“Bulletproof” registrar gets an ICANN bollocking
ICANN has slapped an intensely privacy-focused registrar that compares its stance on takedowns to Elon Musks with a lengthy breach-of-contract notice, claiming that the company is disregarding legitimate abuse reports for no good reason.
Estonia-based Fewmoretaps, which changed its brand to Trustname.com not long after its accreditation was approved in early 2024, has been friendly to malware distributors that use its services, according to ICANN.
The breach notice claims that Trustname, after it had discovered that an abuse report was valid and that one of its customers’ domains was being used to spread malware, did not suspend the domain as required.
Rather, it gave the registrant a three-day headsup to move their domain to another registrar, according to ICANN.
It additionally ignored multiple abuse reports, often for spurious reasons, the notice claims, often only taking action on abusive domains after ICANN Compliance itself got it touch.
Trustname says it is a “registrar built for businesses in competitive niches that often face false or bad-faith abuse reports” and makes hay out of the fact that it offers “bulletproof” privacy by masking registrants details behind two different proxy services located in different jurisdictions.
While the company’s web site claims ad nauseam that its services are not to be used for illegal purposes such as child abuse material and opioid sales, it boldly states that it “disregards” copyright infringement notices.
“Like Elon Musk, we have a strong aversion to individuals who exploit the DMCA, as we believe it lacks legal authority for the vast majority of the world’s population,” the site states.
IP matters are not covered by ICANN contracts, which defined abuse as malware, pharming, phishing and a subset of spam, of course.
Trustname’s site states that it will only take action against domains in “extreme scenarios”.
Such scenarios include “using your website to host illegal content (that we have confirmed after thorough investigations) and getting court orders from all three jurisdictions.”
The three jurisdictions are the US and Saint Kitts & Nevis, where its proxy partners are located, and its home nation of Estonia. Saint Kitts-based Harakiri (Perfect Privacy LLC) was specifically chosen because court orders are hard to come by there.
The company additionally states, in what could be interpreted as an admission of guilt by ICANN Compliance standards:
We will never take any action against a domain name simply because someone filed a complaint – even if your report indicates a violation of our terms. We will only be obligated to take action when we get the relevant court orders.
Trustname, which had fewer than 1,500 gTLD domains under management at the last count, has been given until July 1 to come back into compliance or risk losing its accreditation.
Four more deadbeat registrars face firing squad
ICANN has initiated public compliances proceedings against four unrelated registrars that haven’t paid their fees in a year or more.
US-based Domus, Finland-based Globis, Hong Kong-based Overcasts, and Wanyuhulian Technology from China have all been given until May 27 to cough up or have their accreditation agreements terminated.
None of the registrars currently have any gTLD domains under management. Two of them appear to have never sold a single domain, while Globis and Domus both lost their four-figure DUM almost a year ago.
Wanyuhulian is a particularly interesting case, highlighting some ICANN weirdness.
It was first approved for its Registrar Accreditation Agreement in 2020 and had it renewed in June 2025, but according to ICANN’s breach notice, it was already at least nine months past due with its payments at the time of the renewal.
Not only that, but the notice also claims that Wanyuhulian hadn’t provided the necessary paperwork, known as the Registrar Information Specification, that sets out a registrar’s address, officers and owners:
As part of the RAA renewal process, ICANN requires updated information and documentation from registrars, through which ICANN may verify, for example, current contact information and that the registrar remains established and in good standing.
During the renewal process for Wanyuhulian Technology’s RAA in 2025, the Registrar failed to provide the information requested. To date, ICANN has not received the requested information.
So it appears that ICANN was happy to renew the accreditation of a registrar despite knowing that it was past due with its fees and not knowing for sure who was running it, who owned it, or where it was located.
Bit worrying?
Seven dead registrars on the out
When a registrar stops paying its registry partners, they tend to be cut off relatively quickly. ICANN takes a bit longer.
That seems to be what’s happening to a collection of accredited registrars under the same ownership, which have been given just a few weeks to pay over a year’s worth of overdue ICANN fees or lose their ability to sell names.
ICANN Compliance is gunning for Haveaname, InstantNames, MisterNIC, NetEstate, Neudomain, OpenName, and TopSystem for non-payment of fees going back at least to September 2024.
Probably not coincidentally, that’s the same month that all seven registrars abruptly lost all of their domains under management — not much more than 1,000 per registrar — and apparently lost its .com accreditation.
According to the ICANN notice, Compliance spent the last few months of 2024 unsuccessfully attempting to get in touch with the registrars, before ignoring the case for the whole of 2025 and only returning to it this month.
