.garden 顶级域名沦为“坏街区”
.garden TLD's change to a bad neighborhood

原始链接: https://discourse.ifin.network/t/garden-tlds-change-to-a-bad-neighborhood/627

DomainTools 的分析显示,`.garden` 顶级域名(TLD)中的可疑活动激增。注册量从 2025 年的约 2,500 个猛增至 2026 年的超过 147,000 个,平均风险评分也从 55 分显著跃升至 84 分。 这种下滑主要归因于特定的基础设施提供商。使用 **AliDNS** 域名服务器的域名显示出极高的风险评分(平均为 87 分),而 AliDNS 与 **Dominet** 等注册商的组合则达到了极端的风险水平(高达 94 分)。相比之下,由 Cloudflare 或 Namecheap 等提供商管理的域名则保持了较低且低于平均水平的风险评分。 由于 `.garden` 域名缺乏合法的商业用途且恶意活动泛滥,强烈建议安全专业人员屏蔽整个 `.garden` 顶级域名。各组织也应考虑屏蔽或严格过滤与高风险基础设施(特别是 AliDNS 域名服务器和特定的高风险注册商)相关的流量,以降低潜在威胁。

```Hacker News 最新 | 过往 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 .garden 顶级域名沦为恶意温床 (ifin.network) 9 分,发布者:speckx,1 小时前 | 隐藏 | 过往 | 收藏 | 2 条评论 sikozu 13 分钟前 | 下一条 [–] 我以前根本不知道还有 .garden 这个顶级域名。刚去 Porkbun 查了一下,发现注册费才 1.54 美元,确实很便宜。难怪会被滥用。只要顶级域名够便宜,坏人肯定会批量买入。 回复 OutOfHere 7 分钟前 | 上一条 [–] 仅仅因为一个顶级域名价格便宜且被坏人注册了一些域名,就将其定性为“坏的”,这很荒谬。这是一种典型的刻板印象。过滤机制应该比这更智能。同一个顶级域名下也有很多优质域名。 回复 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 加入 YC | 联系 搜索: ```
相关文章

原文

Last Updated: 2026-06-29T19:00:03Z

What’s Happening

About a month ago, Dave Piscitello from Interisle was looking for information on why the .garden TLD seemed so unfriendly. Accidentally fell off my radar, but I started looking this morning.

TLD(R) is: a voluminous increase in registrations for .garden this year, and AliDNS correlates with much higher risk scores, as nearly half the 2026 dataset. In particular, AliDNS nameservers and Dominet registration accounted for an average risk score 10 points above the average for .garden.

Of the .garden domains we’ve ingested:

During 2025, we ingested about 2.5k .garden domains with an average risk score of 55. So far in 2026, we’ve ingested 147,000 .garden domains with an average risk score of 84! That’s a heck of a change.

As much as I wanted to blame Cloudflare for this one, Cloudflare only accounted for 19k domains, risk score 81. Below average risk! In fact, excluding Cloudflare from the dataset leaves 130k-ish domains and the same risk score average - 84.

At a glance, .garden TLDs are being dragged into the gutter by the 68,000 domains with alidns[.]com nameservers, avg risk score of 87. While alidns Nameservers + Registrar Spaceship accounts for 65k domains with an average risk of 87. alidns + Registrar Dominet is only 3k domains, but the risk score shoots up to 94.

Other nameservers examined:

Spaceship[.]net - 55k domains, avg risk score 72
dnsowl[.]com - 3.5k domains, avg risk score 93
registrar-servers[.]com (namecheap) - 1k domains, avg risk score 63.

Less than 1K:
vercel-dns[.]com - avg risk score 42
dyna-ns[.]net - 66
porkbun[.]com - 49
domaincontrol[.]com (godaddy) - 60

Source: DomainTools.com

Actions

It is unlikely that there are valid business reasons for network environments to allow .garden domains; highly recommend defenders completely block the .garden top-level domain, and allowlist items as needed.

It’s also worth evaluating if your environment can block according to characteristics such as Registrar or Nameservers, and examine what the impact of blocking AliDNS-nameservered or Dominet-registered domains would be.

联系我们 contact @ memedata.com