The Domain Name Industry runs on a system of enforced contract agreements backed by the global authority. 

The Internet Corporation for Assigned Names and Numbers Enforcement Department has today released a third formal enforcement notice to an anonymized bulletproof registrar. Bulletproof registrars have long been able to abuse jurisdictional limitations and slow response times to actively endanger the rest of the internet by servicing bad actor clientele. By refusing to respond to bot sent abuse complaints and deliberately failing to keep validated contacts, bulletproof registrars knowingly spread risk across the Domain Name industry. Today’s news bulletin changes that paradigm, making it clear that ICANN will not tolerate rogue gatekeepers threatening the stability of the internet at large.


| ICANN CONTRACT ENFORCEMENT PROCESS |
| NOTICE OF DEFAULT |
| [Observed Abuse] => [Contractual Warning Issued] => [Allow 15 Day Response] |
|Status: Failure to curb Phishing /Invalid Whois Contact |
|———————————————————————|
| NOTICE OF CANCELLATION |
| [Failure to Comply] => [Incoming Registrar Block] |
| Status: Pending Strike | Incoming Suspension |
|———————————————————————|
| DE-CREDENTIALIZATION |
| [Contract Nullified] => [Forced Mass Migration] |
| Status: Final Strike | Totalvectomy Performed |
|———————————————————————|


With this new Enforcement Strike, ICANN is showing it has contractual tools at its disposal to directly combat this growing problem. By accepting an ICANN license to sell domain names directly to consumers, Registrars sign a legal document promising to police abuse and uphold verified contact information. When a registrar chooses to openly profit from bad actors, cyber squatters, and known malware distributors, there are steps that ICANN can take. For the future of the domain industry, this is a hugely positive development. Bullteproof bad actors serve as poison togoos that drag the reputation of every other registrar down with them. By refusing service to these known bad actors, ICANN ensures that respectable businesses won’t have their localized reputation affected by malicious actors riding on the same registry IP blocks.


A network engineer working with Fortune 1000 digital assets recently explained to me how bulletproof domains can affect brand managers everywhere. While working on threat intelligence integration for his company’s networks, his team began to realize that when you point corporate network filters at threat feeds, sometimes entire registrars get blocked because they reach some abuse density threshold. This means that simply by choosing a shady registrar your company can risk your business emails and website being blocked by corporations around the world. With that in mind, ICANN working to cleanup the industry before a registrar reaches this critically dense point helps legitimate businesses. By swinging at bulletproof registrars first, ICANN is cleansing from the top down.


False WHOIS Data & Ignoring Abuse Complaints: Breaking Down the Violations


Within the Official Ceasing Order document ICANN has made public, are two primary compliance failures that paint a picture of wanton negligence. First and foremost, the accused registrar failed to validatate Whois contact data for incoming domain purchases. Every domain purchased through an ICANN registered registrar is required to undergo a validation process as outlined in the ICANN Whois Accuracy Program Guide. Basically, legitimate registrars are responsible for double checking that every incoming registrant has a valid and verifiable email address, phone number, and physical postal address. This unnamed bulletproof registry wilfully chose not to validate these records, allowing bots to automatically register hundreds (if not thousands) of temporary websites using completely fake information.


Not only did the registrar not bother to validate incoming information, but they also didn’t bother acting on abuse complaints either. Publicly available ICANN Policies state that Registrars are required to “Maintain a publicly available point of contact through which you can receive notices of alleged abuse.” Once ICANN or another secured agency sends a registrar a bulletproof website is hosting phishing emails, the registrar is supposed to take action. Instead, the targeted company consistently ignored these notices. It’s likely they didn’t want to upset their customers.


| WHOIS ACCURACY CHECK | CLEAN REGISTRAR |BULLETPROOF REGISTRAR |
|-------------------------------|----------------------------|----------------------------|
| Validated Every Domain |True | False |
| Ignored Abuse Notices |False |True |
|———————————————————————|
|WHOIS AND ABUSE POLICIES |
|———————————————————————|
|API & Domain Creation Policy |Strict & Secure EPP Validation|Loosely Audited |
|Registrar Background |Publicly Traded Corporation |Private Ownership |
+———————————————————————+


The worst case scenario for a domain name registrar is failure to observe these baseline regulations. When a registrar positions themselves as a entity that will look the other way when foreign governments send warnings, they are essentially begging to be placed on strike. The domain name ecosystem works because 99% of registars realize that censoring certain phrases or poor api security hurts the longterm brand value of their business. When a registrar veers too far outside of these community guidelines, ICANN must take action with its rarely used big stick to ensure the rest of the industry can operate safely.


A Detailed Look At ICANN’s Registrar Strike Process


After ICANN sends out a final warning, the registrar has exactly 15 days to clean up their act or face de-credenticalization. This grace period is when the registrar must validate all of their Whois information AND terminate all domains flagged for abuse. If they cannot prove to ICANN that they have done both, their contract with ICANN will be terminated.


