Summary
- The firm deadline in the record was 26 January 2006, when existing .us registrations using proxy arrangements were to be corrected. The date for ending new proxy sales is less clean: the published Fourth Circuit opinion says 16 February 2006, while the district-court record and the United States’ appellate brief point to 16 February 2005 and report that registrars had stopped offering new anonymous registrations by early March 2005. The discrepancy should be preserved rather than silently resolved.
- The operative authority did not belong to the privacy-service customer or arise from a direct government contract with that customer. NTIA administered the country-code namespace and directed its registry contractor; NeuStar, Inc. controlled the authoritative registration system and registrar agreements; registrars controlled the retail relationship and submitted customer records. That cascade made a federal interpretation effective across the namespace.
- The district court addressed the First Amendment and Administrative Procedure Act arguments, but the Fourth Circuit affirmed solely because Robert Peterson had already disclosed enough identifying information to lack a concrete anonymity injury. The appellate court expressly left open whether the same disclosure rule could injure someone whose speech actually depended on remaining anonymous.
The enforcement clock was clearer than the chronology
The Peterson litigation began because a policy interpretation acquired an operational deadline. A beneficial user could disagree with NTIA’s view of the registry contract, a registrar could entity to losing a commercial privacy product, and a proxy provider could insist that its own public record was accurate. None of those positions changed the authoritative .us database. The practical question was whether anyone with power over that database, or a court with power to enjoin its use, would preserve the disputed arrangement before the deadline expired.
One date is stable across the principal records. Existing registrations using anonymous or proxy arrangements were to be brought into compliance by 26 January 2006. Robert Peterson filed his federal action on 25 January, one day before that deadline, and sought emergency relief intended to prevent the conversion of his proxy-protected record into a public record containing his own contact details. The timing made continuity part of the legal dispute. A judgment delivered after publication could not reproduce the anonymity that publication had destroyed.
The date for stopping new proxy registrations is harder to state without qualification. The published Fourth Circuit opinion says that NeuStar instructed registrars to cease offering proxy registration services by 16 February 2006. The district court memorandum, however, describes NTIA as requiring the cessation of proxy registrations after 16 February 2005. The United States’ appellate brief gives the underlying sequence in still greater detail: an NTIA letter dated 2 February 2005 directed that new anonymous or proxy registrations end by 16 February 2005, and the brief says all registrars had stopped offering new anonymous registrations by early March 2005. That same brief also reproduces the later NeuStar communication with a 2006 year, leaving an internal tension in the litigation record.
The safest institutional reconstruction is therefore bounded. New proxy sales were treated as prohibited during 2005, while existing proxy records were given until 26 January 2006 to be converted. The Fourth Circuit’s 2006 date must still be reported as the text of the published opinion, but it should not be promoted into an uncontested chronology when the contemporaneous instruction, the district court and the reported early-March compliance point to 2005. This is more than a copy-editing problem.
A one-year difference changes how long registrars had already been operating under the new interpretation before an existing customer reached court.
What remained constant was the mechanism. Once NTIA treated the proxy structure as incompatible with the federal statement of work, NeuStar could communicate the requirement through registrar contracts and compliance notices. Registrars then faced a choice about their own access to the namespace. The beneficial user was downstream of every institution capable of changing the rule or pausing its implementation.
The policy entity was a procurement specification
The prohibition did not begin as a statute addressed directly to every .us registrant. Its institutional base was the federal government’s administration of the United States country-code top-level domain and the contract used to procure registry services. On 22 August 2000, the Department of Commerce published a Federal Register notice and draft statement of work for the management and administration of .us. The notice followed a 1998 request for comments, a March 1999 public meeting attended by roughly 60 people and an open electronic mailing list.
That process was participatory, but participation did not allocate final control. The public could comment on the design of the expanded namespace, registrar qualifications, locality-based names, eligibility, dispute policy and registry functions. NTIA remained the procuring authority. Once the statement of work became part of the registry contract, later disagreements were filtered through contract administration rather than through a vote of entities or a user-level adjudication system.
