Cheap Domains, Cheap Security? Budget TLDs vs the Rest
Published
Figures as of 16 August 2026 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.
The headline: the budget-TLD cohort fails at 88.8%
Across the seven best-known budget TLDs — .xyz, .top, .icu, .online, .site, .shop and .club — 88.8% of the 19,248,968 domains we graded in the August 2026 census scored an F. On .com the F rate is 72.4%. On Switzerland’s .ch it is 33.7%. Line the endings up from cheapest promotional price to most expensive, and security grades fall down the same ladder.
The extremes are stark. On .top, 96.1% of graded domains score an F, and just 610 domains out of 2.87 million graded — about 1 in 4,700 — reach an A. And that only counts the .top domains alive enough to grade: 51.5% of the 12.5 million .top names we scanned were dead.
Key numbers
- 88.8% of graded domains on seven budget TLDs (.xyz, .top, .icu, .online, .site, .shop, .club) score an F — 17,100,336 of 19,248,968 graded, August 2026 census.
- .top has the worst grade profile of the cohort: 96.1% F, with .icu close behind at 95.8%.
- The .com F rate is 72.4% across 140,998,915 graded domains — 16.4 points better than the budget cohort.
- Only 0.38% of budget-TLD domains reach a B or better, versus 2.02% on .com and 13.08% on .nl — a 34× gap between the cheapest tier and the best ccTLD in this comparison.
- 6,415 A-grade domains exist across all seven budget TLDs combined — about 1 in 3,000. On .com it’s 1 in 656.
- 51.5% of scanned .top domains were dead — 6,465,016 of 12,548,818 — before grading even began.
What counts as a “budget” TLD here?
An honest label first: our census measures security, not prices. There is no pricing dataset joined to these numbers. The tiers in this article are qualitative, based on public industry knowledge of how these endings are marketed — and we flag that basis every time it matters.
With that stated: .xyz, .top and .icu are the endings most associated with aggressive first-year promotions, routinely advertised at or under a dollar or two (industry knowledge, not census data). .online, .site, .shop and .club sit in a similar promotional bracket, usually a few dollars in year one. By contrast, .com carries a regulated wholesale price of roughly ten dollars (industry knowledge), and European ccTLDs like .ch, .nl, .fr and .de typically retail in the five-to-fifteen-euro range through local registrars, sometimes with residency or local-presence conventions attached (industry knowledge again).
The census supplies the other axis: a security grade for every live domain, computed the same way across every TLD from externally observable checks. Same scanner, same methodology, same month. The only thing that changes between rows in the tables below is the ending.
How steep is the gradient?
Very. Here is the full comparison, sorted by F rate. Grade shares use the graded-row basis for each TLD; “B or better” combines A+, A and B.
| TLD | Tier (industry knowledge) | Graded domains | F rate | B or better |
|---|---|---|---|---|
| .top | budget promo | 2,872,294 | 96.1% | 0.18% |
| .icu | budget promo | 243,620 | 95.8% | 0.22% |
| .xyz | budget promo | 8,593,109 | 89.1% | 0.22% |
| .club | budget promo | 448,613 | 87.6% | 0.85% |
| .site | budget promo | 1,494,103 | 86.0% | 0.53% |
| .shop | budget promo | 3,074,582 | 85.9% | 0.60% |
| .online | budget promo | 2,522,647 | 84.5% | 0.70% |
| .net | standard gTLD | 10,051,876 | 79.9% | 1.39% |
| .info | standard gTLD | 4,113,908 | 77.7% | 3.97% |
| .org | standard gTLD | 10,325,862 | 76.4% | 2.04% |
| .com | standard gTLD | 140,998,915 | 72.4% | 2.02% |
| .io | standard gTLD | 904,498 | 69.3% | 3.51% |
| .uk | ccTLD | 6,167,500 | 64.2% | 2.89% |
| .de | ccTLD | 8,561,956 | 60.9% | 2.25% |
| .fr | ccTLD | 2,639,634 | 47.1% | 3.21% |
| .nl | ccTLD | 3,081,255 | 35.7% | 13.08% |
| .ch | ccTLD | 1,419,168 | 33.7% | 9.98% |
The pattern holds without a single exception in this table. Every budget TLD fails more often than every standard gTLD, and every standard gTLD fails more often than every European ccTLD. The spread between the worst row and the best is 62.4 percentage points. That’s not a nuance. That’s two different internets sharing one DNS.
