Latest news of the domain name industry

Recent Posts

Domain registrars pressured into huge shakeup

Kevin Murphy, October 26, 2011, Domain Registrars

Domain name registrars have agreed to negotiate big changes to their standard contract with ICANN, after getting a verbal kicking from the US and other governments.
While the decision to revamp the Registrar Accreditation Agreement was welcomed by intellectual property interests, it was criticized by non-commercial users worried about diluting privacy rights.
The ICANN registrar constituency said in a statement today that it will enter into talks with ICANN staff in an effort to get a new RAA agreed by March next year.
It’s an ambitious deadline, but registrars have come under fire this week over the perception that they have been using ICANN’s arcane processes to stonewall progress.
So, what’s going to change?
The registrars said that the negotiations will focus on 12 areas, originally put forward by international law enforcement agencies, that have been identified as “high priority”.
They cover items such as an obligation to disclose the names of registrants using privacy services, to work with law enforcement, and to tighten up relationships with resellers.
Here’s a list of all 12, taken from a recent ICANN summary report (pdf).
[table id=1 /]
The changes were first suggested two years ago, and ICANN’s increasingly powerful Governmental Advisory Committee this week expressed impatience with the lack of progress.
There’s a US-EU cybercrime summit coming up next month, and GAC members wanted to be able to report back to their superiors that they’ve got something done.
As I reported earlier in the week, the GAC gave the registrars a hard time at the ICANN meeting in Dakar on Sunday, and it took its concerns to the ICANN board yesterday.
“We are looking for immediate visible and credible action to mitigate criminal activity using the domain name system,” US GAC representative Suzanne Radell told the board.
She won support from Steve Crocker who, in his first meeting as ICANN’s chairman, has shown a less combative style than his predecessor when talking with governments.
He seemed to agree that progress on RAA amendments through the usual channels – namely the Generic Names Supporting Organization – had not met expectations.
“One of the things that is our responsibility at the board level is not only to oversee the process, not only to make sure rules are followed and that everything is fair, but at the end of the day, that it’s effective,” he said.
“If all we have is process, process, process, and it gets gamed or it’s ineffective just because it’s not structured right, then we have failed totally in our duty and our mission,” he said.
An immediate result of the registrars’ decision to get straight into talks was the removal of an Intellectual Property Constituency motion from today’s GNSO Council meeting.
The IPC had proposed that the RAA should be revised in a trilateral way, between the registrars, ICANN, and everyone else via the GNSO.
Yanking the motion, IPC representative Kristina Rosette warned that the IPC would bring it back to the table if the RAA talks do not address the 12 high-priority items.
It would be unlikely to pass – registrars and registries vote against anything that would allow outside interests to meddle in their contracts, and they have the voting power to block such motions.
The ideas in the motion nevertheless stirred some passionate debate.
Tucows CEO Elliot Noss described the GAC’s heavy-handed criticisms as “kabuki theater” and “an attempt to bring politics as usual into the multi-stakeholder process” and said the RAA is not the best way to add protections to the DNS.
“Getting enforcement-type provisions, be they law enforcement or IP protections, into the RAA accomplishes only one thing. It turns the ICANN compliance department into a police department,” he said.
Wendy Seltzer, representing the Non-Commercial Users Constituency, said the changes proposed to the RAA “would reduce the privacy of registrants” and put them at increased risk of domain take-downs.
A broader issue is that even after a new RAA is negotiated registrars will be under no obligation to sign up to it until their current contracts expire.
Because many leading registrars signed their last contract after it was revised in 2009, it could be three or four years before the new RAA has any impact.
I’m not sure it’s going to be enough to fully satisfy the GAC.
Radell, for example, said yesterday that some items – such as the registrar obligation to publish an abuse contact – should be brought in through a voluntary code of conduct in the short term.
She also called for the 20% of registrars deemed to be bad actors (not a scientifically arrived-at number) should be de-accredited by ICANN.
UPDATE (October 27): Mason Cole of the registrars constituency has been in touch to say that the RAA talks will not only look at the 12 “high priority” or law enforcement recommendations.
Rather, he said, “there will be consideration of a broader range of issues.”
This appears to be consistent with the registrars’ original statement, which was linked to in the above post:

The negotiations are in response to the development of a list of recommendations made by law enforcement agencies and the broader Internet community to provide increased protections for registrants and greater security overall.

