Summary
- Register.com v. Verio turned on a coupled system: daily zone-file comparison, automated registrar and WHOIS queries, and solicitation of newly registered domain holders.
- The Second Circuit enforced repeated use after notice, while ICANN said part of Register.com's restriction exceeded its accreditation promise and had to be challenged through ICANN's own remedy process.
The important machine in Register.com v. Verio did not sit in one server. It crossed several of them. According to the court record and a later registry investigation, Verio obtained updated top-level-domain zone files, compared successive copies to isolate new names, identified the sponsoring registrar, queried registrar WHOIS services for contact details, and loaded the results into a sales system.
Register.com said some contacts followed registration within 12 to 24 hours. That timing is an allegation in the source record, not a measured result for every lead, but it captures the commercial purpose: reach a new registrant before the need for hosting and web services had cooled.
That sequence matters because the word “public” describes only one part of it. Registrars were required to make registration data available through query services. That did not answer whether a third party could use a zone-file licence to discover every new name, run automated queries at scale, and turn the replies into direct-mail, telephone and email campaigns. Each step had its own operator, agreement and remedy.
Three permission layers, not one public database
The first layer was the registry. VeriSign Global Registry Services reported that two Verio accounts remained active for access to the .com, .net and .org zone files. One licence limited use to local DNS caching; another identified DNS caching as the specified purpose and prohibited high-volume automated queries against registry or third-party WHOIS systems. Registry logs showed daily access during the reviewed period.
The exact Project Hen House implementation was partly redacted, so VeriSign described the difference-file pipeline as the most technically feasible and likely method rather than as a complete forensic reconstruction.
The second layer was Register.com's WHOIS service. Register.com returned use terms with query results. Those terms prohibited mass solicitation by email, direct mail and telephone, as well as high-volume automated processes applying to its systems. Verio knew about the terms and continued querying.
The Second Circuit majority treated that repeated conduct after notice as acceptance. Its reasoning was not that every term posted anywhere on a website binds every visitor. It relied on a repeat user that knew the condition and returned to obtain more data.
The third layer was Register.com's accreditation agreement with ICANN. ICANN told the district court that Register.com had promised to permit lawful uses of query data subject to specified exceptions, including email spam and high-volume automated processes. In ICANN's view, Register.com's attempt to extend the marketing ban to otherwise lawful direct mail and telephone calls breached that promise.
Yet the same ICANN submission said Verio was not entitled to enforce the accreditation agreement as a third-party beneficiary. The complaint belonged in ICANN's contractual process, not in self-help that ignored Register.com's terms.
This is the case's most useful tension. Register.com could be overreaching in one contractual relationship while Verio was exceeding permission in another. The two possible breaches did not cancel each other. A machine user cannot safely infer that an upstream inconsistency grants downstream access. An operator cannot safely infer that ownership of a service permits restrictions beyond its own accreditation commitment.
What the appellate decision actually resolved
On 23 January 2004, the Second Circuit affirmed a preliminary injunction, with a narrow correction to one trademark reference. The majority upheld restrictions on automated access, use of the obtained data for solicitation, and misleading communications.
The same PDF then reproduces a detailed draft opinion by Judge Fred Parker, who would have reversed much of the order. That Appendix argues against inferring assent and gives greater weight to the public character of WHOIS data and the ICANN agreement. It is valuable contrary analysis, but it is not the court's holding.
The procedural limit is equally important. A preliminary injunction is not a final trial judgment establishing damages or a universal law of machine-readable public data. The three sources do not supply a complete query count, a verified number of contacted registrants, conversion results, or a quantified measure of system degradation. They also do not decide how today's RDAP, privacy rules or modern registration-data policy would treat an equivalent system.
The operational lesson is an interface map
The durable control is not a banner that says “public” or “prohibited.” It is a map of the whole acquisition chain. For every source, an operator should be able to identify who publishes the data, which interface delivered it, whether automation is allowed, which rate and purpose limits apply, when the terms were received, who can change them, and which process decides a dispute.
The same map should distinguish access from reuse. A user may be able to retrieve one record without gaining permission to compile thousands. A registrar may have to publish query data without gaining authority to ban every otherwise lawful downstream use. A registry may provide bulk files for DNS purposes without licensing those files as seed material for repeated queries against other systems.
VeriSign's corrective recommendations followed that logic: notify Verio that further zone-file-enabled querying would violate the licences, make any transition conditional on acknowledging the prohibition, clarify the drafting, and stop high-volume registry WHOIS queries. Those are control-plane measures. They identify the credential, the permitted purpose, the technical behaviour and the consequence.
The case therefore belongs in an infrastructure file, not only a law-school file. It shows how a public directory can become a private acquisition engine when several legitimate interfaces are composed for a new purpose. It also shows why the answer cannot be supplied by the data label alone. The decisive questions live at the joins.
Evidence limits
This analysis separates the Second Circuit majority from Judge Parker's Appendix, ICANN's institutional position from the parties' claims, and VeriSign's observed account activity from its technical inference. It does not claim that automation is inherently unlawful, that public registration data is privately owned, or that the preliminary injunction governs all web services.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
