Scam statistics
Our own figures, not somebody's survey. This is what we can count, because we look it up ourselves every day, and it is updated when the figures are.
Last updated 31 August 2026.
In short
- over 218,000 domains are on the six public blocklists we search.
- 43 suffixes are so overrepresented in scams that they count against a site on their own.
- 138 brands we watch particularly closely, because they are the ones scammers imitate.
- 41 registries we can ask directly when a domain was created.
Why we publish this at all
There are remarkably few figures about scams online, and almost none of them can be checked. Most come from companies selling something, and they are usually counted in a way that makes the problem look large and the solution look effective.
We cannot run a population survey. But every day we look domains up in public registries and blocklists, and those lookups leave figures behind. They are here, with the method, so others can use them and take issue with them.
The blocklists
Six public sources, fetched every six hours and merged into a single lookup. Together over 218,000 domains. There is overlap between them, and the figure is after duplicates are removed.
| Source | What it covers |
|---|---|
| OpenPhish | Phishing pages, that is pages imitating a login to get your details. |
| URLhaus | Addresses that hand out malicious software. Run by abuse.ch. |
| Phishing.Database | Large collection of phishing domains, updated continuously from several sources. |
| Phishing Army | Blocklist assembled from several feeds, intended for DNS filtering. |
| BlocklistProject Scam | Broader scam list, not only phishing. Also fake shops and investment fraud. |
| Spam404 | Older, volunteer run list focused on fake shops. |
What the figure does not mean. It is not the number of scam sites on the internet. It is the number of domains somebody has caught and reported. A scam site typically lives for days or weeks, and most never make it onto a list. So a domain can be a scam even if it is not here, and that is exactly why the blocklists are only one of six signals we use.
Suffixes that are overrepresented
Some domain suffixes are cheap, require no documentation and can be registered in bulk within minutes. They are therefore heavily overrepresented in scams, and they count against a site with us.
43 suffixes count fully against. These are the free ones, those costing under a dollar, and the old wave of cheap gTLDs that are still heavily abused:
.xyz .top .click .shop .online .site .store .live .icu .cyou .rest .bar .buzz .cfd .sbs .lol .mom .pics .skin .tk .ml .ga .cf .gq .autos .monster .quest .bond .sexy .pw .win .date .faith .racing .download .loan .party .science .stream .gdn .men .cricket .accountant
23 suffixes count only half. There are real sites on them, and there is a lot of fraud. They weigh so little that they can never trigger anything alone, and only count when something else is wrong too:
.info .biz .pro .me .tv .cc .fun .work .life .space .website .host .digital .hair .makeup .beauty .cam .rodeo .boats .christmas .fit .uno .review
It does not mean a .shop address is a scam. There are thousands of honest shops on them. The suffix alone can never trigger a warning. It needs the company of other signals to mean anything.
Note what is not on the list: .dk is expensive and requires you to identify yourself, which keeps the volume down. That is also why Danish scams more often sit on a .com or a cheap suffix than on a Danish domain. .id is not there either, although it looks cheap: it is Indonesia's country suffix, and every single Indonesian company would get points for nothing.
The brands that get imitated
We watch 138 names in the address itself. The idea is simple: AT&T does not host its login on weeblysite.com. A well known name on a foreign address is practically never legitimate.
| Category | Names |
|---|---|
| Accounts and tech 20 names | Microsoft, Office 365, Apple, iCloud, Google, Gmail, Amazon, Facebook, Instagram, WhatsApp, Netflix, Spotify, LinkedIn, Adobe, DocuSign, Dropbox, Steam, Discord, HypeSquad, Telegram |
| Payment 6 names | PayPal, Stripe, Klarna, MobilePay, Revolut, Wise |
| Crypto 7 names | Coinbase, Binance, MetaMask, Trezor, Ledger, BlockFi, Kraken |
| Shipping and post 7 names | DHL, PostNord, GLS, FedEx, UPS, USPS, Bring |
| Danish authorities and banks 9 names | MitID, NemID, Skat, Borger.dk, e-Boks, Danske Bank, Nordea, Jyske Bank, Nykredit |
| Telecoms 5 names | AT&T, Verizon, Vodafone, Telenor, TDC |
The list is short on purpose. Every name is a name we raise the alarm about, so there has to be a reason for it to be there. Shipping and post take up a disproportionate share relative to the number of companies, because the fake parcel message is the most sent scam message there is.
Fake letters
The most refined imitation does not use a wrong name at all. It uses the right name written with letters that merely look alike.
| What you see | What your browser sends | What it is |
|---|---|---|
paypal.com | paypal.com | The real one. |
pаypal.com | xn--pypal-4ve.com | The a is Cyrillic. Looks identical. |
аррӏе.com | xn--80ak6aa92e.com | Five Cyrillic characters. Not one Latin letter in the whole name. |
Unicode has over 140,000 characters, and many of them resemble a Latin letter. So we decode the address and fold it down to Latin letters before comparing it with the brand list above. We also look for a single label mixing two alphabets, because real words do not do that.
The hard part is not catching them. It is leaving münchen.de, københavn.dk and jyväskylä.fi alone. There are hundreds of thousands of genuine domains with special characters, and a tool that warns about them is worse than nothing.
How often we get it wrong ourselves
Most tools do not ask themselves that question in public. We measure it like this:
- 200 perfectly ordinary websites are drawn from the Tranco list, ranks 5,000 to 1,000,000, at a fixed interval and without cherry picking. That is the long tail: small shops, associations, local firms.
- 200 known scam domains are drawn from our own blocklists, and the blocklist hit is hidden from the models so they have to find it themselves.
- All 400 are run through the real chain, not a simplified one. Same rules, same models, same thresholds as when you press the button.
- Everything above CAUTION is reviewed by hand. Traffic means people go there, not that the site is honest, so a warning on the list is not automatically a mistake.
The tool is in our code as calibrate.mjs, and the result is measured continuously. The number is not zero, and it never will be. A security tool that claims it is never wrong is lying.
The registries
When a domain was created is the single signal that says the most. We fetch it from the registry itself, not from a guess.
RDAP is the modern protocol, and it covers about 1,200 suffixes via IANA's official list. The suffixes that are missing, and that is most European country domains, we ask over WHOIS on port 43 instead. 41 registries are mapped that way, including .dk, which has no public RDAP at all.
If no registry can answer, it says unknown. We do not use certificate history as a substitute for a registration date, because it is only a lower bound and can therefore make an old domain look new.
Use the figures
Everything on this page may be freely quoted and used, including commercially. Please say where it comes from and when, because the figures change. If you need them in another format, or you think something is counted wrongly, write to us.

