Latest news of the domain name industry

Recent Posts

Chinese registrars on the decline

Kevin Murphy, October 1, 2018, Domain Registrars

Having been on a growth trajectory for some years, the number of ICANN-accredited registrars based in China appears to be on the decline.
According to my records, so far this year 26 registrar contracts have been terminated, voluntarily or otherwise, 11 of which were Chinese. I’m excluding the mass drop of Pheenix accreditations from these numbers.
The country with the next-highest number of terminations was the USA, with three.
ICANN has terminated nine registrars for breaches of the RAA this year, six of which were Chinese.
All the Chinese notices included non-payment of ICANN fees as a reason for termination, though it appears that most of them had a negligible number of gTLD domains under management.
ICANN Compliance tells me there’s no particular focus of China at the moment, this is all a result of regular day-to-day enforcement.
ICANN has sent breach notices to 28 companies this year, seven of which were to Chinese registrars.
Meanwhile, 22.cn has moved 13 of its accredited shell registrars to Hong Kong. Another registrar moved its base from China to Australia.
Seven Chinese registrars have been newly accredited this year,
Net, this has all reduced the number of accredited registrars based in China to 91.
The country still has the second-most registrars ahead of the US, with its almost 2,000 registrars, and a clear 31 registrars ahead of third-place India.

$3.2 million-a-year registrar up for grabs

Kevin Murphy, October 1, 2018, Domain Registrars

Swedish ccTLD registry IIS is to sell off its registrar business, .SE Direkt, which is expected to bring in some $3.2 million in revenue this year.
The foundation said today that .SE Direkt has 121,836 .se domains under management and 87,852 customers, 66,819 of which are corporate.
That represents about 7% of the total .se market by domains.
IIS created the registrar in 2009 as part of its transition to a competitive two-tier sales model.
The registry explained in a note to press:

The idea was that it would work as a transition solution and that domain name holders would gradually transfer to other registrars. The number of customers has not fallen at the expected rate, but after 10 years it is on a level where IIS believes that the time is right to no longer continue with the registrar operations.

The buyer, which will have to be or become an IIS-accredited .se registrar, will get the customer base, domain database and two-year brand license, but none of the staff or other assets of the unit.
.SE Direkt sells .se names for 270 SEK ($30.27) per year.
Its revenue for 2017 was SEK 29.8 million ($3.3 million) and is expected to decline to SEK 28.3 million ($3.2 million) in 2018. The buyer would take over from the start of 2019.
There’s obviously a risk here that revenue is on a downward trajectory due to IIS’s aforementioned strategy of deliberately shedding customers.
Some effort to reverse this trend may be required by whoever takes over.
Stats on churn, usage, transfers and so on can be found in this IIS RFP (pdf).
IIS said that bids from interested parties must be submitted by October 17 and the foundation expects to select the winner by November 1.

Cloudflare selling all domains at cost: “All we’re doing is pinging an API”

Kevin Murphy, September 28, 2018, Domain Registrars

Content delivery network provider Cloudflare has promised to sell domains in all TLDs at the wholesale cost, with no markup, forever.
The company made the commitment yesterday as it announced its intention to get into the registrar business.
Founder Matthew Price used the announcement to launch a blistering attack on the current registrar market, which he said is charging “crazy” prices and endlessly upselling their customers with unwanted, worthless products. He blogged:

why should registrars charge any markup over what the TLDs charge? That seemed as nutty to us as certificate authorities charging to run a bit of math. When we see a broken market on the Internet we like to do something about it.

we promise to never charge you anything more than the wholesale price each TLD charges. That’s true the first year and it’s true every subsequent year. If you register your domain with Cloudflare Registrar you’ll always pay the wholesale price with no markup.
For instance, Verisign, which administers the .com TLD, currently charges $7.85 per year to register a .com domain. ICANN imposes a $0.18 per year fee on top of that for every domain registered. Today, if you transfer your .com domain to Cloudflare, that’s what we’ll charge you per year: $8.03/year. No markup. All we’re doing is pinging an API, there’s no incremental cost to us, so why should you have to pay more than wholesale?

