Latest news of the domain name industry

Recent Posts

Verisign and Afilias in open war over $135m .web

Kevin Murphy, November 11, 2016, Domain Registries

Two of the industry’s oldest and biggest gTLD registries escalated their fight over the .web gTLD auction this week, trading blows in print and in public.
Verisign, accused by Afilias of breaking the rules when it committed $130 million to secure .web for itself, has now turned the tables on its rival.
It accuses Afilias of itself breaking the auction rules and of trying to emotionally blackmail ICANN into reversing the auction on spurious political grounds.
The .web auction was won by obscure shell-company applicant Nu Dot Co with a record-setting $135 million bid back in July.
It quickly emerged, as had been suspected for a few weeks beforehand, that Verisign was footing the bill for the NDC bid.
The plan is that NDC will transfer its .web ICANN contract to Verisign after it is awarded, assuming ICANN consents to the transfer.
Afilias has since revealed that it came second in the auction. It now wants ICANN to overturn the result of the auction, awarding .web to Afilias as runner-up instead.
The company argues that NDC broke the new gTLD Applicant Guidebook rules by refusing to disclose that it had become controlled by Verisign.
It’s now trying to frame the .web debate as ICANN’s “first test of accountability” under the new, independent, post-IANA transition regime.
Afilias director Jonathan Robinson posted on CircleID:

If ICANN permits the auction result to stand, it may not only invite further flouting of its rules, it will grant the new TLD with the highest potential to the only entity with a dominant market position. This would diminish competition and consumer choice and directly contradict ICANN’s values and Bylaws.

Given the controversy over ICANN’s independence, all eyes will be on the ICANN board to see if it is focused on doing the right thing. It’s time for the ICANN board to show resolve and to demonstrate that it is a strong, independent body acting according to the letter and spirit of its own AGB and bylaws and, perhaps most importantly of all, to actively demonstrate its commitment to act independently and in the global public interest.

Speaking at the first of ICANN’s two public forum sessions at ICANN 57 in Hyderabad, India this week, Robinson echoed that call, telling the ICANN board:

You are a credible, independent-minded, and respected board who recognized the enhanced scrutiny that goes with the post-transition environment. Indeed, this may well be the first test of your resolve in this new environment. You have the opportunity to deal with the situation by firmly applying your own rules and your own ICANN bylaw-enshrined core value to introduce and promote competition in domain names. We strongly urge you to do so.

Then, after a few months of relative quiet on the subject, Verisign and NDC this week came out swinging.
First, in a joint blog post, the companies rubbished Afilias’ attempt to bring the IANA transition into the debate. They wrote:

Afilias does a great disservice to ICANN and the entire Internet community by attempting to make this issue a referendum on ICANN by entitling its post “ICANN’s First Test of Accountability.” Afilias frames its test for ICANN’s new role as an “independent manager of the Internet’s addressing system,” by asserting that ICANN can only pass this test if it disqualifies NDC and bars Verisign from acquiring rights to the .web new gTLD. In this case, Afilias’ position is based on nothing more than deflection, smoke and cynical self-interest.

Speaking at the public forum in Hyderabad on Wednesday, Verisign senior VP Pat Kane said:

This is not a test for the board. This issue is not a test for the newly empowered community. It is a test of our ability to utilize the processes and the tools that we’ve developed over the past 20 years for dispute resolution.

Verisign instead claims that Afilias’ real motivation could be to force .web to a private auction, where it can be assured an eight-figure payday for losing.
NDC/Verisign won .web at a so-called “last resort” auction, overseen by ICANN, in which the funds raised go into a pool to be used for some yet-to-be-determined public benefit cause.
That robbed rival applicants, including Afilias, of the equal share of the proceeds they would have received had the contention set been settled via the usual private auction process.
But Verisign/NDC, in their post, claim Afilias wants to force .web back to private auction.

Afilias’ allegations of Applicant Guidebook violations by NDC are nothing more than a pretext to conduct a “private” instead of a “public” auction, or to eliminate a competitor for the .web new gTLD and capture it for less than the market price.

