Latest news of the domain name industry

Recent Posts

“Bulletproof” registrar gets third ICANN bollocking

Trustname.com, a company that advertises itself as a privacy-devoted “bulletproof” registrar, is still refusing to suspend domain names used for phishing, malware, and payment card theft fast enough, according to ICANN.

The Org has sent its third notice of contract breach in five weeks and given Estonia-based Trustname, also known as Fewmoretaps, until August 6 to come back into compliance or lose its accreditation.

ICANN’s notice is focused on one domain this time, which it said was confirmed as hosting “phishing, payment‑card harvesting, and malicious client‑side code” about a week ago.

Trustname confirmed the domain, which Compliance did not name, as abusive on July 11, but it remained up until July 14 when the registrar correctly applied the clientHold suspension status after repeated nagging from ICANN, according to the notice.

“The actions the Registrar took were not prompt,” ICANN said, calling this a violation of Section 3.18.1 of the Registrar Accreditation Agreement.

Compliance first publicly reported Trustname’s alleged sins on June 10, accusing the company of dragging its feet and allowing abusive registrants to transfer their domains out rather than immediately suspending them.

“Bulletproof” registrar gets an ICANN bollocking

ICANN has slapped an intensely privacy-focused registrar that compares its stance on takedowns to Elon Musks with a lengthy breach-of-contract notice, claiming that the company is disregarding legitimate abuse reports for no good reason.

Estonia-based Fewmoretaps, which changed its brand to Trustname.com not long after its accreditation was approved in early 2024, has been friendly to malware distributors that use its services, according to ICANN.

The breach notice claims that Trustname, after it had discovered that an abuse report was valid and that one of its customers’ domains was being used to spread malware, did not suspend the domain as required.

Rather, it gave the registrant a three-day headsup to move their domain to another registrar, according to ICANN.

It additionally ignored multiple abuse reports, often for spurious reasons, the notice claims, often only taking action on abusive domains after ICANN Compliance itself got it touch.

Trustname says it is a “registrar built for businesses in competitive niches that often face false or bad-faith abuse reports” and makes hay out of the fact that it offers “bulletproof” privacy by masking registrants details behind two different proxy services located in different jurisdictions.

While the company’s web site claims ad nauseam that its services are not to be used for illegal purposes such as child abuse material and opioid sales, it boldly states that it “disregards” copyright infringement notices.

“Like Elon Musk, we have a strong aversion to individuals who exploit the DMCA, as we believe it lacks legal authority for the vast majority of the world’s population,” the site states.

IP matters are not covered by ICANN contracts, which defined abuse as malware, pharming, phishing and a subset of spam, of course.

Trustname’s site states that it will only take action against domains in “extreme scenarios”.

Such scenarios include “using your website to host illegal content (that we have confirmed after thorough investigations) and getting court orders from all three jurisdictions.”

The three jurisdictions are the US and Saint Kitts & Nevis, where its proxy partners are located, and its home nation of Estonia. Saint Kitts-based Harakiri (Perfect Privacy LLC) was specifically chosen because court orders are hard to come by there.

The company additionally states, in what could be interpreted as an admission of guilt by ICANN Compliance standards:

We will never take any action against a domain name simply because someone filed a complaint – even if your report indicates a violation of our terms. We will only be obligated to take action when we get the relevant court orders.

Trustname, which had fewer than 1,500 gTLD domains under management at the last count, has been given until July 1 to come back into compliance or risk losing its accreditation.

Registrar shamed for alleged crypto abuse neglect

Kevin Murphy, August 4, 2025, Domain Registrars

ICANN has given a warning to Malaysian registrar WebNic, claiming that it has turned a blind eye to abuse reports in breach of new Registrar Accreditation Agreement rules.

ICANN Compliance says the company, a subsidiary of Kuala Lumpur-based Qinetics, failed to take action to resolve abuse reports made against several domains it manages.

Online reports and databases suggest the names in question were used in phishing attacks attempting to steal cryptocurrency wallet credentials.

Compliance said it “has observed a concerning pattern regarding DNS Abuse mitigation”, saying WebNic continually drags its feet on responding to abuse reports, often only taking action after ICANN gets involved.

