Latest news of the domain name industry

Recent Posts

Maybe now’s the time for ICANN to start dismantling the Soviet Union

Kevin Murphy, February 25, 2022, Domain Policy

Like I’m sure a great many of you, I spent much of yesterday listening to the news and doom-scrolling social media in despair, anger and helplessness.

War has returned to Europe, with Vladimir Putin’s Russia yesterday invading Ukraine on a flimsy pretext, in an apparent effort to begin to recreate the former Soviet Union.

I watched r/ukraine on Reddit, as its number of subscribers increased by tens of thousands in a matter of hours, with people from all over the world wondering what they could do to help, from volunteering to literally take up arms to hollow if well-meaning virtue-signalling.

Can I volunteer for the Ukrainian army? I live in Japan and can’t speak the language, does that matter?

If any Ukrainians can make it to Ottawa, I have a spare couch for as long as you need it!

Here’s a guide to how I survived the snipers in Sarajevo!

Here’s a yellow-and-blue banner I made that you can use on your Twitter!

Slava Ukraini!

It got me thinking: is there anything the domain industry or ICANN community can do? Is there anything I can do?

The only thing I could think of was to run this idea up the flagpole and see if anyone sets fire to it:

Maybe now’s the time for ICANN to start dismantling the Soviet Union.

It may sound ludicrous. The Soviet Union hasn’t existed outside Putin’s fantasies since 1991.

But it’s alive and well in the DNS, where the top-level domain .su has somehow managed to survive the death of its nation, evade any efforts to have it removed, and stick around in the root for over 30 years.

It currently has over 100,000 registered domains.

I’m not suggesting for a second that all of these domains were registered by people who support the return of the USSR, or are even aware of the connection, but it is the ccTLD of choice for sites like this gung-ho propaganda rag, and the Donetsk People’s Republic, the breakaway Ukrainian region.

Whenever I’ve asked people with better in-depth knowledge of ccTLD policy than me for an explanation of why .su continues to exist, despite not having a nation to represent, I generally get a lot of hand-waving and mumbling about a “lack of political will”.

Maybe there’s a political will now, if not at ICANN Org then perhaps in the ICANN community.

My understanding, based on a deep-dive through the public record, is that it might be possible to have .su deleted — the word ICANN uses is “retired” — but the rules are arguably open to interpretation.

A bit of background first

ICANN’s rules concerning ccTLDs are a bit like the UK constitution — they’re not written down in any one document, but have rather evolved over the years through a combination of habit, convention, case law and pure making-it-up-on-the-spot.

ICANN, and IANA before it, “is not in the business of deciding what is and what is not a country”. It has always deferred to the International Organization for Standardization, which maintains a list of names and corresponding country-codes called ISO 3166-1.

If a country or territory appears on the 3166-1 list, its corresponding “alpha-2” code is eligible to become a ccTLD.

SU was listed on 3166-1, the same as any other country, until September 1992, when it was broken up into 15 names and codes corresponding to the 15 former Soviet nations. Russia got RU and Ukraine got UA, for examples, and their ccTLDs are .ru and .ua.

SU was then given a “transitionally reserved” status by the ISO, which basically means it’s due to be phased off the list altogether (albeit not for 50 years) and organizations are discouraged from using it.

In corresponding ccTLDs, every string on the “transitionally reserved” list has either transitioned to a new ccTLD (such as East Timor’s .tp becoming Timor-Leste’s .tl) or split into a collection of new ccTLDs (such as the break-up of the Netherlands Antilles).

Since ICANN took over the root, these and other transitions typically happen with the consent of the local government and the local registry. But the Soviet Union dissolved long before ICANN existed, it doesn’t have a government, and the registry is in no hurry to give up its asset, which is a bit of a money maker.

ICANN stated its intention to retire .su as early as 2003, and the earliest archived IANA record, from 2006, said it was “being phased out”.

It launched a brief consultation on the retirement of ccTLDs in 2006, which prompted a flood of comments from outraged .su supporters.

The following year, there were face-to-face talks between ICANN and the two Moscow companies running .su at the time — the Foundation for Internet Development (FID) and Russian Institute for Public Networks (RIPN).

IANA’s Kim Davies, who now heads the division as an ICANN VP, blogged in 2007, partly in response to these comments, that .su had a chance to remain delegated:

To retain .SU, under current policy they would need to successfully apply for the code to be re-instated into the ISO 3166-1 standard, either as a regular two-letter country code, or as an “exceptionally reserved” code like UK and EU.

