Latest news of the domain name industry

Recent Posts

Whois privacy group finds its new chair

Kevin Murphy, December 8, 2020, Domain Policy

Verisign’s top policy veep is set to become the third chair of the ICANN working group looking at Whois policy in the post-GDPR world.

Keith Drazek has been recommended to head the long-running group, known as the EPDP, and the GNSO Council is due to vote on his appointment next week. He’s likely to be a shoo-in.

He’s VP of policy and government relations at the .com registry, and a long-standing member of the ICANN policy-making community.

I recently opined that ICANN was looking for a “masochistic mug” to chair the group. Drazek was until October the chair of the GNSO Council, and is therefore perfectly qualified for the role.

The third phase of the EPDP process, which in typical ICANNese is denominated “phase 2a”, is likely to be slightly less controversial than the first two.

The EPDP has already decided that ICANN should probably create a Standardized System for Access and Disclosure — SSAD — that may enable law enforcement and intellectual property owners to get their hands on unredacted Whois records.

But governments, IP interests and others have already dismissed the plan as useless, and there’s still a big question mark over whether SSAD is too complex and expensive to be worth implementing.

In the third phase, EPDP members will be discussing rules on distinguishing between legal and natural persons when record-holders decide what info to make public, and whether there should be a standardized system of unique, anonymized email forwarders to contact domain registrants.

They’re both less divisive topics than have been previously addressed, but not without the potential for fireworks.

The email issue, for example, could theoretically enable people to harvest a registrant’s entire portfolio of domains, something very useful for law enforcement and IP lawyers but abhorrent to privacy advocates.

The previous two phases were chaired by Kurt Pritz and Janis Karklins, with Rafik Dammak acting as vice-chair.

After 20 years, DomainTools takes its first VC dough

Kevin Murphy, December 3, 2020, Domain Tech

DomainTools has taken a “significant” investment from a venture capital firm, the first outside funding its received in its 20-year history.

The amount of the investment is undisclosed, but DomainTools said its investor is Battery Ventures.

Battery already owns stakes in numerous software and technology companies, but this appears to be its first foray into the domain name space.

Its principal, Jordan Welu, and partner Dave Tabors will join DomainTools’ board of directors and Andy Rothery, a Battery “executive-in-residence”, will become its executive chairman.

DomainTools said in a press release:

This investment will drive more rapid innovation in DomainTools’ platform capabilities for machine learning-based threat analytics and predictive risk scoring, along with enhanced product development around automating threat intelligence and incident response workflows.

The company is all about the “threat intelligence” nowadays, no doubt partly due to the fact that its original mission of aggregating the world’s Whois data will become decreasingly useful in light of privacy laws such as GDPR.

As a private company its financial position is unknown, but I’ll note that it did take a big chunk of change out of the US taxpayers’ pocket earlier this year under a government coronavirus-related corporate-relief program.

Masochistic mug urgently wanted for thankless, pay-free ICANN leadership role

Kevin Murphy, November 17, 2020, Domain Policy

ICANN still hasn’t found itself a volunteer to head up the next round of no-doubt contentious discussions about Whois policy.

Today it put out its second call for a chair of the Expedited Policy Development Process working group, which is continuing to square the circle of keeping Whois data compliant with data protection law whilst also allowing cops and IP lawyers access to the data.

The EPDP was supposed to have concluded a few months ago with the end of the second phase of talks, but a couple of issues were left unresolved, leading to the creation of a third phase, being spun as “Phase 2a”.

The first issue still to be discussed is if and how registries and registrars should be obliged to make a distinction between the data of private individuals, which is protected by law, and legal entities, which isn’t.

The second is whether it would be possible to have a uniform system of anonymized email addresses across Whois records.

They’re not exactly the most controversial of topics under the Whois umbrella, but they’re not easy asks either.

And the role of chair is time-consuming, uncompensated, with few perks.

ICANN wants somebody who is neutral and, unstated but perhaps more importantly, perceived to be neutral. The chairs of the previous two phases have been policy heavy-hitters Kurt Pritz and Janis Karklins.

