TLD Spam / Abuse Ranking Checker
Aggregate spam/abuse rate for the domain's top-level domain.
This is one independent signal used by the Domain Security Score, and can also be run on its own for any domain.
Based on: Cybercrime Information Center — TLD Spam/Abuse Statistics (Mar–May 2026)
About this validation
Aggregate spam/abuse rate for a domain's top-level domain.
Dataset: March 2026 - May 2026
- Rules reviewed:
- Sep 6, 2026
SEOTechTests methodology: Data source: a static per-TLD dataset from the Cybercrime Information Center's quarterly report, bundled with this site (not a live per-domain lookup, since no such API exists). PASS/WARNING/FAIL thresholds are set on the TLD's malicious-spam-domains-per-10,000-registrations rate; severity is capped at medium so a TLD-wide statistic can never trigger the critical-override rules reserved for a confirmed per-domain detection.
Standards and vendor-documented behavior can change. This reflects the source as last reviewed above, not a permanent guarantee.
FAQ
What does the TLD Spam/Abuse score measure?
The rate of malicious spam domains (per 10,000 registered) reported for the domain's entire top-level domain (e.g. .com, .top) in the Cybercrime Information Center's latest quarterly report -- a property of the TLD as a whole, not of this specific domain.
Why can the reputation of a TLD be useful?
TLDs with very high abuse concentrations (often cheap, high-volume new gTLDs) are a well-documented, real risk-context signal used across the anti-abuse industry -- it helps interpret a domain in context of the neighborhood it registered in.
Why does SEOTechTests use the Cybercrime Information Center dataset?
It's a periodically published, publicly available report specifically measuring per-TLD abuse rates -- the kind of aggregate data typically produced by registry-operator or industry abuse-tracking projects, with a clearly stated reporting period.
Does a high-risk TLD mean that an individual domain is malicious?
No. A higher abuse rate for a TLD is a contextual risk signal, not a finding about this specific domain -- most domains on even a high-abuse-rate TLD are unrelated to that abuse. That's why severity is capped so it can never override a domain's own direct evidence.
How often is the TLD dataset updated?
The Cybercrime Information Center publishes it quarterly. This page always shows the exact reporting period the bundled data covers (see "Dataset" above) rather than presenting historical data as if it were checked today.