The draft statement of work required an accurate and current registry database, a shared registration system and free public access to enhanced WHOIS information. For registrations in the expanded .us space, the specified public fields included the domain name, nameservers, registrar, creation date, the domain-name holder’s name and postal address, and technical and administrative contact details. Those requirements created the legal and operational entity that would later be interpreted against proxy services.
The text did not say in a single sentence that all proxy registrations were forbidden. It required information about the “domain name holder” and separately identified the registrar. That wording left a genuine question about institutional roles. Could an intermediary be the holder of record, accept responsibility for the name, publish accurate details about itself and license use to a customer? Or did “holder” mean the natural person or organisation that controlled and benefited from the name, whose identity therefore had to appear in the registry’s public record?
NTIA adopted the latter position. Peterson argued for the former. The dispute was not about whether a field contained a typographical error. It concerned which person or entity the field was required to describe. A record could accurately identify Domains By Proxy and still fail a rule demanding the beneficial user. Conversely, a record could accurately identify the beneficial user while exposing details that the user had paid an intermediary to keep out of public WHOIS. “Accuracy” did not settle the dispute because the parties disagreed about the entity to be made accurate.
The procurement structure gave NTIA a route to make its interpretation effective without entering a separate agreement with every retail customer. The Fourth Circuit’s archived opinion records that NTIA contracted with NeuStar to manage .us, incorporated the statement-of-work requirements into the federal agreement, authorised NeuStar to contract with third-party registrars and required those registrar agreements to carry forward the federal agreement’s substantive obligations. The resulting chain connected a public procurement instruction to the data submitted in an individual registration transaction.
That is the first institutional lesson of the case. A procurement instrument can perform policy work when it defines the database, specifies the fields, allocates access and conditions the contractor’s relationships with downstream firms. The rule need not appear as a generally applicable statute directed to end users. Control over the registry contract can be enough to determine which records the authoritative system will accept.
Consultation shaped the specification but did not create a remedy
The earlier public process mattered. It supplied a record, disclosed design choices and invited affected actors to raise concerns before the contract was awarded. It would be wrong to describe .us policy as having emerged without any consultation. It would be equally wrong to treat consultation as a substitute for an enforceable right when the contractor later classified a live registration as noncompliant.
The 2000 notice did not set out the later registry-wide detection method, explain how a proxy company would be distinguished from an ordinary organisational registrant, or provide a user-facing appeal from a proxy classification. It did not promise that a disputed record would remain unchanged while a registrant sought review. Public participation helped define what the government would buy; it did not give each entity authority over how the purchased system would apply the resulting fields.
That distinction separates transparency from accountability. A published statement of work may reveal the formal rule. A contractor’s report may reveal that scans are occurring. Neither disclosure answers whether a particular match was correct, whether evidence could rebut it, whether the user would receive reasons, or whether a reviewer could reverse the operational result before publication or loss of service. Accountability requires a decision path and a remedy, not only access to policy documents.
The public source set remains thin on those implementation details. It does not disclose the matching criteria later used to identify suspected proxy or anonymous registrations, the rate of false positives, the treatment of law firms or corporate service companies, the extent of human review, or a provider-side appeal log. That absence does not prove that no internal process existed. It means the available record does not support describing one as a right held by the affected user.
Four arrangements were repeatedly collapsed into one
The litigation becomes more precise when four distinct arrangements are separated: public contact publication, confidential customer-data custody, relay, and registry eligibility.
Public contact publication concerned what any person could retrieve from the .us registration database. Under NTIA’s interpretation, the registry was to display the true and accurate data of the person or entity treated as the domain-name holder. The requirement was not limited to ensuring that someone could receive a message. It attached a public identity record to the status of holding a .us name.
Confidential customer-data custody concerned information kept behind the public proxy record. In Peterson’s appellate brief, he described Domains By Proxy as maintaining its customers’ contact details and as disclosing information in specified circumstances, including in response to law-enforcement requests or compulsory legal process. He invoked that arrangement to argue that anonymity was conditional and that a responsible intermediary remained available.