It also wants somebody with “considerable experience in chairing working groups”, which immediately drains the pool of potential applicants.

If previous phases of the EPDP are any guide, the successful applicant will have to herd the cats through dozens of hours of teleconferences — the more-complex phase two had 74 meetings, most of which were two hours long.

For their efforts, the chair gets no money, and because of coronavirus travel restrictions they won’t even get paid junkets to international face-to-face meetings.

And if the output of the next phase is anywhere as near as divisive as phase two, they probably won’t win much praise either.

That’s perhaps why ICANN has extended the deadline for expressions of interest from last Friday to November 23.

Applicants go here.

.spa registry relocates to .xyz

Kevin Murphy, November 16, 2020, Domain Registries

Newly installed .spa registry Asia Spa and Wellness Promotion Council has started using a .xyz domain for its official registry web site.

The organization last week had its IANA records updated to change its “URL for registration services” from aswpc.org to dotspa.xyz.

It currently resolves to a placeholder “Coming Soon” page.

Choosing a TLD other than its own, which entered the DNS root in September, is pretty unusual.

Most new gTLD registries activate nic.example pretty quickly after delegation, even if they ultimately use a domain such as get.example or register.example for their primary marketing sites.

Activating nic.example is actually an obligation under ICANN contracts. ASWPC has registered that domain, but only whois.nic.spa currently resolves.

The dotspa.xyz domain was registered about a year ago, about a month after ASWPC’s former business partner, DotAsia, washed its hands of its stake in the TLD.

Both the .com and .org versions have been registered for well over a decade, so perhaps .xyz was picked as the default third-choice generic.

But that still doesn’t explain why a registry would select a domain outside its own TLD for its primary site.

ICANN denies Whois policy “failure” as Marby issues EU warning

Kevin Murphy, October 19, 2020, Domain Policy

ICANN directors have denied that recently delivered Whois policy recommendations represent a “failure” of the multistakeholder model.

You’ll recall that the GNSO Council last month approved a set of controversial recommendations, put forward by the community’s EPDP working group, to create a semi-centralized system for requesting access to private Whois data called SSAD.

The proposed policy still has to be ratified by the ICANN board of directors, but it’s not on the agenda for this week’s work-from-home ICANN 69 conference.

That has not stopped there being some robust discussion, of course, with the board talking for hours about the recommendations with its various stakeholder groups.

The EPDP’s policy has been criticized not only for failing to address the needs of law enforcement and intellectual property owners, but also as a failure of the multistakeholder model itself.

One of the sharpest public criticisms came in a CircleID article by Fabricio Vayra, IP lawyer are Perkins Coie, who tore into ICANN last month for defending a system that he says will be worse than the status quo.

But ICANN director Becky Burr told registries and registrars at a joint ICANN 69 session last week: “We don’t think that the EPDP represents a failure of the multistakeholder model, we actually think it’s a success.”

“The limits on what could be done in terms of policy development were established by law, by GDPR and other data protection laws in particular,” she added.

In other words, it’s not possible for an ICANN working group to create policy that supersedes the law, and the EPDP did what it could with what it was given.

ICANN CEO Göran Marby doubled down, not only agreeing with Burr but passing blame to EU bureaucrats who so far have failed to give a straight answer on important liability issues related to the GDPR privacy regulation.

“I think the EPDP came as far as it could,” he said during the same session. “Some of the people now criticizing it are rightly disappointed, but their disappointment is channeled in the wrong direction.”

He then referred to his recent outreach to three European Commission heads, in which he pleaded for clarity on whether a more centralized Whois model, with more liability shifted away from registrars to ICANN, would be legal.

A failure to provide such clarity would be to acknowledge that the EPDP’s policy proposals are all just fine and dandy, despite what law enforcement and some governments believe, he suggested.

“If the European Union, the European Commission, member states in Europe, or the data protection authorities don’t want to do anything, they’re happy with the situation,” he told registrars and registries.

“If they don’t take actions now, or answer our questions, they’re happy with the way people or organizations get access to the Whois data… it seems that if they don’t change or do anything, they’re happy, and then were are where we are,” he said.