The “exceptionally reserved” list is another subdivision of ISO 3166-1. It currently includes four codes that are also ccTLDs — .ac for Ascension Island, a UK territory, .uk itself, and the European Union’s .eu.

The fourth is .su, because FID somehow managed to persuade the ISO 3166 Maintenance Agency to get SU on the list, reversing its 50-year sentence on the transitional list, in 2008. It appears to be the only example of a private, non-governmental, non-UN entity requesting and obtaining a special listing.

There’s been very little public discussion about .su’s fate since then. My suspicion is that it fell off the radar when ICANN CEO Paul Twomey, who made ccTLD relations a cornerstone of his administration, left the Org in 2009.

Or it could be that that the “exceptionally reserved” status was enough to satisfy IANA’s eligibility criteria. But there are several reasons why that might not be the case.

In Davies’ 2007 blog, post he said: “There are other issues that will need to be addressed for .SU to be a viable ccTLD designation, but recognition by the appropriate standard is a prerequisite.”

IANA currently has a web page in which it lays out seven ways a TLD can get into the root. This is what it says about exceptionally reserved strings:

Eligible under ICANN Board Resolution 00.74. This resolution provides for eligibility for domains that are not on the ISO 3166-1 standard, but that the Maintenance Agency deems exceptionally reserved, and requires that the Agency “has issued a reservation of the code that covers any application of ISO 3166-1 that needs a coded representation in the name of the country, territory, or area involved”. There is currently (as of June 2013) only one code eligible under these requirements, “EU” for the European Union.

The cited ICANN board resolution, now incorporated into IANA precedential law, dates from September 2000. It’s the resolution that hacked historical IANA practice in order to set the groundwork for eventually levering .eu into the root.

But the relevant part here is where IANA explicitly rules out any exceptionally reserved string other than EU meeting the requirements to be a ccTLD as of 2013. SU’s ISO 3166-1 status has not changed since 2008.

RIPN and FID explicitly acknowledged this in a joint letter (pdf) to ICANN then-CEO Paul Twomey in 2007. In it, they wrote:

we understand that should ISO-3166/MA add the two letter code “SU” to the exceptionally reserved or indeterminately reserved ISO3166-1 list will not be sufficient to clarify the status of .SU as current ICANN/IANA policies require a venue in which legality of actions can be determined.

To paraphrase: being on the list ain’t no good if you got no country.

They said that if ICANN went ahead and retired .su anyway, they would like 10 to 15 years to transition their registrants to alternative TLDs.

Which handily brings me to now

There has never been a formal community-agreed ICANN policy on retiring ccTLDs, until now.

By happy coincidence, the ccTLD Name Supporting Organization recently finished work on such a policy. It came out of public comment a few weeks ago and will next (I was going to write “soon”, but you know?) come before the ICANN board of directors for consideration.

The proposed policy (pdf) conspicuously avoids mentioning .su by name and seems to go out of its way to kick the can on .su’s potential retirement.

The silence is deafening, and the ambiguity is claustrophobic.

It defines ccTLDs as:

  • 2-letter ccTLDs corresponding to an ISO 3166-1 Alpha-2 Code Element (the majority of ccTLDs).
  • 2-letter Latin ccTLDs not corresponding to an ISO 3166-1 Alpha-2 Code Element
  • IDN ccTLDs as approved by ICANN

The second bullet point is accompanied by a footnote that explains it’s referring to the “exceptionally reserved” codes UK, AC and EU, three of the four ccTLDs on the ISO’s exceptional list.

The ccTLDs .uk and .ac which refer to exceptionally reserved codes UK and AC are grandfathered as ccTLDs and .eu, which corresponds to the exceptionally reserved code EU, was delegated under the relevant ICANN Board resolution from September 2000

There’s no mention of SU, the fourth.

Under the proposed policy, the ball would start rolling on a possible retirement whenever a “triggering event” happens. The relevant trigger for .su (and .uk, .eu and .ac) is the ISO making a change — seemingly any change — to its 3166-1 listing.

IANA, referred to in the policy as the IANA Functions Operator or IFO, would then have to decide whether the change warranted initiating the retirement process, which would take at least five years.

As is so often the case in ICANN policy-making, the difficult decisions seem to have been punted.