The breach notice adds:

The Registrar frequently issued repeated requests for evidence to abuse reporters – even when the original reports appeared actionable – and failed to fully consider information or clarifications provided by the abuse reporter, ICANN or otherwise reasonably accessible to the Registrar. In other cases, the Registrar requested evidence from the abuse reporters that did not appear to be relevant to the reported activity, causing additional delays.

WebNic is not a young, fly-by-night registrar. It’s been around a quarter century and has over 800,000 domains under management just in the gTLDs. Its parent also offers registry back-end services.

The company has until August 19 to make Compliance happy or risk termination proceedings.

Senator says domain industry “enables” Russian disinfo attacks

Kevin Murphy, October 24, 2024, Domain Registrars

An influential US senator has accused major registries and registrars including GoDaddy and Namecheap of facilitating Russian disinformation campaigns.

Senator Mark Warner, the Democrat chair of the Senate Select Committee on Intelligence, told registrars that “legislative remedies” may be required unless they “take immediate steps to address the continued abuse of your services for foreign covert influence”.

The threat came in letters sent to registrar groups Namecheap, GoDaddy, Cloudflare, NewFold Digital, NameSilo, and .com registry Verisign today.

Warner’s letters seem to have been inspired by Facebook owner Meta, perhaps the domain industry’s most prolific antagonist, and align closely with Meta’s views on issues such as cybersquatting and Whois access.

The criticisms also stem from a recent FBI seizure of 32 domains that were being use to proliferate fake news about the invasion of Ukraine and the upcoming US presidential election.

The Russian campaign, known as Doppelganger, used domains such as fox-news.in and washingtonpost.pm to trick visitor into thinking they were reading news sources they trust.

Warner tells the registrars (pdf) they have “ostensibly facilitated sustained covert influence activity by the Russian Federation and influence networks operating on its behalf”.

The main concern appears to be the lack of access to private information in Whois records. Warner’s list of industry sins includes:

withholding vital domain name registration information from good-faith researchers and digital forensic investigators, ignoring inaccurate registration information submitted by registrants, and failing to identify repeated instances of intentional and malicious domain name squatting used to impersonate legitimate organizations

Warner called for “immediate” action “to address the continued abuse of your services” as the US presidential election looms, and in its aftermath. Voters go to the polls November 5.

ICANN gunning for Tencent over abuse claims

Kevin Murphy, September 23, 2024, Domain Registrars

ICANN Compliance is taking on one of the world’s largest technology companies over claims that a registrar it owns turns a blind eye to DNS abuse and phishing.

The Org has published a breach of contract notice against a Singapore registrar called Aceville Pte Ltd, which does business as DNSPod and is owned by and shares its headquarters with $86-billion-a-year Chinese tech conglomerate Tencent.

ICANN says that DNSPod essentially has turned a blind eye to recent abuse reports, allowing phishing sites to stay online long after they were reported, and makes life difficult for people trying to report abuse.

It also has failed to upgrade from the Whois protocol to RDAP and failed to migrate its registration data escrow service provider from NCC to DENIC, according to the notice.

According to ICANN, DNSPod received abuse reports about several domains in July and August but failed to take action at all or until ICANN itself got in touch to investigate. Compliance wants to know why.

ICANN adds that the registrar seems to be requiring reporters to create user accounts and use a web form to submit their reports, even after they’ve already used the abuse@ email address.

Stricter rules on DNS abuse came into force on registrars this April. They’re now required to take action on abuse reports.

“Aceville does not appear to have a process in place to promptly, comprehensively, and reasonably investigate and act on reports of DNS Abuse,” the notice reads.

ICANN has given DNSPod until October 11 to answer its questions or risk escalation.

While DNSPod says it has been around for 17 years, it only received its ICANN accreditation in 2020. Since then, it’s grown to almost 200,000 domains under management in gTLDs.

It’s primarily a DNS resolution service provider, saying it hosts over 20 million domains, and does not appear to operate as a retail registrar in the usual sense.

Owner Tencent may not be a household name in the Anglophone world, but it’s the company behind some of China’s leading social media brands, including QQ and WeChat, as well as a formidable force in gaming and one of the world’s richest companies in any sector.