What happens next is where ICANN shows just how big of a stick it is willing to use. In order to prevent wholesale loss of websites, ICANN has enforcement rules in place that force all registered domains to transfer to another, “safe” registrar. While this is great for unintentional customers that may have registered domains through a_bulletproof registrar_, domain owners that knowingly use bulletproof registrar WILL experience some downtime. For a period of 15 days, no changes can be made to any domains held by the rogue registrar. No transfers, renewals, or DNS modifications can occur.


/<-YOU LOSE DNS CONTROL FOR 15 DAYS->\

|———————————————————————|
|[IRRECUBLE DEFAULT NOTIFICATION SENT] |

│ ▼ (Registrar is cut off from the rest of the world) |
│ [LOCKED CHALLENGE API:STOPPED] |

▼forced_ICANN redirect⬇️
[Bulk Migration to Secure Registrar]
|———————————————————————|
|[Clean Registrar Takes Back Office] |


After the digital mass vaccination is complete, normal life will resume for you, but the registrar you were using will be gone. This monopoly on shutdowns serves as a massive deterrent for would be negligence. You do not want to be the registrar that ICANN has to cut off from the rest of ecosystem.


Don’t get caught with yourRegistrar’s pants down. Make sure all of your domain names are registered through conforming, EPDC registrars. Sticking with big brands isn’t always enough though, do your diligence and make sure that the registrar you’re working with doesn’t slip under the radar.


How To Identify Rogue Registrars & Safely Move Your Domains


So how can you, a business owner, avoid registrar disruptions in your business? First you should know that if you have ever purchased a domain name from a registrar that is not owned by a publicly traded company, you are at risk. Domain name registrars are supposed to adhere to a strict set of ICANN rules and regulations. If a registrar does not openly publish their creation policy, or if they allow you to register a domain without verifying your information, you should move those domains.


+———————————————————————+
| CHECK YOUR REGISTRAR! |
|———————————————————————|
| INSPECT REGISTRAR | SAFE REGISTRAR | ROGUE REGISTRAR |
|———————————————————————|
| Reg Locks | 2FA Enabled | Username / Password only |
|History of ICANN Notices | Zero Previous Notices | Prior Actions Against Them |
|API Standards & Support | Up to Date EPP Programing Languages |Legacy APIs Enabled |
|Ownership Background |Clean Public Business Records | Unknown Ownership |
+———————————————————————+


Upon finding domains in a position of risk, immediately outreach to your registrar and request that they transfer out of their system. To move your domains out you will need to remove any registry locks and obtain a unique EPP push authorization string. If your registrar fights you on the transfer, you can appeal to ICANN to have your domains released to you.


By taking these precautions, you can ensure that the domains you paid hard money for are not suddenly inaccessible because of some official.wrap someone else is running. Moving your domains also allows you to set up modern security infrastructure like hardware 2FA reg locks and DNSSEC. These tools add a level of security to your domains that prevent malicious third parties from ever taking control of your digital property. When major tech companies scan your domains and see these protections are in place, you become a high value account too. That means less uptime issues and connectivity problems down the road.


Quickly Ensuring your Domain Portfolio is ICANN Compliant


So how can you ensure that all of your domain names are safe from an ICANN surprise)? Well first you’ll want to make a list of all your domain names. While you’re at it, make sure you specifically mark which registrar each domain is registered through. Once you have identified domain names that are hosted through suspicious registrars, you will then want to push those domains out. Mass transfer out of rogue registrars can be done by first removing any reg locks and generating an EPP push authorization command. Once pushed to a secure registrar, make sure you place reg locks and enable DNSSC on all of your domains.


| SAFETY CERTIFICATION FOR DOMAIN NAMES |
|———————————————————————|
| Step 1: Pull/create list of ALL domain names & which Registrar |
| they are registered through. |
| Step 2: Identify domains that are not registered through ICANN |
| compliant Registrars. |
| Step 3: Mass push domains to a ICANN Registered Registrar. |
| Step 4: Set Reg Locks and enable DNSSEC. |


Ensure that every single domain name you own has valid, fully verifiable contact information tied to the domain. This cannot be stressed enough, if your contact information is fully validated everybody in the industry can tell. When ICANN comes around to check if your domains are legit, they will see that your contact information is in perfect shape and assume your domains are legitimate. Maintaining a clean inbox helps as well.


Stay vigilant my friends, and monitor websites like nTLDStats to ensure you are never taken by surprise by changes in the ICANN regulatory landscape.


Final Thoughts

Regulatory actions like this are great news for brand managers and domain investors everywhere. Abusive registrars were once considered unfallable, but with ICANNs big bad stick we can sleep a little easier tonight.