Only one ccTLD operator filed a public comment on this proposed policy — it was RIPN, operator of .su. While generally supportive, it worried aloud that triggering events prior to the approval of the policy should not count. Its triggering events were in 2008 and the 1990s, after all.

The policy’s creators again ambiguously kicked the can:

The [Working Group] believes the applicability of the Policy to existing situations or those emerging before the proposed Policy becomes effective is out of scope of its mandate. For situations prior to this Policy coming into force, responsibility lies with the IFO to create a suitable procedure. The WG suggests that such a procedure could be based on and anticipates the proposed Policy.

So… does ICANN get to apply the policy retroactively or not?

My overall sense is that the .su situation, which the record shows was certainly on the minds of the ccNSO during the early stages of the policy-development process, was considered too difficult to address, so they took the ostrich approach of pretending it doesn’t exist.

The .su registry seems to think it’s safe from enforced retirement, but it doesn’t seem to be absolutely sure.

In conclusion

I think the record shows that .su doesn’t really deserve to exist in the DNS, and that there’s an opportunity to get rid of it. ccTLDs are for countries and territories that exist and the Soviet Union hasn’t existed for three decades.

IANA rules don’t seem to support its existence, and upcoming policy changes seem to give enough wiggle room for the retirement process to be kicked off, if the will is there to do so.

It would take years, sure.

Would it help stop innocent Ukrainians getting gunned down in the street this week? No.

Would it be more than simple virtue signalling? I think so.

And if not, why not just do it anyway?

In a world where an organization like UEFA considers Russia too toxic for poxy football match, what would it say about an organization that allows the actual Soviet Union’s domain to continue to exist online?

SpamHaus ranks most-botted TLDs and registrars

Kevin Murphy, January 9, 2018, Domain Registrars

Namecheap and Uniregistry have emerged as two of the most-abused domain name companies, using statistics on botnet command and control centers released by SpamHaus this week.
SpamHaus data shows that over a quarter of all botnet C&Cs found during the year were using NameCheap as their registrar.
It also shows that almost 1% of domains registered in Uniregistry’s .click are used as C&Cs.
The spam-fighting outfit said it discovered “almost 50,000” domains in 2017 that were registered for the purpose of controlling botnets.
Comparable data for 2016 was not published a year ago, but if you go back a few years, SpamHaus reported that there were just 3,793 such domains in 2014.
Neither number includes compromised domains or free subdomains.
The TLD with the most botnet abuse was of course .com, with 14,218 domains used as C&C servers. It was followed by Directi’s .pw (8,587) and Afilias’ .info (3,707).
When taking into account the relative size of the TLDs, SpamHaus fingered Russian ccTLD .ru as the “most heavily abused” TLD, but its numbers don’t ring true to me.
With 1,370 botnet controllers and about five and a half million domains, .ru’s abused domains would be around 0.03%.
But if you look at .click, with 1,256 botnet C&Cs and 131,000 domains (as of September), that number is very close to 1%. When it comes to botnets, that’s a high number.
In fact, using SpamHaus numbers and September registry reports of total domains under management, it seems that .work, .space, .website, .top, .pro, .biz, .info, .xyz, .bid and .online all have higher levels of botnet abuse than .ru, though in absolute numbers some have fewer abused domains.
In terms of registrars, Namecheap was the runaway loser, with a whopping 11,878 domains used to control botnets.
While SpamHaus acknowledges that the size of the registrar has a bearing on abuse levels, it’s worth noting that GoDaddy — by far the biggest registrar, but well-staffed with over-zealous abuse guys — does not even feature on the top 20 list here.
SpamHaus wrote:

While the total numbers of botnet domains at the registrar might appear large, the registrar does not necessarily support cybercriminals. Registrars simply can’t detect all fraudulent registrations or registrations of domains for criminal use before those domains go live. The “life span” of criminal domains on legitimate, well-run, registrars tends to be quite short.
However, other much smaller registrars that you might never have heard of (like Shinjiru or WebNic) appear on this same list. Several of these registrars have an extremely high proportion of cybercrime domains registered through them. Like ISPs with high numbers of botnet controllers, these registrars usually have no or limited abuse staff, poor abuse detection processes, and some either do not or cannot accept takedown requests except by a legal order from the local government or a local court.

The SpamHaus report, which you can read here, concludes with a call for registries and registrars to take more action to shut down repeat offenders, saying it is “embarrassing” that some registrars allow perpetrators to register domains for abuse over and over and over again.

