | IN | Lookalike | Parking | Residual | Dangling |
|---|---|---|---|---|---|
| 2010–2013 | 2 | 1 | 0 | 0 | 1 |
| 2014–2017 | 13 | 5 | 3 | 5 | 0 |
| 2018–2021 | 13 | 6 | 0 | 3 | 4 |
| 2022–2024 | 11 | 0 | 0 | 6 | 5 |
| 2025–2026* | 9 | 2 | 0 | 5 | 2 |
*provisional. Counts include section-level papers (8: one lookalike 2020, five residual 2023–2025, two dangling 2024–2025). By venue: IMC 15, NDSS 10, USENIX Security 9, CCS 5, IEEE S&P 5, TheWebConf 3, PETS 1. 24 of the 48 include the web platform and 18 ran a crawl by the corpus definition — much of this literature measures the DNS, not pages.
What the 48 papers did
Hand-coded from structured reading notes on each paper's full text; the codes and their quotes are on the provenance page. A paper can have several values.
| Question | Answer, papers of 48 |
|---|---|
| Generator | none, names came from records, traffic or apps 37; keyboard typos 8; homoglyphs 5; combosquatting 4; a named tool 4; bit flips 3; homophones 1; user-error names 1 |
| Name and registration sources | WHOIS 31; zone files 20; top list as targets 18; passive DNS 11; active DNS 11; web crawl or corpus 8; CT 6; threat feeds 6; drop lists 5; traffic logs 4; app code or traffic 4; registry data 3; RDAP 1 |
| WHOIS | live 25; historical product 10; RDAP 1; not used 17 |
| Labelling | rules 36; manual 32; blocklist or VirusTotal 13; trained classifier 7; vendor categoriser 6; LLM 0 |
| Registered or claimed names | 19 (registered 15, claimed third-party resources 6) |
| Notified someone | 24; no notification stated 12; nothing to notify 12 |
| Longitudinal | 35; one window 13 |
| Ethics review, as stated | ethics section without a review body 21; nothing 16; IRB approval 4; exemption 3; non-IRB body 3; not required 1 |
| Released code or data | public 14; promised 2; on request 2; none mentioned 30 |
Ethics statements changed with the decade: 12 of the 17 papers from 2015–2019 say nothing about ethics, against 1 of the 27 from 2020–2026. The review body did not follow: 18 of those 27 have an ethics section and no review.
Methodology and limitations of these figures
Every corpus number is a count of papers, from the 5,859-paper extraction, with its denominator named. The 48 is a hand verdict over a 149-paper candidate set; the report script exits if the candidates and the verdicts diverge in either direction. The method table is a hand coding of those 48 by the author of this page from structured reading notes written by four sub-agents with verbatim quotes, not double-coded; 84.7% of the notes' quotes were located mechanically in the papers, most misses being column splices or the notes' own elisions. Treat single-paper differences as soft. The source-family counts in the sources table are hand-coded; the CZDS and RDAP counts in the paragraph under it come from the extraction's own source fields and are corpus-wide. Full-text probes read paper.cols.txt (4 of 5,859 papers have none). Per-paper figures on this page were checked against the papers' text, not the extraction's summaries. The probes, the verdict list with a reason per paper, the codes, the unedited report output and the external checks are on domain_abuse; corpus-wide caveats are on Corpus.
What to report
- Target list and generator. Which names you imitated (list, rank cut, date) and which permutation families you generated, with the tool and release or your own rules published. Say which families you did not generate.
- Registration source and its date. Zone snapshot (which TLDs, which days), CT, passive DNS (vendor, window), and the sentence that says what that source cannot see — at least the transient-domain gap and the ccTLDs you could not cover.
- Registration data. RDAP or WHOIS, live or historical (which product), and how many records were redacted or missing. Do not treat a redacted registrant as “unknown owner” in a defensive-registration rule.
- Registered is not abused. Report the funnel: generated → registered → resolving → classified, with counts at each step and the parked, for-sale and defensive shares, not only the malicious one.
- How you labelled, and on how many by hand. Rules, classifier, blocklist (which, queried when), and the manual sample with its agreement.