GAC slams registrars over “silly” crime domain moves

Kevin Murphy, October 24, 2011, Domain Registrars

ICANN’s Governmental Advisory Committee is seriously annoyed with domain name registrars over what it sees as a failure to take the demands of law enforcement seriously.
The first official day of ICANN’s 42nd public meeting in Dakar, Senegal, was highlighted by a fractious discussion between the GAC and the Generic Names Supporting Organization.
Governments are evidently losing patience with the industry over what they see as incessant foot-dragging and, now, halfhearted bone-throwing.
The US, which is easily the most influential GAC member, was harshly critical of recent efforts by registrars to self-regulate themselves some law enforcement cooperation policies.
US GAC representative Suzanne Radell, saying she was speaking on behalf of the GAC, described a registrar move to start publishing legal service addresses on their web sites at some point in the future as as “paltry”, “mind-boggling” and “silly”.
She heavily implied that if the industry can’t self-regulate, the alternative is governments doing it for them. She was backed up by her counterparts from the UK, Australia and the European Commission.
Registrars have been talking to law enforcement for a few years about how to more effectively work together to prevent crime online.
In October 2009, agencies including the FBI and the UK Serious Organised Crime Agency publish a set of 12 recommendations about how to clean up the industry.
A lot of it was pretty basic stuff like a prohibition on registrar cybersquatting and an obligation to publish an abuse point of contact.
Despite a lot of talking at ICANN meetings, up until a couple of weeks ago there had not been a great deal of tangible progress.
The GNSO passed a resolution, proposed by registrars, to ask for an Issue Report to discuss whether registrars should be forced to post on their sites: a physical address for legal service, the names of key executives, and an abuse contact.
In ICANN’s world, an Issue Report usually precedes a Policy Development Process, which can take a year or more to produce results.
While the GNSO motion passed, it was opposed as inadequate by factions such as the Intellectual Property Constituency, which has close ties to the US government.
As the IPC seemed to correctly predict, the GAC was not amused.
“It is simply impossible for us to write a briefing memo for our political managers to explain why you need a policy to simply put your name on your web site,” Radell told the GNSO Council yesterday. “It is simply mind-boggling that you would require that.”
She pointed out that at a session during the Singapore meeting, registrars had indicated a willingness to address more of the law enforcement demands.
“That’s the context in which we are now coming to you saying this looks pretty paltry and actually it looks a little silly,” she said.
Mason Cole from the registrar constituency denied that they were “roadblocking” law enforcement’s demands, saying that a PDP is the fastest way to create a policy binding on all registrars.
“I think law enforcement was very clear when they made their proposals to us that what they were looking for was binding, enforceable provisions of policy that could be imposed on the registrars,” he said. “A code of conduct or a voluntary method would not arrive at binding, enforceable policy and therefore probably wouldn’t achieve the outcomes that law enforcement representatives were seeking.”
The debate didn’t end yesterday. Radell said she intends to take it up with the ICANN board of directors, presumably at their joint meeting tomorrow.
The implicit threat underlying the GAC’s protest is a legislative one, and Radell and other GAC members made it pretty clear that their governments back home regard domain names as a crucial tool in fighting online crime.

More layoffs planned at NetSol

Kevin Murphy, October 17, 2011, Domain Registrars

Web.com plans to lay off more people than previously expected at recently acquired domain name registrar Network Solutions, according to a report.
“There is significantly more overlap than we originally estimated, and so it’s likely going to be more headcount reduction,” CEO David Brown said in a Reuters interview.
He named marketing, development, and engineering as areas where the merged company plans to cut more than $30 million in costs.
If there was any doubt about it, he confirmed that NetSol’s incumbent CEO faces the chop. Lower-level staff appear to have safer positions.
At least two senior NetSol executives have already jumped shipped since the acquisition was announced.
Senior director of policy Statton Hammock left to form his own consulting business a month ago, and last week senior policy manager Paul Diaz joined the Public Interest Registry.
Web.com announced its $561 million acquisition of NetSol in early August. It had already acquired the company’s old rival, Register.com.

