5 min read

The 2026-2027 TLD Launches Your Brand Protection Program Should Be Watching

Facebook logo
Facebook logo
X (formerly Twitter) logo
X (formerly Twitter) logo
LinkedIn logo
LinkedIn logo
Reddit logo
Reddit logo

Overview

Every time a new top-level domain launches, it creates a brief window of opportunity for cybercriminals. Because registration dates are announced well in advance, attackers know exactly when new extensions become available and can move quickly to secure lookalike domains before any meaningful reputation data exists.

For brand protection teams, that means each TLD launch expands the attack surface. And with extensions like .pay, .fly, .dot, .eat, and .here scheduled to move through launch phases into 2027, organizations face a practical question: How much of that growing domain landscape can they realistically defend?

But, the good news is these launches are predictable and follow a public schedule. By monitoring newly registered domains and looking beyond the extensions and lookalikes already on your radar, you can stay ahead of emerging risks.

Key takeaways

  • New top-level domains launch with no reputation history, so lookalike domains cost next to nothing to register in the days right after general availability.

  • Registration spikes in the thousands hit newly launched TLDs within days of GA, before most brand protection teams even start watching.

  • Attackers also weaponize infrastructure TLDs like .arpa, which means monitoring scoped only to obviously plausible extensions misses live abuse.

  • Defensive registration closes off the cheapest attacks, but no brand can register every string across every new extension, meaning brand protection teams must monitor for domains before they go live.

Key takeaways

  • New top-level domains launch with no reputation history, so lookalike domains cost next to nothing to register in the days right after general availability.

  • Registration spikes in the thousands hit newly launched TLDs within days of GA, before most brand protection teams even start watching.

  • Attackers also weaponize infrastructure TLDs like .arpa, which means monitoring scoped only to obviously plausible extensions misses live abuse.

  • Defensive registration closes off the cheapest attacks, but no brand can register every string across every new extension, meaning brand protection teams must monitor for domains before they go live.

The attackers' launch calendar

Typosquat monitoring on established .com TLDs is, of course, critical to the brand protection process. It looks for some basic attacker tactics like common swaps, doubled letters, and hyphenated inserts that give a lookalike domain away. It works because .com has decades of reputation data behind it.

But every new top-level domain extension resets what a legitimate domain footprint looks like. The blocklist patterns built for .com do not transfer, and the extension itself is unfamiliar to customers and has no history behind it.

The Internet Corporation for Assigned Names and Numbers (ICANN) coordinates the introduction of generic top-level domains (gTLDs), with the Internet Assigned Numbers Authority (IANA) adding approved extensions to the DNS root zone. 

Each new gTLD has a registry operator responsible for managing the extension and its registration policies.

The latest wave of new TLDs includes .pay, .fly, .dot, .eat, and .here, with hundreds of additional new domain extensions moving through ICANN's New gTLD Program.

New gTLD applications

On Oct. 7, 2026, ICANN unveiled a round of more than 1,600 applications of new gTLDs that will now go through a review period. These TLDs could be available for use as early as April 2027, if approved. Proposed new gTLDs include .vpn, .coin, .nft, .cyber, and .chatgpt.

New gTLD applications

On Oct. 7, 2026, ICANN unveiled a round of more than 1,600 applications of new gTLDs that will now go through a review period. These TLDs could be available for use as early as April 2027, if approved. Proposed new gTLDs include .vpn, .coin, .nft, .cyber, and .chatgpt.

Each launch follows its own path to general availability: A sunrise period gives eligible trademark owners early access to domain registration, while some launches also include a limited registration period, landrush period, or Early Access Program (EAP) before registration opens to everyone.

Trademark owners generally need their marks recorded with the Trademark Clearinghouse (TMCH) to use the sunrise and trademark claims protections. 

That gives brand owners something concrete to plan around before general availability: See which protections apply, decide which names matter enough to register, and know when to increase monitoring.

Use the public schedule to your advantage, checking TLD launch schedules against your existing monitoring:

TLD

Period

Start

End

.phone

Sunrise Phase

Oct. 6, 2026

Jan. 4, 2027

.phone

Trademark Claims

Jan. 5, 2027

April 5, 2027

.dot

Trademark Claims

Oct. 20, 2026

Jan. 18, 2027

.eat

Trademark Claims

Nov. 10, 2026

–

.here

Trademark Claims

Nov. 10, 2026

–

.fly

Trademark Claims

Nov. 10, 2026

–

.pay

Trademark Claims

Feb. 1, 2027

May 2, 2027

Upcoming TLD release phases and dates as of Sept. 14, 2026. Launch schedules can change, so confirm dates against the registry schedule before publication.

Abuse concentrates in the newest name spaces

Knowing when a TLD launches matters because of what the name space attracts once it opens to public registration.

Reported abuse is rare across the whole DNS, but it clusters. The DNS Research Federation tracked abuse reports over 90 days in 2025 and found new gTLDs running 32 times the rate of legacy domains like .com and .net, and 25 times the rate of country-code domains.

The same analysis breaks the new gTLDs down by how they are run, and the spread is wide. Generic word TLDs that sell to anyone, .top and .xyz among them, carried the highest reported rate, while community and internationalized TLDs stayed below a tenth of a percent. Brand TLDs, closed to outside registration, recorded no reported abuse at all.

