Half of registrar’s domains are abusive, ICANN says
A fast-growing registrar seems to be experiencing its growth spurt due to extremely high levels of DNS abuse, including phishing, according to the latest public breach notice from ICANN Compliance.
More than half of Bulgarian registrar MainReg’s domains under management are abusive, judging by the notice, which alleges MainReg’s unwillingness to investigate abuse reports in violation of its accreditation contract.
The notice is the first I can recall seeing that cites data from Domain Metrica, an ICANN service that aggregates abuse data from third-party block-lists. An unspecified third-party reporter (hands up in the comments if it was you!) is also cited.
“ICANN Domain Metrica data indicates that in November 2025 approximately 48% of MainReg’s DUMs were reported for phishing, with the figure at 45% as of 5 January 2026,” the notice says.
“The complaining party stated that its own independent analysis identified an even higher proportion of the Registrar’s DUMs engaged in scam‑related activity,” it adds.
MainReg isn’t a huge registrar, but transaction reports show that its DUM tripled between September 2024 and September 2025, from about 10,000 names to about 30,000. The company registered its first name in 2015. Almost all of its names are in .com, .net and .org.
The notice alleges other breaches, such as failing to migrate from Whois to RDAP, and gives MainReg until January 28 to come in compliance or risk termination.
Domain Incite relies on support from readers like you to survive. Please consider making a one-off or recurring donation via PayPal. Please support Domain Incite, the independent source of news, analysis and opinion for the domain name industry and ICANN community.







Recent Comments