July 2025: Domain Activity Highlights

WhoisXML API analyzed 8.3+ million domains registered between 1 and 31 July 2025 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by 49.3+ billion domains from our DNS database’s A record full file dated 3 July 2025.

Next, we studied the top TLDs of 1.1+ million domains detected as indicators of compromise (IoCs) this July.

Finally, we summed up our findings and provided links to the threat reports produced using DNS and domain intelligence sources during the period.

You can download an extended sample of the data obtained from this analysis from our website.

Zooming in on the July 2025 NRDs

TLD Distribution

A majority of the 8.3+ million domains registered in July 2025, 80.0% to be exact, used generic TLD (gTLD) extensions, while the remaining 20.0% used country-code TLD (ccTLD) extensions.

TLD type breakdown of the July 2025 NRDs

The .com TLD remained the most popular extension used by 36.4% of the total number of newly registered domains (NRDs), down from 41.8% in June. The other most used TLDs on the top 5 followed with a significant gap as in the previous month. The remaining four topnotchers were all gTLDs as well, namely, .xyz with an 8.0% share, .top with 5.5%, .shop with 3.3%, and .online with 2.6%.

Top 5 TLDs of the July 2025 NRDs

We then analyzed the July TLDs further to identify the most popular gTLDs and ccTLDs among the new domain registrations.

Out of 594 gTLDs, .com remained the most used, accounting for a 45.5% share, down from 51.7% in June. The rest of the top 5 lagged far behind. In fact, the four other gTLDs only clocked in a 24.3% share in total. The four remaining gTLDs were .xyz with a 10.0% share, .top with 6.9%, .shop with 4.1%, and .online with 3.3%.

Top 5 gTLDs of the July 2025 NRDs

Meanwhile, .cn continued to top the list of 240 ccTLD extensions with an 11.4% share, down from 13.3% in June. The .co ccTLD followed with a 10.3% share. Then came .uk with a 7.9% share, .ru with 7.8%, and .cc with 6.9%.

Top 5 ccTLDs of the July 2025 NRDs

Registrar Distribution

GoDaddy continued to reign supreme among the registrars with a 15.1% share, up from 11.6% in June. Namecheap took the second spot with a 7.5% share. The rest of the topnotchers were Dynadot with a 6.1% share, GMO Internet Group with 6.0%, and Hostinger Operations with 4.7%.

Top 5 registrars of the July 2025 NRDs

WHOIS Data Redaction

More NRDs had redacted WHOIS records in July, 53.1% to be exact. Only 46.9%, meanwhile, had unredacted WHOIS records.

WHOIS redaction breakdown of the July 2025 NRDs

A Closer Look at the July 2025 DNS Records

Top TLDs of the A Record Domains

Next, we analyzed 49.3+ billion domains from our DNS database’s A record full file dated 3 July 2025, which included DNS resolutions from the past 365 days. We found that 45.1% used the .com TLD, up from 44.9% in June. The rest of the top 5 comprised two other gTLDs (i.e., .net with a 9.9% share and .org with 6.8%) and two ccTLDs (i.e., .de with a 3.6% share and .ru with 3.4%).

Top 5 TLDs of the July 2025 A record domains

Cybersecurity through the DNS Lens

Top TLDs of the July 2025 Domain IoCs

We analyzed 1.1+ million domains tagged as IoCs for various threats detected in July. Our analysis revealed that .com remained the most popular TLD with a 17.9% share, up from 17.7% in June. The remaining top TLDs were all gTLDs as well, namely, .org with a 15.3% share, .net with 14.5%, .biz with 10.1%, and .info with 4.9%.

Top 5 TLDs of the July 2025 domain IoCs

Threat Reports

Below are the threat reports we published in July 2025.

  • Down the DNS Funnel and into the Funnull Infrastructure: The Federal Bureau of Investigation (FBI) issued a FLASH report to disseminate IoCs related to Funnull. Threat actors used them to manage cryptocurrency investment fraud scams between October 2023 and April 2025. The report provided links to two lists that WhoisXML API analyzed in two parts.
  • Uncovering the DNS Underbelly of UNC5174: The Shift from SNOWLIGHT to VShell: Chinese-sponsored group UNC5174 used a new open-source tool and command-and-control (C&C) infrastructure dubbed “SNOWLIGHT.” In the same attack, they also began using another tool dubbed “VShell.” Sysdig disclosed 25 IoCs. WhoisXML API expanded the list of IoCs and discovered one alleged victim IP record that communicated with the IoCs and 287 new artifacts.
  • Rounding Up DNS Facts about Operation RoundPress: Additions made to the Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog1 on 9 June 2025 CVE-2025-324332 and CVE-2024-420093 were reportedly abused by APT28 to hack government webmail servers in an operation dubbed “RoundPress.” WhoisXML API expanded the list of 19 IoCs ESET identified and discovered 8,906 new artifacts.
  • Beneath the Belly of the Latest BlueNoroff Attack: A DNS Investigation: The latest BlueNorroff attack used a threat actor-controlled fake Zoom domain. Users who accessed the link downloaded a malicious AppleScript with a keylogger as the final payload. Huntress identified seven domains as IoCs. WhoisXML API discovered that three IoCs were deemed likely to turn malicious upon registration. We also found 21,652 new artifacts.
  • A DNS Exploration of the Latest Educated Manticore Attack: Iranian threat group Educated Manticore launched a spearphishing attack targeting Israeli journalists, high-profile cybersecurity experts, and computer science professors from leading Israeli universities. Check Point Research identified 141 IoCs, which WhoisXML API analyzed. We uncovered 1,753 alleged victim IP records that communicated with the domain IoCs and one victim IP that communicated with an IP IoC. We also discovered that 72 of the domain IoCs were deemed likely to turn malicious upon registration. Finally, we found 1,854 new artifacts.

You can find more reports created in the past months here.

Feel free to contact us for more information about the products and capabilities used to analyze domain registration events or support other use cases.

Try our WhoisXML API for free
Get started