Small percentages produce large numbers at this scale. Nearly 49 million domains are registered across more than 1,100 new gTLDs, with .xyz alone accounting for around 14 million.Interisle Consulting Group’s Cybercrime Supply Chain 2025 study found that new gTLDs made up just 12% of the domain market, but accounted for nearly half of all cybercrime domains reported. 

More than 7.3 million domains used in cyberattacks were registered in bulk.

Registered domains and cybercrime domains across .com/.net, legacy TLDs, country-code TLDs (ccTLDs), and new gTLDs. Source: Interisle Consulting Group.

For a brand protection team, that creates a prioritization problem. Thousands of registrations follow every launch, only a handful will matter to your brand, and reviewing each one by hand is not an option at that volume.

The registration model gives you somewhere to start. An open generic word TLD, for example, that’s selling to anyone at scale carries more risk than a community TLD with verification requirements behind it. Netcraft’s detection network monitors new registrations for brand matches and other risk signals as they appear, so teams can investigate suspicious domains before they become customer-facing threats.

Even infrastructure TLDs get weaponized

Attackers also weaponize infrastructure TLDs.

.arpa is a useful example. It supports infrastructure functions within the Domain Name System (DNS), including reverse DNS, which maps IP addresses back to domain names. It should not host ordinary web content. Yet in March 2026, attackers were documented using .arpa domains to serve phishing content impersonating major brands.

For a brand protection team, the interesting part is where the attack appeared. 

This isn’t a typosquat in the traditional sense. Attackers don’t register .arpa domains hoping that a customer will misread it. The goal is to evade brand protection programs scoped to TLDs that could plausibly impersonate a brand.

The safer assumption is that the brand tells you what to watch for, rather than the extension telling you where to watch. That’s also how Netcraft approaches domain monitoring: looking for relevant brand abuse, registration and hosting activity across TLDs rather than asking teams to predict which extensions attackers will use next.

Drop domains widen the same exposure

And new extensions are only one way unfamiliar domains enter the picture. Sometimes the risky domain is very familiar because your organization used to own it.

When a domain expires, someone else can register it. IT Brew reported that more than 50,000 domains were dropcaught each day across .com, .org, .net, .biz, and .info during the first half of 2026.

Brand protection teams experience this as a different version of the same problem. 

A new extension gives an attacker a name your organization never owned. A dropped domain gives them one that customers, employees, search engines, and other sites already associated with your brand. The attacker does not need to invent a convincing variation when the old domain still carries links, recognition, and traffic.

That's why domain protection can't stop at registration monitoring for new launches. A domain a brand already owned and let lapse is just as exploitable as one it never registered.

Defensive registration cannot cover the board

None of this makes defensive registration pointless. Sunrise and trademark claims periods exist for good reason, and securing the domains most closely associated with your brand can remove some obvious opportunities before attackers get them.

The difficulty is deciding where to stop.

Defensive registration closes the door against the cheapest attacks but it was never built to scale against a namespace that grows every time ICANN delegates another TLD. 

Every new extension creates another set of exact matches, misspellings, added words, hyphens, and other variations you could theoretically own. Add dropped domains to that picture and registration quickly stops being a complete answer.

A more workable division of labor is to register what you cannot afford to lose and monitor what you cannot reasonably own.

That puts more weight on what happens between registration and activation. A suspicious domain does not have to host a phishing page before it becomes worth investigating. Its name, registration timing, infrastructure, and relationship to other known threats can all provide useful signals earlier.

Netcraft calls the action that follows preemptive domain disruption, with the goal of identifying and disrupting malicious lookalike domains before attackers activate them. 

More than 50,000 takedowns later, Netcraft holds a 99.8% success rate, removing phishing URLs in as little as 2.1 hours. Relationships with more than 70 registrars are what keep the escalation path short.

For teams planning around the next wave of TLD launches, that’s the value of knowing the dates in advance: You can secure the names that matter and start watching the rest before someone else registers them.

Should companies defensively register their brand on every new TLD?

No. Defensive registration makes the most sense for a company’s highest-risk exact-match strings, since trademark holders can’t register every permutation across every launch. Some organizations also operate their own branded TLDs, but that does not remove the need to watch for impersonation across other extensions. Sunrise and trademark claims periods can protect priority names during a new launch, while continuous monitoring covers the registrations you cannot reasonably own.

Why are new TLDs risky for brands?

New TLDs have no reputation history, so the blocklist patterns brand protection teams built for .com don’t transfer. Lookalike domains cost almost nothing to register right after general availability, and registration data shows abuse spikes within days of launch.

What is typosquatting and how does it work on newly launched TLDs?

Typosquatting registers a domain that mimics a brand through subtle changes to the URL. On established TLDs like .com, years of reputation data help filters catch these patterns, but with new TLDs, the extension itself is unfamiliar, so a lookalike domain has no reputation.

What are drop domains and why do attackers target them?

Drop domains are expired domains re-registered within hours of lapsing. They carry residual trust from a brand’s former use without requiring typosquatting. Domain takedown services that monitor registration activity continuously catch them the same way they catch new TLD abuse.

What is an impersonation-based attack?

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Don't want to miss out on updates?

Don't want to miss out on updates?

Don't want to miss out on updates?

Join our mailing list for regular blog posts and case studies from Netcraft.