It’s the second huge Chinese tech firm to find itself publicly shamed by ICANN in recent months. Compliance went after Tencent’s primary competitor, Alibaba, on similar grounds in March. Alibaba has since resolved the complaints.

We grassed up .TOP, says free abuse outfit

Kevin Murphy, July 18, 2024, Domain Services

A community-run URL “blacklist” project has claimed credit for the complaints that led to .TOP Registry getting hit by an ICANN Compliance action earlier this week.

.TOP was told on Tuesday that it has a month to sort of its abuse-handing procedures or risk losing the .top gTLD, which has over three million domains.

ICANN said the company had failed to respond to an unspecified complainant that had reported multiple phishing attacks, and now the source of that complaint has revealed itself in a news release.

URLAbuse says it was the party that reported the attacks to .TOP, which according to ICANN happened in mid April.

“Despite repeated notifications, the .TOP Registry Operator failed to address these issues, prompting URLAbuse to escalate the matter to ICANN,” URLAbuse said, providing a screenshot of ICANN’s response.

URLAbuse provides a free abuse blocklist that anyone is free to incorporate into their security setup. Domain industry partners include Radix, XYZ.com and Namecheap.

First registry gets breach notice over new abuse rules

.TOP Registry allegedly ignored reports about phishing attacks and has become the first ICANN contracted party to get put on the naughty step over DNS abuse rules that came into effect a few months ago.

ICANN has issued a public breach notice claiming that the registry, which runs .top, has also been ignoring the results of Uniform Rapid Suspension cases, enabling cybersquatting to take place.

The notice says that .TOP breached new rules, which came into effect April 5, that require it to act on reports of DNS abuse (such as malware or phishing attacks) by suspending the domains or referring them to the responsible registrar.

The registry didn’t do this with respect to a report of April 18, concerning “multiple .top domain names allegedly used to conduct phishing attacks”. It didn’t even read the report until contacted by ICANN, according to the notice.

As of yesterday, only 33% of the phishing domains have been suspended by their registrars, some three months after the attacks were reported, ICANN says.

Compliance is also concerned that .TOP seems to be ignoring notices from Forum, the company that processes URS cases, requiring domains to be locked within 24 hours when they’ve been hit with a charge of cybersquatting.

The registry “blatantly and repeatedly violated” these rules, according to ICANN.

.TOP has been given until August 15 to get its act together or risk having its Registry Agreement suspended or terminated.

The registry has about three million .top domains under management, having long been one of the most successful new gTLDs of the 2012 round in volume terms. It typically sells domains very cheaply, which of course attracts bad actors.

Alibaba hit with ICANN breach notice

One of the companies in the Alibaba Group, China’s biggest registrar and one of the largest technology companies in the world, has been handed a breach notice, containing a long list of complaints including abuse failures and non-payment of fees, by ICANN Compliance.

Alibaba.com Singapore E-Commerce, one of Alibaba’s four accredited registrars, failed to respond to abuse reports and failed to respond to ICANN’s requests for information about its failure to respond to abuse reports, the notice claims.

The breach notice will likely to be the last to be sent out for claims under the current version of the Registrar Accreditation Agreement. In two days, April 5, stricter domain takedown rules approved earlier this year will become effective on all registrars.

The abuse claims seem to cover four domains in .com and .vip that look like typos that could have been used in phishing attacks.

ICANN Compliance says that Alibaba also hasn’t published the names of its officers or its redemption fees, as the RAA also requires. It says the registrar also owes it an unspecified amount of past-due fees.

The chronologies reported in the notice claim Alibaba has been giving Compliance the run-around, failing to respond to calls and emails, since early November.

All four registrars in the Alibaba Group have the same published email and phone details, but it’s not clear whether the same ones are listed in ICANN’s internal directory.

Alibaba.com Singapore is one of four accredited registrars owned by Alibaba, the Chinese e-commerce giant. The parent is not short of a bob or two, reporting revenue equivalent to $126 billion last year. It can afford to pay its ICANN fees.

Of the three Alibaba registrars that have domains the “Singapore” one is the smallest, with about 660,000 domains under management. The other two have 3.2 million and 2.6 million domains to their accreditations.

The company has been told it has until April 17 to come back into compliance or risk getting terminated.