That description should not be converted into a finding that GoDaddy, Domains By Proxy, NeuStar or NTIA completed an independent identity-verification audit. The record shows an asserted custody and disclosure arrangement. It does not establish the documents examined, the assurance level, the freshness of the data, the controls used to detect false identities or the outcome of an external audit. Confidential possession and verified identity are different claims.
Relay concerned reachability. A proxy provider could publish its own postal or electronic contact details, receive communications and forward them to the customer. Relay can protect direct details while allowing technical notices, legal complaints or ordinary correspondence to reach the beneficial user. Its effectiveness depends on forwarding performance, accurate internal records, service continuity and cooperation under the governing terms. None of those functions necessarily requires universal public disclosure of the customer’s home address or telephone number.
Registry eligibility concerned what the authoritative system would recognise as a valid registration structure. Even a reliable relay and an accurate confidential customer file could not preserve a .us registration if the registry treated the intermediary’s appearance as holder as the defect itself. Domains By Proxy could promise forwarding and conditional disclosure. It could not compel NeuStar to accept the proxy as the holder of record. GoDaddy could sell the product, but it could not rewrite the federal contract or bind NTIA to a different interpretation.
The United States’ position made this separation explicit. In its appellate brief, the government argued that direct contact data had to be present in the registry and that the public administrator should not have to depend on a proxy company’s voluntary cooperation. It identified objectives including response to technical problems, fraud and identity-theft prevention, intellectual-property enforcement, continuity if a registrar failed, enforcement of the United States nexus requirement, criminal investigation and maintenance of a public record of those using a public resource. Those were the defendants’ asserted interests.
The Fourth Circuit did not adopt them as merits findings because it stopped at standing.
Peterson’s brief offered a different allocation of responsibility. He relied on registrar language under which a registrant of record could license use of the name to another person while retaining responsibility unless it disclosed the licensee after receiving reasonable evidence of actionable harm. On that theory, the intermediary was not a false placeholder. It was the legally accountable holder, a relay and a conditional disclosure point. That was the appellant’s contractual argument, not a holding that the arrangement complied with the statement of work.
The unresolved interpretive question was therefore not whether public data should be “accurate” in the abstract. It was whose data had to be public, who had to hold the confidential record, and whether reachability and accountability could be supplied by an intermediary without public identification of the beneficial user.
The contract cascade reached the retail transaction
NTIA awarded the registry contract to NeuStar in October 2001. The federal agreement incorporated the statement-of-work requirements. NeuStar’s registrar-facing agreements then incorporated the relevant obligations and required registrars to pass them into customer arrangements. The published appellate opinion treated this structure as the source of GoDaddy’s duty to comply with the disclosure requirement.
By 2002, GoDaddy was offering .us registrations using Domains By Proxy. In the courts’ description, the intermediary appeared in the public holder fields while the customer controlled and used the domain. The product therefore separated public holder-of-record data from beneficial use. It functioned only while the registry accepted that separation.
The enforcement episode followed a Government Accountability Office inquiry into inaccurate or incomplete .us contact data. According to the court opinions and government briefing, NTIA investigated, communicated its interpretation to NeuStar and directed the registry contractor to require registrars to stop proxy services and correct existing records. The standalone NTIA instruction is not among the public sources relied on here, although the government brief identifies a 2 February 2005 letter and the opinions describe its effect.
That missing document limits any claim about the precise reasoning, exceptions or internal legal analysis that accompanied the instruction.
The amended registrar language made the policy more explicit than the original field list. As reproduced in the briefs, it prohibited a registrar and its resellers, affiliates, partners or contractors from offering anonymous or proxy services that prevented the registry from possessing and displaying the true and accurate data elements for a registration. The clause did two institutional jobs. It defined the prohibited product and located responsibility at the registrar level, preventing a registrar from preserving the product merely by moving it to an affiliate or reseller.