- For lifecycle work, the clock. Timestamps at the resolution of the phenomenon (seconds for drop-catching), the registry's own deletion data if you have it, and right-censoring: what share was still live, or still unregistered, when you stopped.
- For dangling records, candidates versus confirmations. Fingerprint matches and confirmed claims as separate numbers, with the fingerprint list and its date.
- Anything you registered or claimed. How many names, for how long, what you collected, whether you answered, what happened to the names afterwards, and who reviewed it.
If you take one thing off this page into a measurement: log, per candidate name, the generator family that produced it, the source and date that showed it registered, the RDAP status and registrar on that date, whether it resolves and what it serves (parked, redirect with or without an affiliate parameter, content, error), and the evidence for or against a defensive registration. Those columns let a later reader rebuild your population with a different generator, date your registration claim, and separate squats from the brand's own names.
Open questions
- RDAP-era registrant evidence. No paper in these venues has measured what fraction of defensive-registration or ownership inferences still work with post-2025 registration data. The 2018 redaction was measured [15Lu, Chaoyi; Liu, Baojun; Zhang, Yiming; Li, Zhou; Zhang, Fenglu; Duan, Haixin; Liu, Ying; Chen, Joann Qiongna; Liang, Jinjin; Zhang, Zaifeng; Hao, Shuang; Yang, Min (2021): "From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]; the 2025 policy and the WHOIS sunset have not been.
- ccTLD coverage. Almost every lookalike count here is a gTLD count. How much squatting sits in ccTLDs with closed zones is unmeasured in this population.
- Typosquatting of DNS names since 2021. No primary lookalike paper in 2022–2024, then a defensive-registration and a dispute study. Whether squatting volume fell, moved to other namespaces, or simply stopped being publishable, this corpus cannot say.
- LLM-hallucinated domains. Measured for package names outside these venues; not yet for domain names in them.
- What happens to research-registered names. None of the 48 follows up on the names an earlier study let expire.
- The review gap. 18 of 27 papers since 2020 have an ethics section and no review body. Whether that is because boards declined or because nobody asked is not recorded.
Related pages
- Security — namespace outline.
- DNS — resolution measurement, resolvers, and DNS as an instrument.
- Phishing — what a lookalike is used for, feeds and cloaking.
- Online scams — fake shops and other scam sites, often on disposable names.
- TLS certificates — Certificate Transparency as a data source.
- Ownership resolution — what a registrant field can and cannot tell you.
- VirusTotal — what a “detected” label is.
- Ethics and Notifying websites — review and disclosure.
- Website selection — target lists.
- [1]
- Kintis, Panagiotis; Miramirkhani, Najmeh; Lever, Charles; Chen, Yizheng; Gómez, Rosa Romero; Pitropakis, Nikolaos; Nikiforakis, Nick; Antonakakis, Manos (2017): "Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
- [2]
- Adjibi, Boladji Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Bailey, Michael; Monrose, Fabian (2025): "The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
- [3]
- Agten, Pieter; Joosen, Wouter; Piessens, Frank; Nikiforakis, Nick (2015): "Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
- [4]
- So, Johnny; Miramirkhani, Najmeh; Ferdman, Michael; Nikiforakis, Nick (2022): "Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
- [5]
- Lauinger, Tobias; Chaabane, Abdelberi; Buyukkayhan, Ahmet Salih; Onarlioglu, Kaan; Robertson, William (2017): "Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers", in: Proceedings of the USENIX Security Symposium. (Link)
- [6]
