Latest news of the domain name industry

Recent Posts

Rightside sells eNom to Tucows for $83.5m

Kevin Murphy, January 23, 2017, Domain Registrars

Tucows is to become “the second largest registrar in the world” by acquiring eNom from Rightside, paying $83.5 million.
The deal will give Tucows another 14.5 million domains under management and 28,000 resellers, giving it a total of 29 million DUM and 40,000 resellers.
That DUM number, which appears to include ccTLDs, makes Tucows the undisputed volume leader in the reseller world and the second-largest registrar overall.
GoDaddy, the DUM leader, had about 55 million domains just in gTLDs at the last count.
Tucows CEO Elliot Noss told analysts that the deal, along with the April 2016 acquisition of Melbourne IT’s reseller business, were “individual opportunistic transactions”.
He said that Tucows will take its time integrating the two companies, but expects to realize cost savings (presumably read: job losses as duplicate administrative positions are eliminated) over 24 months.
The reseller APIs will not change, and Tucows will not migrate names over to its own existing ICANN accreditations. This could help with reseller retention.
For Rightside, the company said the spin-off will allow it to focus on vertical integration between its gTLD registry business and its consumer-facing registrar, Name.com.
Rightside had come in for a certain amount of high-profile investor criticism for its dogged focus on new gTLDs at the expense of its eNom and Name.com businesses.
Activist investor J Carlo Cannell, supported by fellow investor and Uniregistry CEO Frank Schilling, a year ago accused Rightside of putting too much emphasis on “garbage” new gTLDs instead of its more profitable registrar businesses.
Since then, Rightside has rebuffed separate offers for some or all of its gTLDs by rivals Donuts and XYZ.com.
Last June, it also announced plans to modernize eNom, which Cannell and others had accused of looking stale compared to its competitors.

Domain “slammer” making millions in Oz

Kevin Murphy, January 13, 2017, Domain Registrars

A company accused of the domain slamming scam made over $5 million over three years tricking companies into buying domains they didn’t need, it has been alleged.
Consumer Affairs Victoria, an Australian state government watchdog, has reportedly taken Domain Register Pty Ltd to court, claiming tens of thousands of people had been conned by fake invoices.
The company sent letters that appeared to be renewal notices for .com.au names, but were actually solicitations to buy the matching .com for AUD 249 ($186) a year, an Adelaide court reportedly heard.
Domain Register, which appears to be (or was) a reseller of TPP Wholesale, made AUD 7.7 million ($5.5 million) from 31,000 suckers between 2011 and 2014, according to local reports.
auDA, the .au domain registry, warned about the company as far back as 2011.
An example of a bogus invoice attributed to Domain Register can be found here.
It’s not clear whether the defendant in the case is linked to the Brandon Gray slamming outfit, which has also gone by names including Domain Registry of America, Domain Registry of Europe, Domain Registry of Canada and Domain Renewal Group.
Brandon Gray lost its ICANN accreditation in 2014.

ICANN terminates penis pill pimp registrar

Kevin Murphy, January 5, 2017, Domain Registrars

ICANN is to terminate the contract of a Chinese registrar linked to dodgy pharmaceuticals web sites and other malfeasance.
Nanjing Imperiosus Technology Co, which does business as DomainersChoice.com, has been told it will lose its registrar accreditation February 3.
ICANN said in the termination notice that the company had failed to keep records related to abuse reports, failed to validate Whois records, and failed to provide ICANN with registration records, all in breach of the Registrar Accreditation Agreement.
The breaches related to complaints filed by illegal pharmacy watchdog LegitScript last September, I believe.
DomainersChoice and its CEO Stefan Hansmann were listed in Whois as the owners of potentially hundreds of domains that were being used to sell medicines for conditions ranging from heart disease to erectile dysfunction.
The domains 5mg-cialis20mg.com, acheterdutadalafil.com, viagra-100mgbestprice.net and 100mgviagralowestprice.net were among those apparently owned by the registrar.
According to LegitScript, thousands of DomainersChoice domains were “rogue internet pharmacies”.
The registrar has also been linked by security researchers to mass typosquatting campaigns.
The company’s web site even has a typo generator. While one could argue such tools are also useful to brand owners, DomainersChoice’s name suggests it’s geared towards domainers, not brands.
DomainersChoice had about 27,000 domains under management at the last count, which ICANN will now migrate to another registrar.
It’s not known how many of those were self-registered domains and how many were being used nefariously, but LegitScript CEO John Horton estimated (pdf) at least 2,300 dodgy pharma sites used the registrar.

