The purpose of DNS is to spread scams

The purpose of DNS is to spread scams

DNS 的目的竟是传播诈骗

I imagine everyone here has received an unsolicited message telling them that their tax is overdue and that they urgently need to visit Genuine-Tax-Payment-Website.fart or that a parcel is delayed at customs and you can pay a small sum for its release at Almost-The-Right-Acronym.ak. 我想在座的各位都收到过那种垃圾短信,声称你的税款逾期了,需要紧急访问某个“真实税务支付网站.fart”,或者说你的包裹在海关延误了,只需支付一小笔费用就能放行,并附上一个“看似正确的缩写.ak”链接。

You know it is a scam. Most people just mark as spam and move on with their day. But a significant number of people don’t. They hastily visit the site, tap in their credit card details, give it their mother’s maiden name, confirm address, upload a nude selfie, and only then realise that they’ve been had. 你知道这是诈骗。大多数人只会将其标记为垃圾信息然后继续忙自己的事。但仍有相当多的人不会这样做。他们匆忙访问网站,输入信用卡信息,填入母亲的婚前姓氏,确认地址,甚至上传裸照自拍,直到那时才意识到自己被骗了。

The Internet works at pretty close to the speed of light. You can register a .uk domain and a minute later it’s accessible from the other side of the planet. Brilliant for users who want to quickly launch a website. Also brilliant for abusers who want to launch a spam campaign. 互联网的运行速度几乎接近光速。你可以注册一个 .uk 域名,一分钟后它就能从地球的另一端被访问。这对想要快速建立网站的用户来说非常棒,但对想要发起垃圾邮件活动的滥用者来说同样如此。

By the time enough people have reported the scammers’ domain as suspicious, it is too late. In the time it takes for a registrar to disable the domain, or for its name to make its way to the Safe Browsing List, a million messages have already been sent and enough people have handed over their details. 等到足够多的人举报诈骗者的域名可疑时,一切都太晚了。在注册商禁用该域名,或者该域名被列入“安全浏览列表”的这段时间里,数百万条信息已经发出,且已有足够多的人交出了他们的个人信息。

We’re told that “the purpose of a system is what it does”. At the moment, the Domain Name System’s purpose seems to be a vector for criminals to run scams on people at a terrifyingly high rate. How big is this problem? BIG! 人们常说“一个系统的目的就是它的实际功能”。目前看来,域名系统(DNS)的目的似乎成了犯罪分子以惊人的高频率对民众实施诈骗的载体。这个问题有多严重?非常严重!

There’s a great blog post by Andrew Campling which reports on this startling claim: The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis. It estimated that, taking account of subsequent blocklisting and associated domains not themselves blocklisted, the share of names registered by malicious actors may be closer to 20%. DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists (emphasis added) Andrew Campling 的一篇精彩博文报道了这一惊人的结论:研究发现,当年注册的所有新通用顶级域名(gTLD)中,至少有 10% 在分析时已出现在安全黑名单上。据估计,考虑到后续被列入黑名单的情况以及未被列入黑名单但与之相关的域名,恶意行为者注册的域名比例可能接近 20%。(摘自《DNS 滥用与犯罪基础设施:超越定义与黑名单》,重点部分由作者标注)

That links to a presentation by Interisle which contains some rather shocking statistics (albeit with disputed methodology). It looks at generic Top Level Domains (gTLD) - those are things like .com and .fun rather than country code TLDs (ccTLD) like .uk and .de. It says 85 million new registrations of gTLDs were made in 2025. Of those 8.5 million were added to blocklists by May 2025. It reckons that a 10% abuse rate is the likely floor for these numbers and it’s probably closer to 20%. One in five newly registered domains with a gTLD are scams. That’s a bloody crisis. 该博文链接到了 Interisle 的一份演示文稿,其中包含一些相当令人震惊的统计数据(尽管其方法论存在争议)。该报告关注的是通用顶级域名(gTLD),即 .com 和 .fun 这类域名,而非 .uk 和 .de 这类国家代码顶级域名(ccTLD)。报告称,2025 年新增了 8500 万个 gTLD 注册。其中,到 2025 年 5 月,有 850 万个被列入黑名单。报告认为,10% 的滥用率可能是这些数字的底线,实际比例可能更接近 20%。每五个新注册的 gTLD 域名中就有一个是诈骗网站。这简直是一场危机。

13 TLDs had more than 50% of their registrations blocklisted. I can understand why .bid and .loan are popular with scammers. But why .mobi?! What did I ever do to you, eh? Who are the scammers registering these through? Ah, our old friends at NameCheap. See Why do scammers love NameCheap? If those five registrars had more effective policies, it might significantly dent the scammers’ ability to ply their devious wares. Or they might just move on to other registrars. As the report points out: suspension rates for blocklisted domains were 7.4% to 16.3%. The full report is on the Interisle website. 有 13 个顶级域名的注册量中,超过 50% 被列入了黑名单。我能理解为什么 .bid 和 .loan 受诈骗者欢迎,但为什么是 .mobi?!我到底做错了什么?这些诈骗者是通过谁注册的?啊,我们的老朋友 NameCheap。参见《为什么诈骗者喜欢 NameCheap?》。如果那五家注册商能有更有效的政策,可能会显著削弱诈骗者兜售其卑劣勾当的能力。或者,他们可能只是转移到其他注册商那里。正如报告指出的:被列入黑名单域名的暂停率仅为 7.4% 到 16.3%。完整报告可在 Interisle 网站上查阅。

