Skip to main content

How can I prevent dangling DNS threats?

Find out more about dangling DNS threats

The State of Domain Abuse in Australia 2026

Make an inquiry

All fields marked with * are required.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

By submitting this form, you acknowledge that CSC will collect and process your personal data in accordance with our Privacy Notice.

Cybercriminals continue to evolve their tactics, and domain names remain at the center of phishing, fraud, brand impersonation, and other online attacks. This year's annual review of the Australian domain threat landscape examines the latest global domain abuse trends, compares Australia with international peers, covers emerging threats driven by artificial intelligence (AI), and discusses practical strategies to strengthen your organization's digital resilience.

Webinar transcript

Disclaimer: Please be advised that this recorded webinar has been edited from its original format, which may have included a product demo and other engagement features. To set up a live demo, please complete the form above on our website. If you currently are not on our website and are watching this on our YouTube channel, there's a link to the website in the description of this video. Thank you.

Christy: Hello, everyone, and welcome to today's webinar, "The State of Domain Abuse in Australia 2026." My name is Christy DeMaio Ziegler, and I will be your moderator.

Joining us today is Quinn Taggart and Peter Scott. Both have spent more than 20 years at CSC, and it is my pleasure to introduce them. Quinn is a product coach for the Digital Brand Services and assists clients in the areas of online brand and cybersecurity strategy. Quinn has a wealth of experience and knowledge appreciated by brand owners as he helps them to better understand their evolving digital asset portfolio and minimize their risk. Peter is a global brand advisor for CSC's Digital Brand Services based in Australia. Through insights, data, and analysis, he helps to advise on how best to protect and secure brands online. He supports clients globally with domain name management, analysis, domain name security insights, and .BRAND trends.

And with that, let's welcome Quinn to get us started.

Quinn: Thanks, Christy, and thanks, Peter and everybody, for joining in today. We're going to touch on a few things first from our Forbes Global 2000 Report, and this is also known as our Cybersecurity Report. And we're in the midst of updating this for the current list of companies that are in there. So some of this may look familiar to you. But the theories and so on behind it are still absolutely relevant for the current situation.

One of the key things in looking at a portfolio of any size is the registrar choice really does matter when it comes to domain security. What we have found through our research is that companies that use enterprise providers are generally more aware and made more aware of security measures that the companies can use than a consumer-grade registrar. And in a lot of cases, it just comes down to resources. A lot of the consumer-grade registrars are all automation based. Therefore they're not giving you that personal touch. They're not giving you the added layer of an account manager or additional strategic support. So what we have found through our research is that if you are engaged with an enterprise-level registrar, then you're being made aware of all of the additional elements that can help when it comes to domain security.

Now the more common elements that people will pay attention to, one of the key items, of course, is registry lock. And the reason I draw that one out ahead of some of the other ones is simply because of the way in which the consumer-grade registrars operate. They are automation based, as I mentioned. So as a result, the registry lock mechanism is a manual process, and it's designed to add in that extra layer of advice and security to make sure that unauthorized changes don't happen. Automation is great to a point. But when it comes to having your accounts hacked or unauthorized access into it, you really just want to make sure that you have that extra layer of security to be able to make sure that your core and key critical domains don't have anything happen to them.

In the same vein, of course, one of the other key elements that we're looking at is DMARC. DMARC is kind of like the Cadillac version of email security. SPF TXT, other mechanisms that are legacy oriented, they have value, and they've been used and still continue to be used, and they still have functionality as far as that part goes. But DMARC is kind of like the real Cadillac end of it. It's not hard to implement per se. But what it comes down to is just a matter of acceptance and making sure that things are configured properly.

One of the key mechanisms of DMARC is making sure that the reject policy is put into place, meaning that if something is unauthorized and gets rejected, that something actually happens to it. So you can quarantine the email. You can reject it outright and so on. But if you don't set that particular policy in place, all you're doing is watching, and you're not really enabling the security measures that DMARC can provide.