Registrars off the hook for silly ICANN transfer policy

Kevin Murphy, December 27, 2016, Domain Registrars

Domain name registrars have been assured that ICANN Compliance will not pursue them for failing to implement the new Transfer Policy on privacy-protected names.
As we reported late November, the new policy requires registrars to send out “change of registrant” confirmation emails whenever certain fields in the Whois are changed, regardless of whether the registrant has actually changed.
The GNSO Council pointed out to ICANN a number of unforeseen flaws in the policy, saying that vulnerable registrants privacy could be at risk in certain edge cases.
They also pointed out that the confirmation emails could be triggered, with not action by the registrant, when privacy services automatically cycle proxy email addresses in the Whois.
This appears to have already happened with at least one registrar that wasn’t paying attention.
But ICANN chair Steve Crocker told the GNSO Council chair last week that ICANN staff have been instructed to ignore violations of the new policy, which came into effect December 1, in cases involving privacy-protected domains (pdf).
It’s a temporary measure until the ICANN board decides whether or not to defer the issue to the GNSO working group currently looking at policies specifically for privacy and proxy services.

Free .shop domains until Christmas

Kevin Murphy, December 13, 2016, Domain Registrars

The new .shop gTLD is likely to see growth over the coming week or so, as registrars begin to offer them for free.
Two retail registrars in the Key-Systems stable — Moniker and domaindiscount24 — said today they will offer a free .shop to each of their customers until December 23.
The offer is limited to one domain per account, so we’re unlikely to see the same level of growth, speculation and abuse we’ve seen in other TLDs that have offered free registrations.
Other popular registrars are currently selling first-year .shop names for $8 to $10, a discount on the usual retail price of between $25 and $30.
Interestingly and perhaps surprisingly, Key-Systems’ native Germany already has the most .shop registrations to date, with over a quarter of the 100,000 or so names registered so far to registrants in that country.
You have to go to number four in its geographic breakdown league to even get to the first Anglophone nation (the US).

GoDaddy will pay $1.79 billion for HEG in major Euro expansion

Kevin Murphy, December 7, 2016, Domain Registrars

GoDaddy is to substantially increase the size of its European operation with the $1.79 billion acquisition of Host Europe Group.
The market-leading registrar confirmed yesterday earlier reports that it was on track to buy HEG, which counts several big-name British and German registrars among its brands.
The deal is worth €1.69 billion ($1.79 billion), which breaks down to €605 million to HEG shareholders and €1.08 billion in debt. It’s expected to close in the second quarter next year.
HEG’s domain brands include 123Reg and DomainMonster in the UK and DomainFactory in Germany.
The company says it has 1.7 million customers and manages over seven million domains.
But the acquisition is more concerned with HEG’s higher-margin small business hosting business, where the company has nine data centers in Europe and the US.
GoDaddy said in a press release:

Combining GoDaddy’s global technology platform with HEG’s footprint in Europe will enable the rapid deployment of a broader range of products to customers and allow for better scale of product development and go-to-market investments across both companies.

One part of the HEG business, the $92 million-a-year PlusServer, is likely to be sold off, however.
GoDaddy said that unit “serves larger, more mature companies that require a dedicated field sales force and account management”, which is not GoDaddy’s core strength.
The deal means that GoDaddy will become the owner of the annual NamesCon conference, which HEG picked up in August for an undisclosed amount.
The acquisition is unlikely to have closed before this coming January’s NamesCon, so there’s unlikely to be many obvious changes to the 2017 event.
GoDaddy said the acquisition is being financed by debt.
HEG’s current owner is private equity firm Cinven, which paid $545 million in 2013.

