
Scammers Impersonate High-Trust Country Domain Names
Scammers impersonate trusted country URL endings in order to appear more legitimate to consumers.
Country code top level domains (or ccTLDs) are the two letter codes, such as .uk, .cn or .us that usually come at the end of URLs. There is evidence in the GSE that scammers use fake ccLTDs. For example, bkofengland-uk.com may appear to consumers like it is using the legitimate top level domain name .uk, when in fact the real Top Level Domain Name is .com.
Research from the GSE demonstrates that there is a significant difference between the ccTLDs that scammers impersonate and the ccTLDs scammers actually use. Large Language Model-scaled analysis was used to detect ccTLD mimicry, and the analysis is based on ~8 million signals from the first half of 2026, which were queried to produce counts of true ccTLD use vs mimicry. The LLM was specifically instructed to extract non-incidental, strictly delimited country codes (for example, -us would not be extracted from toys-r-us.com as ccTLD impersonation of the United States).
The ccTLDs that scammers impersonate are those which have the lowest report rate in the GSE League Tables. The most impersonated ccTLD is .dk (the ccTLD for Denmark), which consistently ranks highest in the TLD league table. Conversely, the legitimate ccTLDs that scammers actually use the most include .cn, .cc and .ru, which are consistently poorly ranking ccTLDs within the TLD League Tables.
The pattern is clear: rather than securing an official national domain ending, scammers use deceptive formatting to mimic trusted URL endings. Registering a .dk domain name is significantly more difficult for scammers, as Punktum.dk (the official registry for Denmark), enforces mandatory identity and data verification on every registration. Registering a more accessible domain name, such as .cc, requires minimal identity validation, and offers lower upfront costs, providing bad actors with a fast, low barrier option to host malicious infrastructure at scale. Although .cc is the country-code Top Level Domain for the Cocos (Keeling) Islands, it is officially considered generic by Google, and is administered by Verisign through a subsidiary company, eNIC.
Beyond strict registration policies, low abuse of ccTLDs such as .dk can be linked to effective threat mitigation. A 2022 report by CENTR, the association of European ccTLDs, indicated that low levels of abuse in European country-code registries are linked to diverse data verification policies and the rich patchwork of threat mitigation measures in place across Europe. This was backed by a 2023 report by Oxford Information Labs. Nonetheless, scammers manage to exploit these ccTLD brands through TLD impersonation left of the domain - at the second and third-level domain.
A scammer might legitimately register a .cc domain name, while mimicking the trusted .dk ccTLD: politi-dk.cc/. The .cc ending is cheaper and easier to register, while the artificial .dk ending appears more legitimate to consumers.
Lay consumers are not familiar with domain hierarchies, and should not be required to understand them in order to access a safe internet. Scammers are able to exploit the authority and trust that ccTLDs provide. Bad actors are able to compromise trust of the domain name registry ecosystem itself. This renders domain operators as fellow victims of cybercrime, alongside brands whose identities are fraudulently impersonated.