He reiterated similar thoughts at sessions with other stakeholders last week.

But he faced some pushback from members of the pro-privacy Non-Commercial Stakeholders Group, particularly during an entertaing exchange with EPDP member Milton Mueller, who’s unhappy with how Marby has been characterizing the group’s output to the EU.

He specifically unhappy with Marby telling the commissioners: “Should the ICANN Board approve the SSAD recommendations and direct ICANN org to implement it, the community has recommended that the SSAD should become more centralized in response to increased legal clarity.”

Mueller reckons this has no basis in what the EPDP recommended and the GNSO Council approved. It is what the IP interests and governments want, however.

In response, Marby talked around the issue and seemed to characterize it as a matter of interpretation, adding that he’s only trying to provide the ICANN community with the legal clarity it needs to make decisions.

That .sucks weirdness? Worse than I thought

Kevin Murphy, October 16, 2020, Domain Registries

A business plan to turn .sucks into a massive Wikipedia-style gripe site, described by trademark lawyers five years ago as a “shakedown”, has reared it ugly head again.

You may recall that earlier this week I reported how somebody had registered many hundreds of .sucks domain names and listed them for sale on secondary market web sites at cost price. It looked weird, almost as if the registry or an affiliate was the registrant, which the registry denied.

It turns out I only told you half the story, for which I can only apologize.

At the time, the domains in question were not resolving for me, probably due to my terrible, block-happy ISP. But now they are resolving, and they reveal the return of Everything.sucks, a plan first floated by the .sucks registry in 2015.

It’s a network of hundreds of .sucks micro gripe-sites, each targeted to a specific brand and each each populated with content scraped, usually without citation, from Wikipedia, social media, and consumer-review aggregator web sites.

Here’s where jackdaniels.sucks takes you, for example (click to enlarge).

Jack Daniels sucks

The description of the company is taken from Wikipedia. The customer comments below are taken from reviews of an apparently unrelated company called The Whisky Exchange published by TrustPilot, and the social media posts have been pulled from Instagram users deploying the hashtag #jackdanielssucks.

Other pages on the site seem to scrape content from GlassDoor, a site where employees review their employers.

While there’s nothing wrong with gripe sites, automating their creation over hundreds or even thousands of brands that you don’t genuinely have gripes with seems, charitably, churlish.

And these gripe sites are — or at least were — being monetized.

You’ll see a banner ad in the top-right corner of the above screen-grab, offering jackdaniels.sucks for sale. The link took you to a page on Sedo that offers the domain for sale with a buy-now price of $199 (the same as the registry’s wholesale fee).

Banners on other pages led to landers on GoDaddy-owned Uniregistry.com with prices of $599.

These banners, which appeared on every brand’s page that I checked, seem to have disappeared at some point over the last two days. I’m sure the change is unrelated to the fact that I started asking .sucks registry Vox Populi and parent Momentous difficult questions about these trademark-match domains on Wednesday.

While UDRP panels have disagreed over the years, there’s precedent dating back two decades that “trademarksucks.tld” domains with sites that contain genuine, non-commercial criticism can confer legitimate rights to the registrant and are therefore NOT cybersquatting.

I doubt a site that actively tries to sell the domain name in question for above out-of-pocket costs could be considered non-commercial.

Still, it looks like those banners are gone now, and I can’t find any other examples of obvious monetization.

I use jackdaniels.sucks as an example here as it’s the site I took a screenshot of before the changes, but there are many hundreds of similar trademark-match domains being used to feed traffic to Everything.sucks.

I note that unitedinternet.sucks, named after the parent company of Sedo, is for sale for $199 on Sedo and leads to a gripe site on Everything.sucks containing less-than-complimentary remarks. It’s for sale at $599 on Uniregistry.

But who is Everything.sucks?

The concept itself originates with the .sucks registry itself. Before the TLD launched in 2015, it floated the idea to a tsunami of criticism from trademark owners.

