Cybercrime link as t.me gets taken down
Speculation is rampant online right now after t.me, the domain used for short links by the messaging service Telegram, was apparently taken down by the .me registry, affecting as many as a billion users.
t.me seems to have gone dark shortly before 2000 UTC on Monday evening, with Whois/RDAP records showing it is now placed on serverHold status, which usually indicates a registry-level suspension and removal from the .me zone.
The suspension means that millions of short links using t.me are no longer functioning when clicked, leading instead to NXDOMAIN errors. Substituting t.me for telegram.me can be used as a workaround; the longer domain remains unsuspended.
.me is the ccTLD for Montenegro and is managed by local firm doMEn, which is mostly a partnership between US-based domain giants GoDaddy and Identity Digital.
Telegram and doMEn’s partners have yet to publicly address the outage, leading to a great deal of speculation online.
The most plausible explanation put forward so far but not yet confirmed is that the takedown relates to an order issued Monday by the US government’s Office of Foreign Assets Control, which has broad powers to sanction organizations and individuals it believes are linked to crime and terrorism.
OFAC, in an advisory that otherwise largely targets Cuban-linked entities, sanctioned domains and cryptocurrency wallets linked to First VPN Service (1VPNS), which it said was a Ukraine-based cybercrime group selling anonymity services to ransomware attackers and others.
OFAC said: “Numerous ransomware groups have purchased infrastructure from 1VPNS, which they have leveraged in attacks on U.S. companies and institutions—including to hide the origins of their attacks, deploy malware, and manage exfiltrated data.”
The July 13 order sanctioned three 1VPNS domain names — 1vpns.com, 1vpns.net, and 1vpns.org — that had in fact already been taken down by a Europol-led law enforcement operation in May.
But also on the list is the URL t.me/FirstVPNService. The equivalent telegram.me URL was not listed.
This has led to the suspicion that the t.me suspension is a classic case of government using a jurisdictional sledgehammer to crack an overseas nut — ordering doMEn’s US-based registry partners to take down the whole of t.me rather than asking Dubai-based Telegram to take down the specific offending URL or group.
Identity Digital, which holds the pen on .me domain edits, would have been powerless to resist an order from its own government.
While the takedown will doubtless be raised in ongoing policy discussions about when it is appropriate for a registry or registrar to suspend a domain over DNS abuse concerns, it’s less clear whether it will play into the Montenegro government’s nascent efforts to exert more local control over .me.
ICANN rules could hamper agentic AI domain regs
Bulk registration of domain names is likely to become more difficult under policy proposals being considered in ICANN, potentially limiting the potential of agentic AI.
The Generic Names Supporting Organization is in the very early stages of a Policy Development Process that aims to “introduce friction” into bulk registration shopping carts for untrusted registrants.
The PDP was initially conceived last year as targeting API-based registrations, which are believed to be often used by Bad Guys to bulk-register domains for abusive purposes like malware and spam.
But the first version of the draft charter that will govern the PDP is now using “technology neutral” language, recognizing that APIs may not be as relevant in future. Bots and agentic AI are not directly mentioned, but it’s clearly what the authors have in mind.
The charter states:
This PDP would seek to introduce a requirement to put safeguards in place to ensure that registrants, particularly new or untrusted accounts, cannot immediately access domain name registrations at scale until they have demonstrated basic trustworthiness.
Quite how the limits would be put in place, what “at scale” means numerically, and how “trustworthiness” would be defined and earned, are all issues that would have to be hashed out by the PDP working group.
Whatever rules are created would be binding on all ICANN-accredited registrars and their resellers.
The PDP working group has yet to be created, and it seems the absolute earliest any agreed policy could be approved by ICANN would be the end of next year, with the rules coming into effect perhaps the following year.
The PDP is set to be the second of the Domain Abuse Mitigation efforts that began last year under pressure from governments and others and studies such as ICANN’s INFERMAL, which discovered that registrars with freely available APIs were far more likely to be abused by ne’er-do-wells.
Namecheap saw 116,000 phishing attacks last year
Bad guys used Namecheap to register domains associated with over 116,000 confirmed phishing attacks in 2025, according to data released by the company this week.
Across Namecheap and sister registrar Spaceship there were 432,796 reports of phishing and 116,871 of them were confirmed to be phishing attacks, according to data shared to an ICANN policy mailing list.
The stats refer to the number of tickets in the registrars’ support system, not the number of abusive domains, which logically could be lower due to double-counting or higher due to multiple domains listed in the same ticket.
The numbers are low as a percentage of the company’s domains under management — it has over 27 million DUM across its accreditations — at less than half of one percent, but pretty steep in absolute numbers.
The data was shared as part of early-stage discussions about the next wave of ICANN policy on DNS abuse.
A community working group is working on potential new rules for registrars, forcing them to conduct “Associated Domain Checks”.
