# .zip and .mov TLDs

**URL:** https://discourse.pi-hole.net/t/zip-and-mov-tlds/62984
**Category:** Off topic
**Created:** [May 17, 2023, 1:18pm UTC](https://discourse.pi-hole.net/t/zip-and-mov-tlds/62984 "2023-05-17T13:18:23Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![chrislph](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/chrislph/32/32723_2.png) [@chrislph](https://discourse.pi-hole.net/u/chrislph)
#### Post date: [May 17, 2023, 1:18pm UTC](https://discourse.pi-hole.net/t/zip-and-mov-tlds/62984/1 "2023-05-17T13:18:24Z")

</div>

I wonder when we'll start seeing these gaining traction 😟 Something to be aware of...

> **[New ZIP domains spark debate among cybersecurity experts](https://www.bleepingcomputer.com/news/security/new-zip-domains-spark-debate-among-cybersecurity-experts/)**
>
> Cybersecurity researchers and IT admins have raised concerns over Google's new ZIP and MOV Internet domains, warning that threat actors could use them for phishing attacks and malware delivery.

---

<div class="post-metadata">

### Author: ![CallMeCurious](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/c/c4cdca/32.png) [@CallMeCurious](https://discourse.pi-hole.net/u/CallMeCurious)
#### Post date: [May 17, 2023, 7:54pm UTC](https://discourse.pi-hole.net/t/zip-and-mov-tlds/62984/2 "2023-05-17T19:54:22Z")

</div>

I read that article as well. Its an interesting read but I'm not concerned. If you believe in "think before you click" you are going to hover on a link and check it no matter what the file extension / TLD is.

---

<div class="post-metadata">

### Author: ![chrislph](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/chrislph/32/32723_2.png) [@chrislph](https://discourse.pi-hole.net/u/chrislph)
#### Post date: [May 17, 2023, 9:02pm UTC](https://discourse.pi-hole.net/t/zip-and-mov-tlds/62984/3 "2023-05-17T21:02:54Z")

</div>

I suspect the most common usage of these domains will be for malicious reasons. There's an interesting approach detailed [here](https://medium.com/@bobbyrsec/the-dangers-of-googles-zip-tld-5e1e675e59a5). I'm also wary of application behaviour changing such that filenames become clickable domain links. For example double-clicking a filename to select all the text of it could result instead in a domain opening in a browser.

If I start noticing things like that then the TLDs will be going in a blacklist in trusty Pi-hole. It'll be be interesting to see if they find their way onto Spamhaus's [most abused TLDs](https://www.spamhaus.org/statistics/tlds/) live list now that they're generally available.

As you suggest, good practice and common sense are always needed.