Verisign says that NDC was under no obligation to notify ICANN of a change of ownership or control because no change of ownership or control has occurred.
It says the two companies have an “arms-length contract” which saw Verisign pay for the auction and NDC commit to ask ICANN to transfer its .web Registry Agreement to Verisign.
It’s not unlike the deal Donuts had with Rightside, covering over a hundred gTLD applications, Verisign says.

The contract between NDC and Verisign did not assign to Verisign any rights in NDC’s application, nor did Verisign take any ownership or management interest in NDC (let alone control of it). NDC has always been and always will be the owner of its application

Not content with defending itself from allegations of wrongdoing, Verisign/NDC goes on to claim that it is instead Afilias that broke ICANN rules and therefore should have disqualified from the auction.
They allege that Afilias offered NDC a guarantee of a cash payout if it chose to go to private auction instead, and that it attempted to coerce NDC to go to private auction on July 22, which was during a “blackout period” during which bidders were forbidden from discussing bidding strategies.
During the public forum sessions at ICANN 57, ICANN directors refused to comment on statements from either side of the debate.
That’s likely because it’s a matter currently before the courts.
Fellow .web loser Donuts has already sued ICANN in California, claiming the organization failed to adequately investigate rumors that Verisign had taken over NDC.
Donuts failed to secure a restraining order preventing the .web auction from happening, but the lawsuit continues. Most recently, ICANN filed a motion attempting to have the case thrown out.
In my opinion, arguments being spouted by Verisign and Afilias both stretch credulity.
Afilias has yet to present any smoking gun showing Verisign or NDC broke the rules. Likewise, Verisign’s claim that Afilias wants to enrich itself by losing a private auction appear to be unsupported by any evidence.

ICANN to terminate Guardian’s last gTLD

Kevin Murphy, October 27, 2016, Domain Registries

Newspaper publisher Guardian News & Media is out of the gTLD game for good now, with ICANN saying this week that it will terminate its contract for the dot-brand, .theguardian.
It’s the 14th new gTLD registry agreement to be terminated by ICANN. All were dot-brands.
The organization has told Guardian that it started termination proceedings October 21, after the company failed to complete its required pre-delegation testing before already-extended deadlines.
.theguardian was the only possible gTLD remaining of the five that Guardian originally applied for.
It signed its registry agreement with ICANN in April 2015, but failed to go live within a year.
Guardian also applied for .guardian, which it decided not to pursue after facing competition from the insurance company of the same name.
The .observer gTLD, a dot-brand for its Sunday sister paper, was sold off to Top Level Spectrum last month and has since been delegated as a non-brand generic.
Applications for .gdn and .guardianmedia were withdrawn before Initial Evaluation had even finished.

Thick Whois coming to .com next year, price rise to follow?

Kevin Murphy, October 27, 2016, Domain Registries

Verisign could be running a “thick” Whois database for .com, .net and .jobs by mid-2017, under a new ICANN proposal.
A timetable published this week would see the final three hold-out gTLDs fully move over to the standard thick Whois model by February 2019, with the system live by next August.
Some people believe that Verisign might use the move as an excuse to increase .com prices.
Thick Whois is where the registry stores the full Whois record, containing all registrant contact data, for every domain in their TLD.
The three Verisign TLDs currently have “thin” Whois databases, which only store information about domain creation dates, the sponsoring registrar and name servers.
The model dates back to when the registry and registrar businesses of Verisign’s predecessor, Network Solutions, were broken up at the end of the last century.
But it’s been ICANN consensus policy for about three years for Verisign to eventually switch to a thick model.
Finally, ICANN has published for public comment its anticipated schedule (pdf) for this to happen.
Under the proposal, Verisign would have to start offering registrars the ability to put domains in its thick Whois by August 1 2017, both live via EPP and in bulk.
It would not become obligatory for registrars to submit thick Whois for all newly registered domains until May 1, 2018.
They’d have until February 1, 2019 to bulk-migrate all existing Whois records over to the new system.
Thick Whois in .com has been controversial for a number of reasons.
Some registrars have expressed dissatisfaction with the idea of migrating part of their customer relationship to Verisign. Others have had concerns that local data protection laws may prevent them moving data in bulk overseas.
The new proposal includes a carve-out that would let registrars request an exemption from the requirements if they can show it would conflict with local laws, which holds the potential to make a mockery out of the entire endeavor.
Some observers also believe that Verisign may use the expense of building and operating the new Whois system as an excuse to trigger talks with ICANN about increasing the price of .com from its current, frozen level.
Under its .com contract, Verisign can ICANN ask for a fee increase “due to the imposition of any new Consensus Policy”, which is exactly what the move to thick Whois is.
Whether it would choose to exercise this right is another question — .com is a staggeringly profitable cash-printing machine and this Whois is not likely to be that expensive, relatively speaking.
The proposed implementation timetable is open for public comment until December 15.