But as we can see from this graph, we've more than doubled up on DMARC participation since 2020, which is really great. But when we start to look at some of the other measures, like registry lock or even CAA records or DNSSEC, you can see that they may climb a little bit or up and down a little bit, but not at the same effect as DMARC. And we're hoping that the next report will continue that trend.

One of the other key aspects is regionality. And what we're seeing, of course, is just it's a matter of opportunities. People in the Asia-Pacific side of things may not have as many options when it comes to enterprise-level registrars, and so, as a result, may not be gaining the advantage of working with that enterprise-level registrar. And we've seen from the previous slides that working with an enterprise-level registrar has benefits when it comes to being made aware of the security elements that are available to them and, of course, being able to put them into play.

So when we look here, we see the APAC region has kind of trailed a little bit behind EMEA and the Americas, but it's gaining ground, which is a good sign. And we're glad to see that APAC is starting to pick up a little bit as people become more aware. The use of enterprise-level registrars in APAC is still low by comparison to the other two regions, but their awareness of these security features is helping because they're able to go and put those into place.

When we look at suspicious and malicious domains, who's targeted the most? Well, it's not a surprise to see banking at the top of the pile. Although their rank as far as security goes is a little further down the list. But banking has always been one of those ones where if you think phishing, you think banking, and it's one of the more targeted elements. IT, very suspicious that IT is at the top. And then we start to get into diversified financials, which again banking. Utilities, we're seeing a lot of attacks on utilities in the news, and that's not necessarily a surprise per se. But we would expect to see utilities a little higher up on the security percentage side, but they're very much middle or bottom of the pile now. And that's unfortunate because that's where a lot of the danger can happen.

Now when we look at the registrars that are most associated with fake domain registrations, it's not a surprise to see the more popular retail-grade or consumer-grade registrars, like GoDaddy and Namecheap and Network Solutions, show up as being the top three registrars associated with these particular targeted attacks.

For the Cybersecurity Report, we're really looking at substitutions and homoglyph attacks. They're very typo-oriented, and that's an important thing. Anything that's a lookalike can easily fool somebody at a glance when you're looking at throwing a phishing attack at somebody, and that they're also going to use that as a bit of a mechanism for malware or even ransomware attack. So it's important to keep an eye on the landscape as it evolves.

And I'm going to toss it over to Peter.

Peter: Thanks, Quinn. Hi, everyone. Hope you're doing well. We're going to drill into the ASX Top 100 now. Just Quinn touched on the APAC region. So we're going to have a little bit of a deep dive and see how Australia specifically compares.

So when we look at enterprise registrar use, so I've jumped into the ASX, basically had a look here at the core websites for each brand. And as Quinn's mentioned, enterprise class employs the advanced security and controls when we compare it to the basic protection from a consumer registrar. And our analysis basically shows 60% of Australia's top brands use an enterprise-class provider to manage their core domain. So APAC-wise, it's at around that sort of 10% and globally 46%. So it's interesting Australia is really actually leading the way in terms of enterprise registrar use adoption. So I mean this could be due to the heightened awareness in the region around security protocols or even government initiatives. In terms of industries that are leading the way, it's telcos. It's media and education. And it was interesting to note that resources and the hotel industry had quite a low uptake in terms of enterprise registrar use.

When we take a look at registry lock, so again not generally offered by consumer registrars or pushed. This is the ability to lock the domain down from being transferred or updated, and really should be a mandatory requirement for any brand online. Across the ASX, we're seeing 45% of names blocked, when we compare to the APAC broader region looking at 8% and globally around 24%. So again, Australia is leading the way in terms of locking down domains. In terms of industry-wise, it's a similar story to registrar use. but we have the banking coming in with top usage as well.

Looking at the other security protocols, so the security posture across the ASX, we see strong use of DMARC, which is good compared to APAC and globally. We see a low uptake in DNSSEC, which is interesting, and a stronger use from Australian brands in terms of the CAA record use. That low DNSSEC use across the ASX is interesting. If we drill into the DNS usage across some of the ASX brands, we could see some sort of a reason why. Many of the brands are using either consumer grade or cloud provider. So these might not be pushing this DNSSEC across the DNS. And so there may be a reason why there's that lower uptake. In terms of use of domain for DNS in Australia, it's only 4%. So when we compare that globally, I think it's at around 30%. So again the use of the cloud providers and consumer grade could be a reason behind that as well.

