Traditionally, phishing campaigns leveraged generic top-level domains (TLDs) like .com, .net, or known-abuse TLDs such as .ru. Recently, attackers have shifted focus to more “trusted” regional country-code TLDs (ccTLDs), where abuse monitoring and automated blocking may be less stringent.
Two ccTLDs now trending in active abuse are:
- .es — The ccTLD for Spain, openly available for global registration.
- .com.br — The commercial domain extension for Brazil, widely recognized and trusted by local users.