Radix acquires .fun gTLD from Warren Buffett

Kevin Murphy, October 25, 2016, Domain Registries

New gTLD portfolio player Radix has acquired the pre-launch TLD .fun from its original owner.
The company took over the .fun Registry Agreement from Oriental Trading Company on October 4, according to ICANN records.
Oriental is a party supplies company owned by Warren Buffett’s Berkshire Hathaway.
It won .fun in a private auction in April last year, beating off Google and .buzz operator DotStrategy.
It had planned to run it as a “closed generic” — keeping all the domains in .fun for itself — but those plans appeared to have been shelved by the time it signed its RA in January this year.
Evidently Oriental’s heart was not in it, and Radix made an offer for the string it found more attractive.
Radix business head Sandeep Ramchandani confirmed to DI today that .fun will be operated in a completely unrestricted manner, the same as its other gTLDs.
It will be Radix’s first three-letter gTLD, Ramchandani said. It already runs zones such as .online, .site and .space.
.fun is not yet delegated, but Radix is hoping for a December sunrise period, he said.

Uniregistry says it was unaffected by mother of all DDoS attacks

Kevin Murphy, October 25, 2016, Domain Registries

Almost 50 top-level domains were believed to be exposed to the massive distributed denial-of-service attack that hit Dyn on Friday, but the largest of the bunch said it managed to stay online throughout.
As has been widely reported in the mainstream and tech media over the last few days, DNS service provider Dyn got whacked by one of the biggest pieces of DDoS vandalism in the internet’s brief history.
Dyn customers including Netflix, Twitter, Spotify, PayPal and Reddit were reportedly largely inaccessible for many US-based internet users over the space of three waves of attack over about 12 hours.
The company said in a statement that the Mirai botnet was likely the attackers’ tool of choice.
It said that “10s of millions” of unique IP addresses were involved.
It has since emerged that many of the bots were actually installed on webcams secured with easily-guessable default passwords. XiongMai, a Chinese webcam manufacturer, has issued a recall.
In terms of the domain registry business, only about 50 TLDs use Dyn’s DynTLD service for DNS resolution, according to IANA records.
About half of these are tiny ccTLDs. They other half are Uniregistry’s portfolio of new gTLDs, including the like of .link, .car and .photo.
Uniregistry CEO Frank Schilling told DI that the Uniregistry TLDs did not go down as a result of the attack, pointing out that the company also uses its own in-house DNS.
“We like Dyn and think they have a great product but we did not go down because we also run our own DNS,” he said. “If we relied on them exclusively we would have gone down, but that is why we don’t do that.”

Big brands condemn “fraudulent” .feedback gTLD in ICANN complaint

Kevin Murphy, October 25, 2016, Domain Registries

Top Level Spectrum has been accused today of running the gTLD .feedback in a “fraudulent and deceptive” manner.
Over a dozen famous brands, corralled by corporate registrar MarkMonitor, today formally complained to ICANN that .feedback is a “complete sham”.
They reckon that the majority of .feedback domains belong to entities connected to the registry, violate trademarks, and have been stuffed with bogus and plagiarized reviews.
TLS denies any involvement.
MarkMonitor clients Adobe, American Apparel, Best Buy, Facebook, Levi and Verizon are among those that today filed a Public Interest Commitments Dispute Resolution Policy complaint with ICANN.
PICDRP is the mechanism third parties can use to complain about new gTLD registries they believe are in breach of the Public Interest Commitments found in their registry contracts.
The 50-page complaint (pdf), which comes with hundreds of pages of supporting documentation spread over 36 exhibits, purports to show TLS engaging in an “escalating pattern of discriminatory, fraudulent and deceptive registry misconduct”.
While the allegations of wrongdoing are fairly broad, the most interesting appears to be the claim that TLS quietly registered thousands of .feedback names matching trademarks to itself and then filled them with reviews either ripped off from Yelp! or supplied by overseas freelancers working for pennies.
TLS denies that it did any of this.
The .feedback registry is closely tied to the affiliated entity Feedback SAAS, which offers a hosted social platform for product/company reviews. Pricing for .feedback domains is dependent on whether registrants use this service or not.
The complaint states:

