WhoisXML API Blog

Turning Internet-Wide Data into Better New gTLD Decisions

Introducing New gTLD Intelligence Services (NGIS): The intelligence layer for New gTLD applicants, brand protection professionals, and the ICANN community.

Author:
Ching Chiao, Head of APAC & Corporate Development, Whois API, Inc.

As the ICANN community prepares for the next New gTLD application window, set to open in April 2026, one thing is already clear. This round will be far more data-driven than the last.

In 2012, many New gTLD decisions were shaped by marketing narratives, forward-looking projections, and limited historical evidence. Since then, the domain name ecosystem has matured. Registries, governments, brand owners, and evaluators now have access to years of operational, DNS, and abuse data that did not exist during the first round.

For the 2026 program, critical steps such as string selection, public comment periods, formal objections, and GAC advice will increasingly rely on objective, defensible evidence rather than subjective interpretation. Stakeholders are expected to justify positions with data.

This shift reflects a broader expectation across the community. Different stages of the application process raise different questions, from early feasibility and risk assessment to later scrutiny around confusion and public interest.

That shift is what led us to build New gTLD Intelligence Services (NGIS).

December 2025: Domain Activity Highlights

WhoisXML API analyzed 10.2+ million domains registered between 1 and 31 December 2025 to identify the most popular registrars, TLD extensions, and other global domain registration trends. This number rose by 16.9% from 8.7+ million NRDs last month.

We also determined the top TLD extensions used by 27.3+ billion domains from our DNS database’s A record full file dated 4 December 2025, indicating a 14.6% drop from November’s 31.9+ billion domains.

Next, we studied the top TLDs of 1.1+ million domains, up by 5.0% from 1.0+ million in November, detected as IoCs this month.

Finally, we summed up our findings and provided links to the threat reports produced using DNS and domain intelligence sources during the period.

Turning Abuse Signals into Coordinated Action: Strengthening Digital Trust and Internet Resilience in Latin America and the Caribbean

Turning Abuse Signals into Coordinated Action: Strengthening Digital Trust and Internet Resilience in Latin America and the Caribbean

A conversation with Gonzalo Romero, Director of Abuse Signal Coordination (LAC), WhoisXML API

We are pleased to welcome Gonzalo Romero to WhoisXML API as Director of Abuse Signal Coordination for Latin America and the Caribbean (LAC). In this welcome interview, Gonzalo shares his perspectives on Internet abuse intelligence, ecosystem coordination, and digital trust.

Although grounded in his work across LAC, the insights discussed here reflect global challenges and considerations relevant to Internet abuse coordination worldwide.

DNS Reconnaissance: Real-Life Use Cases and Tools

Every successful penetration test or red team exercise begins with a scope. From there, DNS reconnaissance is one of the most useful ways to start building an asset map.
But DNS reconnaissance use cases aren’t limited to pentesting — one can do a lot of interesting things using DNS data as a starting point. In this post, we will look at the other applications of DNS reconnaissance and the tools that turn simple DNS queries into actionable data points for a security assessment. If you need a refresher on DNS basics before diving into DNS reconnaissance, check out this DNS primer.

WhoisXML API Participates in the Black Hat Europe 2025

Brendan O’Doherty, Intelligence Partnerships at WhoisXML API, joined over 4,500 security professionals at Black Hat Europe 2025, which took place from December 8 to 11, 2025, at Excel London in the United Kingdom.

As with Black Hat USA back in August 2025, the week kicked off with a few days of intensive cybersecurity training sessions before transitioning into two days of main briefings and business hall activities.

Here’s a recap of the most prominent themes of the event.

The Dangers of Domain Generation Algorithms and How to Protect Against Them

Cybercrime tactics always evolve, but few techniques are as persistent as the use of domain generation algorithms (DGAs). Even though they have evolved too.

These algorithms are designed to create a moving target for security teams. Attackers use DGAs to be able to rotate between domain names constantly — when one domain is detected, blocked, or taken down by law enforcement, DGAs allow threat actors to generate and switch to a new set of domains in a matter of seconds or minutes.

In this post, we will talk about the types of DGAs, how they are used by attackers, and how to protect against them.

DNS Intelligence: What It Means and Its Role in Cybersecurity

Almost every activity on the Internet involves a DNS query, making DNS a rich source of threat information. There are many ways to use it — from filtering suspicious DNS requests for malware prevention to mapping threat actor infrastructure. In this article, we explore the different kinds of DNS intelligence, how they work, and how they are used in modern cybersecurity.

The Pyramid of Pain: How to Fight Back in Cybersecurity

Cyber threat actors can hurt you, but did you know you can hurt them too? And it’s absolutely legal. You can make their lives harder — perhaps so hard that they stop attacking you altogether or, hopefully, even reconsider their careers. How do you do it?

Every time you block their attacks, you hurt them. You make them change something in the way they attack, which takes time and effort. Some of the changes hurt more than others. In this post, we talk about the Pyramid of Pain — a model that attempts to measure how blocking different things hurts attackers differently — and how it helps security teams evaluate and put different types of threat intelligence to good use.

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.