Internet infrastructure is changing shape with AI. Hosting customers require higher performance, with a growing share of requests coming from automated systems. That shift puts the DNS in a new role. For decades its job was turning names into destinations. Now it is also becoming a trust layer: whether a zone is signed, what mail policy it publishes, which services run beneath it. These are becoming trust signals.
Understanding any of this at scale means measuring it. Domain registration figures tell us that somebody registered a domain. Crawl data records what happened next: whether the domain resolves to a real site, redirects somewhere else, sits parked, or does nothing at all. That is the difference between knowing the size of the namespace and knowing how it behaves.
Our guest has been collecting that second kind of data since 2008. Rickard Vikström is the founder of DomainCrawler, a Stockholm-based domain data platform, that collects and structures internet data. DomainCrawler holds more than 368 billion domain name records and covers 99.5% of all generic and country-code TLDs, refreshing DNS, WHOIS, SSL and technology-stack data weekly. Rickard is also founder and CEO of Internet Vikings, a licensed hosting provider for regulated markets, named European CEO of the Year in the hosting industry in 2025.
DomainCrawler supplied the new gTLD usage data behind Chapter 2 of the Global Domain Report 2026, produced by InterNetX and Sedo. We come to what that research found further.

1. You have been building internet businesses since 2008. Where does that story start, and how did one idea lead to the next?
I started as a system engineer 22 years ago, straight out of school and into a hosting company at 18. I grew from there, and at some point we decided we would rather run our own hosting company. Around the same period we also started an IT security company with a few other entrepreneurs, which we later sold.
Over twenty years that became a small group of companies with the same features: B2B technology, high technical barriers to entry, and a serious commitment to sales and marketing because engineering on its own does not build a business. You can operate the best infrastructure in the market and still fail because nobody knows you exist.
None of it happened alone. Victor Jerlin and I met as teenagers, and that friendship is the actual foundation of everything that followed. He arrived at it the same way I did: a computer at home, curiosity, no degrees and no plan. My father worked with computer systems, so there was a machine in the house early and I took to it. Then you build the next thing, and the one after that, and two decades later somebody describes it as a group of companies.
2. Agentic AI workloads are putting new pressure on hosting infrastructure. What are customers asking for today that they were not asking three years ago?
GPUs because certain workloads run far more efficiently on a GPU than on a CPU, training and inference above all. That is the clearest shift in what people request.
The second shift is price pressure. When memory prices climbed, many providers raised their rates because AI workloads consume so much capacity. That is where we can still differentiate, by delivering the same service at a sensible price.
On whether agentic AI is taking a real share of internet traffic: yes, it is. You can ask an AI assistant to go and crawl something for you. But it remains standard crawling. Ten years ago you would write a small script to fetch the same data. Now you phrase the request in natural language. Whether you interact through a shell or a chat window changes nothing at the network layer. What has changed is volume. That volume became possible because every input got cheap at roughly the same moment. Storage collapsed as well. Before the current memory squeeze you could buy a 20 terabyte drive for a few hundred euros.
3. Compliance has become a cost of entry rather than a differentiator. NIS2 is fully operational and abuse-handling expectations keep rising. Where does that bar sit for hosting and domain businesses?
If you have good customers, a great deal of it resolves itself.
That was the logic behind how we built the hosting side. Target clients who already operate in regulated environments, who are accustomed to being audited and who have their own reasons to stay clean. Abuse then stops being a daily occupation. It is always the same 10% who consume 90% of your time and generate 90% of your incidents. Onboard few of those and you do not spend your week processing takedowns.
As to whether the cost of entry has risen, I would say it sits roughly where it has been for twenty years. It is a server in a data center and what you choose to put on it. The paperwork around that has expanded. The underlying business has changed less than people suggest.
4. As AI agents start navigating and transacting on their own, do DNSSEC and verifiable domain identity become part of how we establish trust for machine-to-machine traffic?
A good question, and I would approach it from the other end. If you can persuade a person to buy a counterfeit handbag from a fake shop, what prevents an agent from buying at the same shop because the price looked better there?
I expect that to become a problem, and I am not convinced DNSSEC resolves it on its own. The same applies to SSL/TLS. Both are genuinely useful and the right question is how far each one protects you. DNSSEC confirms that a domain resolves to what its owner published, that rickard.se really is rickard.se rather than an injected answer. That matters. But it says nothing about who the owner is or whether the business behind the name is legitimate. Establishing that is the difficult part, and no general mechanism for it exists today.
The problem goes beyond counterfeit shops. Consider an AI agent holding your credentials and it follows a link from an email into a phishing page. Nothing obvious prevents it from completing the login form. People will build mechanisms designed specifically to deceive agents, in the same way phishing kits evolved to deceive people. AI agents may turn out to be harder to fool in some respects and easier in others, but I would assume someone is already working on this new malicious scope.
Identity assertions published in DNS do not close the gap either, because standing up another web shop costs nothing and there is still no dependable way to confirm that the site in front of you is the one you meant to reach.
