Sarah built a 47-company UK prospect list over three weeks. Four .co.uk domains on it were registered to impersonate real businesses — one character removed, convincing enough to fool two enrichment tools and a deliverability monitor. Here is what happened, and what Nominet is building to prevent it.
Sarah had been building the UK prospect list for three weeks. Forty-seven companies. She had cross-referenced industries, verified employee counts, confirmed decision-maker titles, and checked every domain against two enrichment tools before sending anything. By her own standard, it was the cleanest list she had built all quarter.
On day two of the sequence, her deliverability monitor flagged four .co.uk addresses as associated with known phishing infrastructure. Not the companies. The domains.
She pulled them individually. Each one was one character removed from a legitimate UK business — hyphens inserted, letters transposed, a double consonant where there should be one. Someone had registered near-identical .co.uk names, built convincing commercial fronts on them, and let them sit in the namespace quietly.
Her emails had delivered to those addresses. The metrics said so. Nobody on the other end had received them. The damage to her sending domain had already started compounding before she understood what had happened.
Her first call was to the enrichment platform. They pulled the resolution logs — the tool had matched the company name to the nearest available .co.uk string and returned it with high confidence. It was not wrong about the string. It was wrong about what the string represented.
Their IT team confirmed that the four domains had legitimate DNS configurations, live MX records, and no technical flags that standard verification surfaces. They were operational. They were just not real.
A namespace is the complete set of registered domain names under a given top-level domain, governed by the registry administering it, whose collective reputation determines the trust signals — and the abuse signals — carried by every domain operating within it. The word "collectively" is where Sarah's problem lives.
The 43 legitimate .co.uk domains on her list were not evaluated by inbox providers, security tools, or enrichment platforms in isolation. They were evaluated as members of the .UK namespace — and the namespace's trust signal is the aggregate of every domain in it, including the four that were registered to impersonate real businesses. When the namespace has a contamination problem, every legitimate address in it carries a fraction of that contamination.
Nominet administers the .UK namespace — approximately 11 million domain registrations across .co.uk, .org.uk, .me.uk, and .uk directly. Before the DHI, its abuse intervention operated primarily through reactive mechanisms: a complaint was filed, the domain was reviewed, action was taken if the evidence met the threshold.
The DHI is built around one stated ambition: to make .UK the most trusted namespace through proactive, proportionate, and collaborative measures. Each word carries operational weight.
When Sarah reported the four domains, she was told something technically accurate and operationally useless: the domains had been registered in compliance with the terms of service in place at the time. Nothing in the existing framework explicitly prohibited registering a near-identical string to an established business name and building a commercial front on it. The conduct was abusive. It was not codified as prohibited.
A Domain Abuse Policy — codified, published, and developed in collaboration with registrars through the UK Registry Advisory Council — defines what constitutes abuse in the .UK namespace, establishes the conditions under which Nominet will intervene, and makes those conditions visible to registrars and registrants before a registration is made rather than discoverable only after enforcement.
Policy defines the rule. Tooling is what makes the rule detectable at the speed abuse actually moves. The four domains Sarah encountered were each one character removed from a legitimate .co.uk registration. That is not a sophisticated technique — it is a systematic one, applied at volume across a namespace where string-similarity detection was not integrated into the registration workflow.
Clean DNS is Nominet's case management tool, streamlining evidence collection and workflows for flagging high-risk domain strings at or before registration — matching new submissions against known abuse signatures: lookalike strings to established brands, term combinations historically associated with phishing campaigns, structural patterns common in fraudulent commercial fronts. The DHI is evaluating making Clean DNS publicly available so registrars can integrate it directly into their registration workflows.
The Registrar Dashboard, launched in May 2026, aggregates 192 datapoints on every .UK domain registered under a given registrar's tag — including abuse levels, hosting data, and security metrics, refreshed monthly. This is the first time registrars have had a systematic, continuous view of the abuse profile of domains they have issued.
Nominet does not sell .UK domains directly to registrants. It operates through a network of accredited registrar partners. Domain abuse does not enter the namespace at the registry level. It enters at the registrar level — through registration processes, verification standards, and the monitoring practices of the specific entity that approved the registration request.
The Registrar Dashboard is not just a monitoring tool — it is an accountability instrument. A registrar whose monthly dashboard shows elevated abuse rates across their tag has, for the first time, a data-driven signal connecting their issuance decisions to namespace health outcomes.
When Sarah's company formally requested domain suspension, the registrar's legal obligation to act was limited. The domains were registered legitimately in terms of the technical process. No law at the time of registration specifically required the registrar to suspend them on the basis of commercial impersonation alone without a formal law enforcement request.
The Crime and Policing Bill introduces powers for appropriate officers to seek court-ordered domain suspensions, including in cases where non-disclosure orders are needed to protect ongoing investigations. Nominet's existing Criminal Practice Policy — a voluntary arrangement with 14 law enforcement agencies — remains the preferred mechanism. The legislation provides the instrument when voluntary cooperation is insufficient or unavailable.
Sarah had no reason to expect that .co.uk domains would be used for near-identical commercial impersonation at the scale she encountered. Nobody had told her the pattern was common. Nobody had published data that would have made her verify differently.
| Abuse Category | Domains Suspended |
|---|---|
| Total .UK domains suspended | 6,315 |
| vs. 2023 suspensions | 2,230 |
| Impersonating UK colleges | 207 |
| Impersonating universities | 80 |
| Associated with mobile provider scams | 176 |
| Fraudulent commercial fronts (Sarah's category) | Documented, categorised, systematic |
Sarah's sequence ran. The damage to her sending domain from four deliveries to phishing infrastructure is sitting in her Google Postmaster data, visible in a complaint rate that moved two weeks after the sequence completed and still has not fully recovered. Three weeks of qualifying work produced a list that was 91.5% accurate. The 8.5% that was wrong was not a random distribution of bad data — it was a systematic attack on the namespace she was working in.
She is building the next UK list now. The DHI has not finished being built — the real-time API integration is still in progress, Clean DNS is not yet embedded in every registrar's workflow, the abuse policy is still being co-developed. The namespace she is working in today is not yet the one the DHI is building toward. But she is verifying differently.
Manually flagging any .co.uk domain within two characters of another registered .co.uk domain with an established commercial history. The exact technique the four spoofed domains used — now checked for before the domain enters the list.
MX verification run after domain resolution, not as a proxy for it. The spoofed domains had live MX records — MX confirmation is necessary but not sufficient. It is now one layer in a stack, not the only layer.
A monitoring rule that flags any .co.uk domain cluster producing zero engagement across multiple contacts without a bounce signal — the pattern the four spoofed domains would have produced from day one if she had been watching for it.
The .UK namespace holds approximately 11 million registrations. Every UK-headquartered company you research, every .co.uk domain you resolve, every contact you build and sequence on .co.uk infrastructure — all of it sits inside a namespace whose health is being actively managed through the DHI in ways that did not exist eighteen months ago.
Sarah's story ends with damage that was done before the infrastructure to prevent it was in place.
The story the DHI is building toward ends differently — with a namespace where the gap between registration and detection is narrow enough that a three-week list-building effort produces a list that is 47 out of 47, not 43.
Every domain that Clean DNS flags before registration is a spoofed address that never reaches a prospect list. Every suspension post-mortem that Nominet publishes is intelligence that the next person building a .UK list can use to verify more carefully.
FindCompanyDomain resolves company names to verified, MX-confirmed operational domains — including .co.uk and .uk — with confidence scoring that reflects current operational status, not just what the registration record says.