There are catches, of course.
For starters, the service is not available yet.
Price wrote that Cloudflare will roll it out gradually — for inbound transfers only — to its “most loyal” customers over an unspecified period. Even customers on its cheapest plans will get access to the queue, he wrote.
Eventually, he said, it will be available “more broadly”.
It will be interesting to see if the no-markup pricing could become available to non-customers too, and whether it sticks to its business model when its support lines start ringing and it becomes apparent the business is actually big ole cash vampire.
Cloudflare has been ICANN-accredited for several years, but it’s only been offering registrations to high-value enterprise customers so far.
My records show that it has not much more than 800 domains under management, all in .com, .net, .org and .info.
The announcement was made, perhaps not coincidentally, a couple days after CRM software provider Zoho made headlines when its 40 million customers were taken offline because its former registrar suspended zoho.com over a trivial level of abuse. In response to the screw-up, Zoho transferred the domain to Cloudflare.

Com Laude acquires Scottish rival

Kevin Murphy, September 11, 2018, Domain Registrars

Brand protection registrar Com Laude has picked up smaller competitor Demys for an undisclosed sum.
Demys, based in Edinburgh, is an ICANN-accredited registrar that specializes in the UK automotive, retail/leisure, media and consumer goods sectors.
It also acts as the registry manager and exclusive registrar for .bentley, the lightly-used dot-brand of luxury car-maker Bentley Motors.
It had around 12,000 gTLD domains under management at the last count, about 7,200 of which were in .com.
It’s about an eighth the size of Com Laude in terms of gTLD domains under management.
Demys has a very light footprint in new gTLDs, with local geo .scot — where it is the largest corporate registrar and fifth-largest registrar overall — being a notable exception.
London-based Com Laude said it was also interested in the company for its brand monitoring services and dispute resolution work.
Two of Demys’ top guys act as arbitrators for UDRP and .uk’s Dispute Resolution Service.

CentralNic acquired yet another company

Kevin Murphy, September 7, 2018, Domain Registrars

Acquisitive registry/registrar CentralNic has picked up another company, paying up to €2.56 million ($2.95 million) for a small Delaware-based registrar.
It will pay €1.5 million up-front for GlobeHosting, with the rest coming in two annual installments.
GlobeHosting may have a US corporate address, but it plays primarily in the Romanian and Brazilian markets.
It’s not ICANN-accredited. Instead, it acts as a Tucows reseller for gTLD domains (though I imagine that arrangement’s days are numbered).
The company had revenue of €849,000 for the 12 months to July 31 2018 and EBITDA of €419,000, CentralNic said.
The timing is arguably opportunistic. Earlier this year, Romanian registry ICI Bucharest (or ROtld) introduced an annual domain registration renewal fee for the first time (for real).
It recently started deleting names that do not pay the fee, a modest €6 per year.
CentralNic said that GlobeHosting, which appears to be notable player in the .ro market, is “expected to benefit” from this change.

.tel’s second-biggest registrar gets canned

Kevin Murphy, August 31, 2018, Domain Registrars

A Chinese registrar that focused exclusively on selling .tel domain names has been shut down by ICANN.
Tong Ji Ming Lian (Beijing) Technology Corporation Ltd, which did business as Trename, had its registrar contract terminated last week.
ICANN claims the company had failed to pay its accreditation fees and failed to escrow its registration data.
The organization had been sending breach notices since June, but got no responses. Trename’s web site domain currently resolves to a web server error, for me at least.
Trename is a rare example of a single-TLD registrar, accredited only to sell .tel domains. It didn’t even sell .com.
It is Telnames’ second-largest registrar after Name.com, accounting for about 6,000 names at the last count. At its peak, it had about 55,000.
Its share seems to be primarily as a result of a deal the registry made with a Chinese e-commerce company way back in 2011.
I’m a bit fuzzy on the details of that deal, but it saw Trename add 50,000 .tel names pretty much all at once.
Back then, .tel still had its original business model of hosting all the domains it sold and publishing web sites containing the registrant’s contact information.
Since June 2017, .tel has been available as a general, anything-goes gTLD, after ICANN agreed to liberalize its contract.
That liberalization doesn’t seem to have done much to stave off .tel’s general decline in numbers, however. It currently stands at about 75,000 names, from an early 2011 peak of over 305,000.
ICANN told Trename that its contract will end September 19, and that it’s looking for another registrar to take over its domains.
With escrow apparently an issue, it may not be a smooth transition.