The plan back then was to sell .sucks domains for .com prices — a discount of a couple hundred dollars — but only to registrants unaffiliated with the trademark owner. These registrants would have had to forward their domains to an Everything.sucks-branded discussion forum.

Back then, Vox Pop said it planned to work with a non-for-profit third party on this initiative.

That third party never materialized, and later in 2015 appeared to mutate into a system called This.sucks, operated by a company called This.sucks Ltd, which took over the Everything.sucks domain name.

This.sucks sold .sucks domains for $12 a year, with the domains pointing to a forum/blogging platform that the company hoped to monetize.

Both This.sucks and Vox Pop denied there was any link between the two companies, but I later uncovered a lot of compelling circumstantial evidence linking the two companies, including the fact that Rob Hall, CEO of Vox Pop parent Momentous, paid for This.sucks’ web site design.

This.sucks appears to have fizzled out in the intervening years, but now Everything.sucks is back with a mystery registrant snapping up thousands of domains, at a cost of at least half a million bucks, under the Everything.sucks brand.

Public Whois is useless nowadays, of course.

But the front page of Everything.sucks describes it as “a non-profit organization and communications forum for social activism”.

Many of the domains that redirect to its site appear to be registered to a Turks and Caicos company called Honey Salt Ltd, a name that does not naturally suggest a non-profit entity.

Others use Momentous’ domain privacy service. All appear to be registered via Momentous-owned registrar Rebel, which sells .sucks domains at cost and is therefore one of the cheapest registrars on the market.

Back in 2015, intellectual property interests expressed doubt that the proposed Everything.sucks third party and the This.sucks third party were not in fact just smokescreens, fronts for the registry itself.

Vox Pop CEO John Berard on Wednesday denied to DI that the company had any involvement in the recent spurt of trademark-match registrations being used by Everything.sucks and expressed a lack of knowledge about the registrant’s intent.

I’ve not yet received comment from Momentous, but I’d be very surprised if the company does not know who is behind Everything.sucks.

At the very least, Vox Pop and Rebel are both privy to the unexpurgated Whois and/or customer records for whoever is running Everything.sucks and whoever it is that has grown the .sucks zone file by about 50% since June.

Something weird’s going on at .sucks

Kevin Murphy, October 14, 2020, Domain Registries

Ever heard of a domainer or cybersquatter putting their freshly-registered domains up for sale at cost?

Me neither, but that’s what seems to be going on at .sucks right now.

The sudden appearance of many hundreds of .sucks domains — many of them matching very famous trademarks — at Sedo and Uniregistry comes as the registry unveils plans to open up a secondary marketplace of its own.

.sucks registry Vox Populi, a part of the Momentous group of companies, wants to open its own marketplace, according to a letter it recently sent to ICANN.

The registry told ICANN it plans to launch a service “whereby a Registrant of a .sucks domain name can list their domain for resale with the Registry”, saying it will “allow our Registrars to show the domain as available for purchase by third parties at the price set by the current Registrant.”

It’s taking a somewhat confrontational approach from the outset, telling ICANN that it does not believe the service would constitute a “registry service” that would require ICANN’s approval under the Registry Service Evaluation Process.

It points to the fact that registrants can already list their .sucks names on existing marketplaces such as Sedo as proof that it’s not a “product or service that only a registry operator is capable of providing, by reason of its designation as the registry operator” requiring the RSEP.

This interpretation strikes me as open to debate, but I’m not going to get into that here.

What’s more interesting is that the vast majority of the domains listed on these competing platforms appear to have been registered relatively recently, in bulk, all via Momentous-owned registrar Rebel, and quite possibly by the same registrant.

What’s weird is that the majority of the .sucks names listed at Sedo have a buy-now price of $199. Some are priced higher. Some priced at $199 at Sedo are priced at $599 at Uniregistry.

$199 is the absolute cheapest you can buy a .sucks domain name anywhere. It’s Rebel’s retail price, and I believe it’s also Vox Pop’s wholesale price. Even the cheapest unaffiliated registrars slap a $50 markup on the registry fee.