the overwhelming majority of domain names registered and activated within the .FEEDBACK TLD — over seventy percent (70%) — are currently owned and operated by Respondent [TLS], and parties working in concert with Respondent

Respondent has solicited and paid numerous third parties, including professional freelance writers who offer to post a set number of words for a fee, to write fabricated reviews regarding Complainants’ products and services.

These ostensibly independent reviews from ordinary consumers are intended to give the appearance of legitimate commentary within .FEEDBACK sites, when, in fact, the reviews are a complete sham.

An investigation carried out by MarkMonitor (pdf) showed that of the 2,787 .feedback domains registered up to July 31, 73% were registered to just five registrants.
The top registrant, Liberty Domains LLC of Las Vegas, owned 47% of these domains.
MarkMonitor believes this company (which it said does not show up in Nevada company records) and fourth-biggest registrant Core Domains LLC (based at the same Vegas mail forwarding service) are merely fronts for TLS, though it has no smoking gun proving this connection.
TLS CEO Jay Westerdal denies the company is affiliated with Liberty.
The MarkMonitor investigation counted 27,573 reviews on these sites, but 22% of them purported have been written prior to the date the domain was registered, in some cases by years.
The company reckons hundreds of reviews can be traced to five freelance writers who responded to February job ads looking for people who could write and post 10 150-word reviews per hour.
Other reviews appear to have been copied wholesale from Yelp! (this can be easily verified by visiting almost any .feedback site and searching for exact-match content on Google).
Westerdal told DI last week that registrants can use an API to import reviews.
The brands’ complaint goes on to criticize TLS for its Free.feedback offering, a very odd, bare-bones web site which seems to offer free .feedback domains.
When you type a domain or email address into the form on Free.feedback, it offers to give you the equivalent .feedback domain for free, automatically populating a second form with the Whois record of the original domain.
According to the complaint, after somebody registers a free .feedback domain, Feedback SAAS starts contacting the person listed in the Whois about their “free trial registration” regardless of whether they were actually the person who signed up the the domain. The complaint states:

Complainants and multiple other trademark owners who received such email notifications from Feedback SAAS and TLS registrars never visited the FREE.FEEDBACK website, and they never requested a free trial registration in the .FEEDBACK TLD

I’ve been unable to fully replicate this experience in attempts to test Free.feedback.
The complaint alleges multiple breaches of the PICs in the .feedback ICANN Registry Agreement.
The brands want ICANN Compliance to conduct a thorough investigation of .feedback, for all Free.feedback domains with phony Whois to be terminated, and for affected trademark owners to get refunds. They also want their legal costs paid by TLS.
ICANN does not typically publish the outcome of PICDRP complaints. Indeed, this is only the second one I’m aware of. It’s difficult to judge what MarkMonitor’s posse’s chances of success are.