All right. So once we've covered that off there, I'm going to jump into some updates and trends from around Australia. So we're going to go through and have a look around at what's happening with domain abuse.

So, in general, online security is still perceived. In Australia, around 54% of consumers and 55% of small businesses stating they're still concerned around online abuse. So it's still a major concern. Most of the concerns around loss of stolen, leaked income or financial scams.

We've also really seen AI explode over the last 12 months. So it seems wherever we go these days it's a topic of conversation, and it's really surged in Australian consumer use. Sixty-one percent of consumers are using AI, and 72% of small businesses are using AI. So we're also seeing threat actors use AI for domain abuse as well, and we'll touch on that shortly.

AI (sic) is still very secure and resilient. auDA does thousands of compliance and audits each year, some of these coming from enforcement bodies, such as Federal Police and Consumer Affairs. The Australian government is also fighting domain abuse through legislation. So we've got the Cyber Security Act of 2024, probably not directly regulating abuse itself like what auDA does, but it's helping to strengthen general anti-abuse efforts by improving the threat visibility through the mandatory ransomware reporting that comes out of that act. Increased visibility also leading to better monitoring of criminal infrastructure, and that enables Australia's Signal Directorate to act faster on malicious domains.

We're also seeing ecosystem resilience with mandates on security baseline for smart devices. This means it's harder for threat actors to create botnets that use DNS hijacking that rely on malicious domains.

We've also got the Scams Prevention Bill of 2025 that's been released. This again indirectly targets domain abuse through enforcing anti-scam obligations on banks and telecommunications. We saw these industries pop up in the security protocols that were mentioned before. So these providers are obliged to take down malicious, fraudulent domains. Banks, they need to monitor and disrupt any payment flows as well. So there's plenty going on in terms of trying to limit domain abuse.

Now I thought this was an interesting graphic from auDA. So this looks at how users detect domain abuse threats in various ways. The URL, it's like a trust signal. There are different parts of it. You've got the HTTPS protocol, www or subdomain, the actual domain itself, and then the TLD extension, and then the subdirectory. So each of these give different trust signals to users. And what auDA found is that Australian consumers see the domain name, so the domain section in the middle, the actual brand string, they see that as one of the most important trust indicators. So that's quite good that users are in tune to that. We see a lot of misspelled typo domains. So I thought that was an interesting statistic.

On the other hand, small businesses see the TLD as most important. So I guess this makes sense seeing as they're the creators of the websites. So still many that don't know about what to look for here. So really important to place emphasis on educating users.

So I'll just take a look at the current landscape. I did this in last year's webinar to take a look at the current landscape to give you an update. So total scams are up about 5% from the previous year. So well over three $300 million. Investment scams that top those out. Phishing scams make up about one-third of those. A lot of the other scams also involve phishing in some way.

It's interesting to note a slight drop in text and phone scams from the previous year. Perhaps users are becoming more aware with greater education. Email again still on top in terms of the contact method. And email is where we see domains used especially for phishing. It's really the vehicle for the delivery method.

So interesting to note that these stats that we see here, these are reported from users. So it's most likely this is the tip of the iceberg in terms of other scams that haven't actually been reported.

Coming up, they've even got Scams Awareness Week coming up shortly. This is led by the Anti-Scam Centre and ACCC. And as always, we recommend brands that are impacted by these scams to try and educate your users to reduce numbers. We see many of the banks do this at the moment with notifications, dedicated websites, and that sort of thing.

We're going to take a look at Australia's landscape in terms of local extensions. So you can see here, in the blue graphic, these are the top extensions in terms of the APAC region. So these ranks are pretty steady from previous years. Obviously, .com.au, .au up there at the top with.com, and co.nz. They sort of rank out the best for the region.