The leverage was not equivalent to an ordinary request for assistance. A registrar’s ability to create and maintain .us names depended on its agreement with the registry and access to the shared registration system. Peterson characterised the practical choice as accepting the amended term or losing the ability to issue .us names. The government described the same structure as contractual compliance: a breach could prompt a demand to cure and, if unresolved, escalation against accreditation.
The United States told the Fourth Circuit that NeuStar sent GoDaddy a breach notice on 27 January 2006 after the existing-record deadline passed and allowed 15 days to cure before considering further action, including de-accreditation. That description appears in an advocate’s brief rather than as a factual finding necessary to the appellate holding, so it should be attributed accordingly. It nevertheless identifies the incentive that made the policy effective. The registry did not need to sue each proxy customer. It could place the registrar’s access to an entire national namespace at risk.
The retail firm then had reasons to comply quickly. A proxy product generated revenue and served customer privacy interests, but continued accreditation supported a larger portfolio. Once a customer-level record was coupled to registrar breach, the registrar bore concentrated institutional risk while the customer bore the exposure risk. That allocation made immediate correction more likely than prolonged adjudication.
Who controlled what
NTIA held the public and contractual authority. It administered the United States country-code namespace, selected the registry contractor, approved the statement of work and could direct the contractor’s performance. The record supports the conclusion that NTIA interpreted the holder-data requirement as incompatible with proxy registration. It does not support treating every step of implementation as a separate exercise of sovereign power by NeuStar.
NeuStar held delegated registry-wide implementation power. It operated the authoritative database, maintained the shared registration system, contracted with registrars and could enforce registrar-facing obligations. Because the database aggregated records from across the namespace, the registry could identify suspected proxy patterns at scale rather than waiting for complaints about individual names. Its power was operational and contractual, backed by its federal customer and control of access to the registry.
Registrars held the retail gate and much of the direct customer data. They accepted orders, collected contact information, submitted records, offered or withdrew proxy products and communicated correction demands. They could change a customer-facing record or decline a transaction. They could not unilaterally make the authoritative registry accept a structure that the federal contract administrator and registry operator had classified as prohibited.
GoDaddy and Domains By Proxy occupied different positions within that retail layer. GoDaddy was the accredited registrar dealing with NeuStar. Domains By Proxy was the intermediary appearing in the public record and, on Peterson’s account, keeping customer details, relaying communications and operating conditional disclosure procedures. The reference does not establish a modern statutory “controller” or “processor” label for any of these actors. It establishes concrete functions: custody, publication, submission, classification and enforcement.
The beneficial user held use and speech interests but little infrastructural control. Peterson could decide what to publish on his site, buy a proxy service, make contractual arguments and seek judicial relief. He could not directly edit the authoritative database, compel the registry to recognise a proxy holder, force the registrar to retain a product that jeopardised accreditation, or obtain an automatic pause merely by filing a complaint.
A federal court held potential power to interrupt the chain, but only in a proper case and through an enforceable order. A temporary restraining order or preliminary injunction could have preserved the existing arrangement while jurisdiction and merits were examined. The district court record shows that Peterson sought emergency relief on the eve of the deadline. The Fourth Circuit later noted that the request for a temporary restraining order became moot when the disclosure requirement took effect without a ruling. He continued to pursue a preliminary injunction, but did not obtain one.
This is the authority boundary that matters. The government could direct its contractor. The contractor could enforce registrar terms. The registrar could alter the customer record. The court could potentially stay enforcement. The customer could ask each institution to act, but had no equivalent control point and no documented right to keep the status quo while the request was decided.
Peterson challenged publication, not merely data collection
Robert Peterson operated pcpcity.us as a forum for political and social discussion. He had obtained the name through GoDaddy and Domains By Proxy. In his appellate brief, he said he used the service to keep his home address and telephone number out of public WHOIS because he feared retaliation connected to controversial speech. His claim was therefore not simply that the government might know who he was. It was that continued use of the .us name was being conditioned on public association between his identity, his contact details and the registration.
The government and NeuStar characterised the entity differently. They argued that the requirement governed the holder of a government-administered domain registration, not every speaker or contributor to the website. The government brief also said the required address need not be residential and could be a business address or post-office box. On that account, the policy did not regulate the content of Peterson’s forum; it imposed conditions on a registrable public resource while leaving him free to speak through the site, another domain or another medium.
