5,666
Total Detected
557
Last 30 Days
5.25M
Zone Scan Total
1,344
Serial Registrants
Incident
After PhishDestroy published this investigation, NameSilo filed a complaint with X (Twitter) that resulted in the suspension of our account. X reviewed the complaint and restored the account within days, stating there was no policy violation. The complaint and X's response are documented in the evidence repository.
Key Findings
Live report available: Full zone scan breakdown, serial registrant analysis, and raw domain lists are published on GitHub Pages.
View Live Report- 5,666 confirmed phishing domains across a registrar with 5.25 million total registrations. While NameSilo's absolute phishing rate (around 0.07%) is lower than NiceNIC's, the concentration within identifiable registrant clusters tells a different story: 1,344 serial registrant accounts are responsible for the overwhelming majority of phishing infrastructure detected.
- Serial registrant clusters are the core problem. Our analysis identified 1,344 distinct registrant profiles that have each registered multiple confirmed phishing domains. These accounts exhibit consistent patterns: similar contact data, shared payment methods inferred from registration timing, and coordinated domain expiration cycles that maximize the operational window while minimizing exposure costs. NameSilo's account verification controls are insufficient to detect or deter this pattern.
- 32.2% of scanned domains are dead. A dead domain rate above 30% indicates a churn-and-burn registration strategy that is well-established in NameSilo's customer base. Registrants deploy phishing infrastructure, drain it of value within days or weeks, and abandon it. The high dead rate is not accidental — it is the fingerprint of an abusive business model that NameSilo's pricing structure makes economically viable.
- Abuse reports submitted, takedowns not executed. PhishDestroy and partner organizations have submitted documented abuse reports against hundreds of NameSilo-registered phishing domains. Response times are inconsistent and a significant proportion of reported domains remain live for days after verified reports. No apparent account-level action has been taken against repeat registrants.
- The investigation triggered a retaliatory Twitter complaint. Following publication of the initial NameSilo report and public amplification on X, NameSilo filed a complaint with Twitter alleging the PhishDestroy account had violated platform rules. X's Trust and Safety team reviewed the complaint and restored the account, finding no violation. This sequence of events — a registrar complaining to a social platform to suppress a security researcher's publication — is documented and archived.
- Publicly traded status does not imply accountability. NameSilo's NASDAQ listing (ticker: URL) places it under SEC disclosure requirements and public shareholder scrutiny. Despite this, phishing domain abuse on the platform has continued unabated through the investigation period. The evidence repository is structured for investor relations and regulatory intake should downstream action become warranted.
Live Detection Feed
Most recent NameSilo phishing domains detected by PhishDestroy. Updated continuously.
| Domain | Detected | Type / Brand |
|---|---|---|
| loading-domain-example.com | 2026-06-20 | phishing |
| another-fake-domain.net | 2026-06-20 | phishing |
| third-placeholder-domain.org | 2026-06-19 | phishing |
| fourth-placeholder-domain.com | 2026-06-19 | phishing |
| fifth-placeholder-domain.xyz | 2026-06-18 | phishing |
Evidence & Related Investigation
Related Articles