|
||
ICANN has terminated the accreditation agreements of two domain name registrars in successive days, including Estonia-based Trustname.com after repeated findings that it failed to respond promptly to phishing and other DNS abuse. A third registrar, Beijing Zihai Technology, received a breach notice this week but remains accredited.
Fewmoretaps OU, which operates as Trustname.com, will lose its ICANN accreditation effective September 11. ICANN issued the termination August 27, one day after delivering the registrar its fourth formal breach notice in 78 days.
Trustname’s unresolved violations centered on DNS abuse handling. ICANN said the registrar failed to take prompt and appropriate action to disrupt domain names used for DNS abuse and failed to investigate and respond appropriately to abuse reports, violating Sections 3.18.1 and 3.18.2 of its Registrar Accreditation Agreement.
The termination notice says Trustname acknowledged shortcomings in cases involving multiple phishing reports and introduced remediation measures beginning in February, with additional changes in June and July. ICANN concluded those measures had not proved effective. In one set of cases, domains were reportedly used to impersonate financial institutions and a government tax agency; Trustname ultimately mitigated the abuse weeks after the initial reports and acknowledged that its actions had not been prompt.
ICANN also cited a sharp rise in reported phishing among Trustname-sponsored domains. Data from ICANN’s Domain Metrica showed the median percentage of the registrar’s sponsored domains reported for phishing rising from about 0.7% in January to about 10% in August. ICANN said the increase continued while Trustname was implementing its remediation measures.
The termination follows formal Trustname breach notices dated June 10, June 26, July 16 and August 26. ICANN invoked both the registrar’s failure to cure earlier breaches and a provision allowing termination after at least three fundamental and material breaches within a 12-month period.
A second registrar, IPIP Inc., will lose its accreditation September 13. ICANN terminated IPIP’s agreement August 28 after the registrar failed to cure an August 5 breach. The unresolved violations included failure to operate a compliant Registration Data Access Protocol (RDAP) service covering its active gTLD domains, make required registration-data escrow deposits, pay accreditation fees, and publish a mechanism for requesting disclosure of non-public registration data.
ICANN’s records describe repeated unsuccessful attempts to obtain compliance from IPIP, including emails that went unanswered or were rejected and telephone calls that failed to reach several registrar contacts.
For both terminated registrars, ICANN said it will use its De-Accredited Registrar Transition Procedure to move the domain names they currently manage to qualified accredited registrars. The termination notices do not state how many domains will require transfer, and reliable current registration totals for the two registrars were not identified.
Meanwhile, ICANN issued Beijing Zihai Technology Co., Ltd., an accredited registrar based in China, a separate breach notice on August 26. That proceeding has not been escalated to termination.
Sponsored byCSC
Sponsored byVerisign
Sponsored byWhoisXML API
Sponsored byIPv4.Global
Sponsored byVerisign
Sponsored byDNIB.com
Sponsored byRadix