Strategic Risk Intelligence

Executive threat landscape with trend analysis and governance-ready narratives

Back to Dashboard
Filters
Clear

Strategic Overview

High-level posture indicators with period-over-period trends

29731
Total Threats
+64.8% vs prior 30d
27034
Active Threats
+67.0% vs prior 30d
9.1%
Neutralized
-2.7pp vs prior 30d
431
Critical Risk
+92.9% vs prior 30d
2593
Emerging (7d)
+26.4% vs prior 30d
Executive Summary

Threat activity has intensified, with total detected threats increasing 64.8% compared to the prior 30-day period. Of 29731 total threats, 431 classified as critical risk and 53.0% are email-capable (impersonation ready). Response posture is a gap requiring attention at 9.1% neutralization, down 2.7pp from the prior period — most identified threats remain unaddressed.

Last updated Apr 07, 2026 03:25
Detection Trends (30 Days)

Threat Composition & Exposure

How mature are detected threats and what systemic exposure do they represent?

Risk Score Distribution
Active High-Risk Domain Age
Threat Lifecycle Funnel

Progression from dormant registration to active threat. Domains can appear in multiple stages.

Dormant
30%
8841
Infrastructure Ready
20%
6051
Active (Live)
38%
11359
Weaponized
22%
6408
Confirmed Phishing
3%
814
Neutralized
9%
2697

Infrastructure Intelligence

Which registrars, nameservers, and TLDs are concentrated in your threat landscape?

Top Registrars
Registrar Count Avg Risk Response Rate
GoDaddy.com, LLC 3874 24
2%
NAMECHEAP INC 1093 57
2%
NameSilo, LLC 992 42
19%
Dominet (HK) Limited 976 34
1%
Dynadot Inc 695 21
2%
HOSTINGER operations, UAB 681 50
6%
Dynadot LLC 614 9
30%
Cloudflare, Inc. 611 42
1%
Spaceship, Inc. 594 22
5%
TUCOWS.COM, CO. 493 46
2%
Top Nameservers
Nameserver Count Avg Risk Share
ns1.parklogic.com., ns2.parklogic.com., ns3.parklogic.com. 9 23
anan.ns.giantpanda.com., meisheng.ns.giantpanda.com. 9 43
ns1.iwantmyname.net., ns2.iwantmyname.net., ns3.iwantmyname.net. 9 7
pns61.cloudns.net., pns62.cloudns.com., pns63.cloudns.net. 9 49
581.ns1.abovedomains.com., 581.ns2.abovedomains.com. 9 42
norman.ns.cloudflare.com., teagan.ns.cloudflare.com. 9 19
ns1.cloudoon.com., ns2.cloudoon.net., ns3.cloudoon.org. 9 38
ns1.dnsowl.com., ns2.dnsowl.com. 9 21
ns.second-ns.com., ns1.your-server.de., ns3.second-ns.de. 9 21
sk.s5.cm.ns1.39.ztomy.com., sk.s5.cm.ns2.39.ztomy.com. 9 28

