How many defensive domains does a big brand register? Fewer than you would think. A 2025 study from Georgia Tech looked at the Fortune 500 and found 19,523 defensively registered domains from 447 companies. Almost 200 of those companies had fewer than ten.
That is a useful number if you are deciding how long your own list should be. It is also a number that needs some care, so I will tell you what the study did, what it found, and where it stops.
The bicycle lock
In Copenhagen everybody locks the bicycle to the frame. Almost nobody locks the saddle. The thief who wants a saddle knows this, and so does the person who has lost three.
Defensive registration looks a bit like that. Most of the big companies in the study locked the frame: the obvious extensions and the obvious variants of the name. The question is what happens to the saddle.
What the study did
The paper is called The Guardians of Name Street, by researchers at Georgia Tech, and it was presented at NDSS in February 2025. Here is the short version:
- The researchers took the 500 companies on the 2023 Fortune list and generated about 146 million candidate look-alike names, using eight kinds of transformation: typos, character swaps that look similar, bit flips, abbreviations, brand-name combinations, TLD swaps, stock tickers and homophones.
- They checked which of those names were registered, and used a deliberately conservative method to decide which ones the company itself, or a brand-protection provider on its behalf, had registered.
- Then they compared the defensive names with the names that were still free, using three years of DNS query data from a large internet provider.
What they found
The lists are short. 447 of the 500 companies had at least one defensive registration. But most engaged sparingly, and almost 200 had fewer than ten.
TLD swaps dominate. Close to two fifths of all defensive registrations were the same name under another TLD. Of the TLD-swapped names that were registered by anyone, 38 percent were defensive. The median company held six TLD swaps across the open generic TLDs in the study.
Companies pick TLDs that fit their business. A company in accommodation was more likely to hold names in extensions about food, for example, than in an extension that had nothing to do with its sector.
Brand-protection providers do most of the work. Nearly three quarters of the defensive names used a third-party nameserver, and many of those belonged to registrars that sell brand protection. Twenty of the 47 registrars in the study advertised it, and they accounted for 99 percent of the defensive names.
It works, with gaps. The defensive names captured a large share of the DNS queries that went to look-alike names: a median of 78 to 94 percent, depending on the provider. But the researchers also found names that were free for long periods while receiving real traffic, and some could have been registered at a standard price. They suggest using passive DNS data to find them.
What a smaller brand can borrow
You probably do not have 146 million candidates, a security team and a passive DNS feed. But three lessons carry over:
- Start with TLD swaps. They were the largest category. Your exact name under the legacy extensions, plus the extensions closest to your business, is a sensible first list.
- Do the quiet variants. The names that companies registered most often were the ones tied to the brand itself, such as brand-name combinations. Typos are numerous, but only a tiny fraction of them were registered.
- Keep the list short, and write it down. The study shows that most large companies keep their list small. A small list that someone owns beats a large list that nobody remembers. See how to turn an approved list into registrations.
When a TLD suddenly gets popular, the same logic applies. The post on .si and brand protection uses it for one extension.
Where the study stops
- It covers the Fortune 500, which are large US companies. A small business has a different budget and a different threat.
- It uses a conservative method, so it undercounts defensive registrations that cannot be proven.
- It excludes brand-plus-keyword combinations, because there are too many.
- The data covers 2020 to 2023. The domain market has changed since then.
- It describes what companies do. It does not say what you should do.
Cost, in perspective
The authors compared costs. A standard registration of the names they found would cost about 15 USD, while a single complaint to WIPO starts at 1,500 USD in filing fees alone, which does not include legal fees. Those are numbers from the paper and the WIPO fee schedule of the time, so check the current fees before you rely on them. The point is the ratio, and not the exact amount.
A registrar registers and renews names. It does not monitor for infringement, and it does not give legal advice. The post on where the handoff sits explains the split, and defensive domain administration covers the registrar's part. The page for brand protection teams has more.
Questions people ask
How many defensive domains should a company register?
There is no standard number. In this study, many large companies held fewer than ten. Your list depends on your risk and your budget.
Which defensive domains are the most common?
Your name under other TLDs, and combinations of the brand name. Typos are common to generate but rarely registered.
Do defensive domains work?
The study found that they captured most of the look-alike traffic it measured, though some busy free names were missed.
Is this legal advice?
No. It is a summary of a published study.
Sources
- Adjibi, Avgetidis, Antonakakis, Bailey and Monrose, The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500, NDSS 2025
- WIPO, Schedule of fees for domain name disputes
- ICANN, UDRP rules
If your own list is longer than ten, I would like to know why. Tell me in the chat on the website.
/Thomas