Cloudflare identifies high-risk top-level domains, with .motorcycles ranking No. 1 among the most abused TLDs.
The domain name system has evolved significantly since its inception. What started out as just a handful of generic top-level domains with .com, .net and .org has expanded to more than 1,400 valid TLDs as of October 2025. Another expansion round is scheduled to begin in April 2026. This growth has made understanding TLD usage patterns and security risks critical for network operators and security teams.
This week, Cloudflare debuted new insights into the state of TLDs, via its Radar platform. The service aggregates data from multiple sources including Cloudflare’s 1.1.1.1 public DNS resolver, email security service and certificate transparency logs. The analysis reveals some unexpected findings:
- The Soviet-era .su TLD ranks No. 1 in DNS visibility, driven primarily by queries from a popular online game.
- Some niche TLDs show malicious email rates exceeding 94%, with .motorcycles leading at 94.7%.
- Despite 1,400+ available TLDs, .com still accounts for over 60% of all DNS queries.
- The AI-focused .ai TLD shows lower adoption than expected given the proliferation of AI companies.
- The .dev TLD ranks No. 7 in DNS visibility.
“One of the biggest surprises was .dev ranking quite so high in the Magnitude rankings and the pre-certificate distribution,” David Belson, head of data insight at Cloudflare, told Network World. “As a developer-targeted domain, my assumption was that usage would be more limited. Similarly, with the explosion of AI-focused companies and AI platforms, I expected that .ai would have had a higher Magnitude ranking, with more widespread usage.”
DNS Magnitude: A new metric for TLD visibility
The Cloudflare Radar TLD report uses the DNS Magnitude ranking system, a metric originally developed by registry authority nic.at. It measures a TLD’s reach across the internet rather than simple query volume. The calculation considers how many unique networks (aggregated client IP subnets) send queries for domains under each TLD. The result is a score from 0 to 10.
This approach provides more accurate visibility data than raw query counts. A small number of sources can generate disproportionately large query volumes. Higher magnitude values indicate broader global visibility.
| TLD | Manager | Magnitude |
| .su | Russian Institute for Development of Public Networks (ROSNIIR) | 9.704 |
| .com | VeriSign Global Registry Services | 9.655 |
| net | VeriSign Global Registry Services | 9.539 |
| .org | Public Interest Registry (PIR) | 9.313 |
| .io | Internet Computer Bureau Limited | 9.278 |
The appearance of .su at the top of the magnitude rankings caught researchers off guard. Originally delegated to the Soviet Union in 1990, the TLD has persisted despite the USSR’s dissolution in 1991. ICANN reportedly plans to retire it in 2030.
Analysis shows that .su doesn’t rank the highest on any single day by unique networks. However, over longer periods (such as seven days), it sees queries from more unique networks than other TLDs. The top hostnames within .su are associated with a popular online world-building game. Over half of queries for that TLD come from the United States, Germany and Brazil.
Email security: Identifying high-risk TLDs
The most immediately actionable data for security teams comes from Cloudflare’s email security analysis. The service identifies TLDs with the highest percentages of malicious and spam messages. The data is based on analysis of the From: header in email messages processed by Cloudflare’s cloud email security service.
Several TLDs show malicious rates above 90%. The .motorcycles TLD leads at 94.7%. This means that 94.7% of all email from that TLD processed by the service was identified as malicious or spam.
“From an email security perspective, our list of the most abused TLDs can certainly be used as an input to decisions about domains or TLDs to block,” Belson explained. “As part of the normal course of business, do you expect to be getting many emails from customers or partners in a .motorcycles or .zw domain? If not, then there’s probably a low risk of blocking something important.”
He added that TLD operators and managers should also monitor the data for their own operations. “TLD operators/managers may want to keep an eye on the query volume graph and geographical distribution table,” Belson said. “Seeing anomalies in those metrics could indicate potential abuse.”
Certificate transparency and anomaly detection
Each TLD page in Cloudflare Radar includes certificate transparency (CT) data. The information shows TLS/SSL certificate issuance volume and the distribution among certificate authorities (CAs). Pre-certificates serve as a proxy for actual certificate deployment.
“A pre-certificate is a special type of certificate used in CT that allows a CA to publicly log a certificate before it is officially issued,” Belson explained. “CAs are not required to log full certificates if corresponding pre-certificates have already been logged, although many CAs do anyway, so typically there are more pre-certificates logged than full certificates.”
Beyond understanding certificate logging mechanics, this data has practical security applications.
“The distribution we show at https://radar.cloudflare.com/certificate-transparency#certificate-tld-distribution can be useful to track potential malicious activity,” Belson noted. “For example, anomalous growth in a given TLD could indicate a large number of certificates being issued in association with a domain-generation algorithm, with those domains being used in a phishing or malicious redirection campaign.”
The persistent dominance of .com
Despite the availability of over 1,400 TLDs, .com continues to dominate. It accounts for more than 60% of DNS queries. Domain count statistics tell a similar story.
“Domain count statistics suggest that .com has nearly an order of magnitude more registered domains than the next most populous TLD,” Belson said. “Given that, it would make sense that .com tops both the DNS Magnitude list and the top pre-certificate TLDs.”
The reasons for this dominance are multifaceted. Belson noted that many of the new TLDs over the years have struggled to gain traction. Sometimes it’s because those new TLDs have notably higher pricing. Another possible reason cited by Belson is because internet users have just become conditioned to treat .com as a default.
The impact on internet infrastructure
Understanding the usage of different TLDs can be useful for organizations and network operators alike.
Belson noted that most domain registrars simply register domains, without providing any additional context. Cloudflare does have its own registrar business and the new service could help to raise some awareness, though the impact extends to all internet users. He added that the service can provide potential domain registrants with additional information about the neighborhood they are about to move into, so to speak – will they be joining a well-known, well-used TLD, or less well-known, less “safe” TLD?
“The decision can impact the perception of their domain, and can potentially impact things like email deliverability,” Belson said. “In addition, much as we do with other Cloudflare data sets, publishing this information can help bring additional transparency to potential abuse and attacks that may otherwise be harder to observe.”
The data is available now at radar.cloudflare.com/tlds. Additional DNS and certificate transparency insights are accessible through the platform’s DNS and security sections




