August 2025: Domain Activity Highlights

WhoisXML API analyzed 8.5+ million domains registered between 1 and 31 August 2025 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by 45.1+ billion domains from our DNS database’s A record full file dated 7 August 2025.

Next, we studied the top TLDs of 1.0+ million domains detected as indicators of compromise (IoCs) this August.

Finally, we summed up our findings and provided links to the threat reports produced using DNS and domain intelligence sources during the period.

You can download an extended sample of the data obtained from this analysis from our website.

Zooming in on the August 2025 NRDs

TLD Distribution

A majority of the 8.5+ million domains registered in August 2025, 83.4% to be exact, up from 80.0% last month, used generic TLD (gTLD) extensions, while the remaining 16.6% used country-code TLD (ccTLD) extensions.

TLD type breakdown of the August 2025 NRDs

The .com TLD remained the most popular extension used by 45.9% of the total number of newly registered domains (NRDs), up significantly from 36.4% in July. The other most used TLDs on the top 5 followed with a significant gap as in the previous month. The remaining four topnotchers were all gTLDs as well, namely, .xyz with a 9.3% share, .top with 7.7%, .shop with 4.4%, and .online with 3.3%.

Top 5 TLDs of the August 2025 NRDs

We then analyzed the August TLDs further to identify the most popular gTLDs and ccTLDs among the new domain registrations.

Out of 620 gTLDs, .com remained the most used, accounting for a 45.9% share, significantly lower than 45.5% in July. The rest of the top 5 lagged far behind. In fact, the four other gTLDs only clocked in a 24.6% share in total. The four remaining gTLDs were .xyz with a 9.3% share, .top with 7.7%, .shop with 4.4%, and .online with 3.3%.

Top 5 gTLDs of the August 2025 NRDs

Meanwhile, .cn continued to top the list of 240 ccTLD extensions with a 13.5% share, slightly higher than 11.4% in July. The .ru ccTLD followed with a 9.2% share. Then came .uk with an 8.9% share, .cc with 8.7%, and .in with 5.7%.

Top 5 ccTLDs of the August 2025 NRDs

Registrar Distribution

GoDaddy continued to reign supreme among the registrars with a 14.0% share, down from 15.1% in July. Namecheap took the second spot with a 10.4% share. The rest of the topnotchers were GMO Internet Group with a 7.8% share, Dynadot with 5.1%, and Spaceship with 4.8%.

Top 5 registrars of the August 2025 NRDs

WHOIS Data Redaction

Fewer NRDs had redacted WHOIS records in August, 49.3% to be exact. A total of 50.7%, meanwhile, had unredacted WHOIS records.

WHOIS redaction breakdown of the August 2025 NRDs

A Closer Look at the August 2025 DNS Records

Top TLDs of the A Record Domains

Next, we analyzed 45.1+ billion domains from our DNS database’s A record full file dated 7 August 2025, which included DNS resolutions from the past 365 days. We found out that 43.0% used the .com gTLD, down from 45.1% in July. The rest of the top 5 comprised two other gTLDs (i.e., .net with a 9.8% share and .org with 7.1%) and two ccTLDs (i.e., .de with a 3.9% share and .ru with 3.5%).

Top 5 TLDs of the August 2025 A record domains

Cybersecurity through the DNS Lens

Top TLDs of the August 2025 Domain IoCs

We analyzed 1.0+ million domains tagged as IoCs for various threats detected in August. Our analysis revealed that .com remained the most popular TLD with an 18.0% share, up from 17.9% in July. The remaining top TLDs were all gTLDs as well, namely, .org with a 15.9% share, .net with 15.1%, .biz with 10.5%, and .info with 4.9%.

Top 5 TLDs of the August 2025 domain IoCs

Threat Reports

Below are the threat reports we published in August 2025.

  • Top 10 Malware of Q2 2025: A Deep Dive into the IoCs: Our analysis of the 62 IoCs uncovered 25,633 new artifacts, 80 of which have already been weaponized for various attacks. In addition, 72,921 unique client IP addresses tied to 2,720 unique Autonomous System numbers (ASNs) queried six distinct domain IoCs. Meanwhile, 34 alleged victim IP addresses communicated with some IP IoCs. Finally, seven domain IoCs were deemed likely to turn malicious 31–233 days before they were dubbed as such.
  • RomCom and TransferLoader IoCs in the Spotlight: In this two-part study, WhoisXML API searched for typosquatting domain groups (with an IoC and look-alike domains) to unravel similarities. We found out that four domain IoCs appeared in five typosquatting groups with 3–8 domains. The typosquatting domain groups were spotted between 650 days before and one day after their current WHOIS record creation dates. The second part, meanwhile, revealed that 19 domain IoCs were deemed likely to turn malicious upon registration. It also unearthed 4,778 new artifacts, many of which have already been tagged as malicious.
  • Spilling the Beans on Multiplatform Cryptominer Soco404: Wiz identified nine domains as IoCs, which WhoisXML API further analyzed. Our deep dive discovered that 1,516 unique client IP addresses communicated with four domain IoCs via 18,052 DNS requests on 15–23 July 2025. Two domain IoCs were also dubbed likely to turn malicious 65–165 days prior to being reported as such. Finally, we uncovered 9,522 new artifacts.

You can find more reports created in the past months here.

Feel free to contact us for more information about the products and capabilities used to analyze domain registration events or support other use cases.

Try our WhoisXML API for free
Get started