Skip to content

High-Risk TLD Zone Detected

It indicates that the domain belongs to a top-level domain (TLD) frequently associated with malicious or fraudulent activity. Such TLDs are often exploited by threat actors because they are low-cost, offer weak registration verification, or are managed by registrars with minimal abuse handling.

Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'High-Risk TLD Zone' mean in domain intelligence analysis?

It indicates that the domain belongs to a top-level domain (TLD) frequently associated with malicious or fraudulent activity. Such TLDs are often exploited by threat actors because they are low-cost, offer weak registration verification, or are managed by registrars with minimal abuse handling.

Why it matters02

Why are certain TLDs considered high-risk in SOC analysis?

Some TLDs—such as .xyz, .top, .club or .tk—are statistically overrepresented in phishing, malware distribution, and spam campaigns. Their abuse rates are significantly higher due to the ease of anonymous registration and poor registrar oversight.

How analysts use it03

Can a domain under a high-risk TLD still be safe?

Yes. While many malicious domains use these TLDs, not all are harmful. However, traffic or communication with such domains should trigger heightened scrutiny, especially when correlated with other malicious indicators such as newly registered status or suspicious hosting patterns.

Often paired with:alert_only
Evidence shape

What High-Risk TLD Zone Detected looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "untrusted_tld",
  "name": "High-Risk TLD Zone Detected",
  "group": "threat_intelligence_feed",
  "subgroup": "fraud_abuse",
  "direction": "malicious",
  "evidence": {
    "category": "phishing",
    "tld_trust": "untrusted",
    "tld": ".zip",
    "fraud_indicators": [
      "typo_squatting",
      "brand_impersonation"
    ]
  }
}
See in API reference
Siblings

Peers in Fraud & Abuse

2 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Brand-Impersonating Domain Detected

It refers to a domain that visually or semantically resembles a legitimate brand or organization’s domain. Such domains

MaliciousCore
Previously Risky Category Detected

It indicates that before being classified as malicious, the domain was previously categorized under a risky or suspiciou

Malicious
In the wild

See High-Risk TLD Zone Detected fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to High-Risk TLD Zone Detected. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.