Security Issue: .edu.eu Domain Suffix Being Used Exclusively for Educational Fraud

What is the name of the domain?

edu.eu

What is the issue you’re encountering

TL;DR: Cloudflare currently treats .edu.eu as a public suffix allowing anyone to add xxx.edu.eu domains to accounts, but extensive research shows this entire domain space is being used exclusively for educational fraud and scams.

What feature, service or problem is this related to?

Nameservers

What are the steps to reproduce the issue?

The Problem

Recent research on all .edu.eu subdomains and found zero legitimate educational institutions. Every single one appears to be either:

  • Fake universities targeting international students
  • Degree mills selling fraudulent credentials
  • Scam operations collecting personal/financial information
  • Identity theft schemes

Technical Issues

  1. Public Suffix Treatment: CF treats .edu.eu as a public suffix despite it not being in Mozilla’s PSL
  2. Scammer Hosting: Multiple fraudulent .edu.eu sites are hosted on Cloudflare infrastructure
  3. Domain Validation: Users can add any xxx.edu.eu subdomain to CF accounts without educational verification

Evidence Summary

  • .edu.eu is NOT an official EU educational domain - it’s operated by a private company
  • Europe’s legitimate universities (Oxford, Cambridge, Sorbonne, etc.) don’t use .edu.eu
  • Documented victim reports of students losing thousands to fake universities
  • Technical analysis shows coordinated fraud operations sharing infrastructure
  • Multiple news outlets have reported on this scam network

Recommendations

  1. Remove public suffix treatment for .edu.eu from Cloudflare systems
  2. Review existing .edu.eu sites hosted on CF for ToS violations
  3. Consider domain-level restrictions given the systematic fraud

The .edu.eu registry enables widespread educational fraud by creating false legitimacy. No legitimate educational institution uses this domain suffix.

Full research report: https://jy.md/edu-eu-domain

Has anyone else encountered this issue? What’s CF’s policy on domain suffixes used exclusively for fraudulent purposes?

A quick script…

Total domains in list: 224
Total domains with at least one A record: 57
Total domains with nameservers containing ns.cloudflare.com: 23
Total domains using CF proxy: 16

Those using the proxy are likely not hosted on Cloudflare but if you file an abuse report with Cloudflare as @cscharff linked to, they will inform the underlying host of your complaint.

If that’s the case, complain to EURid about edu.eu and get them to act on it.

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.