Latest news of the domain name industry

Recent Posts

VeriSign’s upcoming battle for the Chinese .com

Kevin Murphy, February 16, 2011, Domain Registries

Could VeriSign be about to face off against China for control of the Chinese version of .com? That’s an intriguing possibility that was raised during the .nxt conference last week.
Almost as an aside, auDA chief Chris Disspain mentioned during a session that he believes there are moves afoot in China to apply to ICANN for “company”, “network” and “organization” in Chinese characters. In other words, .com, .net and .org.
I’ve been unable to find an official announcement of any such Chinese application, but I’m reliably informed that Noises Have Been Made.
VeriSign has for several quarters been open about its plans to apply for IDN equivalents of its two flagship TLDs, and PIR’s new CEO Brian Cute recently told me he wants to do the same for .org.
While neither company has specified which scripts they’re looking at, Chinese is a no-brainer. As of this week, the nation is the world’s second-largest economy, and easily its most populous.
Since we’re already speculating, let’s speculate some more: who would win the Chinese .com under ICANN’s application rules, VeriSign or China?
If the two strings were close enough to wind up in a contention set, could VeriSign claim intellectual property rights, on the basis of its .com business? It seems like a stretch.
Could China leapfrog to the end of the process with a community application and a demand for a Community Priority Evaluation?
That also seems like a stretch. It’s not impossible – there’s arguably a “community” of companies registered with the Chinese government – but such a move would likely stink of gaming.
Is there a technical stability argument to be made? Is 公司. (which Google tells me means “company” in Chinese) confusingly similar to .com?
If these TLDs went to auction, one thing is certain: there are few potential applicants with deeper pockets than VeriSign, but China is one of them.
UPDATE: VeriSign’s Pat Kane was good enough to post a lengthy explanation of the company’s IDN strategy in the comments.

VeriSign scores big win in .com pricing lawsuit

Kevin Murphy, February 14, 2011, Domain Registries

VeriSign has successfully had an antitrust lawsuit, which claims the company has been raising .com domain name prices anti-competitively, dismissed by a California court.
While it’s encouraging news if you’re a VeriSign shareholder, the Coalition for ICANN Transparency, which filed the suit, will be allowed to amend and re-file its complaint.
The basis for the dismissal (pdf) goes to the central irony of CFIT – the fact that, despite its noble name, it’s not itself a particularly transparent organization.
CFIT was set up in 2005 in order to sue ICANN and VeriSign over their deal that gave VeriSign the right to raise the price of .com and .net domains, and to keep its registry contracts on favorable terms.
While it was cagey about who was backing the organization, those of us who attended the ICANN meeting in Vancouver that year knew from the off it was primarily a front for Momentous.ca, owner of Pool.com and other domainer services.
In dismissing the case last Friday, Judge Ronald Whyte decided that CFIT’s membership is vague enough to raise a question over its standing to sue on antitrust grounds. He wrote:

By failing to identify its purported members, CFIT has made it impossible to determine whether the members are participants in the alleged relevant markets, or whether they have suffered antitrust injury. Because the [Third Amended Complaint] identifies no members of CFIT, it must be dismissed.

While CFIT had disclosed some time ago Pool.com’s involvement, it recently tried to add uber-domainer Frank Schilling’s Name Administration Inc and iRegistry Corp to the list of its financial supporters.
But Whyte was not convinced that the two companies were CFIT “members” with standing to sue.
Whyte decided that CFIT’s complaint, “fatally fails to allege facts showing that iRegistry or Name Administration were financial supporters or members at the time the complaint was filed”.
He also denied CFIT’s demand for a jury trial.
CFIT wants VeriSign to return all the excess profits it has made on .com registrations since it started raising its prices above $6.
If CFIT were to win, it would severely curtail VeriSign’s ability to grow its registry business, and could lead to billions being wiped off its accounts.
The organization has been given leave to file a fourth amended complaint, so it’s not over yet.

Incumbents get the nod for new TLD apps

Kevin Murphy, December 27, 2010, Domain Registries

Domain name registries such as Neustar, VeriSign and Afilias will be able to become registrars under ICANN’s new top-level domains program, ICANN has confirmed.
In November, ICANN’s board voted to allow new TLD registries to also own registrars, so they will be able to sell domains in their TLD direct to registrants, changing a decade-long stance.
Late last week, in reply (pdf) to a request for clarification from Neustar policy veep Jeff Neuman, new gTLD program architect Kurt Pritz wrote:

if and when ICANN launches the new gTLD program, Neustar will be entitled to serve as both a registry and registrar for new gTLDs subject to any conditions that may be necessary and appropriate to address the particular circumstances of the existing .BIZ registry agreement, and subject to any limitations and restrictions set forth in the final Applicant Guidebook.

