Security Stop-Press: Hackers Use Expired Domains To Spread Malware

Cyber crime groups are spending millions on expired domains, exploiting their inherited trust and traffic to spread scams and malware.

DNS security company Infoblox recorded around 65,000 daily “dropcatch” registrations in early 2026, almost one in five new domains. Its Vice President, Renée Burton, called them “a shortcut to both trust and traffic”.

The cyber crime operation dubbed “Sable Squirrel” controls over 10,000 domains, is estimated to have spent more than US$7 million and is linked to 31,000 malware samples.

Some pose as illegal sports-streaming sites while promoting gambling or controlling infected devices. Others remain embedded in compromised websites, providing ready-made victim traffic.

Businesses should catalogue domains, enable automatic renewal, remove obsolete links and DNS records, and treat ownership changes as a warning.

Company Check – Google.co.uk Phased Out

Google is retiring all country-specific search domains, meaning users who try to visit sites like google.co.uk will soon be automatically redirected to google.com instead.

Unified Search Experience

Google is ending its long-running use of country-specific domain names like google.co.uk, redirecting all users to a single global homepage, i.e. google.com. The change, already rolling out, marks a decisive step in Google’s ongoing shift towards a unified, location-aware search experience that doesn’t rely on domain suffixes to deliver local content.

Why Is Google Making This Change Now?

Although announced back in April 2025, Google first restructured its approach to localised results much further back in 2017. At that time, the company moved away from delivering search results based on which domain you typed (such as google.co.uk or google.com.au) and instead began using the physical location of a user to determine what they saw.

Google explained this at the time by noting that “one in five searches is location-related,” suggesting that using a device’s GPS or IP address was a more accurate way to serve local content than relying on top-level domains.

Fast-forward to now, and Google believes its localisation technology has advanced far enough to render ccTLDs (country code top-level domains) obsolete. That includes not just .co.uk for the UK, but also .com.br for Brazil, .co.in for India, .fr for France, and so on.

In a statement issued on 15 April 2025, Google said: “Because of this improvement, country-level domains are no longer necessary. We’ll begin redirecting traffic from these ccTLDs to google.com to streamline people’s experience on Search.”

What Exactly Will Happen, and When?

Google says it’s rolling out the change gradually “over the coming months.” Users who continue typing local addresses like google.co.uk into their browser will automatically be redirected to google.com instead.

What’s important to note is that this redirection is cosmetic and, as such, it won’t alter the substance of search results. Google is keen to reassure users that location-based relevance will still be maintained, saying: “This update will change what people see in their browser address bar, but it won’t affect the way Search works.”

It should be noted, however, that in some cases, users may be asked to log back into their Google account or re-enter search preferences such as language, region, or safe search filters. These prompts are part of the transition and are expected to be minimal.

What About Businesses and Search Professionals?

While most casual users may hardly notice the difference, the change is likely to have more significant implications for businesses, advertisers, and SEO professionals.

For years, digital marketers and local businesses relied on country-specific domains as a signal for local intent. Seeing .co.uk in the address bar reassured UK users they were getting localised content. With that visual cue gone, it seems that businesses may need to work harder to communicate relevance to their audience.

Some SEO consultants have already raised concerns, that ccTLDs have long played a psychological role in establishing trust and a sense of local identity and that removing them could take away a small but meaningful visual cue that helps users quickly judge whether a result is relevant to their region.

On the technical side, it’s more of a mixed bag. For example, consolidating everything under google.com may mean less domain fragmentation and a cleaner search experience, but some businesses fear they’ll have less control over regional visibility.

That said, Google’s localisation signals are now based on far more than just the domain name. For example, language, browser settings, search history, and even device-level data play a role. From a technical standpoint, this change may encourage businesses to invest more in structured data, content localisation, and region-specific marketing rather than relying on domain-level cues.

Will It Save Google Money?

Although cost-cutting wasn’t mentioned in Google’s official statement, it’s difficult to ignore the potential operational efficiencies behind this move.

It’s likely that maintaining dozens of ccTLDs, each with separate infrastructure, legal requirements, and occasional localised content, is expensive. As Google streamlines its services across all its products, it’s plausible this change is part of a broader effort to reduce complexity and overheads.

Keeping a multitude of domains also introduces additional security considerations and potential legal complications in different jurisdictions. Consolidating to google.com, therefore, offers a more scalable, consistent platform from both a technical and administrative point of view.

A Brief History of ccTLDs on Google

Google’s use of country-specific domains stretches back to its early international expansion in the early 2000s. Back then, separate ccTLDs made sense as they helped users access locally relevant content and gave governments and regulators some measure of oversight.

