Used domain names are valuable – to legitimate users and criminals

Many dropped domain names get a second life

Hands typing on desktop computer keyboard in a dark room

When you drop a domain name, you’re letting go of more than an internet address. Often, you’re also giving away the reputation, traffic and recognisability linked to it. And those assets make dropped domain names attractive to other people and organisations. People and organisations who may or may not have an honest purpose in mind for your old domain. Back in 2020, we flagged up the risk of cybercriminals picking up dropped .nl domain names and using them to screen their activities. Now, a study by Infoblox, market leader in the secure network management sector, has shown that the risk we highlighted is as real as ever. Crooks are investing heavily in used domain names for purposes such as illegal streaming, phishing and malware. How do they do that, and what can you do to prevent abuse?

Why dropped domain names get re-registered

Every day, thousands of domain names are dropped because, for example, the business that owned them has closed, the project they were used for has ended, or no one is responsible for renewing them any more. Shortly after being let go, many of those names are given a second life by ‘drop-catchers’. Drop catching – picking up and re-registering domain names that other people have dropped – is a legitimate activity that usually has an honest motive. A name you no longer want may still be useful to someone else in the same line of business, for example. The extra traffic pulled by an established name can help a start-up get going. Or a trader may have a shrewd idea that a used domain name will gain value over time. However, there are risks associated with the re-registration of used domain names, because many such names still have ties to their previous owners.

Why reputation is valuable

A used domain name often comes with ‘extras’, such as backlinks from other sites and a good reputation with search engines. People may have bookmarked the domain and their mail platforms or software may treat it as trusted. From a marketing perspective, that makes many used domain names attractive. It’s easier to grow from an existing base than to build a search engine reputation from scratch. Tools such as MozBar can show you some of a domain’s reputation value. However, the same qualities that make a used domain name attractive to legitimate businesses can also make it attractive to crooks.

Why cybercriminals prefer used domain names

An established reputation is very useful to cybercriminals. A domain name that’s been in use a while, has inbound links and used to belong to a legitimate organisation may be trusted by people and security systems alike. E-mail can also play a part in making used domains attractive. Mail addresses at the domain may be known to suppliers, customers or online services. Sometimes, that enables the new registrant of a used domain name to receive mail intended for the old owner, or to get access to the old owner’s accounts by making password reset requests.

What the Infoblox study shows

While that background makes Infoblox’ findings essentially unsurprising, the scale of cybercriminals’ present-day operations is a concern. The report’s authors say that crooks are buying up and re-registering used domain names in huge numbers. According to Infoblox, tens of thousands of used domain names a day were re-registered in the first half of 2026. Some of those names were then used for malicious purposes, including phishing, illegal streaming, redirects to gambling sites and malware infrastructure. One case cited by the report involved a portfolio of thousands of domain names, representing an estimated investment of more than 7 million dollars. The willingness to put up so much money illustrates the value that crooks attach to the reputation and residual traffic that come with many used domain names.

What can registrants do?

If you no longer need a domain name, it’s a good idea to wait before letting it go. Find out what the name is worth and what risks its re-registration could pose. Make sure you’ve got a record of all the domain names made redundant by a rebranding exercise, merger, takeover or website closure. Check whether they’re still getting traffic, and whether there are any associated inbound links, e-mail addresses or accounts. Consider whether it would be better to retain the domain name, set up a redirect or transfer it to a reliable party. If you do decide that disposal is the best course of action, carefully remove any dependencies before letting the name go. Make sure that no old e-mail addresses are linked to online accounts, update references and inform any customers, suppliers and other contacts who might need to know. Because, when you let a domain name go, it isn’t erased forever. Its second life may be just beginning.