That doesn’t appear to say anything unexpected. ICANN had already made it pretty clear that the new vertical integration rules would be extended to incumbent gTLD registries in due course.
(However, you may like to note Pritz’s use of the words “if and when”, if you think that’s important.)
Neustar’s registry agreement currently forbids it not only from acting as a .biz registrar, but also from acquiring control of greater than 15% of any ICANN-accredited registrar (whether or not its sells .biz domains).
That part of the contract will presumably need to be changed before Neustar applies for official registrar accreditation or attempts to acquire a large stake in an existing registrar.
VeriSign and Afilias, the other two big incumbent gTLD registries, have similar clauses in their contracts.

VeriSign takes over .gov

Kevin Murphy, December 22, 2010, Domain Tech

VeriSign has taken over registry functions at .gov, the top-level domain for the US government.
IANA records show that VeriSign Global Registry Services was named technical contact for .gov possibly as recently as this Monday.
The TLD is still administratively delegated to the US General Services Administration. Google’s cache of the IANA site shows the GSA was the technical contact for .gov as recently as October 29.
VeriSign certainly kept this contract win quiet.
At least, the first I heard about it was tonight, in an email VeriSign sent to the dns-ops mailing list, asking DNS administrators to reconfigure their DNSSEC set-up to reflect the change.

A KSK [Key Signing Key] roll for the .gov zone will occur at the end of January, 2011. This key change is necessitated by a registry operator transition: VeriSign has been selected by the U.S. General Services Administration (GSA) to operate the domain name registry for .gov.

The email expresses the urgency of making the changes, which are apparently needed in part because .gov was signed with DNSSEC before the root zone was signed, and some resolvers may be configured to use .gov as a “trust anchor” instead of the root.
The .gov TLD is reserved for the exclusive use of US federal and state government departments and agencies.
It’s certainly a prestige contract for VeriSign.
This appears to be the GSA page awarding the contract to VeriSign, in September, following an RFP. It’s valued at $3,325,000.

Go Daddy plans Premium DNS service

Kevin Murphy, December 13, 2010, Domain Tech

Go Daddy is to launch a Premium DNS service that will include managed DNSSEC security, the company revealed during sessions at the ICANN meeting in Cartagena last week.
Go Daddy customers can currently get a brief overview of the forthcoming service by logging into their domain manager and finding the Premium DNS “Coming Soon” link, or looking here.
During a session on DNSSEC in Colombia last week, Go Daddy’s James Bladel laid out more detail on the service in a presentation (PDF) which contains screenshots of the interface.
The company started supporting DNSSEC for free on certain TLDs in the summer – it currently supports .net, .biz, .eu, org and .us – but it requires users to manually generate and manage cryptographic keys.
That’s beyond the ken of most domain name owners, so the registrar is adding a premium “set it and forget it” service which will see Go Daddy manage the complexities of DNSSEC.
Bladel said of the service:

it’s as simple as having a DNSSEC on/off switch. So customers who have no particular interest in the behind- the-scenes technology of DNSSEC can simply flip that switch and then enjoy the benefits of a secured domain name.

The DNSSEC standard helps prevent domains being hijacked through cache poisoning attacks by signing each domain’s zone with a validatable cryptographic key. The technology will be available for .com domains early next year.
It’s by no means free or easy for registrars to implement, and there’s been little demand for the technology among registrants, so I’ve been wondering how registrars planned to monetize it.
Now we know how Go Daddy at least plans to do so – the Premium DNS service will have other benefits beyond DNSSEC, which could spur adoption through osmosis.
The service will also include DNS up-time guarantees of 99.999%, vanity name servers, log tracking, and several other perks.
The company has not officially announced the service to customers yet, so I expect we’ll find out more details in due course.