In fact, ccTLDs were once a key part of Google’s global strategy. For example, there was google.ca for Canada, google.co.jp for Japan, google.co.za for South Africa (the list goes on). For over a decade, typing a country-specific address was the main way users navigated to “their version” of Google.

However, by 2017, the writing was already on the wall. As mobile use exploded and GPS-based location detection improved, ccTLDs became more of a legacy feature than a critical component of localisation. By delivering results based on physical location rather than the domain used, Google effectively decoupled the URL from the search experience.

As Google put it back then: “Typing the relevant ccTLD in your browser will no longer bring you to the various country services—this preference should be managed directly in settings.”

Now, eight years later, Google’s retiring those domains for good.

How Can Users Still Control Their Search Experience?

With the ccTLD route disappearing, users who want to customise their search region still have some options. For example, Google recommends visiting the settings on google.com, then selecting ‘Settings’ (bottom-right corner), ‘Search settings’, and then ‘Language and region’.

From there, users can select their ‘Results Region’ and confirm their preferences. It’s not quite as effortless as typing .co.uk into the address bar, but it gives users some control nonetheless. It’s worth noting that this could also become a more critical step for people who travel frequently or use VPNs, where physical location and desired results don’t always align.

What Does This Mean For Your Business?

Google’s move to retire country-specific domains marks the end of an era, but not necessarily a dramatic shift in day-to-day use. For the vast majority of users, the redirection to google.com will be seamless, with local results continuing to surface just as they did before. In that sense, the change is largely symbolic: a visible reminder of how far the technology has come since the days when a .co.uk domain was essential for getting UK-relevant content.

Even so, the impact will be felt in some corners. For businesses and SEO professionals who have built strategies around ccTLDs, there’s now a need to refocus efforts. Visibility in local search will depend less on the domain in the address bar and more on how well a business optimises its content for a specific region using technical signals and structured data. That may be more work in the short term, but it could ultimately lead to a more level playing field, particularly for smaller businesses that don’t operate country-specific sites but still want to compete in local markets.

For UK businesses in particular, there’s a communications challenge. Losing the .co.uk cue means finding other ways to demonstrate relevance and trust to a local audience. Whether through clear regional language, local contact details, or targeted content, companies will need to be intentional about showing that they’re rooted in the UK market. It may also prompt more attention to things like Google Business Profiles, location-based advertising, and hyperlocal content strategies.

For Google, this is as much about simplification as it is about modernisation. By consolidating its domains, the company reduces redundancy, eases infrastructure demands, and likely saves money, all while continuing to meet legal obligations in different countries. It also fits neatly with Google’s wider goal of delivering a consistent user experience across its ecosystem, from Search to Maps to AI-powered features.

Ultimately, this change reflects how the web, and the way we use it, has evolved. Search is no longer bound by the old rules of geography and domain suffixes. It’s now driven by data, context, and personalisation. This means that while the disappearance of google.co.uk from the browser bar may feel like a nostalgic loss for some, the mechanics of search will continue to evolve around us, often invisibly, and usually with far-reaching implications.

Tech Insight : DMARC Diligence (Part 3) : Implementing and Optimising DMARC for Maximum Security

In this third and final part of our series of ‘DMARC Diligence’ insights, we explore the detailed process of DMARC deployment, its monitoring, optimisation, and preparing businesses for future email security challenges.

Last Week … 

Last week in part 2 of this series of ‘DMARC Diligence’ articles, we looked at the crucial yet often neglected aspect of securing non-sending or “forgotten” domains against cyber threats. Here we highlighted the potential risks posed by these domains when not protected by DMARC policies, and offered some guidance on how businesses can extend their DMARC implementation to cover all owned domains, thereby preventing unauthorised use for spam or phishing attacks.

This Week … Implementing DMARC: A Step-by-Step Approach 

As noted in the previous article in this series, implementing DMARC is now critical for UK businesses to protect against threats like email spoofing and phishing.

To briefly summarise a step-by-step approach to implementing this, businesses can start by ensuring Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) are correctly set up for the domain(s), as DMARC relies on these for email authentication. Next, it’s a case of creating a DMARC record with a policy of “none” to monitor traffic without affecting it. This record is added to your DNS.

