Written by 1:31 pm Domain News Views: 0

Q2 2026 Domain Activity: What the Latest DNS Data Reveals

Q2 2026 domain activity and DNS data trends

The Q2 2026 domain activity report reveals strong growth across the global domain market, along with important changes in DNS infrastructure and domain security. During the second quarter of 2026, more than 30 million new domains entered the market, while millions of registrations showed signs of potential malicious activity.

Domain Registrations Increased by 13.1% in Q2

The global domain market recorded strong growth in Q2 2026.

WhoisXML API identified more than 30 million newly registered domains during the quarter. The company recorded more than 26.5 million registrations in Q1, which means Q2 registrations increased by approximately 13.1%.

This growth shows that businesses, developers and individuals continue to create new websites and digital properties.

However, registration growth also creates opportunities for cybercriminals. More than 7.6 million Q2 registrations showed signs of potentially malicious intent.

Security teams should therefore monitor new domain registrations instead of focusing only on existing websites.

.COM Remains the Leading Domain Extension

Despite the growth of newer domain extensions, .COM remained the most popular TLD in Q2 2026.

The five leading gTLDs included:

RankTLDQ2 2026 New Registrations
1.com11,588,825
2.top1,575,021
3.xyz1,332,646
4.shop879,245
5.org776,606

The .COM extension recorded more than 11.58 million new registrations during the quarter.

Alternative extensions also attracted significant interest. In particular, .XYZ moved from fourth place in Q1 to third place in Q2, while .SHOP moved from third to fourth.

These changes show that alternative TLDs continue to compete for attention in the global domain market.

.CN Leads Country-Code Domain Registrations

Country-code domains also recorded significant activity during Q2.

The leading ccTLDs included:

RankccTLDQ2 2026 New Registrations
1.cn983,659
2.uk478,745
3.cc434,814
4.ru421,979
5.br407,748

The .CN extension led the group with almost one million new registrations.

The rankings also changed during the quarter. The .CC extension climbed from fifth place in Q1 to third place in Q2. Meanwhile, .RU moved to fourth place and .BR moved to fifth.

For businesses that target specific countries, these numbers provide useful insight into regional domain demand.

Millions of New Domains Show Potential Malicious Activity

The security findings represent one of the most important parts of the Q2 report.

WhoisXML API identified more than 7.6 million newly registered domains that showed signs of potential malicious intent.

The figure does not mean that every domain definitely hosted malware or conducted an attack. Instead, the analysis identified characteristics that can indicate malicious registration activity.

Cybercriminals often register domains for phishing campaigns, brand impersonation, malware distribution, spam and other fraudulent activities.

Businesses can reduce their exposure by monitoring domains that closely resemble their brands. Security teams can also track typosquatting domains, newly registered look-alike domains and suspicious DNS changes.

DNS Infrastructure Became More Concentrated

The Q2 report also examined DNS infrastructure through MX and NS records.

WhoisXML API analyzed more than 2.8 billion MX domains and more than 4.7 billion NS domains during the quarter.

The number of site owners using the five leading MX domains increased by 6.8%. The figure rose from more than 1.3 billion in Q1 to more than 1.4 billion in Q2.

NS infrastructure showed even stronger growth. Site owners using the five leading NS domains increased by 18.8%, rising from more than 1.2 billion in Q1 to approximately 1.5 billion in Q2.

This concentration creates an important consideration for businesses. Companies that depend on a small number of infrastructure providers could face wider disruption if those providers experience outages, configuration problems or security incidents.

Regular DNS monitoring can help businesses identify unexpected changes and reduce operational risks.

Confirmed Malicious Domains Declined Slightly

The Q2 report also contained a small positive development.

The number of confirmed malicious domains associated with the five leading TLDs declined by 2.3%. The figure fell from more than 2.08 million in Q1 to approximately 2.03 million in Q2 2026.

This decline provides some encouraging news, but businesses should avoid drawing long-term conclusions from a single quarter.

Security teams need to monitor future quarters to determine whether malicious-domain activity continues to decline.

What Q2 2026 Domain Activity Means for Businesses

The latest data provides several important lessons for domain owners and cybersecurity teams.

Domain registrations continue to grow as businesses and individuals launch new websites, services and digital brands.

Despite increasing competition from alternative TLDs, .COM remains the strongest domain extension in the global market.

Country-code extensions also continue to attract significant interest, particularly in major regional markets.

Another important finding involves domain security. Millions of new registrations showed characteristics associated with potential malicious activity.

Businesses should therefore monitor:

  • Newly registered domains that resemble their brands
  • Typosquatting domains
  • Look-alike domains
  • Suspicious DNS changes
  • New MX and NS relationships
  • Domains linked to phishing or malware
  • Expired domains that attackers could register again

Domain intelligence platforms can help security teams investigate these risks. WhoisXML API, for example, provides WHOIS, DNS, historical DNS, domain reputation and threat-intelligence data.

Why Domain Data Matters in 2026

The Q2 2026 data shows that the domain ecosystem continues to expand while cybersecurity risks evolve alongside it.

More than 30 million new domains entered the market during the quarter. At the same time, millions of registrations showed characteristics associated with potential malicious activity.

DNS infrastructure also became more concentrated among leading providers.

For domain investors, this data can reveal registration trends and growing TLD opportunities. For businesses, it highlights the importance of protecting brands across multiple extensions. For cybersecurity teams, new-domain intelligence can provide an early warning about potential threats.

The main lesson is clear: domain data has become a valuable source of both market intelligence and cybersecurity information.

Businesses that combine domain management, DNS monitoring and threat intelligence can identify suspicious activity earlier and protect their digital assets more effectively.

Source and Methodology

This article uses data from the WhoisXML API Global Domain Activity Report: Q2 2026. The report examined newly registered domains from April 1 through June 30, 2026, along with DNS infrastructure and threat-intelligence data.

Domainera has interpreted the reported figures and added practical explanations for domain owners and cybersecurity professionals. Readers should treat classifications such as “potentially malicious” as indicators rather than proof that every listed domain conducted malicious activity.

To know more on Domain topic click herehttps://domainera.net/what-happens-when-a-domain-name-expires/

Last modified: September 11, 2026

Close