---
id: "sinkhole"
kind: "glossary-term"
title: "sinkhole"
language: "en"
category: "Security and abuse"
updated: "2026-10-10T09:10:26Z"
canonical: "https://tldlog.com/glossary/sinkhole/"
translations:
  es: "https://tldlog.com/es/glosario/sinkhole/"
  de: "https://tldlog.com/de/glossar/sinkhole/"
  fr: "https://tldlog.com/fr/glossaire/sinkhole/"
  it: "https://tldlog.com/it/glossario/sinkhole/"
  pt-BR: "https://tldlog.com/pt/glossario/sinkhole/"
  ru: "https://tldlog.com/ru/glossariy/sinkhole/"
  zh-Hans: "https://tldlog.com/zh/cihui/sinkhole/"
---

# sinkhole

A server that receives traffic meant for a malicious domain, run by those fighting the abuse, for example at the request of the police, instead of the criminals. The domain is pointed to it, often under a court order or by agreement with the registry. Infected devices then connect to it instead of to the attackers.

## related terms

- [botnet](https://tldlog.com/glossary/botnet/)
- [command and control domain](https://tldlog.com/glossary/c2-domain/)
- [domain seizure](https://tldlog.com/glossary/domain-seizure/)
- [DGA](https://tldlog.com/glossary/dga/)
- [takedown](https://tldlog.com/glossary/takedown/)