DropCatch spends millions to buy FIVE HUNDRED more registrars

Kevin Murphy, December 2, 2016, Domain Registrars

Domain drop-catching service DropCatch.com has added five hundred new registrar accreditations to its stable over the last few days.
The additions give the company a total accreditation count of at least 1,252, according to DI data.
That means about 43% of all ICANN-accredited registrars are now controlled by just one company.
DropCatch is owned by TurnCommerce, which is also parent of registrar NameBright and premium sales site HugeDomains.
Because gTLD registries rate-limit attempts to register names, drop-catchers such as DropCatch find a good way to increase their chances of registering expiring names is to own as many registrars as possible.
DropCatch is in an arms race here with Web.com, owner of SnapNames and half-owner of NameJet, which has about 500 registrars.
The new accreditations would have cost DropCatch $1.75 million in ICANN application fees alone. They will add $2 million a year to its running costs in terms of extra fixed fees.
That’s not counting the cost of creating 500 brand new LLC companies — named in the new batch DropCatch.com [number] LLC where the number ranges from 1046 to 1545 — each of which is there purely for the purpose of owning the accreditation.
In total, the company is now paying ICANN fixed annual fees in excess of $5 million, not counting its variable fees and per-transaction fees.
Because the ICANN variable fee is split evenly between all registrars (with some exceptions I don’t think apply to DropCatch), I believe the addition of 500 new registrars means all the other registrars will be paying less in variable fees.
There’s clearly money to be made in expiring names.

Privacy risk under new domain transfer policy

Kevin Murphy, November 30, 2016, Domain Registrars

ICANN’s new domain Transfer Policy, which comes into effect tomorrow, creates risks for users of privacy/proxy services, registrars and others haved warned.
The policy could lead to private registrants having their contact information published in the public Whois for 60 days, the GNSO Council expects to formally tell ICANN this week.
“This could threaten privacy for at-risk registrants without clear benefit,” the Council says in a draft letter to the ICANN board.
The revised Transfer Policy was designed to help prevent domain hijacking.
The main change is that whenever there’s a “change of registrant”, the gaining and losing registrants both have to respond to confirmation emails before the change is processed.
However, “change of registrant” is defined in such a way that the confirmation emails would be triggered even if the registrant has not changed.
For example, if you change your last name in your Whois records due to marriage or divorce, or if you change email addresses, that counts as a change of registrant.
It now turns out that ICANN considers turning a privacy service on or off as a change of registrant, even though that only affects the public Whois data and not the underlying customer data held by the registrar.
The GNSO Council’s draft letter states:

ICANN has advised that any change to the public whois records is considered a change of registrant that is subject to the process defined through IRTP-C. Thus, turning a P/P service on or off is, from ICANN’s view, a change of registrant. It requires the CoR [change of registrant] process to be followed and more importantly could result in a registrant exposing his/her information in the public whois for 60 days. This could threaten privacy for at-risk registrants without clear benefit.

My understanding is that the exposure risk outlined here would only be to registrants who attempt to turn on privacy at their registrar then for whatever reason ignore, do not see or do not understand the subsequent confirmation emails.
Depending on implementation, it could lead to customers paying for a privacy service and not actually receiving privacy.
On the other side of the coin, it’s possible that an actual change in registrant might not trigger the CoR process if both gaining and losing registrants both use the same privacy service and therefore have identical Whois records.
The Council letter also warns about a possible increase in spam due to the changes:

many P/P services regularly generate new email addresses for domains in an effort to reduce spam. This procedure would no longer be possible, and registrants may be subject to unwanted messaging. Implementing the CoR for email changes that some providers do as often as every 3-5 days is not feasible.

ICANN has been aware of these issues for months. Its suggested solution is for registrars to make themselves the “Designated Agent” — a middleman permitted to authorize transfers — for all of their customers.
As we reported earlier this week, many large registrars are already doing this.
But registrars and the GNSO Council want ICANN to consider reinterpreting the new policy to exclude privacy/proxy services until a more formal GNSO policy can be created.
While the Policy Development Process that created the revised transfer rules wound up earlier this year, a separate PDP devoted to creating rules of privacy/proxy services is still active.
The Council suggests that this working group, known as PPSAI, could assume the responsibility of clearing up the mess.
In the meantime, registrars are rather keen that they will not get hit with breach notices by ICANN Compliance for failing to properly implement to what seems to be a complex policy.