The registrar web sites are all simple placeholders, with broken SSL certs, doing the bare minimum to stay in compliance with the ICANN Registrar Accreditation Agreement without actually attempting to sell any domains.
While almost all ICANN Compliance breach notices contain an allegation of unpaid fees, this is a rare instance where the allegations stop there; there’s no claim of any other breach.
Half of registrar’s domains are abusive, ICANN says
A fast-growing registrar seems to be experiencing its growth spurt due to extremely high levels of DNS abuse, including phishing, according to the latest public breach notice from ICANN Compliance.
More than half of Bulgarian registrar MainReg’s domains under management are abusive, judging by the notice, which alleges MainReg’s unwillingness to investigate abuse reports in violation of its accreditation contract.
The notice is the first I can recall seeing that cites data from Domain Metrica, an ICANN service that aggregates abuse data from third-party block-lists. An unspecified third-party reporter (hands up in the comments if it was you!) is also cited.
“ICANN Domain Metrica data indicates that in November 2025 approximately 48% of MainReg’s DUMs were reported for phishing, with the figure at 45% as of 5 January 2026,” the notice says.
“The complaining party stated that its own independent analysis identified an even higher proportion of the Registrar’s DUMs engaged in scam‑related activity,” it adds.
MainReg isn’t a huge registrar, but transaction reports show that its DUM tripled between September 2024 and September 2025, from about 10,000 names to about 30,000. The company registered its first name in 2015. Almost all of its names are in .com, .net and .org.
The notice alleges other breaches, such as failing to migrate from Whois to RDAP, and gives MainReg until January 28 to come in compliance or risk termination.
Decades-old US registrar gets a spanking
ICANN Compliance has filed a wide-ranging breach notice against an American registrar that’s been accredited for over 20 years.
Cincinnati-based Netdorm, which does business as DnsExit.com, has been handed a long list of alleged contract violations and an October 16 deadline to fix things or risk termination.
As we’ve seen regularly recently, the registrar’s apparent failures to carry out the technical migrations from Whois to RDAP and from NCC Group to DENIC for escrow services are the biggest of ICANN’s concerns.
Netdorm is also past-due on its fees and has a long checklist of administrative and transparency failures, according to the Compliance breach notice.
Despite being accredited since 2004, the company has been chugging along with fewer than 6,000 gTLD domains under management for many years. It gives away third-level subdomains for free and claims to run over a million of them.
Another registrar goes AWOL
ICANN has started takedown procedures against another registrar that appears to have disappeared from the face of the Earth.
The registrar is 0101 Internet, based in Hong Kong, not to be confused with 101 Domain, which is based in Ireland and California and a completely different company.
0101 has been around for 15 years and had a little over 1,000 domains under management at the last count, mostly .com. Its DUM peaked at over 10,000 over a decade ago but has been declining since.
Currently, its web site doesn’t reliably resolve, which may be the reason ICANN can’t find contractually required information there. Archives show the place on its site where you would usually expect to see a company name or logo, it has just said “Your Brand” for the last few years.
The main problem outlined in ICANN Compliance’s breach notice is that 0101 has not been escrowing its registrant data with DENIC, which could cause problems when its customers’ domains are migrated to a new registrar.
It also hasn’t been paying its ICANN fees, according to the notice.
0101 has until October 3 to come into compliance or risk losing its contract.
Registrar shamed for alleged crypto abuse neglect
ICANN has given a warning to Malaysian registrar WebNic, claiming that it has turned a blind eye to abuse reports in breach of new Registrar Accreditation Agreement rules.
ICANN Compliance says the company, a subsidiary of Kuala Lumpur-based Qinetics, failed to take action to resolve abuse reports made against several domains it manages.
Online reports and databases suggest the names in question were used in phishing attacks attempting to steal cryptocurrency wallet credentials.
Compliance said it “has observed a concerning pattern regarding DNS Abuse mitigation”, saying WebNic continually drags its feet on responding to abuse reports, often only taking action after ICANN gets involved.
The breach notice adds:
The Registrar frequently issued repeated requests for evidence to abuse reporters – even when the original reports appeared actionable – and failed to fully consider information or clarifications provided by the abuse reporter, ICANN or otherwise reasonably accessible to the Registrar. In other cases, the Registrar requested evidence from the abuse reporters that did not appear to be relevant to the reported activity, causing additional delays.
WebNic is not a young, fly-by-night registrar. It’s been around a quarter century and has over 800,000 domains under management just in the gTLDs. Its parent also offers registry back-end services.
The company has until August 19 to make Compliance happy or risk termination proceedings.