So what I did was just to get a bit more in depth on that, I've created this table here in the middle. This is essentially expanded out to have a look at the bad reputation ranks across some of these extensions. So this scoring here I've added in, this is from Spamhaus. And I've grouped all this up. And the reputation data there is highlighting that, in terms of the APAC region, the top sort of more malicious domains are .cn and .hk. So they would be considered some of the risky extensions in the region. Likewise you see the high numbers for .com around observed malicious. Actually, these are observed cases, but obviously they have a higher volume of registration, so that balances out that score. Again, we suggest to protect your brands across these core extensions in the region, but this table just highlights the risky ones.

So it's also worth noting in the pink there these covered by blocks. So you can actually block off some of these. If you've got blocks on your core brands, you can get these done in the same way at the same time.

In terms of the top malicious, these are gTLDs, so just outside of that APAC dataset. So these are the top malicious gTLDs. It's interesting to note here it's basically all new gTLDs that really dominate the list here. So we see .top, .vip, and .loan. They're the ones that are sort of more heightened in Australia in terms of abuse and have a bad reputation. Most importantly, again, these can be covered by blocks. So you don't have to register them all. You can have them blocked out and use one of the blocking programs.

Also interesting to note, when I was going through this list, I saw .sbs. Now this used to be owned by the SBS, a local public broadcaster, and the TLD was opened up a few years back. That one has actually jumped up to rank 28th in terms of bad reputation. So might be another one to look out for. It does have that local sentiment to it.

I'm just going to touch on some recent cyberattacks that have happened here in Australia over the last year. With these cyberattacks, we generally see they sort of relate to ransomware or phishing attacks in some way. And this is where we see malicious domain use being done. We saw a number of local ones, anything from ice cream to health, education, and we also saw the Origin breach.

So we know that ransomware, phishing, and domains, they're all deeply connected and are used in within these cyberattacks. So the domains are the bait, and phishing is the delivery method for the domain that links to the ransomware. So as we mentioned before, one-third of scams come from phishing. So these domains really are the critical infrastructure behind phishing. And we're seeing not only the malicious domains used before the cyberattack and during, it's actually afterwards where a lot of the impact is taking place. So once all that data has been collected from the attack, users are then being contacted, and these malicious domains are being used again as that delivery method.

So these domains are playing a big role, and it's also AI that's coming into it as well, that's playing a big role because AI is now creating it at scale for threat actors. So I might just touch on AI now and see how that's impacting domain abuse currently.

As we said earlier, it's surged in the past year with high amounts of consumer and small business use across Australia. It's massively supercharging domain abuse by allowing threat actors to automate, scale, and even really personalize the attacks. That can be done at zero cost, making the whole attack smarter, faster, and harder to detect.

So we're seeing AI used to automate the domain registration part. So this is AI is able to create genuine look-alike, typos domains at scale. So it does that hard work. And we're seeing websites being cloned in a very short amount of time as well. One of the interesting ones is the ability for it to tailor the language set that they see in some of these scams to particular languages and regions without any human knowledge required. So it really is being done at a quick and fast tick. And so the threat landscape is growing.

And part of this AI, I wanted to touch on a particular TLD that I sort of found interesting. This could be an emerging threat. It looks to be more sort of focused on not front-end users, but more developers and those in the Web 3 space. So this is the .bot TLD. So it's short for robot. This was an Amazon TLD and initially restricted to AI and chat applications. But in 2023, they opened it up to the general public. And this TLD natively implies it's machine-to-machine learning, and so it's really targeted at chatbots, AI technologies. It's low cost, and it's become really popular. So its registrations have doubled in just in 2025.

So way it works is threat actors register .bot domains. They mimic legitimate AI assistants. So you might have brandsupport.bot, and this can be used to trick users to providing any sensitive information, downloading maybe compromised apps. And because it implies machine-to-machine learning, it can come across as legitimate and blend in with other automated traffic. So definitely one to keep an eye out in terms of an emerging threat.

