Nameservers on Risky TLDs
338,980 domains using nameservers on high-abuse TLDs
Analysis by Ishan Karunaratne · Data from 2026-08-24
Domains Affected
338,980
Risky TLDs in Use
15
% of Dataset
0.115%
Rows appear here because of the TLD a nameserver sits on, not because of any abuse finding against the nameserver operator. Several of the largest entries are well-run hosting and site-builder platforms that happen to run their nameservers on one of these extensions. Read this as infrastructure-risk exposure, not as an accusation.
Exposure by Nameserver TLD
Largest Nameservers on These TLDs
| Nameserver Hostname | Domains Served |
|---|---|
| ns1.cargo.site | 82,023 |
| ns2.cargo.site | 82,002 |
| dns4.51dns.top | 11,124 |
| dns8.51dns.top | 7,718 |
| ns1.rankfaster.top | 6,328 |
| ns2.rankfaster.top | 6,328 |
| dns2.51dns.top | 5,142 |
| ns1.dnsservice.xyz | 4,909 |
| ns2.dnsservice.xyz | 4,909 |
| ns2.vigbo.site | 4,712 |
| ns1.vigbo.site | 4,709 |
| ns1.hostperfy.xyz | 3,776 |
| ns2.hostperfy.xyz | 3,774 |
| parking1.gen.xyz | 3,675 |
| parking2.gen.xyz | 3,675 |
| ns1.rvfghjkyde.top | 3,398 |
| ns2.rvfghjkyde.top | 3,393 |
| ns1.doma.xyz | 2,636 |
| ns2.doma.xyz | 2,635 |
| dns6.51dns.top | 2,433 |
| ns2.ghgrt-yubvd.top | 2,350 |
| ns1.432565985.xyz | 2,349 |
| ns2.432565985.xyz | 2,349 |
| ns1.ghgrt-yubvd.top | 2,335 |
| ns1.quickened.online | 2,128 |
| ns2.quickened.online | 2,127 |
| ns1.vdfrtyuidcde.top | 1,992 |
| ns2.vdfrtyuidcde.top | 1,992 |
| ns1.hiddenstate.xyz | 1,931 |
| ns2.hiddenstate.xyz | 1,931 |
| ns1.gqadgyicnd.top | 1,870 |
| ns2.gqadgyicnd.top | 1,853 |
| ns1.ecadtpldfre.top | 1,798 |
| ns2.ecadtpldfre.top | 1,798 |
| ns1.hostycare.online | 1,641 |
| ns2.hostycare.online | 1,638 |
| ns2.51dns.top | 1,457 |
| ns1.newpbn2026.buzz | 1,429 |
| ns2.newpbn2026.buzz | 1,429 |
| ns1.4soulmates.online | 1,373 |
| ns2.4soulmates.online | 1,373 |
| ns1.catch.club | 1,178 |
| ns2.catch.club | 1,178 |
| ns1.herohosty.xyz | 1,172 |
| ns2.herohosty.xyz | 1,171 |
| ns1.viviropada.club | 1,065 |
| ns2.viviropada.club | 1,065 |
| ns1.1serveer.top | 1,040 |
| ns2.1serveer.top | 1,040 |
| rpd.ns2.icemaildns.com.deleted-ns.pw | 1,031 |
Per-hostname figures count NS-record occurrences, so a domain listing two nameservers from the same operator appears against each of them.
What Are Nameservers on Risky TLDs?
Some domains use nameservers hosted on top-level domains that are associated with higher rates of abuse, spam, or malicious activity. These “risky TLDs” are extensions where domain registration is cheap, verification is minimal, and abuse complaint handling may be slow — making them attractive to bad actors and creating a higher risk of domain lapse or suspension.
When a domain’s authoritative nameservers are hosted on a risky TLD, the domain inherits additional risk: the nameserver domain is more likely to lapse (due to low renewal rates), be suspended (due to abuse complaints), or be re-registered by a malicious actor (enabling a nameserver takeover attack). This is analogous to building critical infrastructure on unstable ground.
DNS Checker identifies nameserver domains hosted on TLDs that appear on multiple abuse tracking lists, have disproportionately high abuse-to-registration ratios, or are frequently associated with spam, phishing, and malware campaigns. The goal is not to flag all domains on these TLDs as malicious, but to highlight the elevated infrastructure risk of hosting authoritative nameservers on them.
How DNS Checker Identifies Nameservers on Risky TLDs
The detection pipeline extracts nameserver hostnames from zone files and reads the TLD of each nameserver domain. Those TLDs are matched against a maintained list of extensions repeatedly identified in industry abuse reporting as carrying elevated abuse-to-registration ratios. The list is a fixed input, reviewed and updated by hand — this analysis does not compute per-TLD abuse scores or query blocklist feeds at run time, and a TLD's presence on the list says nothing about any individual nameserver on it.
Nameservers on listed TLDs are reported with the number of domains they serve, so domain owners and registry operators can gauge the scale of exposure. The point of interest is cross-TLD dependency: a .com domain whose nameservers sit on one of these extensions inherits that extension's registration and suspension dynamics.
How to Mitigate Risky TLD Nameserver Exposure
- Host your authoritative nameservers on well-established, reputable TLDs such as .com, .net, or .org. These TLDs have mature abuse handling processes and stable registration ecosystems.
- If you use a DNS hosting provider, verify that their nameserver domains are on reputable TLDs. Most major providers (Cloudflare, AWS, Google, Akamai) use .com or .net for their nameserver infrastructure.
- Avoid using cheap or promotional TLD domains for DNS infrastructure. The low cost that makes these TLDs attractive for domain speculation also makes them attractive to bad actors.
- Monitor the registration status of your nameserver domains. Set up WHOIS monitoring to alert you if a nameserver domain approaches expiration or changes ownership.
Frequently Asked Questions
Which TLDs are considered risky for nameservers?
TLDs with high abuse-to-registration ratios, low-cost bulk registrations, and slow abuse complaint handling are considered higher risk. Specific TLDs change over time as registries improve or degrade their abuse mitigation, so the list here is maintained by hand against published industry abuse reporting rather than pulled live from a feed. Being on the list is a statement about the extension, not about any nameserver operator using it.
Does using a nameserver on a risky TLD mean my domain is compromised?
No. Having a nameserver on a risky TLD does not mean your domain is compromised — it means your DNS infrastructure has an elevated risk profile. The nameserver domain is more likely to lapse, be suspended, or be targeted by bad actors. It’s a proactive risk indicator, not evidence of active compromise.
Why would anyone host nameservers on a risky TLD?
Common reasons include: legacy configurations from when the TLD was less associated with abuse, cost optimization (cheap TLDs for NS domains), geographic preference (ccTLDs in certain regions), or simply lack of awareness about the risk. Some small DNS providers also register nameserver domains on cheaper TLDs to reduce operational costs.