.TOP promises to play nice on DNS abuse
.TOP Registry is off the ICANN naughty step, almost a year after it became the first registry to be hit by a public contract-breach notice over ICANN’s latest rules on DNS abuse.
The Org took the highly unusual step yesterday of publishing a blog post drawing attention to what it clearly sees as a big Compliance win, ahead of its public meeting in Prague later this month, at which abuse will no doubt, as usual, be a key discussion topic.
ICANN said that it has been working with .TOP for months to put in systems aimed at reducing the abuse of .top domains. It posted:
.TOP Registry expressed its commitment to maintaining compliance with the DNS Abuse obligations and continuously strengthening its abuse detection and mitigation processes through newly established collaboration channels and a structured approach designed to drive ongoing enhancement. ICANN Compliance acknowledged that the remedial measures were sufficient to cure the Notice of Breach. We noted that future violations of these requirements will result in expedited compliance action, up to and including the issuance of additional Notices of Breach.
Compliance had hit .TOP with the breach notice last year over allegations that it repeatedly ignored abuse reports submitted by security researchers, and that it was ignoring Uniform Rapid Suspension notices.
Security outfit URLAbuse later revealed it was the party that had reported .TOP to ICANN.
.TOP is a Chinese registry that sells mainly via Chinese registrars, typically at under a couple bucks retail. A non-scientific perusal of its zone files reveals that the majority of the many thousands of domains it sells every day are nothing but disposable junk — random strings of characters with no meaning in any language.
While .top is far from alone in that regard, it is the most successful at the abuse-attractive low-price-high-volume business model. Its zone grew by almost 1.2 million domains in the last 12 months — the biggest growth spurt of any TLD — and it has just shy of four million domains today.
Despite this implausibly rapid growth, ICANN says that abuse reports for .top domains started falling in April and there has been a “noticeable decrease in reported abuse”.
The Org says it will “actively monitor the effectiveness of these new [.TOP] systems and processes, the Registry Operator’s abuse rankings and their compliance with the requirements.”
The registry has told ICANN it has already “mitigated” over 100,000 abusive domain names with its new systems and processes.
Big .gdn registrar at risk
A registrar that exclusively sells .gdn domain names seems to have gone AWOL, and ICANN Compliance is on its case.
Dubai-based Intracom Middle East has been slapped with a breach notice alleging failures to operate a compliant RDAP server, publish the names of its officers, pay its ICANN fees, and escrow its registrant data.
Some of these breaches seem to be due to the fact that the company’s web site is missing in action, today returning NXDOMAIN errors, and has quite possibly been repeatedly hacked.
Archived versions of its site from last year show it was at various times a Polish risotto recipes splog, an Indian burger joint, and a manga cosplay porn site.
It’s Intracom’s second brush with Compliance. Three years ago the case was escalated to a three-month accreditation suspension for pretty much the same infractions.
Unlike most recent Compliance actions, which have been against registrars with essentially no domains under management, this times some domains are actually at risk — over 10,000 of them in fact.
Intracom specializes/d in selling .gdn domains for under a buck apiece. Apart from a few dozen registrations in a few other gTLDs, all of its 10,000 domains were in .gdn. It was once .gdn’s biggest registrar, though that’s no longer the case.
The company has been given to the end of the month to comply or risk termination.
Registrar terminated after ignoring Whois transition
A registrar has lost its right to sell gTLD domains in part due to its failure to migrate from Whois to RDAP.
Spain-based Abansys & Hostytec has had its ICANN registrar contract terminated over a litany of alleged breaches dating back to 2023, and its meager collection of domains will now be given to another registrar.
ICANN said in its termination notice that the company had failed to implement the Registration Data Access Protocol, the successor to Whois that this week became the new industry standard for domain ownership lookups.
The registrar was also past due on its fees, hadn’t given ICANN evidence the was still in good standing, hadn’t had an employee attend compliance training and was not publishing masked contact addresses in Whois results, among other things.
While its accreditation dates back to the noughties, Abansys has never had more than 600 gTLD domains under management and it seems very unlikely that it was making enough money from those domains to cover the cost of compliance.
ICANN said the termination became effective January 26, but it still wants its past-due fees paid.
Separately, Compliance has also sent breach notices to four other registrars — US-based Zoo Hosting, UK-based Nerd Origins, and China-based Mixun and Mixun Network Technology — that cite RDAP failures as an area of non-compliance but appear to be primarily based on non-payment of fees.
All four registrars appear to have got accredited between 2019 and 2021 and stopped paying their fees not long afterwards. None of them has sold a single gTLD domain, ever, and two of their web sites suggest the companies are no longer around.
They’ve all got until February 12 to magically rectify their compliance problems or face execution.






Recent Comments