Over time, it’s important to analyse your DMARC reports in order to identify any unauthorised use. Finally, gradually shift your policy to “quarantine” or “reject” to block or flag unauthenticated emails, enhancing your email security posture. Looking at this approach in a bit more detail, implementing DMARC means:

– Understanding SPF and DKIM. Before implementing DMARC, ensure you have SPF and DKIM records correctly set up for your domain. These records help in email verification and are crucial for DMARC to function effectively.

– Creating a DMARC record. Draft a DMARC TXT record for your DNS. Start with a policy of ‘none’ (p=none) to monitor your email traffic without affecting it. This stage is critical for understanding your email ecosystem and preparing for stricter enforcement without impacting legitimate email delivery.

– Analysing the reports. Use the data collected from DMARC reports (Aggregate reports – RUA, and Forensic reports – RUF) to identify legitimate sources of email and potential gaps in email authentication practices.

– Gradually adjusting policy: Gradually adjust your DMARC policy from ‘none’ to ‘quarantine’ (p=quarantine) as you become more confident in your email authentication setup. This move will start to prevent unauthenticated emails from reaching inboxes but may still allow them to be reviewed.

– Full enforcement. Once you’re assured that legitimate emails are correctly authenticated and not negatively impacted, shift your policy to ‘reject’ (p=reject). This is the final step where unauthenticated emails are actively blocked, providing full protection against phishing, and spoofing under DMARC.

– Continuous monitoring and updating. Email authentication landscapes and practices evolve, so it’s crucial to continuously monitor DMARC reports and update your SPF, DKIM, and DMARC settings as necessary to adapt to new email flows, domain changes, or security threats.

Monitoring and Reporting – The Key to Effective DMARC 

For businesses, effective DMARC implementation relies heavily on consistent monitoring and reporting.

Why? 

By analysing DMARC reports, businesses can gain insights into both legitimate and fraudulent email sources using their domain. This process not only helps in identifying authentication failures but also in refining DMARC policies over time (as suggested in the step-by-step approach above) for better security.
Remember, regular reviews of these reports is essential for adapting to new threats and ensuring email communication integrity.

Optimising DMARC Policies 

Optimising a DMARC policy involves fine-tuning it to create a balance between security against spoofing and phishing, and ensuring legitimate emails are delivered smoothly.

But How? 

The starting point (as mentioned above) is the analysis of your DMARC reports to identify authentication failures and adjust your SPF and DKIM setups accordingly.

A Phased Approach 

Taking a phased approach, i.e. gradually increasing the DMARC policy from ‘none’ to ‘quarantine’ and then to ‘reject’ as confidence in your email authentication improves, is the way to minimise potential disruptions to legitimate email flow while maximising protection against unauthorised use of your domain.

Future-Proofing Your Email Security Strategy 

Going forward, looking at ways to future-proof your business email security strategy, these could include:

– Keeping up to date with emerging threats and trends in email security (continuous education).

– Implementing advanced security technologies like AI-driven threat detection can offer proactive protection.

– Regularly reviewing and updating your email authentication protocols (SPF, DKIM, DMARC) to adapt to changes in your email infrastructure.

– Fostering a security-aware culture within your business e.g., using training to recognising phishing attempts and safe email practices.

– Engage in industry forums and cybersecurity communities to help stay ahead of evolving email threats and to gain and share information about best practices.

What Does This Mean For Your Business? 

For UK businesses, implementing and optimising DMARC, as outlined in this final instalment, is a commitment to safeguarding email communications that benefits your business and your customers. Taking a step-by-step approach, as outlined above, from establishing SPF and DKIM records, through to DMARC policy enforcement, are now crucial for building an effective defence against email spoofing and phishing (these are now major threats). Taking the phased approach of regular monitoring and gradual policy adjustments ensures that businesses can not only react to current threats but also proactively adapt to emerging challenges. This strategic approach to email security is essential in maintaining the trust of your customers and partners, protecting your brand’s reputation, and complying with today’s data protection regulations. It’s also worth remembering that actively engaging in continuous education and leveraging advanced technologies are ways to stay ahead in the fast-evolving cybersecurity landscape.

Tech Insight : DMARC Diligence (Part 2) : The Forgotten Domains : A Hidden Vulnerability

In this second article of the “DMARC Diligence” series, we shift our focus towards securing non-sending or “forgotten” domains and outline a strategy for their protection through DMARC implementation.

Recap Of Part 1 

You may remember that in part one of this DMARC Due Diligence series of articles we laid the groundwork by exploring the essentials of the email authentication protocols SPF, DKIM, and DMARC. We learned how these mechanisms work in tandem to validate email sources, ensuring that only authenticated emails reach their intended destinations. The primary takeaway was the importance of implementing these protocols to shield email communications from the prevalent threats of phishing and spoofing attacks.

