Hijacking
Zero-click redirect abuse
Visitors to a parked or expired domain are instantly forwarded to whoever pays most, including scams, with no page shown and no choice made.
How it works
In classic parking the visitor sees a page of links and chooses one. In zero-click parking, also sold as "direct search" or domain redirect traffic, there is no page: the visit is auctioned in a fraction of a second and the browser is forwarded to the winning bidder. Done properly, the buyer is a relevant advertiser and the user lands somewhere useful.
The abuse comes from who is allowed to bid and how visitors are sorted. Security researchers at Infoblox reported in December 2025 that the system profiled each visitor: people on home connections were passed down chains of redirects to scams, scareware and malware, while visitors who looked like researchers (VPNs, data-centre addresses) were shown a harmless parking page. Arbitrageurs meet this from the other side as buyers: redirect traffic can be valuable, but the visitor did not ask to see the page, and quality varies widely.
Who pays for it
Users, first of all. Brands whose expired or mistyped domains feed the system. Legitimate buyers of redirect traffic, whose feeds are put at risk by unwilling visitors.
Who does it, and why
Operators of malicious ad networks buying redirects, and domain holders who, after parking revenue from Google fell away, sell to any bidder. The Infoblox researchers linked the change in behaviour to that loss of mainstream ad demand.
Warning signs
- A parked domain that behaves differently on a home connection than on a VPN.
- Multiple redirect hops through unrelated domains before the final page.
- Final pages pushing fake virus warnings, subscriptions or downloads.
- Redirect traffic with near-zero engagement on the buyer's page.
Defences
- Domain owners: choose monetisation partners that vet buyers, and test your own domains from home connections.
- Buyers: keep zero-click traffic in its own channel, at low volume, and judge it on quality data.
- Confirm with the feed that redirect traffic is an approved source before sending any.
- Let unused domains lapse to a neutral page instead of selling the traffic blind.
An example
Real research: Infoblox found that in its tests more than 90% of visits to parked domains led to illegal content, scams, scareware, antivirus subscription offers or malware. A study a decade earlier, in 2014, had put malicious redirects from parked domains below 5%.
Documented cases
- Malicious "direct search" redirects on parked domains (2025): Zero-click parking abuse: visitors to parked and typo domains sold on to scams and malware