Skip to main content
DNS Checker(beta)

DNS Provider Concentration

7 TLDs with >90% single-provider dependency

Analysis by Ishan Karunaratne · Data from 2026-08-23

TLDs >90% Concentration

7

TLDs >70% Concentration

10

TLDs >50% Concentration

38

>90% Single Provider

TLDDominant ProviderDomainsShare
.lundbeckCSC Digital Brand Services27399.3%
.lamborghiniAWS Route 5324898.0%
.neustarUltraDNS/Neustar68397.8%
.realtorGoogle Cloud DNS23,10496.6%
.discoverCSC Digital Brand Services10396.1%
.jnjNS1/IBM13194.7%
.weirCSC Digital Brand Services19392.8%

70–90% Single Provider

TLDDominant ProviderDomainsShare
.广东 (.xn--xhq521b)Alibaba Cloud (HiChina)38076.8%
.microsoftAzure DNS10776.6%
.awsAWS Route 5312973.6%

What Is DNS Provider Concentration Risk?

DNS provider concentration occurs when a disproportionate number of domains under a single TLD rely on one DNS hosting provider. This creates a single point of failure: if that provider experiences an outage, DDoS attack, or compromise, the majority of domains under that TLD become unreachable simultaneously. The risk is systemic — affecting not just individual domain owners but the entire namespace of a TLD.

The most notable example of DNS provider concentration risk was the 2016 Dyn DDoS attack, which took down major websites including Twitter, GitHub, Netflix, Reddit, and the New York Times. These sites all depended on Dyn as their DNS provider, and when Dyn’s infrastructure was overwhelmed by a Mirai botnet attack, all of them became unreachable simultaneously despite having no issues with their own servers.

A standard way to express this is the Herfindahl-Hirschman Index (HHI), the measure of market concentration used in antitrust analysis. Under the 2023 DOJ/FTC Merger Guidelines, an HHI above 1,800 marks a highly concentrated market and 1,000–1,800 a moderately concentrated one. (The older 1,500/2,500 thresholds come from the superseded 2010 guidelines.) The figures on this page are single-provider market share per TLD, which is the more direct measure of single-point-of-failure risk: HHI describes the whole distribution, but a TLD can be moderately concentrated overall and still have one provider serving most of it.

How DNS Checker Measures Provider Concentration

For each gTLD in the dataset, DNS Checker extracts all NS records and maps nameserver hostnames to their parent DNS provider organizations. Provider identification uses a curated database of DNS providers with their known nameserver hostname patterns. The analysis then computes each provider’s market share as a percentage of the domains in that TLD.

TLDs are flagged at three concentration thresholds: >90% single-provider share (critical — near-total dependence), >70% single-provider share (high — significant concentration), and >50% single-provider share (moderate — notable concentration). The tables on this page report dominant-provider share, not HHI; a full HHI per TLD would additionally account for how the remaining share is distributed.

How to Reduce DNS Provider Concentration Risk

  1. Use secondary DNS with a different provider. Most DNS providers support zone transfer (AXFR/IXFR) or API-based synchronization to keep a secondary provider in sync with your primary.
  2. Consider providers that operate on different infrastructure (different cloud providers, different geographic regions) to maximize resilience against regional outages or provider-specific attacks.
  3. For registry operators: encourage provider diversity in your TLD by publishing best-practice guides and potentially offering incentives for domains using multi-provider DNS configurations.
  4. Monitor your DNS provider’s status page and subscribe to incident notifications. Have a documented failover procedure to switch to your secondary DNS provider if the primary goes down.
  5. Evaluate providers based on their infrastructure diversity, DDoS mitigation capabilities, and historical uptime. Providers with anycast networks across multiple data centers offer better resilience.

Frequently Asked Questions

What is the Herfindahl-Hirschman Index (HHI)?

The HHI is a standard measure of market concentration calculated by summing the squares of each provider’s market share percentage. An HHI of 10,000 means perfect monopoly (one provider controls 100%), while an HHI approaching 0 means perfect competition. In the context of DNS, a high HHI indicates that a TLD’s domains are concentrated among few providers, increasing systemic risk. Note that the tables above report dominant-provider share rather than HHI.

Why is DNS provider concentration dangerous?

When most domains under a TLD use the same DNS provider, a single outage, DDoS attack, or security compromise at that provider can render the majority of the TLD’s domains unreachable. This was demonstrated during the 2016 Dyn attack, the 2019 Cloudflare outage, and the 2021 Akamai DNS failure — each caused widespread disruption because of provider concentration.

What is secondary DNS and how does it help?

Secondary DNS means running your DNS zone on two or more independent providers simultaneously. If your primary provider goes down, resolvers can still get authoritative answers from your secondary provider. Zone data is synchronized via AXFR/IXFR (zone transfers) or API-based replication. This is the most effective mitigation for provider concentration risk.

Is provider concentration an issue for .com and .net?

Large TLDs like .com and .net generally have lower concentration risk because their massive domain counts support a diverse provider ecosystem. However, even these TLDs show significant concentration — Cloudflare alone serves DNS for tens of millions of .com domains. Smaller gTLDs with niche registries are often far more concentrated.

Related Tools

Data updated daily. Last snapshot: August 23, 2026