The “B or better” column tells the same story from the top of the scale. A domain on .nl is 34 times more likely to hold a B or better than the average budget-cohort domain — and on .top the multiple stretches past 70. Even .com, hardly a security showcase at 72.4% F, produces solid grades at more than five times the budget cohort’s rate.
Why do cheap TLDs grade so badly?
The obvious explanation is the honest one, so we’ll lead with it: this is correlation, not causation. A one-dollar domain is not less capable of an A than a ten-euro one. Every check we grade — SPF, DMARC, HTTPS, HSTS, DNSSEC and the rest — works identically on .top and on .ch, and most of them cost nothing but a DNS edit. The registry operating a budget TLD does not degrade anyone’s security.
What a one-dollar price does is select a population. Three mechanisms plausibly drive the gradient, and none of them requires anyone to behave badly:
Disposable registrations. When a name costs a dollar, it gets registered for purposes with a lifespan of weeks: campaigns, tests, throwaways, bulk speculative buys, and, yes, abuse. Nobody configures DMARC on a domain they plan to abandon. The .top dead rate makes the point brutally: over half the names we scanned on that TLD were already dead at scan time. The graded survivors are the live fraction of a churn machine.
Parking at scale. Bulk-registered names sit on parking pages or registrar defaults, which rarely ship with security headers, email authentication or DNSSEC. Default state on most infrastructure is an F, and a parked domain is pure default state.
Who’s buying. Established organisations with security teams gravitate to .com and their national ccTLD. Registrants picking the cheapest available ending are, in aggregate, the least likely to have anyone whose job includes reading a DMARC report. The ccTLD end of the table reflects the mirror image: local-presence conventions, longer holding periods and, in .nl’s and .ch’s case, national ecosystems that have actively pushed DNSSEC and mail authentication for years.
The price isn’t the cause. The price is a filter, and the filter sorts by intent.
Is anything on a budget TLD actually secure?
Yes — and the exceptions matter, because they prove the ending itself is innocent. Across all seven budget TLDs combined, 6,415 domains hold an A or A+, and 72,864 hold a B or better. Someone put a well-configured, fully authenticated, properly served domain on a .icu — 59 someones reached an A there, out of 243,620 graded.
That is a rounding error as a share (0.033% of the cohort holds an A), but it is an existence proof. The checks pass fine on these TLDs when anyone tries. The 88.8% F rate measures how rarely anyone tries.
It also means the gradient can’t be dismissed as a measurement artifact. If budget TLDs were somehow ungradeable — broken infrastructure, hostile registries — nothing on them would score well. Instead they produce the full grade range at radically shifted proportions, exactly what a population difference looks like and exactly what a methodology bias doesn’t.
What does this mean if you own a budget-TLD domain?
Nothing bad, and possibly something useful. Your grade is yours, not your TLD’s. No check in our methodology reads the ending; a .xyz with enforcing DMARC, valid TLS and HSTS outgrades a bare .com every time.
But you inherit the neighbourhood’s reputation whether you like it or not. Mail filters, threat-intel feeds and allow/deny heuristics are trained on the aggregate behaviour of each TLD, and the aggregate behaviour of a 96%-F TLD is what it is. That is an argument for being demonstrably better than your neighbours, not for moving. The demonstration is cheap: most of the checks that separate an F from a C, and a C from a B, are free DNS records and web-server headers. On a budget TLD, well-configured is a differentiator precisely because it’s rare — you’d be one of 6,415, not one of 17 million.
How we measured this
- Source: August 2026 census round, methodology v9, figures as of 16 August 2026. Domains scanned from our EU measurement infrastructure; every TLD graded by the same 34 externally observable checks.
