Summary

  • Published on 20 November 2018, AFPUB-2018-GEN-001-DRAFT02 proposed longer normative validation windows—15 days followed by another 15 days—and a six-month minimum periodic cadence, replacing Draft 1’s two-plus-three-business-day sequence and three-month cadence.
  • Draft 2 nevertheless retained an example using the old two-plus-three-day clock, while adding an immediate account-access restriction, cure through successful revalidation and a continuing path towards revocation-related procedures.
  • AFRINIC staff understood the restriction to disable every MyAFRINIC function except correction of the abuse mailbox, including online voting; the legal adviser judged that voting consequence disproportionate to an administrative contact-update failure.
  • A private registry can test whether an address receives a neutral message. It cannot turn that bookkeeping test, or dissatisfaction with an abuse response, into policing, punishment, confiscation or adjudication.

L3 — Thirty days on paper, five days in the example

Draft 2 opened with an institutional paradox. It gave an AFRINIC resource holder substantially more time to complete a contact validation and required periodic checking less often, but it also put a more immediate consequence between a failed check and the holder’s ordinary use of the member account. The change therefore cannot be described simply as either leniency or severity. On the calendar, the proposal relaxed the machinery. At the point of failure, it tightened the screw.

The baseline matters. Draft 1’s normative section 8.4 allowed no more than two business days for the initial validation. If that failed, escalation to the LIR opened a further period of no more than three business days. Section 8.5 required validation when an abuse contact was created or updated, at least once every three months, and whenever AFRINIC saw fit. Non-compliance then led to more exhaustive follow-up under the registry’s relevant policies and procedures, particularly those associated with revocation of resources.

Draft 1’s example followed the same basic rhythm: a code valid for two working days, followed by three additional business days before permanent invalidity and a repeat test.

Draft 2, published on 20 November 2018 under the identifier AFPUB-2018-GEN-001-DRAFT02, changed each of the important timing settings in its normative text. The initial validation period became no more than 15 days. A failed attempt escalated to the LIR for a further period of no more than 15 days. The minimum periodic frequency moved from at least every three months to at least every six months. Checks on creation or update remained, as did the power to validate whenever AFRINIC saw fit. Read only as a schedule, the redline offered a larger opportunity to notice a message, locate the responsible colleague and correct a stale record.

It also halved the stated minimum frequency of recurring tests.

The proposal added operating discretion to that relaxed schedule. AFRINIC could modify the initial and escalation periods if it explained its motivation to the community. It could similarly modify the periodic frequency and offered a slow-start rationale: there might be one validation during the first year, followed by a gradual increase. That clause acknowledged a practical truth. A registry-wide validation programme imposes work on both the registry and the people whose records it tests. Starting slowly could expose faulty email design, delivery problems or staffing demands before they affected the whole membership.

But discretion with an explanation is not the same thing as a stable rule. A member trying to organise compliance would need to know not merely what the text said on publication, but whether AFRINIC had altered the periods, how the explanation was communicated and which clock applied to a particular message. The proposal did not turn the 15-day windows into a deadline for fixing the underlying abuse reported by a third party. They governed the contact-validation steps.

Conflating the two would be consequential: validating receipt of a neutral code is an objective act, whereas investigating a complaint, deciding what happened and choosing a response can require evidence, legal judgement and operational context.

A redline that did not finish its own work

Draft 2’s most revealing drafting defect was not hidden in a marginal issue. Its normative rule said 15 days for the initial validation and another 15 days after escalation, yet its example procedure continued to give the validation code two working days and then three additional business days before permanent invalidity. The example had survived from Draft 1 even though the governing numbers above it had changed.

It is tempting to tidy this inconsistency for the reader by treating the normative wording as decisive and the example as obsolete. The evidence does not permit that editorial repair. Both clocks appeared in the preserved Draft 2 text. No source establishes which procedure staff would have programmed or applied if that draft had become operative. The proper conclusion is therefore narrower and more useful: Draft 2 proposed a 15-plus-15-day normative framework while carrying a contradictory two-plus-three-day example.

That is not a pedantic complaint. The difference is between a potential 30-day sequence and a five-business-day illustration. An operator could experience the shorter example as an abrupt failure while believing that the normative text promised much longer. Staff converting policy prose into email expiry settings, queue timers and portal states would face the same uncertainty. Legal advisers and counterparties could not confidently price the cure period. Even the meaning of “permanent invalidity” in the example would sit uneasily beside a normative escalation window that had not yet expired.

Ambiguity becomes more expensive when the result is merely a warning flag; it becomes materially more expensive when the next step disables account functions. A contact can fail for reasons that are neither refusal nor neglect: spam filtering, a temporary outage, staff turnover, a language mismatch, an automated-reporting pattern that triggers defences, or a handover that leaves the database update a day behind the organisational change. A clear clock does not eliminate those false positives, but it bounds the exposure. Competing clocks make an ordinary communication defect harder to distinguish from a formal default.

