.xyz is a legitimate generic top-level domain. The ending alone does not make a website safe, unsafe, trustworthy, or fraudulent.
Treat an unknown .xyz link the same way you should treat any unfamiliar domain: check the complete address, how you received it, who operates the site, what it asks you to do, and what independent security sources report. Use more caution when money, passwords, identity documents, downloads, or crypto-wallet approvals are involved.
Current threat data also means the concern should not be dismissed. Spamhaus recorded 47,547 .xyz domains in its malicious or suspicious detections from October 2025 through March 2026. That is evidence of real abuse in the namespace. It is not evidence that every .xyz site, or even most .xyz sites, is malicious.
1) Separate the TLD from the website
IANA's delegation record lists .xyz as a generic top-level domain and XYZ.COM LLC as its sponsoring organization. It operates in the public Domain Name System like .com, .net, and other generic endings.
Registration creates control of a name. It does not verify that the registrant is honest, licensed, secure, or connected to a brand mentioned on the site. That limitation applies across open domain extensions.
Legitimate organizations use .xyz. Alphabet operates abc.xyz, Block operates block.xyz, and Starship Technologies operates starship.xyz. Criminals can also register or compromise domains under many endings.
The useful question is not “Can a safe site use .xyz?” It can. The useful question is “What does the exact site, link, and transaction show?”
2) Read the current abuse data correctly
The Spamhaus report for October 2025 through March 2026 provides a current, measured view:
.xyz measure | Reported value |
|---|---|
| New domains observed | 2,669,919 |
| Zone size used in report | 8,205,754 |
| Malicious or suspicious detections | 47,547 |
| Prior six-month detections | 39,660 |
| Change | +20% |
| Rank by raw count among all TLDs | 11th |
| Rank by raw count among gTLDs | 7th |
Dividing 47,547 by the 8,205,754-name zone gives about 0.58%. That is a context calculation, not a claim that the true abuse rate was exactly 0.58%.
Spamhaus says the report reflects domains its systems observed, identified, and listed. It does not represent every malicious or poor-reputation domain on the internet. A domain may also be maliciously registered or may be a legitimate site later compromised by an attacker.
.xyz did not appear in the report's top 20 gTLDs by percentage of zone listed; the twentieth entry in that table was 2.98%. That does not erase the 47,547 detections. It shows why both raw count and namespace size matter.
3) Put abuse statistics in market context
Domain abuse is not an .xyz-only problem.
Interisle's 2025 analysis examined about 85 million new gTLD registrations. By mid-May 2026, 8.5 million, or 10%, had been added to blocklists for malicious activity. Its model projected that the eventual figure could be closer to 16.8 million, or 20%.
Those are market-wide gTLD findings, not .xyz figures. They show that cheap, disposable registrations and weak provider controls can be useful to criminals across multiple open namespaces.
The report also found abuse concentrated among particular registrars and registries. Provider practices matter. A TLD label alone discards the registrar, hosting, account behavior, site content, and attack method that make a specific case risky.
4) Check the exact address
Read the address from right to left around the final dot.
In account.example.xyz, the registered domain is example.xyz. Text placed before it is a subdomain. In example.xyz.login-check.com, the registered domain is login-check.com, not example.xyz.
Look for:
- misspellings and substituted characters;
- extra words such as
verify,secure,wallet,support, orbilling; - a brand name placed in a subdomain of an unrelated registered domain;
- shortened links that hide the destination;
- copied login pages on a different domain; and
- a displayed link whose real destination differs when inspected.
CISA's phishing guidance highlights urgent or emotional language, requests for personal or financial information, and incorrect email addresses or links as common signs.
Do not click a suspicious link merely to investigate it. Navigate to the known organization through a bookmark, app, search result you independently verify, or a manually typed address.
5) Treat HTTPS as encryption, not identity
HTTPS is necessary for transmitting sensitive data, but a valid certificate does not prove that the site operator is trustworthy.
Chrome's connection guide explains that a secure connection keeps information sent to or received from a site private. It also tells users to verify the site name in the address bar, even on a secure connection.
A phishing site can obtain HTTPS for its own domain. The certificate can accurately confirm an encrypted connection to the attacker's site.
Stop if the browser displays a certificate, privacy, malware, or deceptive-site warning. Do not bypass it to reach a login, payment, download, or wallet connection.
6) Use independent safety checks
Google Safe Browsing checks URLs against Google-generated lists of unsafe web resources. Its site-status tool can help you investigate a URL without first loading the page normally.
A warning is a strong reason to stop. A clean result is not a guarantee. Google's own hacked-site guide says a clean Safe Browsing verdict does not prove a site has not been hacked to distribute spam.
Use a second reputable source when the stakes are high. Do not upload confidential links, private document URLs, reset tokens, or invitation links to a public scanner.
Browser and security-tool warnings also change over time. A newly created attack may not yet appear on a list, while a remediated site may retain a warning until a review completes.
