Threat actors are actively acquiring expired domains, referred to as "dropcatch domains" by DNS threat intelligence firm Infoblox. This strategy allows them to inherit existing website traffic and reputation, which they then use to redirect unsuspecting users to scam websites and malware distribution points on a large scale.
During the first half of 2026, approximately 50,400 dropcatch domains were re-registered daily in generic top-level domains (gTLDs) such as ".com." When country code top-level domains (ccTLDs) are included, this figure rises to around 65,000 daily registrations. This means that nearly 20% of all new daily gTLD and ccTLD registrations are dropcatch domains.
Infoblox highlights that these domains are particularly dangerous because they retain reputation and connections from their previous legitimate use. Security products and reputation-based algorithms may view them more favorably than genuinely new registrations, a fact that threat actors exploit to bypass detection. This inherited trust makes it easier for malicious actors to deceive users.
Analysis shows that .net and .xyz are the top TLDs for dropcatch activity, surpassing .com. Other prominent TLDs include .org, .vip, .online, .store, .site, .app, and .shop. Major registrars like GoDaddy, Namecheap, and DropCatch.com facilitate these re-registrations, with each handling thousands of median daily dropcatch domains.
Domains expire for various reasons, but most gTLDs have a recovery policy allowing registrants to renew within a grace period. Once this period ends, the domain becomes available again. Custom drop catching services track domains nearing deletion and automatically attempt to register them for customers who place backorders, often leading to auctions if multiple parties are interested.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Threat actors are acquiring expired domains, termed "dropcatch domains," to exploit their inherited reputation and traffic for redirecting users to scams and malware. This practice accounts for nearly 20% of all daily new domain registrations, posing a significant security risk by leveraging previously legitimate web addresses.