Transferring domains gets more complex this week

Kevin Murphy, November 28, 2016, Domain Registrars

A new anti-hijacking domain name transfer policy comes into effect this week at all ICANN-accredited registrars, potentially complicating the process of not only selling domains but also updating your own Whois records.
But many registrars have already rewritten their terms of service to make the new rules as hassle-free as possible (and essentially pointless).
From December 1, the old ICANN Inter-Registrar Transfer Policy starts governing inter-registrant transfers too, becoming simply the Transfer Policy.
Now, when you make updates to your Whois records that appear to suggest new ownership, you’ll have to respond to one or two confirmation emails, text messages or phone calls.
The policy change is the latest output of the interminable IRTP work within ICANN’s GNSO, and is designed to help prevent domain hijacking.
But because the changes are likely to be poorly understood by registrants at the outset, it’s possible some friction could be added to domain transfers.
Under the new Transfer Policy, you will have to respond to confirmation emails if you make any of the following:

  • A change to the Registered Name Holder’s name or organization that does not appear to be merely a typographical correction;
  • Any change to the Registered Name Holder’s name or organization that is accompanied by a change of address or phone number;
  • Any change to the Registered Name Holder’s email address.

While registrars have some leeway to define “typographical correction” in their implementation, the notes to the policy seem to envisage single-character transposition and omission errors.
Registrants changing their last names due to marriage or divorce would apparently trigger the confirmation emails, as would transfers between parent and subsidiary companies.
The policy requires both the gaining and losing registrant to verify the “transfer”, so if the registrant hasn’t actually changed they’ll have to respond to two emails to confirm the desired changes.
Making any of the three changes listed above will also cause the unpopular 60-day transfer lock mechanism — which stops people changing registrars — to trigger, unless the registrant has previously opted out.
Registrars are obliged to advise customers that if the change of registrant is a prelude to an inter-registrar transfer, they’d be better off transferring to the new registrar first.
The new policy is not universally popular even among registrars, where complexity can lead to mistakes and therefore support costs.
Fortunately for them, the Transfer Policy introduces the concept of “Designated Agents” — basically middlemen that can approve registrant changes on your behalf.
Some registrars are taking advantage of this exception to basically make the confirmation aspects of the new policy moot.
Calling the confirmation emails an “unnecessary burden”, EuroDNS said last week that it has unilaterally made itself every customer’s Designated Agent by modifying its terms of service.
Many other registrars, including Tucows/OpenSRS, NameCheap and Name.com appear to be doing exactly the same thing.
In other words, many registrants will not see any changes as a result of the new Transfer Policy.
The truism that there’s no domain name policy that cannot be circumvented with a middleman appears to be holding.

GoDaddy in talks to buy massive registrar Host Europe – report

Kevin Murphy, November 25, 2016, Domain Registrars

GoDaddy is reportedly talking to Host Europe Group, one of Europe’s largest registrars, about an acquisition.
Reuters today reported that the deal, should it go ahead, could be worth as much as $1.8 billion.
GoDaddy has been favored over rival bids from United Internet (owner of United-Domains) and buyout firm Centerbridge, Reuters said.
HEG is the parent company for several registrar brands. Notably, it owns 123-reg and DomainMonster, two of the UK’s largest registrars.
123-reg had over 900,000 gTLD domains on its books at the last count. HEG overall says it manages over seven million domains.
The company was acquired by private equity group Cinven for £438 million ($545 million) in 2013.
It has 1.7 million customers and 1,300 employees spread across eight countries. It primarily operates in the UK and Germany.
HEG had 2015 revenue of €269.8 million ($286.3 million) and made a loss of €55.6 million ($59 million).
For GoDaddy, the acquisition is a chance to shift its revenue mix away from domains and more towards the more profitable hosting market, according to Reuters.