Active Threats & Response

Response effectiveness, emerging threats, and recent risk changes

Response Effectiveness
1291
Taken Down
1553
Blacklisted
2697
Total Neutralized
Takedown Rate 4.3%
Blacklist Rate 5.2%
Neutralization Rate 9.1%
Discovery Method Breakdown
Emerging Threats (Last 7 Days, Risk 50+)
Lookalike Domain Target Domain Risk Score Registrar Website Detected
coinbasewallet-support.com BLOCKED coinbase.com 100 HOSTINGER operations, UAB Parked 4 days, 23 hours ago
scoinbase.com BLOCKED coinbase.com 100 HOSTINGER operations, UAB Parked 3 days, 8 hours ago
replykraken.help kraken.com 95 NameSilo, LLC Parked 3 days, 8 hours ago
peelshopify.com shopify.com 95 Porkbun LLC Phishing 3 days, 8 hours ago
replies-kraken.com kraken.com 95 NameSilo, LLC Parked 5 days, 23 hours ago
airbnb-reserve.online airbnb.com 90 NameSilo, LLC Offline 3 days ago
1948562-coinbase.com BLOCKED coinbase.com 90 NameSilo, LLC Parked 6 days, 16 hours ago
sign-airwallex.work BLOCKED airwallex.com 90 NameSilo, LLC Parked 6 days, 17 hours ago
sign-airwallex.cfd BLOCKED airwallex.com 90 NameSilo, LLC Parked 6 days, 17 hours ago
sign-airwallex.xyz BLOCKED airwallex.com 90 NameSilo, LLC Parked 6 days, 17 hours ago
instagramvideodownloader.online BLOCKED instagram.com 90 GoDaddy.com, LLC Phishing 3 days, 8 hours ago
helper-coinbase.com BLOCKED coinbase.com 90 NameSilo, LLC Parked 3 days, 8 hours ago
checkoutcommeune.com checkout.com 85 Porkbun LLC Live 3 days, 8 hours ago
ma-xfinity.com xfinity.com 85 Automattic Inc. Phishing 19 hours, 17 minutes ago
jpmorganchaselegal.com jpmorgan.com 85 TUCOWS.COM, CO. Phishing 23 hours, 52 minutes ago
Recent Risk Increases
Lookalike Domain Target Domain Previous Current Change What Changed Date
cridlandbookings.com booking.com 10 50 +40 +Dangerous Email Provider (10pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) Mar 28, 2026
eu-58432580-booking.homes BLOCKED booking.com 40 80 +40 +Blacklisted (30pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) +Website Live (10pts) Mar 28, 2026
tcprbookings.com booking.com 10 50 +40 +Dangerous Email Provider (10pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) Mar 28, 2026
eu-30848712-booking.homes BLOCKED booking.com 40 80 +40 +Blacklisted (30pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) +Website Live (10pts) Mar 28, 2026
linkpoolcloud.com icloud.com 20 60 +40 +Dangerous Email Provider (10pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) +Website Live (10pts) Mar 28, 2026
githublogin.org github.com 10 50 +40 +MX Records (15pts) +SPF Records (15pts) +Website Live (10pts) Mar 29, 2026
expedialogisticsllc.com expedia.com 15 55 +40 +Dangerous Email Provider (10pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) +Website Parked (5pts) Apr 02, 2026
web-zoom.us zoom.us 45 85 +40 +Dangerous Email Provider (10pts) +Dangerous Registrar (25pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) +Website Live (10pts) Mar 29, 2026
protonetswick.info proton.me 0 40 +40 +Dangerous Email Provider (10pts) +MX Records (15pts) +SPF Records (15pts) Mar 26, 2026
lava-icloud.com icloud.com 10 50 +40 +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) +Website Live (10pts) Mar 29, 2026
gojicloud.com icloud.com 35 75 +40 +Dangerous Registrar (25pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) +Website Live (10pts) Mar 28, 2026
shopiify.com shopify.com 10 50 +40 +MX Records (15pts) +SPF Records (15pts) +Website Live (10pts) Mar 28, 2026
arcmailcloudservices.com icloud.com 20 60 +40 +Dangerous Email Provider (10pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) +Website Live (10pts) Mar 26, 2026
arcmailcloud.com icloud.com 20 60 +40 +Dangerous Email Provider (10pts) +MX Records (15pts) +SPF Records (15pts) +Very Recent Domain (10pts) +Website Live (10pts) Mar 25, 2026
bookingmassages.com booking.com 10 50 +40 +MX Records (15pts) +SPF Records (15pts) +Website Live (10pts) Mar 25, 2026

Domain-Level Analysis

Which of your brands are most targeted and carry the highest aggregate risk?

Most Targeted Domains
# Legitimate Domain Lookalikes Avg Risk High Risk Threat Level Response Rate
1 booking.com 2271 31 238 Medium
6%
2 icloud.com 1936 31 222 Medium
15%
3 americanexpress.com 1361 32 2 Medium
1%
4 checkout.com 1099 26 42 Medium
7%
5 binance.com 943 23 30 Low
19%
6 whatsapp.com 838 21 22 Low
17%
7 shopify.com 791 22 36 Low
2%
8 schwab.com 728 14 8 Low
32%
9 intuit.com 643 32 60 Medium
4%
10 wise.com 614 27 9 Medium
2%
Domain Protection Status
10/10
DMARC Protected (quarantine/reject)
7/10
BIMI Configured (brand logo in inbox)
# Domain Lookalikes DMARC Policy Protected BIMI
1 booking.com 2271 reject
2 icloud.com 1936 quarantine
3 americanexpress.com 1361 reject
4 checkout.com 1099 reject
5 binance.com 943 quarantine
6 whatsapp.com 838 reject
7 shopify.com 791 reject
8 schwab.com 728 reject
9 intuit.com 643 reject
10 wise.com 614 reject
Highest Average Risk Domains
# Legitimate Domain Avg Risk Max Risk Lookalikes Severity Response Rate
81 visa.com 23 90 458 Low
1%
82 uber.com 23 75 400 Low
2%
83 bancobpm.it 23 70 8 Low
25%
84 unicredit.eu 23 95 51 Low
22%
85 binance.com 23 100 943 Low
19%
86 deutsche-boerse.com 23 60 32 Low
3%
87 alipay.com 23 75 244 Low
5%
88 doordash.com 22 100 170 Low
4%
89 bnpparibasfortis.com 22 55 11 Low
9%
90 shopify.com 22 95 791 Low
2%