Registrars not happy with VeriSign abuse plans

Kevin Murphy, October 12, 2011, Domain Registrars

VeriSign has been talking quietly to domain name registrars about its newly revealed anti-abuse policies for several months, but some are still not happy about its plans for .com malware scans.
The company yesterday revealed a two-pronged attack on domain name abuse, designed to counteract a perception that .com is not as secure a space as it should be.
One prong, dealing with law enforcement requests to seize domains, I covered yesterday. It’s already received criticism from the Electronic Frontier Foundation and American Civil Liberties Union.
The other is an attempt to introduce automatic malware scanning into the .com, .net and .name spaces, rather like ICM Registry has said it will do with all .xxx domains.
Unlike the daily ICM/McAfee service, VeriSign’s free scans will be quarterly, but the company intends to also offer a paid-for upgrade that would search domains for malware more frequently.
On the face of it, it doesn’t seem like a bad idea.
But some registrars are worried about the fading line between registrars, which today “own” the customer relationship, and the registries, which for the most part are hidden away in the cloud.
Go Daddy director of network abuse Ben Butler, asked about both of yesterday’s VeriSign proposals, said in a statement that they have “some merit”, but sounded several notes of caution:

This is going to make all registrars responsible for remediation efforts and negative customer-service clean up. The registrar at this point becomes the “middle man,” dealing with customers whose livelihood is being negatively impacted. As mentioned in their report, the majority of sites infected with malware were not created by the “bad guys.”
While there is an appeal process mentioned, it could take some time to get issues resolved, potentially leaving a customer’s website down for an extended period.
This could also create a dangerous situation, allowing registries to gain further control over registrars’ operations – as registrars have the relationship with the registrant, the registrar should be responsible for enforcing policies and facilitating remediation.

It has also emerged that VeriSign unilaterally introduced the malware scanning service as a mandatory feature of .cc and .tv domains – which are not regulated by ICANN – earlier this year.
The changes appear to have been introduced without fanfare, but are clearly reflected in today’s .tv registration policies, which are likely to form the basis of the .com policies.
Some registrars weren’t happy about that either.
Six European registrars wrote to VeriSign last month to complain that they were “extremely displeased” with the way the scanning service was introduced. They told VeriSign:

These changes mark the beginning of a substantive shift in the roles of registries regarding the monitoring and controlling of content and may lead to an increase of responsibility and liability of registries and registrars for content hosted elsewhere. As domain name registrars, we hold the position that the responsibilities for hosted content and the registration of a domain name are substantially different, and this view has been upheld in European court decisions numerous times. In this case, Verisign is assuming an up-front responsibility that surpasses even the responsibilities of a web hoster, and therefore opens the door to added responsibilities and legal liability for any form of abuse.

In the end, the registrar community will have to face the registrant backlash and criticism, waste countless hours of support time to explain this policy to the registrants and again every time they notice downtimes or loss of performance. These changes are entirely for the benefit of Verisign, but the costs are delegated to the registrants, the registrars and the hosting service providers.

The registrars were concerned that scanning could cause hosting performance hits, but VeriSign says the quarterly scan uses a virtual browser and is roughly equivalent to a single user visit.
They were also worried that the scans, which would presumably ignore robots.txt prohibitions on spidering, would be “intrusive” enough to potentially violate European Union data privacy laws.
VeriSign now plans to give all registrars an opt-out, which could enable them to avoid this problem.
It looks like VeriSign’s plans to amend the Registry-Registrar Agreement are heading for ICANN-overseen talks, so registrars may just be digging into a negotiating position, of course.
But it’s clear that there is some unease in the industry about the blurring of the lines between registries and registrars, which is only likely to increase as new gTLDs are introduced.
In the era of new gTLDs, and the liberalization of ICANN’s vertical integration prohibitions, we’re likely to see more registries having hands-on relationships with customers.