VeriSign launches free cloud domain security service

Kevin Murphy, December 2, 2010, Domain Tech

VeriSign is to offer registrars a hosted DNSSEC signing service that will be free for names in .com and the company’s other top-level domains.
The inventively named VeriSign DNSSEC Signing Service offloads the tasks associated with managing signed domains and is being offered for an “evaluation period” that runs until the end of 2011.
DNSSEC is an extension to DNS that allows domains to be cryptographically signed and validated. It was designed to prevent cache poisoning attacks such as the Kaminsky Bug.
It’s also quite complex, requiring ongoing secure key management and rollover, so I expect the VeriSign service, and competing services, will be quite popular among registrars reluctant to plough money into the technology.
While some gTLDs, including .org, and dozens of ccTLDs, are already DNSSEC-enabled, VeriSign doesn’t plan on bringing the technology online in .com and .net until early next year.
The ultimate industry plan is for all domain names to use DNSSEC before too many years.
One question I’ve never been entirely clear on was whether the added costs of implementing DNSSEC would translate into premium-priced services or price increases at the registrar checkout.
A VeriSign spokesperson told me:

The evaluation period is free for VeriSign-managed TLDs and other TLDs. After that period, the VeriSign-managed TLDs will remain free, but other TLDs will have $2 per zone annual fee.

In other words, registrars will not have to pay to sign their customers’ .com, .net, .tv etc domains, but they will have to pay if they choose to use the VeriSign service to sign domains in .biz, .info or any other TLD.

Domain universe breaks through 200 million

Kevin Murphy, November 29, 2010, Domain Registries

VeriSign is reporting that the number of registered domain names worldwide broke through the 200 million mark in the third quarter.
There were 202 million domains at the end of September, according to the company’s Domain Name Industry Brief, which was published today.
Over half of those domains, 103 million names in total, can be found in the .com and .net namespaces that VeriSign manages.
In a not-so-subtle plug for VeriSign’s 2011 growth strategy, the company also declared that the next ten years will be “The Decade of the International Internet”.

In the coming decade, the Internet will continue to become a ubiquitous, multi-cultural tool, fueled in part by the adoption of IDNs. By enabling online content and businesses to be represented in local scripts and languages, IDNs help the Internet to expand the power of technology to regions and cultures, and connect the world in new ways. Over the past year, several new IDNs for ccTLDs have been approved. The next step will be approval of IDNs for generic Top Level Domains (gTLDs).

The company, of course, plans to apply to ICANN to operate IDN versions of .com and .net, although it has not to date discussed openly which languages or strings it wants.
The VeriSign report also says that ccTLD registrations grew 2.4%, compared to the same quarter last year, to 79.2 million domains.
I expect this growth would have been tempered had it not been for the relaunch of .co, which occurred during the quarter, but it does not merit a mention in the report.
The report also reveals that .info has overtaken .cn in the biggest-TLD charts, although this is due primarily to the plummeting number of registrations in the Chinese ccTLD.

ICANN had no role in seizing torrent domains

Kevin Murphy, November 29, 2010, Domain Policy

Okay, this is getting a bit silly now.
As you may have read, the US government “seized” a bunch of domain names that were hosting sites allegedly involved in piracy and counterfeit goods over the Thanksgiving weekend.
Over 80 domains, all of them in the .com namespace, had their DNS settings reconfigured to point them to a scary-looking notice from the Department of Homeland Security’s ICE division.
Somehow, in several reports over the last few days, this has been pinned on ICANN, and now some pro-piracy advocates are talking about setting up alternate DNS roots as a result.
Claims that ICANN colluded with the DHS on the seizures seem to have first appeared in TorrentFreak, which broke the news on Friday.
The site quoted the owner of torrent-finder.com:

“I firstly had DNS downtime. While I was contacting GoDaddy I noticed the DNS had changed. Godaddy had no idea what was going on and until now they do not understand the situation and they say it was totally from ICANN.”

For anyone involved in the domain name industry and the ICANN community, this allegation screams bogosity, but just to be on the safe side I checked with ICANN.
A spokesperson told me he’s checked with ICANN’s legal, security and compliance departments and they all had this to say:

ICANN had nothing to do with the ICE investigation… nobody knew anything about this and did not take part in the investigation.

All of the seized domains were .coms, and obviously ICANN has no technical authority or control over second-level .com domains. It’s not in the position to do what the reports allege.
If anybody were to ask ICANN to yank a domain, all it could do would be to politely forward the request to the registrar (in the case of torrent-finder.com, apparently Go Daddy) or the registry operator, which in the case of .com is of course VeriSign.
It would make more sense, save more time, and be less likely to create an international political incident, for the DHS to simply go directly to Go Daddy or VeriSign.
Both are US companies, and the DHS did have legal warrants, after all.
That’s almost certainly what happened here. I have requests for comment in with both companies and will provide updates when I have more clarity.
In the meantime, I suggest that any would-be pirates might be better served by switching their web sites to non-US domains, rather than trying to build an alternate root system from the ground up.
UPDATE: Ben Butler, Go Daddy’s director of network abuse, has just provided me with the following statement, via a spokesperson:

It appears the domain names were locked directly by VeriSign. Go Daddy has not received any law enforcement inquiries or court orders concerning the suspension of the domains in question.
Go Daddy has not been contacted by ICE or DHS on the domain names in question.

