May 2025: Domain Activity Highlights | WhoisXML API

May 2025: Domain Activity Highlights

The WhoisXML API research team analyzed 8.5+ million domains registered between 1 and 31 May 2025 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by 54.6+ billion domains from our DNS database’s A record full file dated 1 May 2025.

Next, we studied the top TLDs of 1.3+ million domains detected as indicators of compromise (IoCs) this May.

Finally, we summed up our findings and provided links to the threat reports produced using DNS, IP, and domain intelligence sources during the period.

You can download an extended sample of the data obtained from this analysis from our website.

Zooming in on the May 2025 NRDs

TLD Distribution

A majority of the 8.5+ million domains registered in May 2025, 79.4% to be exact, used generic TLD (gTLD) extensions, while the remaining 20.6% used country-code TLD (ccTLD) extensions.

TLD type breakdown of the May 2025 NRDs

The .com TLD remained the most popular extension used by 37.6% of the total number of newly registered domains (NRDs), up from 36.5% in April. The other most used TLDs on the top 5 followed with a significant gap as in the previous month. Four other gTLDs, namely, .top with a 7.5% share, .xyz with 3.8%, .shop with 2.7%, and .org with 2.6%, completed the roster.

Top 5 TLDs of the May 2025 NRDs

We then analyzed the May TLDs further to identify the most popular gTLDs and ccTLDs among the new domain registrations.

Out of 639 gTLDs, .com remained the most used, accounting for a 47.4% share, up from 46.6% in April. The rest of the top 5 lagged far behind. In fact, the four other gTLDs only clocked in a 21.0% share in total. The four remaining gTLDs were .top with a 9.5% share, .xyz with 4.8%, .shop with 3.4%, and .org with 3.3%.

Top 5 gTLDs of the May 2025 NRDs

Meanwhile, .cn topped the list of 252 ccTLD extensions with a 9.9% share. The .de ccTLD followed with an 8.5% share. Then came .ru with an 8.2% share, .uk with 7.6%, and .cc with 5.0%.

Top 5 ccTLDs of the May 2025 NRDs

Registrar Distribution

GoDaddy continued to reign supreme among the registrars with a 14.7% share as in April. Namecheap took the second spot with an 11.2% share. The rest of the topnotchers were Dynadot with a 4.5% share, NameSilo with 3.9%, and Hostinger with 3.8%.

Top 5 registrars of the May 2025 NRDs

WHOIS Data Redaction

More NRDs had redacted WHOIS records in May, 59.1% to be exact, up from 58.8% in April. The remaining 40.9%, meanwhile, had public WHOIS records.

WHOIS redaction breakdown of the May 2025 NRDs

A Closer Look at the May 2025 DNS Records

Top TLDs of the A Record Domains

Next, we analyzed 54.6+ billion domains from our DNS database’s A record full file dated 1 May 2025, which included DNS resolutions from the past 365 days. We found that 43.5% used the .com gTLD, down very slightly from 43.9% in April. The rest of the top 5 comprised two other gTLDs (i.e., .net with a 9.9% share and .org with 6.5%) and two ccTLDs (i.e., .de with a 3.6% share and .ru with 3.4%).

Top 5 TLDs of the May 2025 A record domains

Cybersecurity through the DNS Lens

Top TLDs of the May 2025 Domain IoCs

As usual, we analyzed 1.3+ million domains tagged as IoCs for various threats detected in May. Our analysis revealed that .com remained the most popular TLD with a 23.3% share, up very slightly from 23.0% in April. The remaining top TLDs were all gTLDs as well, namely, .org with a 13.7% share, .net with 13.0%, .biz with 8.6%, and .info with 4.1%.

Top 5 TLDs of the May 2025 domains IoCs

Threat Reports

Below are the threat reports we published in May 2025.

  • Tempering Tax Season Troubles with DNS Intel: Microsoft cybersecurity researchers identified 11 domains and one IP address as IoCs related to ongoing tax-themed phishing campaigns. WhoisXML API expanded the current IoC list and uncovered two alleged victim IP records, obtained from the Internet Abuse Signal Collective (IASC), tied to one Autonomous System number (ASN) and 365 potentially connected artifacts.
  • Unlocking the DNS Strongbox of BADBOX 2.0: WhoisXML API analyzed 109 IoCs related to the threat and found more domains and IP addresses that could be part of the BADBOX 2.0 network. Our DNS deep dive led to the discovery of 3,254 connected artifacts.
  • Exploring the DNS Flipside of SideWinder: The SideWinder advanced persistent threat (APT) group, active since 2012 and known for targeting government, military, and business entities throughout Asia, primarily Pakistan, China, Nepal, and Afghanistan, changed gears. Researchers identified 35 domains as IoCs that we analyzed. We uncovered 579 connected artifacts.
  • Hunting for DNS Traces of Hundreds of Malicious Google Play Apps: Bitdefender uncovered a large-scale ad fraud campaign involving hundreds of malicious apps available for download in Google Play. The security researchers identified 428 URLs as IoCs that we extracted 197 unique domains from. Our expansion analysis of the IoCs led to the discovery of 624 connected artifacts.

You can find more reports created in the past months here.

Feel free to contact us for more information about the products and capabilities used to analyze domain registration events or support other use cases.

Try our WhoisXML API for free
Get started