Skip to main content
DNS Checker(beta)

Nameservers on Risky TLDs

347,428 domains using nameservers on high-abuse TLDs

Analysis by Ishan Karunaratne · Data from 2026-10-09

Domains Affected

347,428

Risky TLDs in Use

15

% of Dataset

0.113%

Rows appear here because of the TLD a nameserver sits on, not because of any abuse finding against the nameserver operator. Several of the largest entries are well-run hosting and site-builder platforms that happen to run their nameservers on one of these extensions. Read this as infrastructure-risk exposure, not as an accusation.

Exposure by Nameserver TLD

Nameserver TLDDomains Served
.site103,318
.top91,534
.xyz45,326
.online28,148
.click21,462
.club18,650
.pw10,127
.icu7,728
.monster7,384
.buzz5,270
.space4,978
.quest2,370
.fun1,093
.rest210
.surf164

Largest Nameservers on These TLDs

Nameserver HostnameDomains Served
ns1.cargo.site82,846
ns2.cargo.site82,828
dns4.51dns.top10,874
dns8.51dns.top7,512
ns1.rankfaster.top6,325
ns2.rankfaster.top6,325
dns2.51dns.top5,636
ns1.dnsservice.xyz4,908
ns2.dnsservice.xyz4,908
ns2.vigbo.site4,722
ns1.vigbo.site4,720
parking2.gen.xyz3,966
parking1.gen.xyz3,965
ns1.hostperfy.xyz3,616
ns2.hostperfy.xyz3,615
ns1.rvfghjkyde.top3,377
ns2.rvfghjkyde.top3,372
ns1.doma.xyz2,815
ns2.doma.xyz2,814
dns6.51dns.top2,405
ns1.432565985.xyz2,347
ns2.432565985.xyz2,347
ns2.hostycare.online2,346
ns1.hostycare.online2,345
ns2.ghgrt-yubvd.top2,335
ns1.ghgrt-yubvd.top2,325
ns1.viviropada.club2,184
ns2.viviropada.club2,184
ns1.quickened.online2,112
ns2.quickened.online2,111
ns1.bylonferka.club1,997
ns2.bylonferka.club1,997
ns1.vdfrtyuidcde.top1,974
ns2.vdfrtyuidcde.top1,974
ns1.hiddenstate.xyz1,902
ns2.hiddenstate.xyz1,902
ns1.vlanekstd.click1,854
ns1.ecadtpldfre.top1,796
ns2.ecadtpldfre.top1,796
ns2.klanekreans.click1,790
ns1.liderdns001.club1,705
ns2.liderdns001.club1,705
ns1.onezonedns11.club1,502
ns2.onezonedns11.club1,502
ns1.gqadgyicnd.top1,441
ns2.gqadgyicnd.top1,429
ns1.domaindnscontrol32.club1,418
ns2.domaindnscontrol32.club1,418
ns2.51dns.top1,403
ns1.4soulmates.online1,373

Per-hostname figures count NS-record occurrences, so a domain listing two nameservers from the same operator appears against each of them.

What Are Nameservers on Risky TLDs?

Some domains use nameservers hosted on top-level domains that are associated with higher rates of abuse, spam, or malicious activity. These “risky TLDs” are extensions where domain registration is cheap, verification is minimal, and abuse complaint handling may be slow — making them attractive to bad actors and creating a higher risk of domain lapse or suspension.

When a domain’s authoritative nameservers are hosted on a risky TLD, the domain inherits additional risk: the nameserver domain is more likely to lapse (due to low renewal rates), be suspended (due to abuse complaints), or be re-registered by a malicious actor (enabling a nameserver takeover attack). This is analogous to building critical infrastructure on unstable ground.

DNS Checker identifies nameserver domains hosted on TLDs that appear on multiple abuse tracking lists, have disproportionately high abuse-to-registration ratios, or are frequently associated with spam, phishing, and malware campaigns. The goal is not to flag all domains on these TLDs as malicious, but to highlight the elevated infrastructure risk of hosting authoritative nameservers on them.

How DNS Checker Identifies Nameservers on Risky TLDs

The detection pipeline extracts nameserver hostnames from zone files and reads the TLD of each nameserver domain. Those TLDs are matched against a maintained list of extensions repeatedly identified in industry abuse reporting as carrying elevated abuse-to-registration ratios. The list is a fixed input, reviewed and updated by hand — this analysis does not compute per-TLD abuse scores or query blocklist feeds at run time, and a TLD's presence on the list says nothing about any individual nameserver on it.

Nameservers on listed TLDs are reported with the number of domains they serve, so domain owners and registry operators can gauge the scale of exposure. The point of interest is cross-TLD dependency: a .com domain whose nameservers sit on one of these extensions inherits that extension's registration and suspension dynamics.

How to Mitigate Risky TLD Nameserver Exposure

  1. Host your authoritative nameservers on well-established, reputable TLDs such as .com, .net, or .org. These TLDs have mature abuse handling processes and stable registration ecosystems.
  2. If you use a DNS hosting provider, verify that their nameserver domains are on reputable TLDs. Most major providers (Cloudflare, AWS, Google, Akamai) use .com or .net for their nameserver infrastructure.
  3. Avoid using cheap or promotional TLD domains for DNS infrastructure. The low cost that makes these TLDs attractive for domain speculation also makes them attractive to bad actors.
  4. Monitor the registration status of your nameserver domains. Set up WHOIS monitoring to alert you if a nameserver domain approaches expiration or changes ownership.

Frequently Asked Questions

Which TLDs are considered risky for nameservers?

TLDs with high abuse-to-registration ratios, low-cost bulk registrations, and slow abuse complaint handling are considered higher risk. Specific TLDs change over time as registries improve or degrade their abuse mitigation, so the list here is maintained by hand against published industry abuse reporting rather than pulled live from a feed. Being on the list is a statement about the extension, not about any nameserver operator using it.

Does using a nameserver on a risky TLD mean my domain is compromised?

No. Having a nameserver on a risky TLD does not mean your domain is compromised — it means your DNS infrastructure has an elevated risk profile. The nameserver domain is more likely to lapse, be suspended, or be targeted by bad actors. It’s a proactive risk indicator, not evidence of active compromise.

Why would anyone host nameservers on a risky TLD?

Common reasons include: legacy configurations from when the TLD was less associated with abuse, cost optimization (cheap TLDs for NS domains), geographic preference (ccTLDs in certain regions), or simply lack of awareness about the risk. Some small DNS providers also register nameserver domains on cheaper TLDs to reduce operational costs.

Related Tools

Data updated daily. Last snapshot: October 9, 2026