Summary

  • ICANN’s contract vocabulary separates validation of data format from verification through an affirmative response. Neither operation, by itself, authenticates the respondent’s legal identity or adjudicates rights in a domain.
  • A sound evidence model therefore keeps four questions apart: is the record syntactically usable, is a contact reachable, who can operate the registrar account, and who has the legally superior claim? Each question has a different decision-maker and a different remedy.

The word “verified” carries too much weight

A registration record looks authoritative because it is structured, timestamped and served by infrastructure that can change the domain’s operational state. That appearance invites a shortcut: if a registrant email was “verified”, the person named in the record must have been identified and the record must prove ownership.

ICANN’s own instruments do not support that shortcut. The current form of the Registrar Accreditation Agreement retains the RDDS Accuracy Program Specification. It requires registrars, within defined events and time limits, to check the presence and format of required data. Email syntax is tested against an applicable standard; telephone and postal fields have their own format checks.

A separate step asks the registrar to contact the registered-name holder or account holder and receive an affirmative response. If that response is not received, the registrar must use manual verification or, in specified circumstances, suspend the registration until verification is completed.

The 2015 ICANN advisory makes the distinction unusually plain. “Validation” concerns whether data is in a standards-consistent format. “Verification” concerns contacting a point of contact and receiving an affirmative response. A format complaint can require correction without requiring the registrar to contact the holder at all. The words describe contractual procedures, not a general identity-assurance standard.

This yields the first two evidentiary layers.

  1. Field validity. Does an email address have a permissible form? Does a telephone number or postal address satisfy the specified structural checks? A yes means the record can be processed. It does not show that the address exists or belongs to the named party.
  2. Contactability. Did a person controlling an email address or telephone number answer the registrar’s challenge? A yes links a responsive channel to the registration process at that time. It does not reveal whether the responder used a nominee, a compromised mailbox, a shared corporate account or a false name.

Account control is a third question

Registrar account control is operational evidence. Login credentials, multifactor-authentication events, payment records, transfer authorisations, change logs and support interactions may show who could instruct the registrar. They can be more probative than a public RDAP display when a domain is hijacked or when two people claim to speak for the same organisation.

Yet control is not identical to entitlement. A departing employee may retain credentials. An agent may be authorised to manage a domain without owning the underlying business interest. A thief may temporarily control the account. A privacy or proxy service may occupy the published field while holding a separate customer record. The system needs account-control evidence because it explains how a change happened; it must not convert that evidence into an automatic verdict on who should prevail.

The 2025 Registration Data Policy, effective from 21 August 2025, reinforces this institutional boundary. It governs how registrars and registry operators collect, transfer, escrow, publish, redact, disclose and retain registration data. It includes specific treatment of the registrant-organisation field and lawful disclosure. Those rules make the data lifecycle more legible. They do not turn ICANN, a registry operator or an accredited registrar into a court for beneficial ownership, employment authority, succession, fraud or contractual title.

Legal identity and rights require a fourth forum

The fourth layer asks a different question: which natural person or legal entity has the better claim under the governing contract and applicable law? That may depend on incorporation records, agency authority, employment terms, purchase agreements, court orders, arbitral awards, inheritance documents or evidence of fraud. The answer can require compulsory evidence and adversarial procedure that a contact challenge was never designed to provide.

ICANN Contractual Compliance can examine whether a registrar followed the RAA, investigated an inaccuracy complaint and applied the required suspension or correction steps. In a March 2026 Board accountability decision, the public record described Compliance investigating a complaint and determining that the registrar had suspended the domain consistently with the RAA and its accuracy specification. That is evidence about contractual compliance. It is not a judicial declaration that the person who answered, complained or appeared in the record owned the domain.

The distinction matters because the remedies differ. A malformed field calls for correction. A dead contact channel calls for re-verification or a contractually defined hold. Compromised account control calls for containment, credential recovery and preservation of logs. A contested legal claim calls for the applicable dispute mechanism, court or other authorised decision-maker. Using one remedy to answer another layer’s question can transfer a domain to the wrong party, destroy evidence or turn a temporary hold into an unreviewed adjudication.

What the audit numbers do—and do not—show

ICANN’s October 2023 accuracy audit report supplies useful process evidence. Across audits conducted from 2016 through 2022, the report aggregates 80 registrars representing about 127.8 million domains. It records categories of validated deficiency: ten registrars lacked a contact-information validation process; six had a process with deficient validation methods; four had deficient retention procedures; and one had a deficient verification process.

Those figures should not be restated as a percentage of domains with a false owner. The audit sampled registrar controls and mapped the domains represented by the audited registrars. It did not adjudicate the beneficial identity behind every registration, and the report’s “potentially affected” domain counts are not findings that each domain contained inaccurate data. The proper inference is narrower: process design, evidence retention and the ability to demonstrate verification are themselves governance risks at scale.

The policy debate has recognised the same measurement limit. ICANN’s 2023 assessment said proposed accuracy scenarios were not expected to provide data about identity verification or whether contact information genuinely belonged to the data subject. In 2025, the GNSO Council’s Accuracy Small Team recommended examining the existing validation and verification process and its effect on registrants.

It cited research associating pre-registration contact checks with fewer malicious registrations, while treating that as a reason to examine the process—not as proof that contact verification establishes legal identity. By March 2026, Council discussion was still following through on accuracy guidance. One participant expressly noted that guidance cannot prevent a bad actor from entering garbage data and then committing abuse.

A four-column evidence ledger

Registrars and reviewers can reduce category errors by recording every consequential assertion in four columns:

  • format: the field checked, the rule applied, the time and the result;
  • reachability: the channel challenged, the response method, the time and whether re-verification later failed;
  • control: the account, authentication and change evidence showing who could operate the registration;
  • legal authority: the contract, corporate mandate, dispute decision or court order that establishes why a person was entitled to act.

The columns may corroborate one another. They must not be collapsed. A verified inbox is valuable evidence that a channel responded. It is not a title deed.

Sources