The domains started being listed on the aftermarkets after a sharp spike in .sucks sales back in June, where my data shows that over 2,000 names were registered, via Rebel, in the space of about 24 hours.

The .sucks zone file has been growing ever since, swelling from 7,347 — where volume had been flattish and under 8,000 names for years — to 11,255 since June 16, the date of the first spike.

Almost every .sucks listing I spot-checked on Sedo has three things in common: the $199 price-tag, a recent registration date, and a seller who signed up for the service in 2020 submitting their home territory as Turks and Caicos.

Turks and Caicos, which is also where Rebel is legally based, is a British island territory in the Caribbean with fewer than 38,000 inhabitants. It’s often used for offshore company registrations.

Whois records for the domains I checked with June reg dates use Momentous privacy service Privacy Hero, while other more-recent regs list the registrant as Honey Salt Ltd, a company apparently also based in Turks and Caicos.

So what we seem to have here is a registrant willing to invest half a million dollars or more in .sucks domain names, a great many matching famous brands, and then list them for resale at the exact same price he paid for them.

Why would a cybersquatter pay $199 for jackdaniels.sucks or dolceandgabbana.sucks or unitedinternetmedia.sucks and then put them up for sale for $199? It makes no sense to me.

And it comes at a time when Vox Pop is trying to persuade ICANN that there’s a thriving aftermarket for .sucks domains.

I put all these observations to the CEOs of Momentous and the registry earlier today, and Vox Pop chief John Berard got back to us to say:

With regard to those 2,000 registered names, that was most welcome. I don’t know much more than that about Honey Salt… I am certainly not going to speculate on their plans.

That they are in the Turks and Caicos is interesting, for sure. But you know as well as I that the Caribbean is a hotbed of domain name innovation and investment.

He later added: “Yes, take it to the bank that VPR [Vox Populi Registry] is not behind the registrations.”

On the issue of the registry’s own secondary market plans, Berard said:

we are trying to catch up to others in the domain name industry who first saw the customer value of fostering a secondary market. I think we may be the first registry to do it, but we, i am sorry to say, weren’t the first to market.

If I receive more information or commentary on this weirdness I shall provide updates accordingly.

Forty weddings and a funeral? .wed is dead but may come up for auction

Kevin Murphy, October 12, 2020, Domain Registries

.wed has become the first commercial, open, non-branded new gTLD to have its registry contract unilaterally terminated by ICANN, and it could soon be looking for a new home.

ICANN terminated the contract with US-based Atgron last week, almost three years after imposing emergency measures to protect registrants after the company’s business model failed miserably.

The company wanted to provide a space for engaged couples to promote their weddings for about $50 a year, but its business model was based around basically forcing registrants to abandon their names by charging a $30,000 renewal fee after year two.

Unsurprisingly, it attracted few registrants — about 300 at its 2016 peak — and only one registrar.

By the time the end of 2017 rolled around, it was languishing at 39 domains (for the purposes of a whimsical headline, let’s round it up to 40) and its agreement with its back-end registry operator was on the verge of expiring.

In the hope of keeping its customers’ domains working, Atgron turned off its Whois for a week, attracting the attention of ICANN and triggering a criterion for transitioning to an Emergency Back-End Registry Operator.

It’s been on an EBERO, in this case Nominet, since December 2017, with all domains essentially frozen.

In the meanwhile, it’s been fighting against contract termination with ICANN, first in mediation and then in arbitration.

Last month, the arbitrator ruled that Atgron was in breach for failure to pay its ICANN fees, and ICANN terminated the registry agreement October 5.

.wed is certainly not the first new gTLD to get terminated by ICANN — there’s been about a dozen to date — but it is the first to be a non-dot-brand.

This means ICANN will get to test its Registry Transition Process for the first time.

When a dot-brand dies, ICANN just removes it from the root and lets it stay dead on the grounds that there’s no plausible successor and no registrants will suffer.

In this case, we’re talking about an open, non-branded gTLD with a generic string that could potentially rack up many thousands of registrations.

There’d be no obligation for a future operator to take on the silly business model.

The Registry Transition Process will go one of two ways.