- Grade denominators: per-TLD grade shares use the graded-row basis from the census grade-by-TLD extract (the same per-row basis as our score histograms; it carries roughly 0.05% re-scan duplicates, which is immaterial at these magnitudes). The budget-cohort aggregate (19,248,968 graded; 88.8% F) is the sum of the seven TLDs’ graded rows.
- Dead and unreachable figures (e.g. the 51.5% .top dead rate, on a denominator of 12,548,818 scanned names) come from the census disposition rollup, which is a per-domain basis. Dead domains are excluded from the grade percentages in this article; only graded domains appear in the F-rate columns.
- Price tiers are qualitative. No pricing dataset is joined to the census. “Budget”, “standard” and ccTLD tiers reflect public industry knowledge of how these endings are marketed, and every price statement in this article is labelled as industry knowledge, not census data. Promotional first-year prices also differ sharply from renewal prices, which we make no claims about.
- Correlation, not causation. We report that cheap promotional pricing and poor security grades co-occur at TLD level. We do not claim pricing causes insecurity, and we describe plausible selection mechanisms (churn, parking, registrant mix) rather than asserting any one of them. No per-domain price or registrant data was used or held.
- Cohort choice: the seven budget TLDs were selected in advance as the endings most publicly associated with sub-$2 promotions (industry knowledge), not selected after seeing their grades. The comparison set (.com, .org, .net, .info, .io, .uk, .de, .fr, .nl, .ch) covers the largest standard gTLDs and a spread of large European ccTLDs.
- Aggregate only. We publish TLD-level statistics. We never name, grade or publish data about an individual registrant’s domain.
- Data is stored and processed within the EU.
What this means
If your security team screens incoming email or evaluates third-party vendors by domain, TLD is a fast and legitimate first-pass filter. A .top or .icu sender sitting at 96% F as a TLD population is not automatically malicious, but the base rate matters when deciding how much scrutiny to apply. Mail from a budget TLD deserves closer inspection not because cheap TLDs are inherently dangerous, but because the aggregate of their registrants — heavily skewed toward transient, unconfigured domains — is exactly what abuse campaigns exploit.
For businesses that own domains on budget TLDs, the practical message is that differentiation is both achievable and valuable. On a TLD where fewer than 1 in 3,000 domains holds an A, your well-configured domain stands out in every threat feed and reputation database that tracks TLD-level behaviour. Deploying SPF, DMARC at enforcement, DNSSEC, and HTTPS costs nothing but time, and on a .xyz or .shop it is a genuine competitive signal — you are provably not the parking page or the throwaway campaign domain that the 88.8% F rate describes.
For security professionals building allow/deny lists or vendor risk criteria, this data provides a quantified baseline to justify TLD-level screening policies. A 62.4 percentage-point security gap between the worst and best TLDs in this comparison is large enough to be operationally significant. European ccTLDs — particularly .nl at 13.08% B-or-better and .ch at 9.98% — are performing in a different category from the budget tier, and that difference reflects real differences in registrant populations and national ecosystem practices, not measurement artifact.
Data to cite
- “88.8% of graded domains across seven budget TLDs — .xyz, .top, .icu, .online, .site, .shop, and .club — scored an F in the August 2026 census, against 72.4% on .com and 33.7% on .ch.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “.top has the worst grade profile of the budget cohort, with 96.1% of its 2,872,294 graded domains scoring an F and only about 1 in 4,700 reaching an A.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “Only 0.38% of budget-TLD domains reach a B or better, compared to 2.02% on .com and 13.08% on .nl — a 34× gap between the cheapest promotional tier and the best-performing ccTLD in this comparison.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “51.5% of scanned .top domains — 6,465,016 of 12,548,818 — were dead before grading even began, reflecting the TLD’s role as a churn-heavy disposable-registration market.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “6,415 A-grade domains exist across all seven budget TLDs combined — roughly 1 in 3,000 — proving the security checks work identically on these endings when anyone tries.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “The spread between the worst-performing TLD (.top, 96.1% F) and the best (.ch, 33.7% F) is 62.4 percentage points — two different internets sharing one DNS.” — defaults.exposed August 2026 Domain Security Census (432M domains)
FAQ
Are cheap domains less secure? On aggregate, dramatically: 88.8% of graded domains across .xyz, .top, .icu, .online, .site, .shop and .club scored an F in our August 2026 census, versus 72.4% on .com and 33.7% on .ch. But the mechanism is who registers them, not the price tag itself — the security checks work identically on every TLD, and 6,415 budget-TLD domains prove it by holding an A.