Google could shake up the registry market with new open-source Nomulus platform

Kevin Murphy, October 19, 2016, Domain Registries

Google has muscled in to the registry service provider market with the launch of Nomulus, an open-source TLD back-end platform.
The new offering appears to be tightly integrated with Google’s various cloud services, challenging long-held registry pricing conventions.
There are already indications that at least one of the gTLD market’s biggest players could be considering a move to the service.
Donuts revealed yesterday it has been helping Google with Nomulus since early 2015, suggesting a shift away from long-time back-end partner Rightside could be on the cards.
Nomulus, which is currently in use at Google Registry’s handful of early-stage gTLDs, takes care of most of the core registry functions required by ICANN, Google said.
It’s a shared registration system based on the EPP standard, able to handle all the elements of the domain registration lifecycle.
Donuts contributed code enabling features it uses in its own 200-ish gTLDs, such as pricing tiers, the Early Access Period and Domain Protected Marks List.
Nomulus handles Whois and likely successor protocol RDAP (Registration Data Access Protocol).
For DNS resolution, it comes with a plug-in to make TLDs work on the Google Cloud DNS service. Users will also be able to write code to use alternative DNS providers.
There’s also software to handle daily data escrow to a third-party provider, another ICANN-mandated essential.
But Nomulus lacks critical features such as billing and fully ICANN-compliant reporting, according to documentation.
So will anyone actually use this? And if so, who?
It’s too early to say for sure, but Donuts certainly seems keen. In a blog post, CEO Paul Stahura wrote:

As the world’s largest operator of new TLDs, Donuts must continually explore compelling technologies and ensure our back-end operations are cost-efficient and flexible… Google has a phenomenal record of stability, an almost peerless engineering team, endless computing resources and global scale. These are additional potential benefits for us and others who may contribute to or utilize the system. We have been happy to evaluate and contribute to this open source project over the past 20 months because this platform provides Donuts with an alternative back-end with significant benefits.

In a roundabout way, Donuts is essentially saying that Nomulus could work out cheaper than its current back-end, Rightside.
The biggest change heralded by Nomulus is certainly pricing.
For as long as there has been a competitive market for back-end domain registry services, pricing has been on a per-domain basis.
While pricing and model vary by provider and customer, registry operators typically pay their RSPs a flat fee and a buck or two for each domain they have under management.
Pricing for dot-brands, where DUM typically comes in at under 100 today, is believed to be weighted much more towards the flat-fee service charge element.
But that’s not how Nomulus is to be paid for.
While the software is open source and free, it’s designed to run on Google’s cloud hosting services, where users are billed on the fly according to their usage of resources such as storage and bandwidth consumed.
For example, the Google Cloud Datastore, the company’s database service that Nomulus uses to store registration and Whois records, charges are $0.18 per gigabyte of storage per month.
For a small TLD, such as a dot-brand, one imagines that storage costs could be reduced substantially.
However, Nomulus is not exactly a fire-and-forget solution.
There is no Google registry service with customer support reps and such, at least not yet. Nomulus users are responsible for building and maintaining their registry like they would any other hosted application.
So the potentially lower service costs would have to be balanced against potentially higher staffing costs.
My hunch based on the limited available information is that for a dot-brand or a small niche TLD operating on a skeleton crew that may lack technical expertise, moving to Nomulus could be a false economy.
With this in mind, Google may have just created a whole new market for middleman RSPs — TLD management companies that can offer small TLDs a single point of contact for technical expertise and support but don’t need to build out and own their own expensive infrastructure.
The barrier to entry to the RSP market may have just dropped like a rock, in other words.
And Nomulus may work out more attractive to larger TLD operators such as Donuts, with existing teams of geeks, that can take advantage of Google’s economies of scale.
Don’t expect any huge changes overnight though. Migrating between back-ends is not an easy or cheap feat.
As well as ICANN costs, and data migration and software costs, there’s also the non-trivial matter of shepherding a horde of registrars over to the new platform.
How much impact Nomulus will have on the market remains to be seen, but it has certainly given the industry something to think about.

Donuts will cut off sham .doctors

Kevin Murphy, October 17, 2016, Domain Registries

Donuts has outlined plans to suspend or delete .doctor domain names used by fake medical doctors.
Despite protestations from governments and others, .doctor will not be a restricted gTLD when it goes to general availability next week — anyone will be able to register one.
However, Donuts said last week that it will shut down phony doctor sites:

While we are firmly committed to free speech on the Internet, we however will be on guard against inappropriate or dangerous uses of .DOCTOR. Accordingly, if registrants using this name make the representation on their websites that they are licensed medical practitioners, they should be able to demonstrate upon request that in fact they hold such a license. Failure to so demonstrate could be considered a violation of the terms of registration and may subject the registrant to registrar and registry rights to delete, revoke, suspend, cancel, or transfer a registration.

