Home / Blogs

GAC Communiqués and Community Activity on DNS Abuse

This blog post and the associated report aim to provide an overview of DNS Abuse1 related issues the Governmental Advisory Committee (GAC), part of the ICANN multi-stakeholder model, has identified. We also summarize the relevant community activity taking place to address these areas of interest and highlight remaining gaps.

From 2016 to June 2023, the GAC referenced four primary categories of activity related to DNS Abuse: (1) contractual obligations, (2) enhanced reporting, (3) work on compromised and malicious registrations, and (4) measurement. Often, these issues have also been raised in additional ICANN forums, including The Security and Stability Advisory Committee (SSAC) and The Generic Names Supporting Organization (GNSO).

Community responses have included the development of tools, educational resources, research projects, and measurement initiatives. These responses collectively work to increase the global Internet community’s understanding of the DNS Abuse ecosystem and what mitigation and disruption practices best contribute to a safer online environment.

In addition, contractual obligations related to DNS Abuse have been adopted by the ICANN Board. As this process continues, the community would benefit from increased awareness as to the tools and resources that exist to assist them with their new contractual requirements.

Several initiatives have been introduced to help reporters send reports to the correct part of the Internet ecosystem, but more work is needed to ensure reports are actionable and sufficiently evidenced and to raise awareness of the available tools.

Various projects have improved our ability to distinguish between compromised and maliciously registered domain names; ensuring these are appropriately mitigated and prevented requires a full public policy approach beyond the ICANN community and needs to include the wider Internet ecosystem.

There is considerable activity taking place to measure DNS Abuse, which is adding to our overall understanding and providing the opportunity to benchmark. The next step will be to improve the accuracy—by reducing false positives, managing edge cases, and providing analysis on specific issues of interest (such as aging domains or incentive schemes).

This blog post and the associated report were prepared by the DNS Abuse Institute (Institute). The Institute focuses on initiatives to help reduce DNS Abuse by fostering collaboration, creating best practices, and developing open, industry-shared solutions provided at no cost. The Institute was created in 2021 by Public Interest Registry, the registry operator for the .ORG top-level domain, in furtherance of its non-profit mission.

The DNS Abuse Institute remains committed to further ICANN community work on this issue and will assist in whatever ways are appropriate. The Institute runs two main initiatives for the community:

NetBeacon, the Institute’s centralized abuse reporting system, intends to address the problems of complexity and quality when it comes to reporting DNS Abuse, specifically phishing, malware, botnets, and spam, to registrars and registries. NetBeacon attempts to eliminate barriers to reporting online abuse, such as a lack of technical knowledge, confusion on how to report abuse, and the inability to navigate the DNS ecosystem. NetBeacon makes the reporting process more productive by standardizing and enriching reports, benefitting abuse reporters, registrars, and registries.

DNSAI Compass (“Compass”) measures the observed prevalence and persistence of phishing and malware in unique domain names across the DNS, both in terms of aggregate trends and on a TLD/registrar level. Compass provides aggregate data on observed mitigation, mitigation time, and registration type (malicious or compromised). Individualized Dashboards are also available, free of charge, to help domain registrars and registries to better understand and combat DNS Abuse.

  1. DNS Abuse is defined as being composed of five broad categories of harmful activity insofar as they intersect with the DNS: malware, botnets, phishing, pharming, and spam (when it serves as a delivery mechanism for the other forms of DNS Abuse 

By Rowena Schoo, Director of Programs and Policy at The DNS Abuse Institute

Filed Under


Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

I make a point of reading CircleID. There is no getting around the utility of knowing what thoughtful people are thinking and saying about our industry.

Co-designer of the TCP/IP Protocols & the Architecture of the Internet



IPv4 Markets

Sponsored byIPv4.Global

Domain Names

Sponsored byVerisign


Sponsored byVerisign

New TLDs

Sponsored byRadix

Threat Intelligence

Sponsored byWhoisXML API

Brand Protection

Sponsored byCSC


Sponsored byDNIB.com