More consolidation? Endurance said to be up for sale

Kevin Murphy, August 27, 2018, Domain Registrars

Endurance International Group is reportedly up for sale, perhaps the next piece of consolidation or privatization in a rapidly changing domain name market.
Bloomberg, citing unnamed sources, reports today that EIG is “is considering strategic options, including a possible sale”.
EIG owns domain brands Domain.com, BigRock, BuyDomains and ResellerClub, along with a bunch of hosting properties such as HostGator.
Bloomberg’s sources stressed that no final decision has been made, and that the company could remain public.
It’s currently listed on Nasdaq where it has a market cap today of almost $1.38 billion .
The company would be far from the first to change ownership in the last couple of years.
Most recently, Web.com (Network Solutions et al) announced a plan to go private in a $2 billion deal.
A year ago, Neustar went private in a $2.9 billion deal.
In terms of industry consolidation, we’ve more recently seen KeyDrive reverse into CentralNic and MMX buy ICM Registry.

How a single Whois complaint got this registrar shitcanned

Kevin Murphy, August 15, 2018, Domain Registrars

A British registrar has had its ICANN contract terminated after a lengthy, unprecedented fight instigated by a single complaint about the accuracy of a single domain’s Whois.
Astutium, based in London and with about 5,000 gTLD domains under management, finally lost its right to sell gTLD domains last week, after an angry battle with ICANN Compliance, the Ombudsman, and the board of directors.
While the company is small, it does not appear to be of the shady, fly-by-night type sometimes terminated by ICANN. Director Rob Golding has been an active face at ICANN for many years and Astutium has, with ICANN approval, taken over portfolios from other de-accredited registrars in the past.
Nevertheless, its Registrar Accreditation Agreement has been torn up, as a result of a complaint about the Whois for the domain name tomzink.com last December.
Golding told DI today that he considers the process that led to his de-accreditation broken and that he’s considering legal action.
The owner of tomzink.com and associated web site appears to be a Los Angeles-based music producer called Tom Zink. The web site seems legit and there’s no suggestion anywhere that Zink has done anything wrong, other than possibly filling out an incomplete Whois record.
The person who complained about the Whois accuracy, whose identity has been redacted from the public record and whose motives are still unclear, had claimed that the domain’s Whois record lacked a phone and fax number and that the registrant and admin contacts contained “made-up” names.
Historical Whois records archived by DomainTools show that in October last year the registrant name was “NA NA”.
The registrant organization was “Astutium Limited” and the registrant email was an @astutium.com address. The registrant mailing address was in Long Beach, California (the same as Zink). There were no phone/fax numbers in the record.
Golding told DI that some of these details were present when the domain was transferred in from another registrar. Others seem to have been added because the registrar was looking after the name on behalf of its client.
The admin and technical records both contained Astutium’s full contact information.
Following the December complaint, the record was cleaned up to remove all references to Astutium and replace them with Zink’s contact data. Judging by DomainTools’ records, this seems to have happened the same day as ICANN forwarded the complaint to Astutium, December 20.
So far, so normal. This kind of Whois cleanup happens many times across the industry every day.
But this is where relations between Astutium and ICANN began to break down, badly.
Even though the Whois record had been cleaned up already, Golding responded to Compliance, via the ICANN complaints ticketing system:

Please dont forward bigus/meaningless whois complaints which are clearly themselves totally inaccurate… No action is necessary or will be taken on bogus/incomplete/rubbish reports. [sic]

Golding agreed with me today that his tone was fairly belligerent from the outset, but noted that it was far from the first time he’d received a compliance complaint he considered bogus.
In the tomzink.com case, he took issue with the fact that the complainant had said that the admin/tech records contained no fax number. Not only was this not true (it was Astutium’s own fax number), but fax numbers are optional under ICANN’s Whois policy.
He today acknowledges that some parts of the complaint were not bogus, but notes that the Whois record had been quickly updated with the correct information.
But simply changing the Whois record is not sufficient for ICANN. It wants you to show evidence of how you resolved the problem in the form of copies of or evidence of communications with the registered name holder.
The Whois Accuracy Program Specification, which is part of the RAA, requires registrars to verify and validate changes to the registered name holder either automated by phone or email, or manually.
Golding told DI that in this case he had called the client to advise him to update his contact information, which he did, so the paper trail only comprises records of the client logging in and changing his contact information.
What he told ICANN in January was:

