Summary

  • Critical registry functions include DNS, DNSSEC, EPP, RDAP and Data Escrow.
  • A gTLD can have only one Main RSP and one DNSSEC RSP, while it may use multiple DNS RSPs.
  • At minimum, an applicant must provide a Main RSP, a DNSSEC RSP and a DNS RSP.

The number of provider organizations is not a reliable measure of registry-service coverage. The Applicant Guidebook assigns functions to RSP types. A Main RSP operates the registration database, undertakes escrow of domain registration data and operates EPP and RDAP. Each gTLD can have only one Main RSP.

DNS is structured differently. A DNS RSP operates one or more DNS servers for a gTLD, and a gTLD may use multiple DNS RSPs. DNSSEC has its own role: the DNSSEC RSP performs the cryptographic operations required for DNSSEC, and a gTLD can have only one DNSSEC RSP.

The Guidebook also defines a Proxy RSP. It performs registration validation to comply with applicable local law in a jurisdiction. This is an optional additional registry service that must be approved through the RSP Evaluation Program. A gTLD may use multiple Proxy RSPs, with each providing access to a different jurisdiction.

These rules make the minimum composition precise without requiring that every role belong to a different organization. At minimum, the applicant must provide a Main RSP, a DNSSEC RSP and a DNS RSP. One organization may be evaluated for one or more RSP types, but this article does not infer that a particular provider has been evaluated or selected.

The evidence boundary is important. A complete function map does not prove that an RSP has passed evaluation, accepted an applicant, entered a contract or begun operations. It only demonstrates whether the applicant’s recorded plan assigns the required functions to the permitted RSP roles.

Analysis

For governance, the useful control is a function-to-provider matrix. Rows should represent DNS, DNSSEC, EPP, RDAP and Data Escrow. Columns should identify the intended provider, RSP type and the evidence supporting that assignment. This matrix is BTW guidance, not a document format mandated by ICANN.

The cardinality check belongs beside the coverage check. One Main RSP must account for the registration database, EPP, RDAP and escrow functions. One DNSSEC RSP must account for DNSSEC cryptographic operations. One or more DNS RSPs may account for authoritative DNS service. Optional Proxy RSP entries should state the jurisdiction they cover and record the required RSP Evaluation Program approval evidence or its current status.

Sources