One button block known top-level domains associated with malware
Eric Nix
DNSFilter should offer an option to one-click a button to block TLDs associated with malware. There are various lists that list the top offenders. This could be done dynamically. It would prevent the need to maintain a universal block list for TLDs.
Minetta Gould
updated the status to
open
Thanks for the additional info, Eric Nix & Erick Maldonado!
I'll pass this idea along to our Secirity Intelligence team for consideration 💖
Eric Nix
Minetta Gould One other idea... Have a TLD section and list all the top spam/malware domains. Have an "enable all" function with ability to disable certain domains. For example, if xyz is one but a company wants to allow it, they could toggle xyz off.
Erick Maldonado
I'm not sure what exactly the OP had in mind or how DNSF will implement this, but would it be a "Threat" Category called something like "Malware TLD" without Machine Learning?
From a quick AI assisted search I found this report from "Spamhaus Domain Reputation". I just downloaded the report and pulled some data from this partially broken link: https://www.spamhaus.org/resource-hub/domain-reputation/domain-reputation-update-oct-2025-mar-2026/
Photo Viewer
View photos in a modal
Eric Nix
HaGeZi's TLD block list is a start, but DNSFilter could verify itself which ones are most abused. Customers could then create universal bypass lists if they need access to particular FQDNs within the TLD list (if they have the TLD block enabled).
Minetta Gould
updated the status to
more information needed
Thanks for the request, Eric! The underlying goal here makes sense—reducing the manual overhead of maintaining a TLD block list is a real pain point.
That said, we want to be thoughtful before committing to something like this, because blanket TLD blocking carries meaningful false-positive risk. Legitimate TLDs like
.zip
, .app
, and .dev
regularly appear on high-risk lists but are also widely used for real business traffic—a one-click block could cause unintended outages without much warning.Could you share the specific lists you're referencing? Understanding which TLDs are in scope and how they're being classified would help us evaluate whether there's a safe, granular way to surface this kind of functionality without the collateral damage risk. 🙌
If we don't hear back within a week, we'll go ahead and close this one out.