If ICANN compliance are unable to do the simple job they have been tasked with (to correctly vet and format the queries before sending them on, as they have repeatedly agreed they will do *on record* at meetings) then Registrars have zero obligations to even look at them. Any ‘lack of compliance’ is firmly at your end and not ours in this respect.
However in this specific case we chose to look, contacted the registrant, and had them update/correct/check the records, as can easily be checked by doing a whois

ICANN then explained that “NA NA” and the lack of a phone number were legitimate reasons that the complaint was not wholly bogus, and again asked Golding to provide evidence of Astutium’s correspondence with Zink.
After ignoring a further round or two of communication via the ticketing system, Golding responded: “No, we don’t provide details of private communications to 3rd parties”.
He reiterated this point a couple more times throughout February, eventually saying that nothing in WAPS requires Astutium to “demonstrate compliance” by providing such communications to ICANN, and threatening to escalate the grievance to the Ombudsman.
(That may be strictly true, but the RAA elsewhere does require registrars to keep records and allow ICANN to inspect them on demand.)
It was around the same time that Compliance started trying to get in touch with Golding via phone. While it was able to get through to the Astutium office landline, Compliance evidently had the wrong mobile phone number for Golding himself.
Golding told DI the number ICANN was trying to use (according to ICANN it’s the one listed in RADAR, the official little black book for registrars) had two digits transposed compared to his actual number, but he did not know why that was. Several other members of ICANN staff have his correct number and call him regularly, he said.
By February 27, Compliance had had enough, and issued Astutium with its first public breach notice (pdf)
Allowing a compliance proceeding to get to this stage is always bad news for a registrar — when ICANN hits the public breach notice phase, staff go out and actively search for other areas of potential non-compliance.
Golding reckons Compliance staff are financially incentivized, or “get paid by the bullet point”, at this stage, but I have no evidence that is the case.
Whatever the reason, Compliance in February added on claims:

  • that Astutium was failing to output Whois records in the tightly specified format called for by the RAA (Golding blames typos and missed memos for this and says the errors have been corrected),
  • that Astutium’s registration agreement failed to include renewal and post-renewal fees (Golding said every single page of the Astution web site, including the registration agreement page, carries a link to its price list. While he admitted the text of the agreement does not include these prices, he claimed the same could be said of some of the biggest registrars),
  • that the registration agreement does not specify how expiration notices are delivered (according to Golding, the web site explains that it’s delivered via email)
  • that the address published on the Astutium web site does not match the one provided via the Registrar Information Specification, another way ICANN internally tracks contact info for its registrars (Golding said that his company’s address is published on every single page of its site)

A final bullet point asked the company to implement corrective measures to ensure it “will respond to ICANN compliance matters timely, completely and in line with ICANN’s Expected Standards of Behavior”.
The reference to the Expected Standards of Behavior — ICANN’s code of politeness for the community — is a curious one, not typically seen in breach notices. Unless I’m reading too much into it, it suggests that somebody at ICANN wasn’t happy with Golding’s confrontational, sometimes arguably condescending, attitude.
Golding claims that some of ICANN’s allegations in this breach notice are “provably false”.
He told us he still hasn’t ruled out legal action for defamation against ICANN or its staff as a result of the publication of the notice.
“I’ll be in California, serving the paperwork myself,” he said.
Astutium did not respond to the breach notice, according to ICANN documents, and it was escalated to full-blown termination March 21.
On March 30, the registrar filed a Request for Reconsideration (pdf) with ICANN. That’s one of the “unprecedented” things I referred to at the top of this article — I don’t believe a registrar termination has been challenged through the RfR process before.
The second unprecedented thing was that the RfR was referred to Ombudsman Herb Waye, under ICANN’s relatively new, post-transition, October 2016 bylaws.
Waye’s evaluation of the RfR (pdf), concluded that Astutium was treated fairly. He noted multiple times that the company had apparently made no effort to come into compliance between the breach notice and the termination notice.
Golding was not impressed with the Ombudsman’s report.
“The Ombudsman is totally useless,” he said.
“The entire system of the Ombudsman is designed to make sure nobody has to look into anything,” he said. “He’s not allowed to talk to experts, he’s not actually allowed to talk to the person who made the complaint [Astutium], his only job is to ask ICANN if they did the right thing… That’s their accountability process.”
The Board Accountability Mechanisms Committee, which handles reconsideration requests, in June found against Astutium, based partly on the Ombudsman’s evaluation.
BAMC then gave Golding a chance to respond to its decision, before it was sent to the ICANN board, something I believe may be another first.
He did, with a distinctly more conciliatory tone, writing in an email (pdf):