Here, in Part Two of the three-part series, we take a look at some key issues around securing non-sending or “forgotten” domains.

The Risk Of Non-Sending Domains 

Businesses often accumulate multiple domain names, yet routinely only a select few which are actively used for emails. This leaves a number of domains essentially dormant, with no emails being sent from them. These can be referred to as non-sending or “forgotten” domains.

However, their existence and registration on servers mean that even if they are dormant/forgotten, they’re still viable for exploitation and make ideal targets for cybercriminals to conduct spoofing and phishing attacks under the guise of your reputable name.

How Big Is The Problem? 

The problem of dormant or forgotten domains and their exploitation for email spoofing is significant and aligns with broader issues of email server misconfiguration and domain spoofing that impact businesses globally. For example, a KnowBe4 study (which used a domain spoof test) discovered that 82 per cent of email servers are misconfigured, thereby potentially enabling domain spoofing. Domain spoofing extends beyond email to include website spoofing, where fraudsters profit from the reputation of reputable domains, costing advertisers up to $1 million in lost revenue per month.

Recent Examples  

Examples of non-sending or “forgotten” domains being exploited by cyber-criminals include:

– As reported by Krebs back in 2020, attackers exploiting an authentication weakness at GoDaddy (the world’s largest domain name registrar) by using legitimate but inactive domains to distribute malware, including a potent strain of ransomware named Gand Crab. Despite efforts to fix the vulnerability and clean up affected domains, new campaigns exploiting these dormant domains emerged, thereby highlighting the ongoing challenge of securing unused domains against cyber exploitation.

– Just this month, Cyber Security Company, Guardio Labs reported uncovering what they referred to as a major “SubdoMailing” campaign which involved the hijacking of 8,000+ trusted domains to send millions of spam and malicious phishing emails daily. The big brands whose subdomains they reported were being exploited in the campaign included MSN, VMware, McAfee, The Economist, Cornell University, CBS, Marvel, and eBay.

The DMARC Solution For Non-Sending/Forgotten Domains 

As highlighted in the previous article in this series, DMARC offers a way to authenticate mail and specify how unauthenticated emails should be treated. However, its real power lies in its ability to be applied to all your domains, active or dormant. This means that by configuring DMARC records for your non-sending domains, you can effectively seal off a potential backdoor for attackers, preventing them from masquerading as your business in malicious campaigns.

Step-by-Step DMARC Implementation For Non-Sending Domains 

With this in mind, here’s an example of a step-by-step strategy for businesses with multiple domains for using DMARC to close the backdoor vulnerability that non-sending/forgotten domains provide:

– Conduct a comprehensive domain audit to identify all the domains your business owns. Next, distinguish between those used for sending emails and those that are not.

– For your non-sending domains, establish DMARC records in the DNS with an initial policy of p=none. This monitoring mode allows you to collect data on how these domains might be exploited without impacting legitimate email traffic.

– Analyse DMARC reports. Regularly reviewing the DMARC reports to identify unauthorised usage of your non-sending domains can provide insights to guide you in tightening the DMARC policy to more restrictive settings (p=quarantine or p=reject), effectively blocking malicious emails.

– Ongoing vigilance. With the cyber threat landscape perpetually evolving, getting into the habit of continually monitoring your DMARC reports and adjusting your policies as needed can help maintain robust protection against emerging threats.

What Does This Mean For Your Business? 

Acknowledging and securing your non-sending/forgotten domains with DMARC is now not just a technical safeguard but is now an essential strategy in fortifying your business’s cybersecurity posture. With email fraud now rampant, overlooking these domains could leave your business susceptible to cyberattacks, compromising your integrity and the trust you’ve built with your clients and partners.

Also, as regulations around data protection become increasingly stringent, ensuring that all your domains are shielded with DMARC demonstrates a proactive stance on cybersecurity. This not only helps compliance with laws like GDPR but also positions your business as a trustworthy and secure entity in the digital marketplace.

The protection of non-sending domains via DMARC implementation, therefore, is a crucial step in closing the security gaps within your business’s digital domain strategy.

Next Week…

Next week, in the last of this three-article series, we’ll be focusing on a detailed step-by-step guide for DMARC implementation, the crucial role of monitoring and reporting for effective DMARC management, strategies for optimising DMARC policies, and preparing for future email security challenges. The hope is that this series will provide UK businesses with insights into maximising email security, enhancing brand protection, and ensuring compliance with evolving regulations.