Amid Ukraine crisis, Russia scared ICANN might switch off its domains

Kevin Murphy, September 19, 2014, Domain Policy

Russia is reportedly worried that the current wave of Western sanctions against it may wind up including ICANN turning off its domain names.
According to a report in the local Vedomosti newspaper, the nation’s Security Council is to meet Monday to discuss contingency plans for the possibility of being hit by internet-based sanctions.
Part of the discussion is expected to relate to what would happen if the US government forced ICANN to remove the local ccTLDs — .ru, .рф, and the discontinued .su — from the DNS root, according to Vedomosti’s source.
The paper reports, citing a source, that “officials want to control the entire distribution system of domain names in RUnet entirely”. RUnet is an informal term for the Russian-language web.
The report goes on to explain that the government’s goal is not to isolate the Russian internet, but to ensure it remains functioning within the country if its ccTLDs are cut off in the rest of the world.
Russia has been hit by sanctions from the US and Europe in recent months due to its involvement in the Ukraine crisis, but so far these have been of the regular economic kind.
Frankly, I find the possibility of the US government asking ICANN to intervene in this way — and ICANN complying — unlikely in the extreme. It would go dead against the current US policy of removing itself almost entirely from the little influence it already has over the root system.

Almost five million Russian domains registered

Kevin Murphy, September 19, 2012, Domain Registries

Coordination Center for TLD RU broke through the four-million-domain milestone for the Russian ccTLD .ru on Monday, according to a press release.
Including internationalized domain names under .РФ, of which there are 800,000, ccTLD.ru is managing closer to five million domains.
It took 11 months to grow from 3.5 million domains, according to the registry.
The .ru zone is the fifth-largest ccTLD, after .de, .tk, .uk, and .nl, according to Verisign’s last Domain Name Industry Brief.

Russians flee from IDN during first junk drop

Russia’s internationalized ccTLD, .РФ, lost 18% of its registered domains under management after its first launch anniversary, according to the registry.
Coordination Center for ccTLD said that the registry peaked at 954,012 names on December 28, but DUM had dropped to 779,264 by February 15, a 174,748 domain decline.
While the Center spun this as lower than expected – some experts had apparently predicted 25% to 30% of the early-adopter names would expire – it’s still relatively high.
Telnic deleted about 15% of its names during .tel’s first junk drop, the most recent in the gTLD space, for example.
The Russian registry has also made an eye-opening set of stats related to .РФ available on a new web site.
It reveals that just 33% of .РФ domains resolve to a web site (any web site, presumably including parking) while 29% do not even have name servers.

Little interest in Russian gTLDs?

Kevin Murphy, January 18, 2012, Domain Registries

Despite being given the opportunity to launch top-level domains in Cyrillic script, only a handful of companies from Russia are expected to apply to ICANN for new gTLDs.
That’s according to Andrey Kolesnikov, CEO of Coordination Center for TLD RU, which runs the country’s .ru and .РФ registries.
“There won’t be many applications from Russia, only from about 10 companies,” he said at a recent press conference, while estimating at least 1,000 applications overall.
Just 10 applicants is a surprisingly low estimate, given the resurgence of interest in Russian domain names in 2011.
The year-old .РФ (.rf, for Russian Federation) domain has been a roaring success in volume terms. Launched in late 2010, it now has about a million registered domains.
CC itself is planning to apply for .ДЕТИ, which means “.children” in Russian.
RU-Center, the largest Russian registrar, intends to apply for the city-gTLDs .МОСКВА and .moscow.
Other IDN-friendly nations may be more enthusiastic about new gTLDs. ICANN CEO Rod Beckstrom said last week that he heard that Indian companies could apply for as many as 100.

Russian registry to apply for “.children”

Kevin Murphy, November 28, 2011, Domain Registries

The Russian .ru domain name registry has announced plans to apply for .ДЕТИ, the Russian word for “.children”, under ICANN’s new generic top-level domains program.
It’s the first public announcement of a top-level internationalized domain name that is not geographic nor a transliteration of an existing TLD.
Coordination Center for TLD RU, the registry, said that the initiative was inspired by the success of .РФ (.rf), which is on track to register its millionth domain before the end of the year.
Registry CEO Andrey Kolesnikov said in a statement: “We kicked off preparations for the applying for another top-level domain – .ДЕТИ, which should for an Internet space reserved exclusively for the youngest users.”
IDN gTLDs are one of the benefits of the new gTLD program that nobody — not even trademark interests — disputes, but until now there were no “proper” examples to cite.
VeriSign and Afilias have already announced plans for IDN versions of their existing gTLDs – .com, .net and .info – and ICANN has approved IDN ccTLDs for a couple dozen nations.

