Home / Blogs

The Reporting Gap: What Happens Between a DNS Abuse Complaint and a Takedown

A phishing site gets reported. Somewhere between that report and an actual takedown, most of the delay nobody talks about happens. Not because nobody is watching. Because the system watching it is buried under its own backlog, and the people generating the most reports have no visibility into any of it.

The Scale Nobody Can Ignore

Phishing volume keeps climbing, and it isn’t slowing down. APWG recorded 971,181 phishing attacks in Q1 2026, up 13.8 percent from the 853,244 recorded just the quarter before. That’s not a spike. It’s the continuation of a trend that has run through every quarter tracked, and it means the enforcement system isn’t dealing with a stable, known quantity of abuse. It’s chasing a moving target that grows faster than any single registrar’s abuse team can realistically keep pace with. Certain registrars show up disproportionately often in this data too. APWG has flagged NameSilo and NameCheap repeatedly as the registrars most frequently used by BEC scammers, which tells you concentration isn’t hypothetical. It’s measurable, and it’s been measurable for a while.

What ICANN’s Own Numbers Show

Between April 2024 and April 2026, ICANN Contractual Compliance opened close to 530 investigations tied to DNS Abuse mitigation requirements. It resolved more than 480 of them. About 66 percent ended with a registrar or registry actually acting on the domain, usually suspension. Another 8 percent led to disruption measures, the kind used on compromised sites rather than ones registered specifically to abuse. Add it up and roughly a quarter of investigations closed without the abuse actually being stopped.

The bigger number sits elsewhere. ICANN’s own investigations directly mitigated more than 25,000 abusive domains over that two-year window. Systemic fixes that some registrars put in place after being investigated reportedly cleaned up hundreds of thousands more. That second number should be the headline. Most abuse getting stopped isn’t stopped by a single complaint working through the system. It’s stopped because a registrar got caught once, faced consequences, and changed how it operates afterward. Enforcement, in other words, is working mostly as a deterrent for the registrars it actually reaches, not as a fast response mechanism for the individual victim filing a report today.

Where the Gap Actually Lives

That distance between individual complaints and systemic fixes is where India’s DNS abuse problem sits. A single fake job portal reported through a registrar’s abuse form doesn’t wait for ICANN’s enforcement cycle. It waits for whatever internal queue that registrar runs, if that registrar has a working abuse contact at all. Under Section 3.18 of the Registrar Accreditation Agreement, abuse contacts have to be visible on a registrar’s homepage, and forms can’t require a login before accepting a report. Those sound like small requirements. In practice, they’re often the first place enforcement breaks down, before a single complaint is even reviewed. A user who can’t find where to report abuse never generates a complaint ICANN or anyone else can act on. That failure never shows up in any dashboard, because it never became data in the first place.

The Timeline Nobody Agrees On

When registrars are responsive, industry estimates put phishing and malware takedowns at 24 to 72 hours. Uncooperative registrars stretch that to weeks. There’s a narrower rule that some coverage has flattened into a blanket “24 hour takedown policy,” but that’s not accurate. The 24-hour clock only starts when a law enforcement agency contacts a registrar directly with its own evidence. Everyone else, including the ordinary user reporting a scam that stole their data, works against a much vaguer timeline that depends entirely on which registrar they landed with, how well documented their complaint is, and whether that registrar happens to be one of the ones ICANN’s enforcement has already reached.

The Part the Data Can’t Fix

ICANN’s compliance team flags something worth sitting with: complaint volume keeps rising month over month, but the share of valid, actionable complaints stays low. Many reports fall outside ICANN’s scope entirely or don’t include enough evidence to act on. That’s not a failure of enforcement. It’s a failure of the reporting process being legible to the people actually harmed, mostly first time internet users who have no idea what “evidence” a registrar or ICANN expects them to supply. A screenshot, a timestamp, a header record, these are second nature to a security researcher. They are not second nature to someone who just found out a website they trusted wasn’t real.

What This Means Going Forward

None of this means the enforcement system doesn’t work. The data says it does, for the domains it reaches. What it doesn’t do is close the distance between when abuse actually starts and when someone with the authority to stop it hears about it in a form they can act on.

The real accountability gap isn’t in what happens once a complaint clears the bar. It’s in how many complaints never clear it, and how long the domains attached to them stay live while nobody’s clock is technically running yet. Fixing the enforcement mechanism matters. Fixing who can actually use it, and how quickly they can be heard, matters more.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By Garv Chauhan, Student at National Forensic Sciences University

Garv Chauhan is a cybersecurity student at the National Forensic Sciences University, New Delhi, researching Digital Public Infrastructure and digital rights across Asia through NetMission Asia. He is a Fellow of APNG18 and contributes to internet governance forums, including Youth IGF India, Youth IGF Asia, and ICANN.

Visit Page

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

New TLDs

Sponsored byRadix

DNS

Sponsored byDNIB.com

Cybersecurity

Sponsored byVerisign

Brand Protection

Sponsored byCSC

DNS Security

Sponsored byWhoisXML API

Domain Names

Sponsored byVerisign

IPv4 Markets

Sponsored byIPv4.Global