Summary
- ICANN’s OCTO-044 reports that its combined methods associated 56.4% of reputation-list seed domains in a seven-day 2025 gTLD sample with at least one other domain. The number is sample coverage, not a rate for all domains or proof of common ownership.
- The study deliberately used public technical registration and DNS data, but ICANN says it could not validate clusters against registrant/account-holder ground truth. It calls for privacy-preserving evaluation with registrars.
On 6 October, ICANN announced the release of a new Office of the Chief Technology Officer report, Associated Domain Analysis Using Public Data (OCTO-044). Its headline result is striking: across the study’s seven-day sample, the combined methods tagged 56.4% of reputation-block-list seed names as associated with at least one neighboring domain.
That percentage answers a narrow question. The seeds were phishing, malware and botnet command-and-control gTLD names first added to several reputation lists from 24 to 30 September 2025; they were no more than six months old when flagged. About 4,000 newly registered names per day entered that sample. The result is not the percentage of all new domains that are abusive, nor a current market-wide measurement.
OCTO-044 uses observable technical features: registrar identity, authoritative nameservers, creation times and, for one method, shared IPv4 resolution with nameserver data. It groups registrations that occur within seconds or hours, or names that resolve through the same infrastructure. A lexical-similarity filter then narrows candidate groups. The report says these methods overlap, so the method-specific coverage figures—about 16% for batch registration, 33% for bulk registration and 18% for bulk resolution—cannot be added together.
The most consequential limit is not hidden in the fine print. “Associated” describes a technical relationship inferred from those features. It does not identify who owns a name, who operated it or why it was registered. ICANN says bulk registration can be legitimate, including defensive registrations, advertising networks and traffic distribution. Shared infrastructure can create false positives; strict lexical thresholds can also miss real associations.
The study did not compare its clusters with a ground-truth dataset of registrants or account holders. The report says ICANN lacks visibility of that personal information, generally held by registrars and some registries, and that a comprehensive privacy-preserving evaluation requires ongoing collaboration with the registrar community. That is an uncompleted validation step, not proof that the method is wrong. It is also why a cluster label should remain an investigative lead rather than stand in for attribution.
Timing claims need the same care. Under the data collection and daily processing actually modeled in the study, association analysis detected 4.6% of the sample before an RBL listing. A hypothetical condition with data processed within 30 minutes raises the modeled share to 10.0%. The faster figure is not an observed operational outcome: OCTO-044 says registration data could arrive with delays of days, and some data may be updated weekly.
ICANN says it plans further work to validate the results, reduce processing delays and distribute outputs to relevant stakeholders. Those steps will determine whether the method is useful beyond the retrospective baseline. For now the report supports a measured conclusion: public data can surface groups worth examining at scale, but the study has not shown that each group shares an owner, an abusive purpose or a case for suspension.
Sources:
- ICANN announcement, 6 October 2026: https://www.icann.org/en/announcements/details/new-icann-report-introduces-a-method-for-associated-domain-detection-06-10-2026-en
- ICANN OCTO-044, Associated Domain Analysis Using Public Data, 18 September 2026: https://www.icann.org/en/system/files/files/octo-044-18sep26-en.pdf
- ICANN OCTO publications: https://www.icann.org/octo-ssr/
- GNSO DNS Abuse Mitigation PDP 1: https://gnso.icann.org/en/group-activities/active/dns-abuse-mitigation-pdp-1
- ICANN Bylaws: https://www.icann.org/en/governance/bylaws
- Lu Heng, “The Policy Mirror” (analytical perspective only): https://heng.lu/the-policy-mirror/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