5. If no protocol solves it, is there something the industry could do collectively?
This is where the strength of the internet meets its limitation. There is no single organization. You cannot go to the UN and declare that all domain names will now work a particular way. The ccTLD space is delegated country by country, and Turkey has different rules from Germany, Germany different rules from Sweden, about what may sit on a website.
That decentralization is why nobody can switch the internet off. It is also why nobody can guarantee with certainty that you are you and I am me. We can be reasonably confiden but we cannot be sure.
ICANN does not solve it, because verifying who sits behind a domain is not what ICANN does. The IETF does not either. Nobody does, because a central register of that information would become a single point of failure for the entire network.
No organization in the world holds full authority over the internet, and that is exactly why it became a global one. Everyone can connect. Everyone can build. Something is legal in one jurisdiction and illegal in another, which cuts both ways but does protect expression. You do not get the openness without the ambiguity.
6. DomainCrawler has been indexing the internet since 2008. What are two recent insights from looking at the data?
Two things. A far more diverse internet than twenty years ago, and a considerably more vulnerable one.
The first is the volume of AI-generated counterfeit and scam sites. Phishing pages, fake shops, near-copies of real brands. I encounter many of them when working through data nowaday. That is recent and it is growing.
The second is about the diversity of the modern internet. Twenty years ago it was predominantly Latin script. Today you have Chinese, Japanese, Thai, the Indic languages, and many more. That has broadened the web substantially and brought localization with it.
The TLD data shows it. Look at which extensions grew over the past fifteen years. The Chinese ccTLD enormously, but also extensions that were small before and belong to large-population countries. Africa is the clearest illustration. Two decades ago penetration across much of the continent sat below 2%. In North and Southern Africa it now runs between 60 and 70%, according to ITU figures. Hundreds of millions of people are now online. They arrived on smartphones rather than laptops. Why buy a laptop when the phone is already in your hand? Given one choice, I would take the phone too.
The other side of that is exposure. Adoption at that pace means more people getting scammed, more people who have not learned how the web behaves, more people who assume something is true because it is published.
7. DomainCrawler supplied the new gTLD data for the Global Domain Report 2026. What did you measure, and what did it show?
Registration numbers show that someone registered a domain. Crawl data reveals behavior for this registration. That distinction is the reason the collaboration made sense: registration counts have always been available, but a count cannot tell you whether anyone built anything.
We classified how domains under new gTLDs resolve: developed website, redirect, parked, or nothing at all. We ran the same classification across legacy gTLDs for comparison.
We found 12.4% of new gTLD domains hosting a developed website against 27% for legacy gTLDs, while 62.9% of new gTLD registrations are inactive compared with 35.9% on the legacy side. Roughly two thirds of that namespace is registered but dark.
That does not surprise me. The first registrant in almost any new extension is a brand owner protecting the string defensively, and defensive registrations never produce a website.

Furthermore, registration volume and real usage do not follow the same track. Among the extensions with the most developed websites, .shop stands out: around a quarter of its registrations carry a live site. .xyz is the counterexample. It has more than twice as many registrations but fewer developed sites, so its conversion rate sits closer to 8%. The strongest performer is .dev, where nearly 27% of domains host something, because its audience registers in order to build.
Redirects tell you how a namespace is positioned. We found out more than half of all redirects from new gTLDs points to .com. That confirms .com as the launchpad, and new gTLDs mostly operating as a secondary layer in someone’s naming strategy rather than as the primary destination.
How domains resolve: new gTLDs vs. legacy gTLDs – DomainCrawler data from the Global Domain Report 2026
| – | new gTLDs | legacy gTLDs |
|---|---|---|
| Developed | 12.4% | 27% |
| Parked | 12.6% | 15.9% |
| Inactive | 62.9% | 35.9% |
| Redirect | 3.6% | 10.9% |
| Undeveloped | 8.4% | 10.3% |
8. If you could give a B2B company one piece of advice about a major infrastructure decision around AI, something that will still look sensible in five years, what would it be?
Adopt evidence rather than enthusiasm. We moved to AI as a decision at group level.
People experiment in the evenings and I encourage them to do that. At the company level I want to make sure a tool is doing real work before it becomes part of how we operate. We do use AI where it improves something tangibly.
I compare it to twenty-five years ago, when everyone built websites and everybody was suddenly a webmaster. Anyone could do it, and it helped nobody to have the entire company producing internal sites and intranets. That work was centralized eventually, people learned to handle it properly, and the value appeared then. I expect a similar arc here with AI.
The infrastructure layer rewards that patience in any case. Domains, DNS and hosting are long-lived assets. A zone file you configure today will outlast several generations of the tooling above it, and the same applies to where your domains resolve, who operates them and whether they are signed. Those decisions compound in a way that software choices generally do not. So take the AI tools that earn a permanent place in that stack, and treat everything else as an experiment until it proves otherwise.