The statement goes on to say that Go Daddy believes that it should be the registrar’s responsibility to handle such takedown notices.

With regard to the registry taking action against the domain names in question, Go Daddy believes the proper process lies with the registrar and not the registry. This gives the registrar the ability to communicate with their customer about what has happened and why. When the registry acts, Go Daddy is unable to provide any information to our customers regarding the seizure of their domain names.
Go Daddy routinely cooperates with government and law enforcement officials to enforce and comply with the law.

I’ll post any statement I receive from VeriSign when I have it.
UPDATE: VeriSign sent this statement:

VeriSign received sealed court orders directing certain actions to be taken with respect to specific domain names, and took appropriate actions. Because the orders are sealed, further questions should be directed to the U.S. Department of Homeland Security.

ICANN drops the bomb – registries can buy registrars

Kevin Murphy, November 10, 2010, Domain Registries

ICANN has just authorized the biggest shake-up of the domain name industry in a decade, lifting all the major cross-ownership restrictions on registrars and registries.
A surprise resolution passed on Friday at the ICANN board’s retreat could enable registries such as VeriSign to acquire registrars such as Go Daddy, and vice-versa.
The new rules will also allow registrars to apply for and run new top-level domains and, subject to additional conditions, may enable existing registries to eventually start selling direct to end users, potentially bypassing the registrar channel.
The implications of these changes could be enormous, and I expect they could be challenged by affected parties.
The board resolved that ICANN “will not restrict cross-ownership between registries and registrars”, subject to certain yet-to-be written Code of Conduct for preventing abuse.
These looser ownership restrictions will be included in the new TLD Applicant Guidebook. Existing registries will be able to transition to the new rules over time through contract changes.
ICANN will develop mechanisms for enforcing anti-abuse rules through contractual compliance programs, and will have the ability to refer cross-ownership deals to competition authorities.

These provisions may be enhanced by additional enforcement mechanisms such as the use of self-auditing requirements, and the use of graduated sanctions up to and including contractual termination and punitive damages.

The decision appears to have been made partly on the grounds that while almost all existing registry contracts include strict cross-ownership restrictions, it has never been a matter of formal policy.
A vertical integration working group which set out to create a bottom-up consensus policy earlier this year managed to find only deadlock.
ICANN chairman Peter Dengate Thrush said:

In the absence of existing policy or new bottom-up policy recommendations, the Board saw no rationale for placing restrictions on cross-ownership. Any possible abuses can be better addressed by properly targeted mechanisms. Co-ownership rules are not an optimal technique in this area.

Most members of the VI working group broadly favored some level of cross-ownership restriction, such as a 15% cap, while a smaller number favored the “free trade” position that ICANN seems to have gone for.
The companies campaigning hardest against cross-ownership being permitted were arguably Afilias and Go Daddy, though the likes of NeuStar and VeriSign also favored some restrictions.
Opponents of integrating registry and registrar functions argued that giving registrars access to registry data would harm consumers; others countered that this was best addressed through compliance programs rather than ownership caps.
The big winners from this announcement are the start-up new TLD registries, which will not be forced to work exclusively within the existing registrar channel in order to sell their domains.

VeriSign to deploy DNSSEC in .com next March

Kevin Murphy, October 29, 2010, Domain Tech

VeriSign is to start rolling out the DNSSEC security protocol in .net today, and will sign .com next March, the company said today.
In an email to the dns-ops mailing list, VeriSign vice president Matt Larson said that .net will get a “deliberately unvalidatable zone”, which uses unusable dummy keys for testing purposes, today.
That test is set to end on December 9, when .net will become fully DNSSEC-compatible.
The .com TLD will get its own unvalidatable zone in March, but registrars will be able to start submitting cryptographic keys for the domains they manage from February.
The .com zone will be validatable later in March.
The DNSSEC standard allows resolvers to confirm that DNS traffic has not been tampered with, reducing the risk of attacks such as cache poisoning.
Signing .com is viewed as the last major registry-level hurdle to jump before adoption kicks off more widely. The root zone was signed in July and a few dozen other TLDs, such as .org, are already signed.