What can be done? I don’t know. In the first instance, it might make sense for registrars to do strong Know Your Customer (KYC) checks on anyone buying a domain. But that stops anyone who wants to anonymously register I-Hate-Nintendo.whatever without risking the wrath of Intellectual Property lawyers. Also, criminals have access to stolen money and stolen cards. They can convince a hapless mule to register a domain on the criminals’ behalf. 能做些什么呢?我不知道。首先,注册商对任何购买域名的人进行严格的“了解你的客户”(KYC)审查可能是有意义的。但这会阻碍那些想要匿名注册“我讨厌任天堂.whatever”且不想冒着激怒知识产权律师风险的人。此外,犯罪分子拥有被盗资金和被盗信用卡。他们可以诱骗倒霉的“钱骡”代为注册域名。

Registrars could ask for an escrow payment. Pay €9 for the domain name put €900 in escrow. If your domain appears on a blocklist within the year, you forfeit the money. Criminals with stolen funds are unlikely to care but it would probably put off lots of people from getting a new domain. 注册商可以要求托管付款。支付 9 欧元的域名费,同时托管 900 欧元。如果你的域名在一年内出现在黑名单上,这笔钱将被没收。拥有赃款的罪犯可能不在乎,但这可能会让许多人望而却步,不再轻易注册新域名。

There are various banned words and phrases depending on the TLD. For example, South Sudan has a list of political words which they don’t want associated with their .ss ccTLD. But if one gTLD bans a word, a different one might not. A scammer doesn’t care if the gTLD is .arse or .elbow - they just want the start of the domain to look legitimate. 根据顶级域名的不同,有各种被禁用的词汇和短语。例如,南苏丹有一份政治词汇列表,他们不希望这些词与他们的 .ss 国家代码顶级域名关联。但如果一个 gTLD 禁用了某个词,另一个可能不会。诈骗者不在乎顶级域名是 .arse 还是 .elbow——他们只希望域名的开头看起来合法。

Some registrars have strings that they don’t allow. In fairness to NameCheap, when I tried to register dwp-payments-gov-uk.pizza it told me that domain was banned. It wouldn’t let me get any gTLD with that name. But all it takes is one registrar to be slightly lax and the scammers get through. Increasing the complexity of the rules is also a hell of a burden on smaller registrars. Besides, it’s pretty easy to get a generic enough looking domain and stick the confusing bit on a subdomain. 一些注册商有禁止使用的字符串。平心而论,NameCheap 在我尝试注册 dwp-payments-gov-uk.pizza 时确实提示该域名被禁止。它不允许我使用该名称注册任何 gTLD。但只要有一家注册商稍微松懈,诈骗者就能得逞。增加规则的复杂性对小型注册商来说也是巨大的负担。此外,获取一个看起来足够通用的域名,并将容易混淆的部分放在子域名中是非常容易的。

Perhaps there ought to be a delay before a new domain goes live to allow people to object to it? That would give governments, banks, delivery companies, and a dozen more “important” organisations a right to veto any “dodgy” looking domain. But suppose someone wants to register gov-uk-stole-my-horse.horse to protest the government’s cruel policy of stealing horses - is that a legitimate use of a domain? What if the Darwin Pensioner Divas - a group of elderly singers - want to take payments for their new album of goth/punk covers, can the DPD delivery company veto dpd-payments.music? Do we want a domain name system where powerful companies control exactly which domains we can register? 也许新域名在上线前应该有一个延迟期,以允许人们提出异议?这将赋予政府、银行、快递公司以及其他十几个“重要”组织否决任何看起来“可疑”域名的权利。但假设有人想注册“政府偷了我的马.horse”来抗议政府残酷的偷马政策——这算不算域名的合法使用?如果“达尔文养老金歌唱团”(一群老年歌手)想要为他们的新哥特/朋克翻唱专辑收款,DPD 快递公司可以否决 dpd-payments.music 吗?我们真的想要一个由大公司精确控制我们能注册哪些域名的系统吗?

If I have an idea for a domain on a Friday night do I have to wait until Monday before it can be launched? Are those companies realistically able to parse millions of domains per year and have a low false-positive rate? All of these things are possible - but all of them come with an impact on legitimate users. To be clear, I don’t know what the right answer is. What is ICANN doing about it? Lots! It has been a few years since I’ve been to… 如果我在周五晚上想到了一个域名,难道我必须等到周一才能上线吗?这些公司真的有能力每年解析数百万个域名并保持较低的误报率吗?所有这些措施都是可能的,但它们都会对合法用户产生影响。明确地说,我不知道正确的答案是什么。ICANN 在这方面做了什么?做了很多!距离我上次参加……已经过去几年了。