Freenom Is Back, and No Longer Free - webhosting.today
Skip to content
Market Insights →
Search
© webhosting.today<br>All Rights Reserved.
Freenom Is Back, and No Longer Free. The Free-Domain Registry Behind Years of Phishing.
by Natalia Nowak<br>·<br>July 27, 2026<br>·<br>Security<br>·<br>7 min read
Freenom, the registry that once handed out millions of domain names for free and in doing so became one of the internet’s biggest sources of phishing, has quietly returned. The trade publication Domain Incite reported on July 23 that the company is again selling domains in three of its country-code extensions, .tk, .cf and .gq, starting at €8.22 a year . The change from its old model is the whole point: the domains are no longer free.
That single word carries weight. Freenom’s free domains were the fuel for years of abuse, until Meta sued the company in 2023 and it said it would leave the domain business for good. Two and a half years later it is back, running the same registries it promised to exit, with the one part of its model that made the mass abuse possible now removed.
Key facts
The news: per Domain Incite (July 23), Freenom has resumed paid sales in .tk, .cf and .gq from €8.22 a year , reversing its 2024 pledge to exit the domain business
What Freenom was: operator of five free country-code domains; .tk was the world’s largest such extension, with more than 31 million registrations in 2016
The abuse: the research firm Interisle found Freenom’s extensions were 5 of the 10 most-abused top-level domains in 2021, and over 60 percent of all country-code phishing domains by November 2022
The reckoning: Meta sued in 2022 and 2023, seeking roughly $500 million ; registrations stopped, phishing on the extensions fell from over 60 percent to under 15 percent, and Freenom settled in February 2024 on confidential terms
The aftermath: ICANN cut off its registrar accreditation, about 12.6 million domains went dark, and Mali and Gabon reclaimed .ml and .ga
The empire built on free domains
Freenom’s business was giving domains away. Built around a deal to run Tokelau’s .tk extension and consolidated under the Freenom brand in 2012, it offered free registrations in five country-code domains, standing in for Tokelau, Mali, Gabon, the Central African Republic and Equatorial Guinea, or .tk, .ml, .ga, .cf and .gq. The offer worked. By 2016, .tk was the largest country-code domain in the world, with more than 31 million registrations, ahead of China’s .cn.
The money came from the domains themselves. Freenom gave a name away but reserved the right to take it back at any time, and it kept the valuable and expired ones for itself, pointing their traffic at pages of ads. A registrant got a free web address; Freenom got an enormous pool of names it could monetize and recycle. Its founder, the Dutch entrepreneur Joost Zuurbier, had turned a tiny Pacific territory’s domain into one of the most-registered strings on the internet.
Parked Domains Lost Their Ad Engine. What Replaced It Is Drawing Scrutiny.
How free domains became a phishing engine
Free and anonymous is an attractive combination if you send phishing emails. Because anyone could register a Freenom domain at no cost and without meaningful checks, criminals did so at scale, spinning up throwaway names for fake login pages and malware. The measurements were stark. The security research firm Interisle found that in 2021, Freenom’s five extensions accounted for five of the ten most-abused top-level domains anywhere. By November 2022, according to Interisle data cited by the security journalist Brian Krebs, Freenom’s domains made up more than 60 percent of all the phishing domains reported across every country-code extension on the internet. At the company’s peak, its names were used in around 14 percent of all phishing attacks worldwide.
The point was volume, not the ratio of bad to good on any single extension. Because .tk alone held tens of millions of names, its share of abuse looked smaller as a percentage, yet the sheer supply of free, disposable domains made Freenom’s extensions the default choice for large-scale abuse.
Meta sued, and the phishing collapsed
The reckoning came from a brand owner, not a regulator. In December 2022, and again in an amended complaint in March 2023, Meta, the owner of Facebook, Instagram and WhatsApp, sued Freenom and Zuurbier in a California federal court. Meta accused the registry of cybersquatting and of knowingly profiting from domains used to phish its users, and pleaded thousands of counts that together sought roughly $500 million .
Freenom’s response told its own story. Within days it stopped accepting new registrations, posting only a note blaming temporary technical issues. What happened next was the clearest evidence that the free model had been driving the abuse: phishing on its extensions fell off a cliff. Interisle’s measure of Freenom’s share of country-code phishing dropped from over 60...