- Akiwate, Gautam; Savage, Stefan; Voelker, Geoffrey M.; Claffy, Kimberly C. (2021): "Risky BIZness: risks derived from registrar name management", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [7]
- Vissers, Thomas; Joosen, Wouter; Nikiforakis, Nick (2015): "Parking Sensors: Analyzing and Detecting Parked Domains", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
- [8]
- Miramirkhani, Najmeh; Barron, Timothy; Ferdman, Michael; Nikiforakis, Nick (2018): "Panning for gold.com: Understanding the Dynamics of Domain Dropcatching", in: Proceedings of the ACM Web Conference. (DOI)
- [9]
- Squarcina, Marco; Tempesta, Mauro; Veronese, Lorenzo; Calzavara, Stefano; Maffei, Matteo (2021): "Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern Web", in: Proceedings of the USENIX Security Symposium. (Link)
- [10]
- Liu, Daiping; Hao, Shuai; Wang, Haining (2016): "All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS Records", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
- [11]
- Akiwate, Gautam; Jonker, Mattijs; Sommese, Raffaele; Foster, Ian D.; Voelker, Geoffrey M.; Savage, Stefan; Claffy, K. C. (2020): "Unresolved Issues: Prevalence, Persistence, and Perils of Lame Delegations", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [12]
- So, Johnny; Sanchez-Rola, Iskander; Nikiforakis, Nick (2025): "Lost in the Mists of Time: Expirations in DNS Footprints of Mobile Apps", in: Proceedings of the USENIX Security Symposium. (Link)
- [13]
- Hortea, Gabriel; Girish, Aniketh; Vallina-Rodriguez, Narseo; Tapiador, Juan (2026): "Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps", in: Proceedings on Privacy Enhancing Technologies. (DOI)
- [14]
- Sommese, Raffaele; Akiwate, Gautam; Affinito, Antonia; Müller, Moritz; Jonker, Mattijs; Claffy, K. C. (2024): "DarkDNS: Revisiting the Value of Rapid Zone Update", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [15]
- Lu, Chaoyi; Liu, Baojun; Zhang, Yiming; Li, Zhou; Zhang, Fenglu; Duan, Haixin; Liu, Ying; Chen, Joann Qiongna; Liang, Jinjin; Zhang, Zaifeng; Hao, Shuang; Yang, Min (2021): "From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
- [16]
- Szurdi, Janos; Kocso, Balazs; Cseh, Gabor; Spring, Jonathan; Felegyhazi, Mark; Kanich, Chris (2014): "The Long “Taile” of Typosquatting Domain Names", in: Proceedings of the USENIX Security Symposium. (Link)
- [17]
- Nikiforakis, Nick; Van Acker, Steven; Meert, Wannes; Desmet, Lieven; Piessens, Frank; Joosen, Wouter (2013): "Bitsquatting: exploiting bit-flips for fun, or profit?", in: Proceedings of the ACM Web Conference. (DOI)
- [18]
- Suzuki, Hiroaki; Chiba, Daiki; Yoneya, Yoshiro; Mori, Tatsuya; Goto, Shigeki (2019): "ShamFinder: An Automated Framework for Detecting IDN Homographs", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [19]
- Hu, Hang; Jan, Steve T.K.; Wang, Yang; Wang, Gang (2021): "Assessing Browser-level Defense against IDN-based Phishing", in: Proceedings of the USENIX Security Symposium. (Link)
- [20]
- Kaleli, Beliz; Kondracki, Brian; Egele, Manuel; Nikiforakis, Nick; Stringhini, Gianluca (2021): "To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
- [21]
- Roberts, Richard; Goldschlag, Yaelle; Walter, Rachel; Chung, Taejoong; Mislove, Alan; Levin, Dave (2019): "You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS Certificates", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
- [22]
- Tian, Ke; Jan, Steve T. K.; Hu, Hang; Yao, Danfeng; Wang, Gang (2018): "Needle in a Haystack: Tracking Down Elite Phishing Domains in the Wild", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [23]
- Adjibi, Vinny; Avgetidis, Athanasios; Antonakakis, Manos; Dainotti, Alberto; Bailey, Michael; Monrose, Fabian (2026): "Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century’s Worth of Squabbles", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
- [24]
- Liu, Suqi; Foster, Ian D.; Savage, Stefan; Voelker, Geoffrey M.; Saul, Lawrence K. (2015): "Who is .com?: Learning to Parse WHOIS Records", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [25]
