Top Level Domains

At PGH Networks, our primary focus is to keep our clients well-informed about the latest developments in the dynamic field of cybersecurity. Today, we want to draw your attention to a critical issue related to new top-level domains (TLDs) that could
potentially pose threats to your online security. Let’s start by understanding what a TLD (Top-Level Domain) is. Essentially, it is the “.com,” “.net,” “.org,” or “.edu” part of a website or email address. In the case of pghnetworks.com, the bolded segment represents the TLD or Top-Level Domain. Traditionally, only a limited number of these TLDs were in common use. However, in
recent times, a plethora of new TLDs has emerged, making it significantly easier for cybercriminals to mimic a legitimate company. As an example, consider the image below showcasing a malicious website that appears to be a Microsoft login page. The website’s name, microsoft-office.zip, seems legitimate, especially given our familiarity with .zip files, as seen in the address bar.

Recognizing the existence of these TLDs serves as the most effective safeguard.
Certain businesses may find it beneficial to purchase several of these domains to
protect against potential misuse by unauthorized entities attempting to impersonate
their company. Here are some prevalent new TLDs to be mindful of:
- careers
- .io
- .cloud
- .us
- .law
- .tech
- .inc
If you’re curious about the range of TLDs accessible for your company or any other
entity, explore this website for more information. https://www.namecheap.com/
Written by
PGH Networks Team
The PGH Networks team — Pittsburgh-based managed IT, cybersecurity, and cloud specialists helping local businesses run securely and grow.
Related reading

CISA Orders Urgent Zimbra Patch: What Pittsburgh SMBs Should Do
CISA ordered urgent patching of an actively exploited Zimbra flaw. Here is what Pittsburgh SMBs running Zimbra should do this week to stay ahead of attackers.

Defender's Own Boot Driver Can Be Turned Against You
Check Point Research shows Microsoft Defender's BTR.sys driver can be abused to wipe security tools at boot. What Pittsburgh SMBs should do this week.

Max-Severity Entra ID Flaw Exploited: What Pittsburgh SMBs Should Do
Microsoft patched a max-severity Entra ID flaw exploited in attacks. Here is what Pittsburgh SMBs on Microsoft 365 should check this week, step by step.