|
||
Public comments on an ICANN proposal to require registrars to investigate domains associated with known DNS abuse are converging around a central question: how far an investigation should extend before an association becomes too weak to justify action against another domain.
The Generic Names Supporting Organization’s DNS Abuse Mitigation PDP 1 is considering “Associated Domain Checks,” or ADCs. Under the initial report now open for public comment, a registrar presented with actionable evidence that one domain is engaged in DNS abuse would be required to investigate other domains associated with the customer account or registrant. The report contains eight preliminary recommendations and five implementation-guidance items.
The comments filed so far broadly support the concept but repeatedly emphasize evidentiary limits. Fatima Cambronero, whose individual submission was filed September 21, argues that evidence sufficient to associate another domain with a registrant or campaign should trigger investigation, not establish that the second domain itself is abusive. She distinguishes among evidence that triggers the ADC, indicators connecting additional domains to the investigation, and evidence supporting mitigation against a particular associated domain.
That distinction matters because domains can share registration information, infrastructure, naming patterns or other characteristics without sharing malicious control. Earlier commenters similarly called for safeguards against treating individual shared attributes as conclusive evidence. Karen Yousefi warned that incorrect associations could disrupt legitimate domains, while Laura Ndubi argued for objective criteria, proportionality and mechanisms for registrants to challenge adverse actions.
A September 22 submission from ICANN’s Internet Service Providers and Connectivity Providers Constituency supports the recommendations as a package. The ISPCP favors flexible rather than rigid criteria for determining association, but says weaker or circumstantial indicators should not be determinative by themselves. It also calls for future measurements of false positives, appeals or reinstatements when ICANN evaluates whether the policy is operating proportionately.
The proposed checks would move registrar obligations beyond responding only to the domain identified in an abuse report. That could make coordinated campaigns easier to investigate, particularly where an actor operates multiple domains, while increasing the importance of how registrars determine association and document their decisions.
The PDP also distinguishes maliciously registered domains from legitimate domains that have been compromised. Cambronero supported excluding compromised domains from the trigger for a broader ADC, arguing that a hacked domain should not by itself lead to scrutiny of other domains belonging to its registrant.
The consultation remains open through September 28 at 23:59 UTC. ICANN staff will then prepare a public-comment summary, and the working group is scheduled to begin reviewing the submissions at ICANN87 in Bali.
Sponsored byVerisign
Sponsored byRadix
Sponsored byIPv4.Global
Sponsored byDNIB.com
Sponsored byCSC
Sponsored byWhoisXML API
Sponsored byVerisign