Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale.

DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party.

During the first half of 2026, 50,400 dropcatch domains were re-registered each day in the generic top-level domains (gTLDs) like ".com" alone, a figure that jumps to around 65,000 when country code top-level domains (ccTLDs) are taken into consideration. These account for nearly 20$ of all daily gTLD and ccTLD registrations, meaning one out of five newly registered domains is a dropcatch domain.

"These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life," Infoblox said in an exhaustive three-part report shared with The Hacker News. "Researchers, security products, and reputation-based algorithms may view it more favorably than a genuinely brand-new registration. Threat actors know this and take advantage of it."

The cybersecurity company's analysis shows that .net and .xyz lead when it comes to dropcatch activity at the TLD level, surpassing .com, which comes in at the third spot. Other prominent TLDs include .org, .vip, .online, .store, .site, .app, and .shop. Most of these domains are re-registered via registrars like GoDaddy, Namecheap, and DropCatch.com, with each accounting for 5,246, 4,385, and 3,568 median daily dropcatch domains.