Domain Registry of America still slamming, still scamming

Kevin Murphy, October 6, 2011, Domain Registrars

Domain name slamming is alive and well in the ICANN-accredited registrar community.
I’ve just received a letter in the mail offering me the chance to transfer and renew domainincite.com for the knock-down price of £25 ($38) a year.
It’s Domain Registry of America again, still slamming almost a decade after it was first sued for the completely unethical practice of conning people into transferring their domain names.
Domain Renewal GroupThe letter looks like a renewal notice. Besides ostensibly coming from “Domain Renewal Group”, it also contains the prominent text “Domain Name Renewal Service”.
Domain Renewal Group and Domain Registry of America are one and the same – fronts for the ICANN-accredited registrar Brandon Gray Internet Services Inc, dba NameJuice.com.
The letter, as you can see from the scan, is a little less bogus than the ones DROA started sending out back in 2001. The text states now much more clearly that “this is not a bill”.
But domain slamming has always relied upon people not reading the letter properly and/or not understanding the intricacies of domain transfers, and this is no different.
DROA’s business depends upon its letters finding their way into the hands of gullible individual registrants or accounting departments that will blindly pay official-looking notices.
At the prices the company charges – pretty much the most expensive in the industry – very few people will have transferred their domains because they thought they were getting a good deal.
There have been numerous complaints and lawsuits against DROA over the last decade.
In November 2009, the UK Advertising Standards Agency found DROA in breach of truthfulness and honesty guidelines for a substantially similar mailshot and ruled:

The mailing must not appear again in its current form.

And last year, the .ca registry CIRA terminated Domain Registry of Canada, another Brandon Gray front, for slamming .ca registrants using the same methods.
So isn’t it about time ICANN shut these muppets down too?
Unfortunately, ICANN can only use contracts to enforce compliance, and I’m not sure there are any sticks in the 2001 Registrar Accreditation Agreement that it can use to beat them.
DROA has plainly breached Go Daddy’s Whois access policy by slamming me (the letter was sent to my Whois billing address, not my actual residence), but I don’t think there’s much Go Daddy can do about that short of suing.
As far as I can tell, Brandon Gray, which has about 130,000 domains under management, got its ICANN accreditation in about 2003. It was previously an eNom reseller.
So its accreditation is probably going to be up for renewal within the next couple of years.
Fortunately, ICANN has just this week introduced stricter new accreditation application rules that are specifically designed to weed out the scumbags.
Any company or individual with a track record of dishonesty is no longer welcome at ICANN.
So if there’s nothing that can be done before then, at the very least when Brandon Gray’s accreditation expires ICANN should not renew it.
What’s more, other registrars should lean on ICANN to make sure Brandon Gray is shown the door. It’s been bringing their industry into disrepute for the best part of a decade and it’s time for it to stop.

WordPress.com’s registrar service: Slow cookin’ makes good eatin’

Kevin Murphy, September 26, 2011, Domain Registrars

WordPress.com provider Automattic has not abandoned its plans to start offering domain names directly to its users, according to its lead developer.
It’s been about 11 months since the company received its ICANN accreditation, but it is currently still acting as a Go Daddy reseller.
“Our registry product is still under development,” Automattic founder and chief barbecue taste tester (really) Matt Mullenweg said in an email. “Slow cookin’ makes good eatin’.”
WordPress.com announced last week that it would start offering .me domains, alongside .com, .org, and .net, saying it would give users a better chance to get a domain they liked.
The .me registry, Domen, is a joint venture whose partners include Go Daddy and Afilias.
“GoDaddy is a valued partner and we continue to use many of their services as part of our business,” Mullenweg added.
Domain names are WordPress.com’s best-selling add-on product. According to DomainTools, over 226,000 domains are hosted on the same servers as WordPress.com.

NBT agrees to $236m buy-out

Kevin Murphy, September 23, 2011, Domain Registrars

Following in the footsteps of larger rival Go Daddy, the UK-based registrar Group NBT has agreed to be bought out by private investors for £153 million ($236m).
NBT owns registrars including NetNames, Ascio and Indom.
The all-cash offer comes from investors led by HgCapital and represents a 22.5% premium on the company’s closing share price yesterday.
At 550p a share, the offer stands to make a profit for anybody who has bought NBT shares in the last ten years, according to the company.
The news came as NBT reported an annual profit, excluding certain items, up organically 9% at £8.9 million ($13.8m) on revenue that was up 4% at £45.7 million ($70.6m).
Including the results from French registrar Indom, which the company acquired last December, profit was up 18% at £9.6 million ($14.8m) on revenue up 13% to £49.5 million ($76.5m)
The NBT deal is merely the latest in a series of buyouts and mergers to hit the registrar market this year.
As well as Go Daddy’s $2 billion+ change of control, Network Solutions recently sold out to Web.com for $561 million in cash and stock, and Tucows acquired EPAG Domainservices for $2.5 million.
At least one city analyst thinks the buyout timing relates to ICANN’s forthcoming new generic top-level domains program, and is bullish on Top Level Domain Holdings shares as a result.
Will the wave of consolidation continue? Who’s next?

