Massive spike in use of .es domains for phishing abuse

Discussion in 'other security issues & news' started by stapp, Jul 5, 2025 at 9:44 AM.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,926
    Location:
    UK
    https://www.theregister.com/2025/07/05/spain_domains_phishing/
     
  2. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,627
    Location:
    Flat Earth Matrix
    It is good to know that blocking unused TLDs is still a good idea. It is not like I would ever visit .es or .ru
     

    Attached Files:

  3. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    2,063
    Added .es to my list of blocked TLDs. Just to be on the safe side.
     
  4. longshots

    longshots Registered Member

    Joined:
    Oct 20, 2017
    Posts:
    695
    Location:
    Australia
    Blocked it - job done.
    What a typical over reaction.
    When this campaign is over they will move to another country TLD.
    There are 243 national top-level domains are assigned, with 195 of them reserved for independent countries and 48 are owned by dependent territories.
    How many do you block before you realise you boarded the wrong train?
     
  5. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    2,063
    It's not necessarily an overreaction. There are currently more than one hundred entries on my list of blocked of TLDs, .es just being one of them.
     
  6. longshots

    longshots Registered Member

    Joined:
    Oct 20, 2017
    Posts:
    695
    Location:
    Australia
    Once they realise that they are not getting an acceptable success rate they will move on.
    They may move to a new TLD. Perhaps an .me or a .ch.

    You will, of course, have the option of also blocking them.
    Let's just hope that you, or any of your friends don't use ProtonMail.
    Proton Mail offers a variety of email address domains for its users, including @proton.me, @protonmail.com, @pm.me, and @protonmail.ch.
    The default domain for new accounts is usually @proton.me.
     
  7. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    2,063
    I don't use Proton Mail, so blocking .me and/or .ch would not cause any problems here. Apart from that, I could still use proton.me/.es etc. even if I blocked the TLDs .me and .ch in my browser because I use an email client for handling emails. And if I used Proton Mail in my browser, I could still whitelist proton.me/.es etc. So there are plenty of options here to choose from.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.