That’s the idea that when a registrar confirms a domain is abusive they should check the Bad Guy’s other domains for similar abuse and yank those too, particularly if they were part of a bulk registration.
One of the many factors playing into these policy discussions is the administrative burden, and cost, that this would place on registrars. With 116,000 confirmed cases of abuse, the work-hours for abuse staff (or a potentially unreliable AI) quickly adds up.
Namecheap was named in the Anti-Phishing Working Group’s Q4 2025 report as the number one registrar abused in business email compromise attacks, a subset of phishing, with 25% of the total.
ICANN looking at new bulk reg rules
ICANN seems set to start creating more rules governing DNS abuse, including limits on bulk registrations and more tracking of registrants.
A small team of GNSO volunteers have put together a list (pdf) of dozens of proposed policy change areas, covering everything from registrant data accuracy to pricing to API access to getting ICANN Compliance to be more proactive.
While most of the ideas in the team’s analysis received a broad range of views, it settles on three areas, all related to bulk registration of abusive domains, that it thinks are ripest for further policy work.
The first is “Associated Domain Checks”. The small team think it’s worth looking into whether registrars should have to investigate proactively domains registered by known abusive registrants.
The group also thinks it’s worth looking into better industry information-sharing about domain generation algorithms, which bad actors use to create vast numbers of gibberish names that can be used in spam runs, phishing attacks, or botnets.
Finally, the group thinks rules around API access to registrar platforms should be looked at, given that bulk-registered abusive domains often seem to use APIs to programmatically obtain thousands of throwaway domains in seconds.
The small team thinks a Policy Development Process looking at just these three issues could be completed relatively quickly and the community could address the remaining issues later.
Whether the recommendations go to a PDP is now up to the GNSO Council, which will vote on the matter this Thursday. Assuming the vote passes, which seems likely, ICANN staff would then have to prepare a formal Issue Report, setting out the scope of future work, if any.
A PDP would likely take years to complete.
The three priority topic areas reflect closely the Governmental Advisory Committee advice coming out of June’s ICANN 83 public meeting. Both small team and GAC heavily source ICANN’s INFERMAL research and a recent NetBeacon white paper as their inspirations.
Governments erect bulk-reg barrier to new gTLD next round
No new gTLDs should be added to the internet until ICANN develops policies addressing the abuse of bulk domain name registrations, according to the Governmental Advisory Committee.
The GAC this afternoon drafted formal Advice for the ICANN board stating that policy work on bulk regs should get underway before ICANN 84, which takes place in Muscat, Oman in late October.
While the wording still may change before it is sent to ICANN, the current draft advice reads:
The GAC advises the board: To urge the GNSO Council to undertake all necessary preparation prior to ICANN84 towards enabling targeted and narrowly scoped Policy Development Processes (PDPs) on DNS Abuse issues, prioritizing the following: to address bulk registration of malicious domain names; and the responsibility of registrars to investigate domains associated with registrar accounts that are the subject of actionable reports of DNS Abuse.
The advice on bulk regs is fairly self-explanatory: the GAC has become aware that spammers typically shop around for the cheapest TLDs then register huge amounts of domains on the assumption that some will start getting blocked quite quickly.
The second part of the advice probably needs some explanation: under the current ICANN contracts, registrars have to deal with abuse reports concerning domains they sponsor, but they’re under no obligation to investigate other domains belonging to the registrants of those domains.
So, if a scumbag registers 100 domains for a spam campaign and only one of them is reported as abusive, the registrar can comply with its contract by simply suspending that one domain. The GAC thinks it should be obliged to proactively investigate the other 99 names too.
The advice seems to have been inspired by two sources: NetBeacon’s recent Proposal for PDPs on DNS Abuse (pdf) and data from Interisle Consulting.
Both pieces of advice obviously could have an impact on registrars’ top and bottom lines. They could lose revenue if they currently make a lot of money from bulk regs, and their costs could be increased with new obligations to investigate abuse.
An added wrinkle comes in the GAC’s rationale for its advice, which suggests that dealing with bulk regs and abuse probes should be a gating factor for the next round of new gTLDs going ahead. It reads:
Before new strings are added to the DNS as a result of the next round, further work on DNS Abuse is needed to stem the increasing cost to the public of phishing, malware, botnets, and other forms of DNS Abuse.
The core text of the advice was compiled in furtive huddles on the edges of sessions at ICANN 83, and I believe Switzerland held the pen, but it seems the US government was the driving force behind the push to make abuse a barrier to the next round.
As I reported on Monday, the US GAC rep said that “in light of the global phishing problem… and similar concerns the United States is of the view that we should not expand the DNS too broadly”.
.TOP promises to play nice on DNS abuse
.TOP Registry is off the ICANN naughty step, almost a year after it became the first registry to be hit by a public contract-breach notice over ICANN’s latest rules on DNS abuse.