So I'm going to jump and touch on Round 2 of the new gTLDs. So the application window just recently closed there, and we're awaiting the reveal day, in October, for various types of new extensions that have come through. Interesting sort of a sneak peek into what's happened there. Just recently, we've just had some extensions being named. This is unofficially. So some applicants have come out and basically named some of the extensions that they've applied for.

Obviously, at the end of the year, ICANN is going to come out with an official list. But some of the ones that we're hearing, we're hearing .socialmedia, livestream, .portal, .status, .drone, and even some other interesting ones, .wellness, and there's even .meow. So I thought that was interesting.

So yeah, let's see how many get applied for. We had over 1,900 applications in 2012 for the first round. So that turned into 600 extensions today. So yeah, determining the right path through all of these extensions is going to be tricky. So we really feel blocking programs are going to be what's going to really help to protect your brand instead of having to register the whole lot of domains.

So in terms of .BRANDs, probably the last round it was about one-third of the applications were branded. So these are the .googles, .apples, these sort of more branded domains. Within Australia, we had around 13 brands that currently are using the .BRAND, so ANZ, Auspost, and La Trobe. There are a few that currently use it. So it'll be really interesting to see how many more of these and how many more Australian brands applied and what we'll see.

Just finally, for me, so with reveal day coming in October, we're going to see these probably go live a lot of these names late 2027. So the time is going to fly. So really a good time now to get your portfolio in order. There's going to be all these new extensions. So it's good to get a handle on how your portfolio is doing. So we suggest reviewing the portfolio. Run a reverse WHOIS and find out what names are out there. You can bring them back in and get a handle on them. Review any of your core brand strings and register any gaps across any of the bad reputation extensions that we've sort of discussed. Let CSC know if you need help. We definitely can help with all of that.

Quinn: We're going to look at how do you mitigate your domain-based attacks. There are a couple of different things that you can do and you know there are some findings. There are lots of studies and lots of reading and so on that are out there for you to have a look at.

We did a CISO Outlook Survey, and what we found was a little over 70% of respondents say the level of threats was either critical or very critical. Now that's a telltale statistic, because if the CISOs are thinking that things are at a point, then that's going to cascade down into the frontline staff. And so everybody really needs to be aware of all the threats that are out there. It only takes one click, one errant click to compromise the network. And so it's important for everybody to do their part to be aware of all the different types of threat mechanisms that are out there. It's not just phishing. It's not just malware. It's ransomware attacks that usually start with some sort of an email or a text message or the like. So make sure that you're aware of these types of attacks. Internally, a lot of technology teams will be doing random testing. Our organization does that all the time.

And that's important for people to be able to take the time to recognize the threats as they come through. And they can come from a variety of different things. But of course, when you look at the exposed surfaces, once you're inside the firewall, I mean, you've got to be physically present. So you need to get inside the building and be at a terminal in order to really kind of take advantage of the physical presence part of it. But where's the external threat? The external threat is coming in through your global domain portfolio. So it's important to make sure that all the doors are locked, and all the windows are closed.

It's not just your core domain. It's not just your key brands and your email domain and the like. It's everything that's in your portfolio and making sure that all the doors are closed and all the locks are enabled. One of the phraseologies I use all the time is you've got a $1 million house and a $10 lock. And if that's the route you're going to take, somebody is going to break in.

So the security risks in today's landscape are going to come in from a wide variety of different places. I'm not going to itemize through all of these. You can read the slide as you wish. But one of the key things is when it comes to domains in general. And so we've got typosquatting.

We have malicious domain registrations, which can include homoglyphs. Now homoglyphs are look-alikes. So you can have characters from different language sets that look a lot like characters from a Latin character set. That's an important one. I'm sure everybody's seen the Apple computer example out on TikTok or on social media. And a lot of those are not as valid as they used to be because the registries have kind of taken action on those. But there are other ways to do that. You can take an accented "e" and maybe on a quick visual look, it'll look exactly like an "e." And you'll move along, and you'll take it as legitimate.