Ultimately my aim has always been to have the ‘final decision’ questioned as completely disproportionate to the issue raised… and the process that led to the decisions looked into so that improvements can be made, and should there still be unresolved issues, opportunity to work in a collaborative method to solve them, without the need to involve courts, lawyers, further complaints/challenge processes and so on.

And then the ICANN board voted to terminate the company, in line with BAMC’s recommendation.
That vote happened almost a month ago, but Astutium did not lose its IANA number until a week ago.
According to Golding, the company is still managing almost all of its gTLD domains as usual.
One registry, CentralNic, turned it off almost immediately, so Astutium customers are not currently able to manage domains in TLDs such as .host, he said. The other registries still recognize it, he said. (CentralNic says only new registrations and transfers are affected, existing registrants can manage their domains.)
After a registrar termination, ICANN usually transfers the affected domains to another accredited registrar, but this has not happened yet in Astutium’s case.
Golding said that he has a deal with fellow UK registrar Netistrar to have the domains moved to its care, on the understanding that they can be transferred back should Astutium become re-accredited.
He added that he’s looking into acquiring three other registrar accreditations, which he may merge.
So, what is to be learned from all this?
It seems to me that we may be looking at a case of a nose being cut off to spite a face, somebody talking themselves into a termination. This is a compliance issue that probably could have been resolved fairly quickly and quietly many months ago.
Another takeaway might be that, if the simple act of making a phone call to a registrar presents difficulties, ICANN’s Compliance procedures may need a bit of work.
A third takeaway might be that ICANN Compliance is very capable of disrupting registrars’ businesses if they fail to meet the letter of the law, so doing what you’re told is probably the safest way to go.
Or, as Golding put it today: “The lesson to be learned is: if you don’t want them fucking with your business, bend over, grab your ankles, and get ready.”

ICANN closes GoDaddy Whois probe

Kevin Murphy, August 9, 2018, Domain Registrars

ICANN has closed its investigation into GoDaddy’s Whois practices with no action taken.
Senior VP of compliance Jamie Hedlund yesterday wrote to David Redl, head of the US National Telecommunications and Information Administration, to provide an update on the probe, news of which first emerged in April.
The NTIA and members of the intellectual property community had complained that GoDaddy was throttling Whois access over port 43 and that it was masking certain fields in the output.
That was when GoDaddy and the rest of the ICANN-regulated industry was working under the old rules, before the new temporary Whois policy had been introduced to comply with the EU General Data Protection Regulation.
Hedlund told Redl in a letter (pdf):

Based on our review and testing (including outside of ICANN’s network), GoDaddy is not currently masking WHOIS data or otherwise limiting access to its WHOIS services. Consequently, the complaints related to GoDaddy’s masking of certain WHOIS fields, rate limiting, and whitelisting of IP addresses have been addressed and closed.

GoDaddy had said earlier this year that it was throttling access over port 43 in an attempt to reduce the availability of Whois data to the spammers that have been increasingly plaguing its customers with offers of web site development and search engine optimization services.

Blacknight calls for Ireland to slash domain prices

Kevin Murphy, August 3, 2018, Domain Registrars

Irish registrar Blacknight Solutions has called for its local ccTLD registry to cut the price of .ie domains in order to drive growth.
In a press release, CEO Michele Neylon said that .ie names — typically renewing at over €20 — can cost twice as much as other European ccTLDs.
He said that a recently liberalization of registration rules set out by registry IEDR led to a burst of 29,000 new registrations in the first half of the year.
This relaxation has presumably led to cost savings that could be passed on to consumers, he said.
According to Blacknight, there are 46 .ie domains registered per 1,000 head of population, which ranks Ireland 16th out of 22 European countries.