The Org took the highly unusual step yesterday of publishing a blog post drawing attention to what it clearly sees as a big Compliance win, ahead of its public meeting in Prague later this month, at which abuse will no doubt, as usual, be a key discussion topic.
ICANN said that it has been working with .TOP for months to put in systems aimed at reducing the abuse of .top domains. It posted:
.TOP Registry expressed its commitment to maintaining compliance with the DNS Abuse obligations and continuously strengthening its abuse detection and mitigation processes through newly established collaboration channels and a structured approach designed to drive ongoing enhancement. ICANN Compliance acknowledged that the remedial measures were sufficient to cure the Notice of Breach. We noted that future violations of these requirements will result in expedited compliance action, up to and including the issuance of additional Notices of Breach.
Compliance had hit .TOP with the breach notice last year over allegations that it repeatedly ignored abuse reports submitted by security researchers, and that it was ignoring Uniform Rapid Suspension notices.
Security outfit URLAbuse later revealed it was the party that had reported .TOP to ICANN.
.TOP is a Chinese registry that sells mainly via Chinese registrars, typically at under a couple bucks retail. A non-scientific perusal of its zone files reveals that the majority of the many thousands of domains it sells every day are nothing but disposable junk — random strings of characters with no meaning in any language.
While .top is far from alone in that regard, it is the most successful at the abuse-attractive low-price-high-volume business model. Its zone grew by almost 1.2 million domains in the last 12 months — the biggest growth spurt of any TLD — and it has just shy of four million domains today.
Despite this implausibly rapid growth, ICANN says that abuse reports for .top domains started falling in April and there has been a “noticeable decrease in reported abuse”.
The Org says it will “actively monitor the effectiveness of these new [.TOP] systems and processes, the Registry Operator’s abuse rankings and their compliance with the requirements.”
The registry has told ICANN it has already “mitigated” over 100,000 abusive domain names with its new systems and processes.
Verisign agrees to .com takedown rules
Verisign has agreed to take down abusive .com domains under the next version of its registry contract with ICANN.
The proposed deal, published for public comment yesterday, could have financial implications for the entire domain industry, but it also contains a range of changes covering the technical management of .com.
Key among them is the addition of new rules on “DNS Abuse” that require Verisign to respond to abuse reports, either by referring the domain to its registrar or by taking direct action
Abuse is defined with the now industry-standard “malware, botnets, phishing, pharming, and spam (when spam serves as a delivery mechanism for the other forms of DNS Abuse listed in this definition)”.
The language is virtually identical to the strengthened DNS abuse language in the base Registry Agreement that almost all other gTLD registries have been committed to since their contracts were updated this April. It reads:
Where Registry Operator reasonably determines, based on actionable evidence, that a registered domain name in the TLD is being used for DNS Abuse, Registry Operator must promptly take the appropriate mitigation action(s) that are reasonably necessary to contribute to stopping, or otherwise disrupting, the domain name from being used for DNS Abuse. Such action(s) shall, at a minimum, include: (i) the referral of the domains being used for the DNS Abuse, along with relevant evidence, to the sponsoring registrar; or (ii) the taking of direct action, by Registry Operator, where Registry Operator deems appropriate.
The current version of the .com contract only requires Verisign to publish an abuse contact on its web site. It doesn’t even oblige the company to respond to abuse reports.
In domain volume terms, .com is regularly judged one of the most-abused TLDs on the internet, though newer, cheaper gTLDs usually have worse numbers in terms of the percentage of registrations that are abusive.
Verisign will also get an obligation that other registries don’t have — to report to ICANN “any cyber incident, physical intrusion or infrastructure damages” that affects the .com registry.
ICANN won’t be able to reveal the details of such incidents publicly unless Verisign gives its permission, but in a side deal (pdf) the two parties promise to work together on a process for public disclosure.
Verisign will also have to implement two 20-year-old IETF standards on “Network Ingress Filtering” that describe methods of mitigating denial-of-service attacks by blocking traffic from forged IP addresses.
The contract is open for public comment.
ICANN gunning for Tencent over abuse claims
ICANN Compliance is taking on one of the world’s largest technology companies over claims that a registrar it owns turns a blind eye to DNS abuse and phishing.
The Org has published a breach of contract notice against a Singapore registrar called Aceville Pte Ltd, which does business as DNSPod and is owned by and shares its headquarters with $86-billion-a-year Chinese tech conglomerate Tencent.
ICANN says that DNSPod essentially has turned a blind eye to recent abuse reports, allowing phishing sites to stay online long after they were reported, and makes life difficult for people trying to report abuse.
It also has failed to upgrade from the Whois protocol to RDAP and failed to migrate its registration data escrow service provider from NCC to DENIC, according to the notice.