UK gov takes its lead from ICANN on DNS abuse

Kevin Murphy, February 23, 2024, Domain Registries

The UK government has set out how it intends to regulate UK-related top-level domain registries, and it’s taken its lead mostly from existing ICANN policies.

The Department for Science, Innovation and Technology said last year that it was to activate the parts of the Digital Economy Act of 2010 that allow it to seize control of TLDs such as .uk, .london, .scot, .wales and .cymru, should those registries fail to tackle abuse in future.

It ran a public consultation that attracted a few dozen responses, but has seemingly decided to stick to its original definitions of abuse and cybersquatting, which were cooked up with .uk registry Nominet and others and closely align to industry norms.

DSIT plans to define abuse in the same five categories as ICANN does — phishing, pharming, botnets, malware and vector spam (spam that is used to serve up the first four types of attack) — in its response to the consultation, published yesterday (pdf).

But it’s stronger on child sexual abuse material than ICANN. While registries and registrars have developed a “Framework to Address Abuse” that says they “should” take down domains publishing CSAM, ICANN itself has no contractual prohibitions on such content.

DSIT said it will require UK-related registries to have “adequate policies and procedures” to combat CSAM in their zones. The definition of CSAM follows existing UK law in being broader than elsewhere in the world, including artworks such as cartoons and manga where no real children are harmed.

DSIT said it will define cybersquatting as “the pre-emptive, bad faith registration of trade marks as domain names by third parties who do not possess rights in such names”. The definition omits the “and is being used in bad faith” terminology used in ICANN’s UDRP. DSIT’s definition includes typosquatting.

In response to the new document, Nominet tweeted:

DSIT said it will draft its regulations “over the coming months”.

Registries and registrars vote ‘Yes’ to new DNS abuse rules

Kevin Murphy, December 14, 2023, Domain Registrars

ICANN’s contracted registries and registrars have voted to accept new rules requiring them to take action on DNS abuse.

The new rules come after a vote lasting a few months with some quite high thresholds for success.

The current Registrar Accreditation Agreement merely requires registrars to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse”, which is pretty vague and barely enforceable.

The amendments, which still need to be rubber-stamped by the ICANN board, make it much clearer what registrars are expected to do in which circumstances. A new paragraph is added that reads:

3.18.2 When Registrar has actionable evidence that a Registered Name sponsored by Registrar is being used for DNS Abuse, Registrar must promptly take the appropriate mitigation action(s) that are reasonably necessary to stop, or otherwise disrupt, the Registered Name from being used for DNS Abuse. Action(s) may vary depending on the circumstances, taking into account the cause and severity of the harm from the DNS Abuse and the possibility of associated collateral damage.

For registries, the new text for the base gTLD Registry Agreement is similar, but with a little more wiggle-room:

Where a Registry Operator reasonably determines, based on actionable evidence, that a registered domain name in the TLD is being used for DNS Abuse, Registry Operator must promptly take the appropriate mitigation action(s) that are reasonably necessary to contribute to stopping, or otherwise disrupting, the domain name from being used for DNS Abuse. Such action(s) shall, at a minimum, include: (i)the referral of the domains being used for the DNS Abuse, along with relevant evidence, to the sponsoring registrar; or (ii) the taking of direct action, by the Registry Operator, where the Registry Operator deems appropriate. Action(s) may vary depending on the circumstances of each case, taking into account the severity of the harm from the DNS Abuse and the possibility of associated collateral damage.

In both cases, DNS abuse is defined by the now industry standard line: “malware, botnets, phishing, pharming, and spam (when spam serves as a delivery mechanism for the other forms of DNS Abuse listed in this Section)”.

There are a few other quality of life updates, such as the requirement for registrars to acknowledge receipt of abuse reports and to have their abuse reporting mechanism “conspicuously and readily accessible from” their home pages.

ICANN needed registrars representing over 90% of registered gTLD domains (adjusted slightly to make GoDaddy’s voice less powerful). That threshold was passed last week, with 94% of domains voting in favor of the amendments.

For registries, ICANN required a simple majority of registries (counted by contract rather than company) and for all registries voting in favor to have been responsible for two thirds of all registry fees paid last year.

Judging by the financial thresholds, .com and .net, which are not on the base RA, were not involved.