Which TLD has the worst security grades? Of the TLDs in this comparison, .top: 96.1% of its 2,872,294 graded domains scored an F, and only about 1 in 4,700 reached an A. It also had the highest death rate we measured here — 51.5% of the 12.5 million .top names scanned were dead.
Does using a .xyz or .top domain hurt my security? Not technically. Your grade depends entirely on your own configuration — DNS records, TLS, headers — and none of our 34 checks reads the TLD. The practical caveat is reputational: mail filters and threat feeds learn from TLD-level aggregates, so a well-configured domain on a 96%-F ending is swimming against its neighbourhood’s statistics.
Why do European ccTLDs grade so much better? Selection and ecosystem. ccTLDs like .nl (35.7% F, 13.08% B or better) and .ch (33.7% F) combine local registrant bases holding domains long-term with national registries and ISPs that have pushed DNSSEC and mail authentication for years. It is aggregate-level correlation — our census doesn’t observe registrant identity or intent.
Is a .com more secure than a budget TLD? More secure than the budget cohort on every aggregate we measured — 72.4% F versus 88.8%, and a B-or-better rate five times higher — but that is a low bar cleared, not an endorsement. Nearly three in four graded .com domains still fail. The gap between .com and the best ccTLDs (33.7% F on .ch) is larger than the gap between .com and the budget tier.
How has this changed since July 2026? This report uses the August 2026 census round; the same TLD cohort is re-measured each round for trend tracking. The ordering of TLDs by F rate is consistent across rounds — budget TLDs persistently underperform standard gTLDs and ccTLDs. Specific percentage-point movement between July and August editions will be published in the trend comparison once both rounds are fully processed.
Should I move my business domain away from a budget TLD? Not necessarily. Your grade is determined by your configuration, not your ending. If you configure SPF, enforcing DMARC, DNSSEC, HTTPS, and HSTS on a .xyz, you will outgrade the vast majority of .com domains. What budget TLDs cannot fix is your neighbourhood’s reputation in mail and threat-scoring systems. If that is a concern, the answer is to be demonstrably well-configured — which is rare enough on these TLDs to be a meaningful signal.
See where your own domain stands
Whatever your domain cost, its grade is free to fix. Our census grades real, live domains across 34 externally observable security checks, and most of what a failing domain is missing is a DNS record or a server header — the barrier is almost never cost, it’s that nobody told the owner it mattered. You can check your domain privately and free, and see exactly which checks you pass.
Check your domain free at defaults.exposed — find out whether your domain is one of the well-configured exceptions on your TLD, or part of the 88.8% F majority. Takes 30 seconds. No account needed.
Read the flagship census report: The State of Domain Security 2026 →
Also in this series: The Internet Security Grade Curve · The Fully Protected Few
How to cite this report
Press / blog: defaults.exposed (2026). Cheap Domains, Cheap Security? Budget TLDs vs the Rest. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/cheap-domains-cheap-security
Academic: defaults.exposed. (2026, August 18). Cheap Domains, Cheap Security? Budget TLDs vs the Rest. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/cheap-domains-cheap-security
In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=19,248,968 budget-TLD graded domains)
About the defaults.exposed August 2026 Census
The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.
Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026
Aggregate data only. Data stored and processed in the EU.
Aggregate data only. Data stored and processed in the EU.
How to cite this report
Press / blog: defaults.exposed (2026). Cheap Domains, Cheap Security? Budget TLDs vs the Rest. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/cheap-domains-cheap-security
Academic: defaults.exposed. (2026, August 18). Cheap Domains, Cheap Security? Budget TLDs vs the Rest. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/cheap-domains-cheap-security
In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=19,248,968 budget-TLD graded)
About the defaults.exposed August 2026 Census
The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.
Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026