According to ICANN, DNSPod received abuse reports about several domains in July and August but failed to take action at all or until ICANN itself got in touch to investigate. Compliance wants to know why.
ICANN adds that the registrar seems to be requiring reporters to create user accounts and use a web form to submit their reports, even after they’ve already used the abuse@ email address.
Stricter rules on DNS abuse came into force on registrars this April. They’re now required to take action on abuse reports.
“Aceville does not appear to have a process in place to promptly, comprehensively, and reasonably investigate and act on reports of DNS Abuse,” the notice reads.
ICANN has given DNSPod until October 11 to answer its questions or risk escalation.
While DNSPod says it has been around for 17 years, it only received its ICANN accreditation in 2020. Since then, it’s grown to almost 200,000 domains under management in gTLDs.
It’s primarily a DNS resolution service provider, saying it hosts over 20 million domains, and does not appear to operate as a retail registrar in the usual sense.
Owner Tencent may not be a household name in the Anglophone world, but it’s the company behind some of China’s leading social media brands, including QQ and WeChat, as well as a formidable force in gaming and one of the world’s richest companies in any sector.
It’s the second huge Chinese tech firm to find itself publicly shamed by ICANN in recent months. Compliance went after Tencent’s primary competitor, Alibaba, on similar grounds in March. Alibaba has since resolved the complaints.
ICANN approves domain takedown rules
ICANN’s board of directors has formally approved amendments to its standard registry and registrar contracts aimed at forcing companies to take action against domains involved in DNS abuse.
At its meeting last weekend, the board passed a resolution amending the Registrar Accreditation Agreement and Base gTLD Registry Agreement to include tougher rules on tackling abuse.
Registrars must now “promptly take the appropriate mitigation action(s) that are reasonably necessary to stop, or otherwise disrupt, the Registered Name from being used for DNS Abuse” when provided with evidence of such abuse.
Registries have a similar obligation to take action, but the action might be to refer the abusive domain to the appropriate registrar.
The rules follow the now industry-standard definition of DNS abuse: “malware, botnets, phishing, pharming, and spam (when spam serves as a delivery mechanism for the other forms of DNS Abuse listed)”.
The changes were crafted by ICANN along with registries and registrars and voted through late last year by a hefty majority of both camps.
The two contracts are now in the hands of the ICANN CEO and her lawyers for final action before becoming enforceable.
Registries and registrars vote ‘Yes’ to new DNS abuse rules
ICANN’s contracted registries and registrars have voted to accept new rules requiring them to take action on DNS abuse.
The new rules come after a vote lasting a few months with some quite high thresholds for success.
The current Registrar Accreditation Agreement merely requires registrars to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse”, which is pretty vague and barely enforceable.
The amendments, which still need to be rubber-stamped by the ICANN board, make it much clearer what registrars are expected to do in which circumstances. A new paragraph is added that reads:
3.18.2 When Registrar has actionable evidence that a Registered Name sponsored by Registrar is being used for DNS Abuse, Registrar must promptly take the appropriate mitigation action(s) that are reasonably necessary to stop, or otherwise disrupt, the Registered Name from being used for DNS Abuse. Action(s) may vary depending on the circumstances, taking into account the cause and severity of the harm from the DNS Abuse and the possibility of associated collateral damage.
For registries, the new text for the base gTLD Registry Agreement is similar, but with a little more wiggle-room:
Where a Registry Operator reasonably determines, based on actionable evidence, that a registered domain name in the TLD is being used for DNS Abuse, Registry Operator must promptly take the appropriate mitigation action(s) that are reasonably necessary to contribute to stopping, or otherwise disrupting, the domain name from being used for DNS Abuse. Such action(s) shall, at a minimum, include: (i)the referral of the domains being used for the DNS Abuse, along with relevant evidence, to the sponsoring registrar; or (ii) the taking of direct action, by the Registry Operator, where the Registry Operator deems appropriate. Action(s) may vary depending on the circumstances of each case, taking into account the severity of the harm from the DNS Abuse and the possibility of associated collateral damage.
In both cases, DNS abuse is defined by the now industry standard line: “malware, botnets, phishing, pharming, and spam (when spam serves as a delivery mechanism for the other forms of DNS Abuse listed in this Section)”.
There are a few other quality of life updates, such as the requirement for registrars to acknowledge receipt of abuse reports and to have their abuse reporting mechanism “conspicuously and readily accessible from” their home pages.
ICANN needed registrars representing over 90% of registered gTLD domains (adjusted slightly to make GoDaddy’s voice less powerful). That threshold was passed last week, with 94% of domains voting in favor of the amendments.
For registries, ICANN required a simple majority of registries (counted by contract rather than company) and for all registries voting in favor to have been responsible for two thirds of all registry fees paid last year.
Judging by the financial thresholds, .com and .net, which are not on the base RA, were not involved.






Recent Comments