If Atgron has already picked a successor registry, ICANN will conduct a series of evaluations that look like they would be a piece of cake for any existing gTLD portfolio owner to pass.

But if Atgron has no heir apparent, it goes to an RFP which basically amounts to an auction, with the company prepared to pay Atgron the most money becoming the company’s presumed preferred successor.

With Atgron still owing ICANN money — presumably hundreds of thousands of dollars — in past-due fees, I’ve little doubt what ICANN’s preferred outcome would be.

For Atgron, there’s the distinct possibility that it could make more money from crashing .wed into the ground than it ever did by actually selling domains.

.wed is not a bad string — it’s short, meaningful, and has a niche of potential registrants already forced to overpay for almost everything else — and I’m fairly confident it could easily find a new home at an existing registry.

Europe’s top dogs could decide the future of Whois

Kevin Murphy, October 5, 2020, Domain Policy

ICANN is pleading with the European Commission for legal clarity to help solve the two-year-old fight over the future of Whois in the age of GDPR.

CEO Göran Marby has written to three commissioners to ask for a definitive opinion on whether a centralized, mostly automated Whois system would free up registries and registrars from legal liability if their customers’ data is inappropriately disclosed.

It’s a question ICANN has been asking for years, but this time it comes after the ICANN community has come up with a set of policy recommendations that would create something called SSAD, for System for Standardized Access/Disclosure.

SSAD is supported by registries, registrars and non-commercial interests, but has been broadly criticized by governments, intellectual property interests, security experts and others as being not fit for purpose.

While it would create a centralized gateway for funneling Whois queries to contracted parties, and an accreditation system for those making the queries, the decision to accept or refuse the query would still lie with registries and registrars and be largely human-powered.

It’s been described as a glorified, $9 million-a-year ticketing system that will fail to provide better access to Whois to those who say they need it (largely the IP interests).

But registries and registrars say they cannot accept a solution that offloads decision-making to a centralized third party such as ICANN, unless that third party shoulders all the legal liability for mistakes, and whether that’s possible is far from clear this early in the life of GDPR.

As Marby told the commissioners:

Legal clarity could mean the difference between ICANN having a fragmented system that routes most requests for access to non-public registration data from requestors to thousands of individual registries and registrars for a decision, on the one hand, versus ultimately being able to implement a centralized, predictable solution in which decisions about whether or not to disclose non-public registration data in most or all cases could be made consistently, predictably, in a manner that is transparent and accountable to requestors and data subjects alike.

In GDPR lingo, the question is who becomes the “controller” of the data in a centralized system. The controller is the one that could get slapped with huge fines in the event of a privacy breach.

There’s a concept of “successive controllers”, where data is passed through a chain of handlers. ICANN wants clarity on whether, should a registrar send data to an ICANN central gateway, its liability ends there, before the final disclosure decision is made.

It’s asking the European Commission to exercise its authority under the GDPR to force the European Data Protection Board to issue a blanket opinion clarifying these issues, with the expectation that SSAD as currently envisaged could evolve over time to be something more like what the IP folk want.

For ICANN, such a ruling could help quell criticism from its influential advisory bodies, notably the Governmental Advisory Committee, which have come out strongly against the SSAD proposals.

If ICANN chooses to wait for the European Commission and EDPB responses to its new request, it’s highly unlikely we’re going to see the ICANN board fully approve SSAD at its annual general meeting later this month.

Three-letter .blog domains priced up to $100k

Kevin Murphy, September 25, 2020, Domain Registries

Knock Knock Whois There, the .blog registry, said it is going to release its inventory of three-character domains next month.

Roughly 47,000 names will be released at premium fees, with prices ranging “from a few hundred dollars to over $100K”, the company said.

That number suggests that pretty much all of the alphanumeric combinations and hyphenated L-L, N-N, L-N and N-L variants will be available.

The premium pricing only applies to year one; the names will renew at the standard rate of between $10 and $30.

The names will be released October 7 on a first-come, first-served basis.

.blog is doing pretty well by new gTLD standards, with over 190,000 registered names.