Compromising legitimate domains themselves is an easy way for the bad actors to get in. And a lot of times when you're looking at a consumer-grade registrar, it's as easy as a social engineering attack or just guessing, brute forcing somebody's passwords and getting in. Making sure you've got two-factor authentication enabled and so on.

One of the other key items is dormant domain names. On the surface, if somebody registers your brand in a domain name, but there's no content or it doesn't appear like there's any content to it, it doesn't necessarily mean it's not a threat. You can enable email on a domain name and not have a website. The procedures are independent of each other. And so you can easily utilize a domain that has no content for phishing attacks. So it's important to encompass all of the different elements when you're reviewing your monitoring and enforcement statistics.

So domain security continues to be a bit of an overlooked gap, and the reason why is a lot of people are focusing on the firewall. They're focusing on internal. They're not really paying attention as much to the external threats that are out there. But more than 90% of successful cyberattacks start with a phishing email. That's a startling statistic. So it's really, really, really important to not only educate yourself on what's going on, but making sure that the staff within your organization are also as educated and making sure that nobody is clicking on an errant link or falling for any of the social engineering attacks that we're seeing today.

Registrar choice, I'm going to hype on this one again, just to make sure that people understand it does matter. When you're dealing with a consumer-grade registrar, there are downsides to that. Sure, domains are cheap, easy to get, but there's a trade-off that goes along with that. Typically, you're not getting the strategic guidance and support that you normally would get. And also, too, a lot of times, because it's automation driven, you're not getting any of the additional manual processes, like registry lock, that could easily benefit you from unauthorized changes against your core and critical domain names.

Your enterprise-class registrars are going to have that extra layer of support. The account management team is going to be there to support you and guide you through it. And then, of course, if it's a one-stop shop, you're going to be able to not only get your domain registrations taken care of, but you have monitoring, enforcement. All of those different ancillary services that all tie together are going to be all part of the one service model.

One of the big things in looking at an enterprise-class provider is those added safeguards, right? So we're up to speed on ICANN registry. We're up to speed on any of the changes in the industry landscape. We've got technology behind it. But the people are the big deal. Peter and I both have 20 years plus experience. That's the bulk of the staff that are here behind the scenes at CSC. And that extra layer of experience makes a big difference. We kind of look at the years in the domain industry as like a 10 to 1 thing. So for every year of experience, it's 10 years of your life.

But kidding aside, we're doing domains 110% of our day. We understand a lot of our clients are not. Domains are a small percentage, 5%, 7% of their day. Whereas we're doing this all day, every day. Take advantage of an enterprise-level registrar and the experience that they're able to provide you. I'll get off the soapbox on that one.

But cybersecurity as a whole is only as strong as your weakest vendor, and it's one of the key items when you think about it. If you're doing business with a lot of different vendors, especially if they have access into your system via some sort of a vendor portal or an API, for tracking inventory or invoicing, anything along that line that gives them access into your potential network, it puts them into a position where if they get compromised, potentially that ends up being a network problem for you or a cybersecurity problem for yourself. So it's really important for you to take time to evaluate your vendor list and make sure that they are compliant as well.

When we look at your current domain inventory, one of the key things, and this is kind of the four-step program that we use as the foundation for the Brand Advisory team here at CSC, is being able to assess and optimize your portfolio as a whole. So register the right things in the right places at the right time. Utilize the blocking mechanisms as they are available. Now blocks don't cover everything, but they do cover a sizable chunk of change. And if those extensions are meaningful towards your brand, a blocking mechanism might be a cost-effective way to be able to handle that. Making sure that you're securing the right place or the right pieces to the pie in between.

And, of course, rounding out the whole cyclical event is going to be monitoring and enforcement. And that's always the tipping point, the balancing act when it comes to managing your portfolio effectively is making sure that you have a robust monitoring and enforcement package in. You can't register everything. You can't cover all the holes. It's a complete nightmare sometimes of whack-a-mole in trying to cover up all the typos and the random permutations of your brand online. And that's where monitoring and enforcement can come into play. It is reactive. It's not proactive. But at least if you cut down the time it takes for you to react, then you're going to be in a much better position to be able to deal with the threats.