Summary

  • Every abuse report must enter a visible intake and investigation process, but the stronger mitigation duty begins only when readily available information supports a reasonable determination that a gTLD name is being used for the contract's defined forms of DNS Abuse.
  • The required result is to stop or disrupt that abusive use through a prompt and proportionate action. The contract does not make suspension automatic, set one universal clock, or give ICANN general authority over website content and hosting.

A complaint arrives with a domain name, a screenshot and a demand: take it down. That formulation is operationally attractive because it appears to convert harm into one clear instruction. ICANN's contracts do something more careful. They divide the route from report to remedy into stages, assign different duties to registrars and registries, and leave room to protect legitimate services when a domain has been compromised rather than created for abuse.

The first stage is intake. Section 3.18.1 of the Registrar Accreditation Agreement requires a registrar to maintain a readily accessible abuse email address or webform, confirm receipt, and take reasonable and prompt steps to investigate and respond appropriately to reports of abuse. A report therefore cannot be ignored merely because it arrives incomplete. The receipt creates a traceable event; the investigation asks whether the reported conduct falls within the registrar's responsibility and what information can reasonably be obtained.

The second stage is the actionable-evidence threshold. Under section 3.18.2, a registrar that has actionable evidence that a sponsored registered name is being used for DNS Abuse must promptly take mitigation actions reasonably necessary to stop or disrupt that use. ICANN's advisory explains “actionable” as enough readily available information for a reasonable determination. For phishing, a full URL, a screenshot of the impersonating page, the target brand and the message that carried the link can make the allegation testable. Account history, name servers, registration date, EPP status and the content at the reported URL can add context.

This threshold does not erase the duty to investigate. If the reporter omitted a useful item, the registrar may hold information the reporter could not possess. The contract distinguishes “the report does not yet prove the case” from “there is nothing to investigate.” That distinction prevents a poor submission from becoming either an automatic sanction or a convenient dead end.

Scope matters just as much as proof. For these agreements, DNS Abuse is limited to malware, botnets, phishing, pharming, and spam when spam delivers one of the other four. Fraud, defamation, copyright claims, harmful speech and other illegal or abusive content may be serious, but they do not become contractual DNS Abuse merely because a domain is involved. Other laws, policies and contractual provisions may apply. ICANN's DNS-abuse amendment is not a general Internet-content code.

Once the evidence is actionable, discretion narrows but does not disappear. The registrar must act promptly and must be able to explain why its action was appropriate to the case. A newly registered look-alike domain displaying only a fake bank login is very different from a long-standing corporate domain whose single franchise subdomain was compromised.

Suspending the first name can directly stop a phishing campaign. Suspending the second can also disable legitimate web pages, email and unrelated subdomains. Notification to the registrant, site operator or host, combined with a time-bound request to remove the malicious material, may disrupt the abuse with less collateral damage.

Registry operators occupy a different control layer. When a registry reasonably determines from actionable evidence that a domain in its top-level domain is being used for DNS Abuse, it must promptly contribute to stopping or disrupting that use. At minimum, it must refer the domain and relevant evidence to the sponsoring registrar or take direct action where appropriate.

A registrar normally has the customer account and a closer view of one registered name. A registry may be better placed for a threat spanning many registrars, such as domains generated for a botnet. The contractual design is therefore a routing rule for responsibility, not a contest over who can impose the harshest measure.

“Prompt” is deliberately not a single number. The advisory says contracted parties must show continuing attentiveness proportionate to possible harm. Imminent, large-scale victimization may require action in hours; a compromised legitimate service may require enough investigation to avoid destroying the service one is trying to protect. The example timelines in the advisory illustrate possible compliant responses, but they are not contractual deadlines.

Escalation to ICANN adds another evidentiary layer. Its complaint guide asks for the relevant gTLD names, a clear explanation and proof of the abusive use, evidence that the issue was first reported to the registrar or registry, subsequent communications, and a reason the response was inadequate.

The May 2026 compliance dashboard records large numbers of complaints rejected as invalid or unactionable because no prior report to the contracted party was evidenced. That is not a finding that the underlying harm was unreal. It shows that ICANN Contractual Compliance evaluates a contractual failure, and therefore needs a record connecting the abuse, the responsible party, the notice and the response.

The resulting accountability is more demanding than “complaint in, suspension out.” Registrars and registries must keep operable contacts, confirm receipt, investigate, gather or assess evidence, choose a proportionate measure, act with urgency appropriate to the harm, preserve records and explain their reasoning when Compliance asks. Reporters, in turn, improve the chance of action by supplying the domain, complete abusive URL, screenshots, timing, impersonated target, delivery message and the correspondence trail.

What the contract still does not order is equally important. It does not require every domain to be suspended. It does not promise that a DNS-level action will remove content from a host. It does not place ccTLD policy, hosting companies or website administrators under ICANN's registrar and gTLD-registry agreements. It does not treat every allegation as proof. Its enforceable promise is narrower: evidence must become a reasonable finding, and a contracted party with that finding must promptly use the powers it actually has to stop or disrupt the defined DNS abuse without inflicting avoidable collateral harm.

Sources