New in Domain Trust: Badge Testing, Sponsorship Opportunities, and a Market Under Pressure
GCA’s Domain Trust uses the power of data sharing, community building, and mutual agreement to reduce the number and impact of malicious domains. On August 25, the Domain Trust Community convened its 18th meeting in two sessions, East and West, to increase participation across time zones. The agendas were aligned, but each session drew a different group and took a different turn.
Growth, Engagement, Platform Usage, and Sustainability Updates
Both sessions opened with a check against four annual goals: community growth, ecosystem engagement, data platform usage, and sustainability. Slides for the East session and West session are public.
Growth has been moderate and almost entirely organic. Development of the Domain Trust Badge is bringing registrars into conversations they had not previously joined, along with smaller registries and organizations working on domain abuse from other angles.
Engagement has been particularly strong because participants bring different perspectives, experiences, and approaches to the same challenges. Bringing those voices together is helping everyone better understand the problem, identify gaps, and develop solutions that are more practical and effective across the broader ecosystem.
The Domain Trust platform now holds more than 43 million unique domains that are potentially malicious and takes in roughly 150,000 per week, with further automated feeds expected. Usage remains the weak point: of more than 70 registered users, 24 are active and only 13 have been active in the last 30 days. Both sessions repeated the same request: the Community can help move those ratios. The platform is free, and, once a user is qualified, onboarding only requires two signatures. Either as a gateway to share and obtain data on domain abuse with a larger community or as a tool to support the Badge efforts, the platform is always there to help.
On the sustainability front, GCA is launching a sponsorship campaign this month with six tiers ranging from USD $1,500 to $250,000 a year. The campaign is built on visibility in 2026, with added value data insights planned for later rounds. Some funding has already been secured, but GCA needs additional funders to ensure the initiative succeeds. Participants will receive an email invitation with sponsorship details, and the process will repeat annually, with no automatic renewals.
The Badge: From Concept to Implementation
Year one of the Domain Trust Badge development effort ran from June 2025 through June 2026, largely centering around activities at ICANN 83 in Prague and ICANN 86 in Seville.
The Action Working Group, now 30+ organizations strong, has met eight times and categorized about 20 baseline actions across three groups: policy, coordination with other anti-abuse efforts and law enforcement, and performance. A measurement framework has been prototyped, and the concept was presented publicly in Seville. Implementation now runs in two phases: testing from September 15 to the end of 2026, then adjustment through the first quarter of 2027, with the objective of arriving at ICANN 88 in Lisbon (March 2027) with something tangible.
Two tests start this month. The first is a self-assessment tool for registries and registrars, which walks through each action anonymously and collects feedback at every step. The second concerns the Domain Trust metric, or DTm, which combines abuse rate, mitigation rate, and response time into a single score between 0 and 100 that cannot be reverse-engineered into its components. The algorithm has been run against the GCA repository, producing histograms that participants recognized as a fair description of the industry, and it will now be shared with other data repositories so the same test can run across a year of data and reveal any divergence between sources.
More registrars are needed, particularly large ones. The self-assessment tool has not yet been used by the people it was built for. The DTm results may diverge more than expected, which would change how a threshold is defined. And there is the day zero problem: one registry has already volunteered to be among the first Badge holders, but few organizations want to be first alone. The self-assessment tool will try to close those gaps, collecting feedback from possible participants and offering them a real-life test on how the entire process will look.
All registries and registrars participating in the Domain Trust Community will receive a personal invitation to test the tool.
Community Updates: Email Authentication
The East session covered DMARC adoption from the perspective of a registry (AFNIC in France), based on work tracking SPF, DKIM, DMARC, and BIMI across the .fr TLD since 2023. SPF adoption is still rising but appears to be plateauing around 70 percent, and DKIM rose sharply across 2024 and 2025, most likely driven by large email service providers. DMARC adoption is also growing, but the largest share of policies remain at p=none, and records are rarely revisited once published. Two failure modes stood out: policy values machine-translated from online manuals into French, which renders the record useless, and roughly 30 percent of published BIMI assertion records misconfigured.
The session also circulated the report GCA published with DMARC Manager on the global postal sector, which scanned all 191 Designated Postal Operators in July 2026 and found 81 percent not fully protected against spoofing, only 19 percent at p=reject, and 34 percent with no DMARC record at all.
Community Updates: Phishing Infrastructure and Malicious Registrations
The West session covered a phishing campaign captured by AIDE, GCA’s honeypot platform. One hour of traffic on January 27 from a single VPS address produced around 20,000 delivery attempts in two bursts. The first posed as a OneDrive share leading to a fake Microsoft login, aimed overwhelmingly at South African real estate, telecom, and finance businesses. The second targeted personal inboxes with a fake job offer, where the trap was the reply address, a one-letter-off lookalike of a financial brand registered months earlier and already carrying a poor reputation score. Every early warning signal was present, and the campaign ran anyway. The findings will be shared with the .za registry (ZADNA) and with national actors in South Africa.
Interisle Consulting then presented its analysis of 2025 gTLD registrations. Of 85 million new domains, 8.5 million had been blocklisted by May 2026, and that 10 percent is a floor, since associated domain checks suggest the real figure may reach 20 percent. Abuse appears in virtually all open gTLDs and at 88 percent of accredited registrars, but it is heavily concentrated: five registrar families accounted for 53 percent of blocklisted registrations, four registry families for 76 percent, and eight registrars saw more than half of their own new registrations blocklisted. In one case study, a zone grew from 7,000 to 132,000 domains, 58 percent were blocklisted, and the renewal rate collapsed to 4.6 percent once the wave passed.
The explanation offered was economic. Registration friction is low, tolerating abuse can be commercially rational when carrying it costs less than deterring it, and volume discounts reward bulk sales regardless of who is buying, while the costs land on victims, businesses, and society. Mitigation was described as necessary but not sufficient, and the coming expansion of the gTLD space is expected to make the picture worse unless prevention improves. Interisle’s slides are available here.
Discussion
The discussion that followed centered on one question: could a Domain Trust Badge change any of this?
The skeptical view was that industrial-scale criminal registration will not be deterred by a voluntary label, and that some operators have business models for which adopting one would make no sense. A second objection concerned measurement, since organizations that sign up early are already different from the general population, a selection problem that makes impact hard to attribute. One suggestion was to track malicious registration trends among Badge holders over time and test whether they improve.
The response was that the Badge is designed as a positive incentive rather than a deterrent, closer to an environmental label than to an enforcement mechanism, since good actors currently have no credible way to demonstrate what they do about abuse. The measurement approach is deliberately collective and relative, following the pattern established with MANRS, where participants score better than the industry average on routing security. The threshold is meant as a baseline rather than a gold standard, set below the current average of the community so that organizations outside it can realistically join, supported by a candidate status that gives a full year and access to a shared resource pool to improve.
Save the Date
The next Domain Trust Community Meeting, DTCM 19, is scheduled for December 1. We will announce the initial sponsors and share the ecosystem report and the first evaluations of the self-assessment tool and the DTm tests.
We are also reviewing how these sessions are scheduled and run, with the aim of making it easier for more of the Community to take part. We will announce those changes when the invitations go out. If you’d like to join, please reach out to us at [email protected].
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.