Typing a domain name directly into a browser has become increasingly perilous, according to fresh findings on the state of parked domains. An investigation by security researchers at Infoblox uncovered that the vast majority of dormant, expired, or misspelled domain names—often called parked domains—now funnel users toward malicious sites offering scams, malware, and fraudulent services rather than the benign placeholder pages they once hosted.
Parked domains traditionally served as a monetization mechanism: when users landed on these pages through typos or expired registrations, domain parking companies would display paid links to third-party websites. This system was relatively safe a decade ago. A 2014 study found that parked domains redirected visitors to malicious destinations less than five percent of the time, regardless of whether users clicked any links on the parking page.
The situation has inverted entirely. Infoblox researchers conducted extensive testing over recent months and discovered a troubling new reality. "In large scale experiments, we found that over 90% of the time, visitors to a parked domain would be directed to illegal content, scams, scareware and anti-virus software subscriptions, or malware, as the 'click' was sold from the parking company to advertisers, who often resold that traffic to yet another party," the researchers stated in their published findings.
Targeting by IP Address and Device Profile
The malicious redirects operate with sophisticated targeting mechanisms. Infoblox discovered that parked domains remain benign when accessed through a virtual private network (VPN) or from non-residential IP addresses, but immediately redirect residential users to harmful content. A Scotiabank domain misspelling—scotaibank[.]com—exemplifies this behavior: users with VPN protection see a standard parking page, while those on residential connections get redirected to scam and malware sites.
David Brunsdon, a threat researcher at Infoblox, explained the mechanics of these attacks. "It was often a chain of redirects — one or two domains outside the parking company — before threat arrives," he noted. "Each time in the handoff the device is profiled again and again, before being passed off to a malicious domain or else a decoy page like Amazon.com or Alibaba.com if they decide it's not worth targeting." The profiling process uses IP geolocation, device fingerprinting, and cookies to determine which users warrant malicious redirects.
Widespread Typosquatting Infrastructure
The research uncovered a sprawling typosquatting operation centered on scotaibank[.]com, which harbors nearly 3,000 lookalike domains. One particularly dangerous variant, gmai[.]com, has been configured with its own mail server to capture misdirected emails. Users who accidentally omit the "l" from "gmail.com" find their messages delivered directly to scammers rather than bouncing back. This domain has featured prominently in recent business email compromise campaigns, with lures claiming payment failures and attachments containing trojan malware.
Infoblox traced this domain holder through a common DNS server—torresdns[.]com—and identified a network of typosquatting domains targeting major internet destinations. The targeted platforms include Craigslist, YouTube, Google, Wikipedia, Netflix, TripAdvisor, Yahoo, eBay, and Microsoft.
Brunsdon observed that domain parking services claim their displayed search results are tailored to the parked domains themselves, yet testing revealed almost none of the content matched the lookalike domain names being examined.
DNS Misconfiguration Exploits
Another threat actor operates domaincntrol[.]com, a domain differing from GoDaddy's name servers by just one character. This operator has long exploited DNS configuration typos to route users to malicious sites. Recent discoveries show the malicious redirects activate selectively: they occur only when queries originate from users employing Cloudflare's DNS resolvers (1.1.1.1), while other visitors encounter a non-loading page.

Government Domain Lookalikes
Even government domains face exploitation through typosquatting. During the research, an Infoblox team member attempting to report a crime to the FBI's Internet Crime Complaint Center accidentally visited ic3[.]org instead of ic3[.]gov. "Their phone was quickly redirected to a false 'Drive Subscription Expired' page. They were lucky to receive a scam; based on what we've learnt, they could just as easily receive an information stealer or trojan malware."
Attribution and Affiliate Networks
Infoblox emphasized that the malicious activity they documented cannot be attributed to any identified threat actor. The domain parking and advertising platforms mentioned in the study were not implicated in the malvertising campaigns themselves. However, the report reveals a problematic supply chain: while parking companies claim to work exclusively with premium advertisers, traffic from these domains frequently flows through affiliate networks that resell it multiple times, eventually reaching advertisers with no direct relationship to the original parking companies.
Google's Policy Shift
Recent policy changes at Google may have inadvertently worsened the situation. Google Adsense previously defaulted to permitting ads on parked pages, but in early 2025 implemented a new default that requires ad operators to explicitly opt in to parking domain placements. This shift means fewer legitimate ads appear on parked pages, potentially leaving more space for malicious redirects to operate unchecked.
Source: Krebs on Security