7) Inspect registration context with RDAP
ICANN Lookup uses the Registration Data Access Protocol to return current registration data from registries or registrars. It may show:
- creation and expiration dates;
- registrar;
- domain status codes;
- nameservers;
- DNSSEC status; and
- available contact or abuse details.
A domain created yesterday for an unsolicited investment platform deserves more scrutiny than an established official address. Age still does not prove safety. Old domains can be sold, stolen, abandoned, or compromised, and legitimate launches can be new.
Redacted ownership is also not proof of fraud. ICANN's RDAP FAQ explains that privacy law and policy mean some registration data is not returned publicly.
Use RDAP to understand context and inconsistencies. Do not turn one field into a verdict.
8) Verify the organization independently
Before sending money or sensitive information, leave the site and verify the operator through sources it does not control.
Check:
- the legal company or nonprofit name;
- an official registration or regulator record where relevant;
- a phone number or email found independently;
- a physical address that matches the claimed operation;
- refund, privacy, delivery, and complaint terms;
- current public profiles with consistent history; and
- whether the offer appears on the organization's established app or main site.
Call a bank, employer, exchange, marketplace, or government office using a number from its official app, statement, or independently located website. Do not use the contact details inside the suspicious message.
For a crypto transaction, read the wallet approval, contract, chain, asset, amount, and spender. A polished page and familiar logo do not make an irreversible approval safe.
9) Judge what the site asks you to do
Risk rises when an unknown site asks for:
- a password, recovery code, or one-time code;
- remote access to a device;
- identity documents before explaining the legal entity and purpose;
- payment by gift card, crypto, wire, or another hard-to-reverse method;
- wallet connection or unlimited token approval;
- an executable, browser extension, or mobile configuration profile;
- an “activation,” “tax,” “release,” or “security” fee before withdrawal; or
- action under an artificial deadline.
No suffix makes those requests safe. Slow down, verify independently, and stop when the story changes after payment.
For ordinary ecommerce, use a payment method with appropriate dispute rights and keep order records. CISA's shopping guidance recommends checking the vendor's public profile and considering credit rather than debit because protections may differ.
10) Know what the registry does
XYZ Registry publishes an anti-abuse program covering spam, phishing, malware, and illegal activity. Its reporting form asks complainants for the domain, URL, headers, screenshots, antivirus reports, or other evidence appropriate to the incident.
That program provides an escalation route. It does not pre-approve every registration or guarantee that abuse will never appear.
If you encounter a malicious .xyz site:
- preserve the full URL and non-sensitive evidence;
- report it to the service being impersonated;
- report it through the browser or security provider;
- send a documented report to the registrar or hosting provider; and
- use the registry's abuse form when appropriate.
Report financial loss or identity theft to the relevant bank, platform, law-enforcement, and consumer-protection channels in your country.
11) Build a trustworthy .xyz site
An owner cannot control the reputation of every domain in the extension. The owner can reduce avoidable doubt and protect the exact property.
- Use a reputable registrar and enable phishing-resistant MFA where available.
- Turn on domain-transfer protection and registrar lock.
- Keep registrant and recovery details current.
- Use DNSSEC when the registrar, DNS provider, and operating plan support it.
- Maintain HTTPS, updates, backups, malware monitoring, and least-privilege access.
- Configure SPF, DKIM, and DMARC before using the domain for email.
- Publish a clear legal identity, contact route, privacy notice, and applicable transaction terms.
- Keep brand names, social profiles, app-store listings, and support channels consistent.
- Monitor Safe Browsing, blocklists, certificate issuance, and unexpected DNS changes.
- Prepare a response process for compromised pages, accounts, and subdomains.
Do not add security badges that cannot be substantiated. A transparent identity and predictable behavior are more useful than a generic “100% safe” claim.
12) Factor price into the risk model
On August 15, 2026, Namecheap displayed a $2.00 promotional first year and a $19.48 renewal for a standard .xyz. CentralNic announced that the standard wholesale price would rise from $12.10 to $13.30 on August 25, 2026 at 14:00 UTC.
Low introductory prices can reduce the cost of both experimentation and disposable abuse. They also help legitimate founders, students, artists, and developers launch sites. Price is an incentive, not proof of intent.
For a legitimate project, budget the renewal rather than the launch badge. Check whether the exact label is standard, numeric, or premium, and compare several years of ownership.
13) Use the 10-step safety check
Before trusting an unfamiliar .xyz website:
- Identify the exact registered domain.
- Ask how and why you received the link.
- Stop if the browser shows a security warning.
- Check the URL with a reputable safety service.
- Review current RDAP context.
- verify the legal identity independently.
- contact the organization outside the message.
- inspect what data, payment, download, or approval it requests.
- compare claims with reliable external sources.
- walk away if urgency or inconsistency remains.
A .xyz ending is one context signal, not a verdict. The complete evidence determines whether a particular interaction is worth the risk.