A Donuts spokesperson said that the registry will have the right to conduct spot-checks on sites, but at first will only police the gTLD in response to complaints from others.
“We have the right to spot check, but no immediate plans to do so,” he said.
In a few fringe cases, the failure to present a license would not result in the loss of a domain.
For example, a “registrant is in a jurisdiction that doesn’t license doctors (if that exists)” or a “registrant that represents him/herself as a licensed medical doctor, but uses the site to sell cupcakes”, the spokesperson said.
ICANN’s Governmental Advisory Committee had wanted .doctor restricted to medical doctors, but Donuts complained noting that “doctor” is an appellation used in many other fields beyond medicine.
It can also be used in fanciful ways to market products, the registry said.
ICANN eventually sided with Donuts, allowing it to keep an open TLD as long as it included certain Public Interest Commitments in its registry contract.
.doctor goes to GA October 26.

Rightside new gTLD renewals can top 80%

Kevin Murphy, October 14, 2016, Domain Registries

Rightside says it is seeing encouraging renewal figures from its oldest batch of new gTLDs.
The company this week revealed that renewals after two years of ownership on average stand at 81%.
In a blog post, Rightside broke out some numbers for .dance, .democrat, .ninja, .immobilien, .social, .reviews and .futbol.
Those seven are the only ones in its portfolio to have gone through two full renewal cycles.
The renewal rate after year one was a modest 69% — in other words it lost almost a third of its installed base after 12 months — but this increased to 81% after the second year.
The actual number of domains involved in quite tiny — 81% equates to just 21,000 names across all seven TLDs.
Breaking out a couple of TLDs, Rightside wrote:

Our first gTLD to market, .DANCE, saw a 70% renewal rate in year one expand to 83% in year two for that same subset of domains. Our best performing gTLD of the seven is .IMMOBILIEN, which renewed at 83% in its first year, and grew to a stupendous 87% in its second—which certainly makes sense given the permanent nature of real estate.

But Rightside reckons the numbers reflect well on the new gTLD industry. It said:

domain investors with portfolios including new gTLDs recognize the long-term value of these domain names, and rather than let them drop after the first year, are holding onto them to find the right buyer continue to earn parking revenue. Second—and likely the more significant driver—is that end users are actually picking up these domain names and putting them to use.

.xxx to get lower ICANN fees, accept the URS

Kevin Murphy, October 14, 2016, Domain Registries

ICM Registry has negotiated lower ICANN transaction fees as part of a broad amendment to its Registry Agreement that also includes new trademark protection measures.
The company’s uniquely high $2 per-transaction fee could be reduced to the industry standard $0.25 by mid-2018.
As part of the renegotiated contract, ICM has also agreed to impose the Uniform Rapid Suspension policy on its registrants.
URS is the faster, cheaper version of UDRP that allows trademark owners to have domain names suspended in more clear-cut cases of cybersquatting.
The $2 fee was demanded by ICANN when ICM first signed its RA in 2011.
At the time, ICANN said the higher fee, which had doubled from a 2010 draft of the contract, was to “account for anticipated risks and compliance activities”.
The organization seemed to have bought into the fears that .xxx would lead to widespread misuse — something that has noticeably failed to materialize — and was expecting higher legal costs as a result.
The companion TLDs .adult, .porn and .sex, all also managed by ICM, only pay $0.25 per transaction.
The overall effects on registrants, ICANN and ICM will likely be relatively trivial.
With .xxx holding at roughly 170,000 domains and a minimal amount of inter-registrar transfer activity, ICM seems to be paying ICANN under $400,000 a year in transaction fees at the moment.
Its registry fee is usually $62, though a substantial number of domains have been sold at lower promotional pricing, so the cost to registrants is not likely to change a great deal.
The reduction to $0.25 would have to be carried out in stages, with the earliest coming this quarter, and be reliant on ICM keeping a clean sheet with regards contract compliance.
Under the deal, ICM has agreed to adopt many of the provisions of the standard Registry Agreement for 2012-round gTLDs.
One of those is the URS, which may cause consternation among domainers fearful that the rights protection mechanism may one day also find its way into the .com registry contract.
ICM has also agreed to implement its existing policies on, for example, child abuse material prevention, into the contract as Public Interest Commitments.
The RA amendment is currently open for public comment at ICANN.