Domains of deception: phishing through the lens of ownership
Mina Erfan, Paula Branco, Guy-Vincent Jourdan · Computers & Security · 2026
Phishing attacks exploit a variety of hosting and domain ownership models, making them a dynamic and challenging threat to address. Many existing proactive detection methods focus on identifying newly registered domains, often relying on data sources like Certificate Transparency (CT) logs and Domain Name System (DNS) records. Although effective, these approaches capture only part of the attacks, leaving unanswered questions about the proportion of threats they can detect. To answer this question, we conducted a year-long study, collecting phishing reports from multiple sources and using a machine-learning classifier to analyze phishing domains. As a result of this study, we introduce two new datasets—PhishXtract and PhishXtract-Class—designed to support and advance future research in this area. By analyzing features such as the Internet presence and historical activity, we classified these domains into three types: attacker-owned, compromised, and third-party hosted. This helped us build a clearer framework for understanding the phishing domain ownership patterns observed during the year-long study. Our findings show that most phishing attacks are not hosted on attacker-owned domains. Instead, attackers often abuse legitimate infrastructures and third-party platforms to create their campaigns. Furthermore, by analyzing the reporting feeds, we were able to assess their unique and overlapping contributions to phishing detection and identify the platforms most frequently exploited by attackers. Overall, our findings provide an understanding of current phishing strategies, highlighting the reliance on legitimate infrastructures over attacker-owned domains and emphasizing the need for targeted detection strategies tailored to different hosting models exploited by attackers.