Bob Parsons worth $1.5bn, ranked 293 on Forbes 400

Kevin Murphy, September 22, 2011, Domain Registrars

Go Daddy executive chairman Bob Parsons is the 293rd wealthiest person in America, with a self-made fortune of $1.5 billion, according to the latest Forbes 400 rich list.
In its annual league table, published yesterday, Forbes ranks Parsons tied with tech investors such as LinkedIn co-founder Reid Hoffman and Groupon co-founder Evan Lefkofsky.
Parsons, Go Daddy’s founder and erstwhile CEO, is a debutant on the list following his sale of a majority stake in the company to a group of institutional investors.
KKR, Silver Lake and Technology Crossover Ventures collectively bought out more than half of Go Daddy in a deal announced in July, reportedly worth north of $2 billion.

Melbourne IT makes three senior hires

Kevin Murphy, September 21, 2011, Domain Registrars

Aussie domain registrar Melbourne IT has recruited three senior executives from elsewhere in the industry to bulk up its Digital Brand Services business.
SSL evangelist Tim Callan, formerly with VeriSign, has been appointed chief marketing officer. He moved to Symantec after the VeriSign security business changed hands, but left in May.
Lena Carlsson, Melbourne’s new VP of domain strategy, is a former Swedish civil servant and former vice-chair of ICANN’s Governmental Advisory Committee.
Rob Holmes has also been recruited from brand management rival Corporation Services Company as the new global director of brand protection services.
The hires all appear to have been made over the last few months and were announced in a press release today.

Go Daddy’s 60-day domain lockdown loophole

Kevin Murphy, September 8, 2011, Domain Registrars

Perhaps the most common complaint of the many leveled at Go Daddy over the years is that it refuses to allow customers to transfer domains to another registrar for 60 days after an ownership change.
The latest person to fire this criticism at the company is tech blogger Scott Raymond, who published a lengthy tirade against Go Daddy and its policy on ZDNet today.
Raymond points out that Go Daddy seems to be in violation of ICANN’s Inter-Registrar Transfer Policy, which explicitly prohibits the rejection of a transfer request due to a recent Whois change.
He’s not alone. Even Andrew Allemann of Domain Name Wire, hardly Go Daddy’s fiercest critic, said as recently as May that he thinks the company is in violation of the IRTP.
With good reason – this April 2008 ICANN advisory seemed to be specifically written with a ban on Go Daddy’s 60-day policy in mind.
But is the company non-compliant? ICANN doesn’t seem to think so.
I’ve tracked down this November 2009 email from David Giza, then ICANN’s head of compliance, in which he describes what seems to amount to a loophole Go Daddy and other registrars exploit.
Giza explains that the 2008 advisory “only addresses mandatory updates to Whois contact information, not a transfer or assignment to a new registrant”.
Registrants are obliged to keep their Whois data up-to-date; that’s what he means by “mandatory”.
Giza’s email adds:

the transfer policy does not prohibit registrars from requiring registrants to agree to the blocking of transfer requests as a condition for registrar facilitation of optional services such as the transfer of a registration to a new registrant.
We understand GoDaddy.com’s 60-day lock is a voluntary opt-in process where registrants are made aware of and agree to the restriction that the domain name is not to be transferred for 60-days following the completion of transfer. As such, this practice is not prohibited by the transfer policy.

In other words, there are “Whois Changes” and there are “Registrant Changes”, and registrars are only allowed to trigger a lock-down in the latter case, according to Giza.
And according to DNW’s reporting on the subject, that’s exactly what Go Daddy continues to do — locking the domain if certain fields in the registrant record are changed.
So the 60-day lock appears to be kosher, at least in the opinion of ICANN’s erstwhile compliance chief. Whether that could change under the department’s new management is unknown.
As it happens, the subject was raised by a recent working group that was looking into revising the IRTP, but it was so contentious that consensus could not be found.
The problem has been bounced down the road. The most recent mention came in this ICANN issue report (pdf, page 14-15).
Anyway, if I lost you several paragraphs ago, the net result of all this seems to be that Go Daddy probably isn’t breaking the rules, but that nobody can agree whether that’s a good thing or not.
The fact that one has to do this much digging into ICANN esoterica just to figure out whether Go Daddy is screwing its customers over isn’t very reassuring, is it?