- Lauinger, Tobias; Buyukkayhan, Ahmet Salih; Chaabane, Abdelberi; Robertson, William K.; Kirda, Engin (2018): "From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [26]
- Lauinger, Tobias; Onarlioglu, Kaan; Chaabane, Abdelberi; Robertson, William; Kirda, Engin (2016): "WHOIS Lost in Translation: (Mis)Understanding Domain Name Expiration and Re-Registration", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [27]
- Halvorson, Tristan; Der, Matthew F.; Foster, Ian D.; Savage, Stefan; Saul, Lawrence K.; Voelker, Geoffrey M. (2015): "From .academy to .zone: An Analysis of the New TLD Land Rush", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [28]
- Alrwais, Sumayah; Yuan, Kan; Alowaisheq, Eihal; Li, Zhou; Wang, XiaoFeng (2014): "Understanding the Dark Side of Domain Parking", in: Proceedings of the USENIX Security Symposium. (Link)
- [29]
- Khan, Mohammad Taha; Huo, Xiang; Li, Zhou; Kanich, Chris (2015): "Every Second Counts: Quantifying the Negative Externalities of Cybercrime via Typosquatting", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
- [30]
- Lever, Chaz; Walls, Robert J.; Nadji, Yacin; Dagon, David; McDaniel, Patrick D.; Antonakakis, Manos (2016): "Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in Domains", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
- [31]
- Alowaisheq, Eihal; Wang, Peng; Alrwais, Sumayah; Liao, Xiaojing; Wang, XiaoFeng; Alowaisheq, Tasneem; Mi, Xianghang; Tang, Siyuan; Liu, Baojun (2019): "Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downs", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
- [32]
- Ma, Zane; Faulkenberry, Aaron; Papastergiou, Thomas; Durumeric, Zakir; Bailey, Michael D.; Keromytis, Angelos D.; Monrose, Fabian; Antonakakis, Manos (2023): "Stale TLS Certificates: Investigating Precarious Third-Party Access to Valid TLS Keys", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [33]
- Liu, Guannan; Jin, Lin; Hao, Shuai; Zhang, Yubao; Liu, Daiping; Stavrou, Angelos; Wang, Haining (2023): "Dial "N" for NXDomain: The Scale, Origin, and Security Implications of DNS Queries to Non-Existent Domains", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [34]
- Chen, Qi Alfred; Osterweil, Eric; Thomas, Matthew; Mao, Zhuoqing Morley (2016): "MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
- [35]
- Saric, Kevin; Savins, Felix; Ramachandran, Gowri Sankar; Jurdak, Raja; Nepal, Surya (2024): "Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains", in: Proceedings of the ACM Web Conference. (DOI)
- [36]
- Schmidt, David; Tagliaro, Carlotta; Borgolte, Kevin; Lindorfer, Martina (2023): "IoTFlow: Inferring IoT Device Behavior at Scale through Static Mobile Companion App Analysis", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
- [37]
- AlHamdan, Abdullah; Staicu, Cristian-Alexandru (2025): "Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its Ecosystem", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
- [38]
- Wen, Shushang; Zhang, Yiming; Shen, Yuxiang; Li, Bingyu; Duan, Haixin; Lin, Jingqiang (2025): "Automatic Insecurity: Exploring Email Auto-configuration in the Wild", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
- [39]
- Randall, Audrey; Liu, Enze; Akiwate, Gautam; Padmanabhan, Ramakrishna; Voelker, Geoffrey M.; Savage, Stefan; Schulman, Aaron (2020): "Trufflehunter: Cache Snooping Rare Domains at Large Public DNS Resolvers", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [40]
- Pauley, Eric; Sheatsley, Ryan; Hoak, Blaine; Burke, Quinn; Beugin, Yohan; McDaniel, Patrick D. (2022): "Measuring and Mitigating the Risk of IP Reuse on Public Clouds", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
- [41]
- Kalafut, Andrew J.; Gupta, Minaxi; Cole, Christopher A.; Chen, Lei; Myers, Nathan E. (2010): "An empirical study of orphan DNS servers in the internet", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [42]