The date history needs the same discipline. The surviving material for Draft 1 contains an August/March discrepancy: the details or current-version listing identifies 12 August 2018, while the revision history says 12 March 2018. There is no basis for silently choosing one. Fortunately, the central event here does not depend on resolving it. The hard date is 20 November 2018, when Draft 2 was published. The relevant comparison is the text of Draft 1 against the text of Draft 2, not an invented certainty about the earlier page’s date.

More time, fewer routine checks, sharper first consequence

The timing redline makes sense only alongside the remedies redline. Draft 1 had already connected non-compliance to more exhaustive follow-up, especially procedures related to resource revocation. Draft 2 did not delete that harder tail. Instead, it inserted a new first consequence. On initial non-compliance, the account’s access to its resources would be blocked except for the ability to correct the abuse-c or abuse-mailbox information. Successful revalidation would restore access. More exhaustive follow-up under relevant policies and procedures, especially revocation-related ones, remained available afterwards.

This structure looks graduated: validate, escalate, restrict, cure, and only then consider further procedures. Graduation is normally preferable to an immediate jump to the harshest result. Yet the proportionality of a ladder depends on what its first rung removes. If the restriction truly covered only the defective contact field, it might be understood as a focused correction state. If “access to its resources” covered the whole member portal and functions unrelated to the mailbox, then an administrative test would change the holder’s wider institutional and operational position before any substantive abuse allegation had been adjudicated.

Draft 2’s escalation clause widened the question further. It addressed suspected gaming of validation as well as an incorrect response or lack of response to abuse cases. Its tools included revalidation, AFRINIC intermediation and possible use of relevant procedures. These are not all the same kind of event. Gaming an objective validation code concerns the integrity of the registry’s test. An “incorrect” response to an abuse case invites an evaluative decision about the adequacy of an operator’s conduct.

The first can be assessed against a technical protocol; the second may depend on disputed facts, law, contractual duties, security risks and the complainant’s expectations.

That distinction is the policy boundary. A mailbox check can answer: did this address receive the neutral message and return the required proof? It cannot answer: was the reported activity unlawful, who was responsible, was the operator’s investigation adequate, or what remedy should follow? Draft 2’s longer windows softened the objective test’s schedule. Its new restriction and retained procedural tail nevertheless made it more important to prevent an objective contact test from sliding into a judgement about a contested complaint.

Proposal, assessment, ratification and operation are different facts

The language of institutional analysis often creates false certainty by compressing a long policy lifecycle into a single verb. Here, “AFRINIC required” would be too broad if it implied that Draft 2 became an operative rule in 2018. The evidence establishes publication of a proposal on 20 November 2018. It also establishes an AFRINIC staff and legal assessment dated 20 April 2019. It does not establish that Draft 2 was adopted, deployed or used against any member.

That separation is essential because the later lifecycle moved beyond Draft 2. AFRINIC records Draft 7, dated 17 May 2021, as the later version ultimately ratified. The ratified-policy overview dates that event to 4 February 2026. Ratifying Draft 7 in 2026 did not retroactively adopt Draft 2 in 2018. Nor does later ratification prove the exact date or completeness of a production implementation. Publication, assessment, ratification and technical rollout are separate claims requiring separate evidence.

The 2019 assessment is valuable precisely because it shows how AFRINIC’s own staff and legal adviser read the proposed consequences before any assumption of implementation. Staff estimated roughly six months of software development, including WHOIS changes dependent on the solution eventually ratified. A development estimate is evidence that the text would require material technical work; it is not evidence that the work occurred. The contingency—what solution was ultimately ratified—also confirms that the proposal’s path was unsettled.

Nothing in the record supports a story about a particular 2018 member being targeted, refusing to cooperate or losing MyAFRINIC, WHOIS, IRR, voting or number-resource access under Draft 2. Nor does the phrase “whenever AFRINIC sees fit” prove selective validation. The article’s concern is structural. It follows the consequences authorised by the proposal’s wording and interpreted in AFRINIC’s assessment, not an allegation about an enforcement episode that the evidence does not show.

This precision improves rather than weakens the analysis. Proposed institutional architecture matters before it is used. A draft reveals what its authors and assessors considered a plausible connection between a data-quality test and member rights. The correct response is to examine that connection without pretending that a proposed power was exercised. Draft 2 is important as a design choice: it paired a more forgiving clock with a more consequential failure state, and it left the old clock embedded in the illustration that staff might have had to translate into code.

The paradox is therefore complete. On paper, a holder could have as many as 15 days at the initial stage and 15 more after escalation, with recurring validation no more frequent than every six months at minimum. In the example, the old five-business-day sequence survived. At the consequence layer, failure could move beyond a questionable address to the member account and onward towards revocation-related procedures. The draft slowed the test while shortening the institutional distance between a failed test and a wider restriction.