Court throws out Russian gaming scandal claims

Kevin Murphy, November 2, 2011, Domain Registrars

Russian registrar RU-Center has won its appeal against a $7.5 million government fine, following claims that it gamed the launch of .РФ, registering tens of thousands of names to itself.
The Moscow Arbitration Court yesterday reversed the decision of the Federal Antimonoply Service, according to a statement from RU-Center, the .РФ registry and local media reports.
The dispute centers on the launch of the Cyrillic-script ccTLD last November, which saw over 200,000 registrations in the first six hours and half a million domains registered in the first few weeks.
RU-Center was quickly hit by claims that it had used its access to the registry, ccTLD Coordination Center, to register over 65,000 premium names to itself in order to auction them to users.
It later emerged that some of the Coordination Center’s launch policy-setters had ownership interests in RU-Center either directly or through family members.
In challenging the FAS ruling, RU-Center said that it only registered domains in its own name, via other registrars, because it had taken over 120,000 pre-orders from customers but was limited to filing 4,800 registrations per hour by the registry.
It also said that the domains remained in its own name because registry rules prohibited transfers during the first year of registration. The transfers will be effective November 11, it said.

Some IDNs fly, while some fail

Kevin Murphy, August 14, 2011, Domain Registries

Russia may have witnessed a domain name boom this year with the launch of .РФ last November, but other internationalized domain names are proving far from popular.
Jordan’s الاردن. country-code top-level domain has taken only about 150 registrations since its launch last October, according to a report in the Jordan Times.
The poor showing has been attributed to both a lack of awareness and a lack of demand. The article quotes Mahmoud Al Kurdi, sales and marketing manager at regional presence provider Virtuport:

If a person does not even know how to type the address of a certain website in English letters, he or she can type in Arabic letters on Google and search for the website. I see no point in typing address in Arabic letters. It is not convenient.

The sentiments are echoed in the article by other local experts, while the registry, the National Information Technology Centre, said it is planning a marketing campaign to drum up interest.
There could be other reasons for slack adoption – Jordan’s IDNs costs $140 for the first two years and $35 per year thereafter. There are also strict rules governing who can register.
Meanwhile in Russia, .РФ had taken 855,751 registrations by June 30, according to the registry’s first-half 2011 report, following its scandal-tinged launch eight months earlier.
Russia is of course substantially larger than Jordan – which has a population smaller than that of London – with ten times as many internet users as Jordan has citizens.

Will a Russian domain sell for more than Sex.com?

Kevin Murphy, November 25, 2010, Domain Sales

The scandal-hit Russian domain name market may yet produce some of the most expensive domain name sales of all time. Premium .рф generics are already attracting eight-figure bids.
Bids of $10 million have apparently been placed on at least two domains, квартиры.рф and бетон.рф (apartments.rf and concrete.rf), in the controversial quasi-landrush auction managed by RU-Center, the largest Russian registrar.
IDNblog.com is reporting the apartments.rf asking price, and a reader was kind enough to send me a screenshot of the concrete.rf auction.
If these bids are for real, and these auctions were to close, they would immediately occupy the number two and three slots on the league table of all-time biggest-ticket domain sales
Before sex.com sold for $13 million, DNJournal’s top twenty list had fund.com in the top spot, at $9,999,950, followed by porn.com at $9,500,000 and diamond.com at $7,500,000.
The RU-Center auctions may not close, however.
As I reported yesterday, the registrar and five others are being investigated on antitrust grounds by Russian competition authorities, after allegedly registering tens of thousands of domains to themselves.
The auctions are currently frozen and the .рф registry, Coordination Center for ccTLD, has made noises about applying “sanctions” to the registrars that could include de-accreditation.
RU-Center, which confusingly does business at nic.ru, has defended its position in at least two articles here and here (in Russian, naturally).
As far as I can tell, none of these auctions will close until the registrar and the registry resolve their differences and/or the Russian government probe concludes.
However, it’s pretty obvious that the demand for Cyrillic generic IDNs is enormous in Russia, and could easily challenge .com on the big-sale league tables.