- Vissers, Thomas; Barron, Timothy; Van Goethem, Tom; Joosen, Wouter; Nikiforakis, Nick (2017): "The Wolf of Name Street: Hijacking Domains Through Their Nameservers", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
- [43]
- Alowaisheq, Eihal; Tang, Siyuan; Wang, Zhihao; Alharbi, Fatemah; Liao, Xiaojing; Wang, XiaoFeng (2020): "Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting Referral", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
- [44]
- Zhang, Fenglu; Zhang, Yunyi; Liu, Baojun; Alowaisheq, Eihal; Ying, Lingyun; Li, Xiang; Zhang, Zaifeng; Liu, Ying; Duan, Haixin; Zhang, Min (2023): "Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [45]
- Zhang, Yunyi; Zhang, Mingming; Liu, Baojun; Liu, Zhan; Zhang, Jia; Duan, Haixin; Zhang, Min; Shi, Fan; Xu, Chengxi (2024): "Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure", in: Proceedings of the USENIX Security Symposium. (Link)
- [46]
- Zhang, Yunyi; Liu, Baojun; Duan, Haixin; Zhang, Min; Li, Xiang; Shi, Fan; Xu, Chengxi; Alowaisheq, Eihal (2024): "Rethinking the Security Threats of Stale DNS Glue Records", in: Proceedings of the USENIX Security Symposium. (Link)
- [47]
- Zhang, Mingming; Zhang, Yunyi; Liu, Baojun; Duan, Haixin; Zhang, Min; Shi, Fan; Xu, Chengxi (2025): "Misty Registry: An Empirical Study of Flawed Domain Registry Operation", in: Proceedings of the USENIX Security Symposium. (Link)
- [48]
- Szurdi, Janos; Christin, Nicolas (2017): "Email Typosquatting", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [49]
- Li, Ruixuan; Xiao, Shaodong; Liu, Baojun; Lin, Yanzhong; Duan, Haixin; Pan, Qingfeng; Chen, Jianjun; Zhang, Jia; Liu, Ximeng; Lu, Xiuqi; Shao, Jun (2024): "Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service Provider", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
- [50]
- Liu, Guannan; Gao, Xing; Wang, Haining; Sun, Kun (2022): "Exploring the Unchartered Space of Container Registry Typosquatting", in: Proceedings of the USENIX Security Symposium. (Link)
- [51]
- Neupane, Shradha; Holmes, Grant; Wyss, Elizabeth; Davidson, Drew; De Carli, Lorenzo (2023): "Beyond Typosquatting: An In-depth Look at Package Confusion", in: Proceedings of the USENIX Security Symposium. (Link)
- [52]
- Muzammil, Muhammad; Wu, Zhengyu; Balasubramanian, Aruna; Nikiforakis, Nick (2024): "Panning for gold.eth: Understanding and Analyzing ENS Domain Dropcatching", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
docs/idn.md, step “If the skeleton of the registrable part of a hostname is identical to one of the top domains…” — https://chromium.googlesource.com/chromium/src/+/main/docs/idn.md, checked 2026-09-25.https://www.verisign.com/resources/zone-file/: “The TLD zone files do not contain domain names in the following states: serverHold, clientHold, pendingDelete, and redemptionPeriod. In addition, they do not contain domain names that are not associated with name servers.” The same page directs requests for the .com, .net and .name zones to CZDS. Fetched 2026-09-25.https://newly-registered-domains.whoisxmlapi.com/, fetched 2026-09-25. A vendor's own description, not an audited coverage figure.https://www.icann.org/en/announcements/details/icann-update-launching-rdap-sunsetting-whois-27-01-2025-en — fetched 2026-09-25.https://www.icann.org/en/blogs/details/rdrs-extended-as-icann-seeks-community-input-on-next-steps-20-11-2025-en — fetched 2026-09-25.https://www.wipo.int/amc/en/domains/news/2026/news_0001.html — fetched 2026-09-25.projectdiscovery/nuclei-templates, directory http/takeovers/, 73 templates, one of them godaddy-parked-domain.yaml — listed via the GitHub API on 2026-09-25..com Registry Agreement Appendix 7 §3.3.2 (“The current length of this Pending Delete Period is five calendar days”) — both fetched 2026-09-25.https://learn.microsoft.com/en-us/azure/security/fundamentals/subdomain-takeover, page dated 2026-07-20, fetched 2026-09-25.