Phishing groups are abusing .arpa domains for their operations, a TLD that's not supposed to host anything except IP-address-to-domain maps
Abusing .arpa: The TLD That Isn’t Supposed to Host Anything
The .arpa domain is being abused to host phishing content on domains that should not resolve to an IP address, but do.
Infoblox Blog (www.infoblox.com)