Those accounts identify different constitutional entities. Peterson treated the domain name as an important instrument of anonymous publication and audience access. The defendants treated it as a registration benefit whose holder could be publicly identified without regulating the content carried through it. The distinction would matter to a First Amendment analysis of burden, forum, tailoring and alternatives. The Fourth Circuit did not decide which account should prevail.
Peterson also argued under the Administrative Procedure Act that NTIA had made a substantive policy change without required notice and comment. The government answered that proxy use had never complied with the original statement of work and that NTIA was administering a federal contract rather than promulgating a new legislative rule. The district court accepted the contract-related exception in 5 U.S.C. § 553(a)(2) and treated the earlier public process as additional support. The appellate court did not reach the APA issue because standing disposed of the case.
The timing amplified the institutional imbalance. Peterson filed one day before the deadline for existing registrations. The registry and registrar had already spent months operating under the upstream interpretation, while the court was being asked to intervene at the point of conversion. The operational clock did not pause for the legal one.
The district court reached issues the Fourth Circuit did not
On 17 April 2006, the district court issued its memorandum opinion and denied the requested preliminary injunction. It addressed both threshold and merits questions. It concluded that the contact-information requirement did not regulate the content of Peterson’s website, treated the measure as a content-neutral time, place and manner restriction, credited government interests including technical response, prevention and investigation of fraud and crime, intellectual-property enforcement, treaty-related administration and preservation of .us for eligible United States users, and found alternative channels available.
The court also rejected Peterson’s APA theory. It treated the disputed action as falling within the APA’s contract-related exception to notice and comment and regarded the earlier statement-of-work process as sufficient in any event. Finally, it held that Peterson lacked injury in fact because he had already made identifying information public.
That combination has often been compressed into the phrase that the “courts upheld” the proxy ban. The compression is misleading. The district court did reach constitutional and administrative-law merits. The Fourth Circuit did not affirm on those grounds. An appellate judgment resting solely on standing determines that this claimant could not obtain a merits ruling on this record. It does not establish that every application of the policy complies with the First Amendment.
The preliminary-injunction posture also mattered. Interim relief requires more than a plausible claim. The district court considered likelihood of success, irreparable harm, injury to the defendants and the public interest. It found the balance against Peterson. Yet the appellate court could affirm without endorsing that balancing because Article III injury came first.
The district court’s treatment of harm was tied to Peterson’s own disclosures. He had published his full name, place of residence, professional status, litigation materials and links to other work associated with his identity. The court concluded that the additional registration data would not create the kind of anonymity injury he alleged. It did not conduct a general inquiry into the consequences for a person who had kept legal identity, location and direct contact details private.
The Fourth Circuit stopped at injury
The Fourth Circuit decided the consolidated appeals on 27 February 2007. Its published opinion began and ended with standing. After recounting the statement of work, contract cascade, proxy arrangement and enforcement deadlines, the court said it needed to look no further than whether Peterson had suffered an injury in fact.
Peterson invoked the recognised interest in anonymous speech and argued for a form of partial anonymity. He acknowledged that his name and some biographical information appeared on his site, but maintained that he had not publicly tied his home address and telephone number to the domain registration. The court rejected that position as applied to him. It observed that he had disclosed his name, hometown, professional membership, writings and links to prior material under his own name.
In the court’s view, the remaining contact information was readily obtainable from facts he had voluntarily revealed, so registry publication exposed him to no danger he had not already created.
The reasoning was claimant-specific. The court did not hold that partial anonymity is never protected or that public disclosure of registration contact data can never burden anonymous speech. Its footnote expressly reserved whether the disclosure requirement might injure an individual’s right to speak anonymously in other circumstances. That reservation is central to the case’s institutional meaning.
Peterson also attempted to bring a First Amendment overbreadth challenge on behalf of other users, including people whose safety or speech might genuinely depend on keeping location data private. The court held that relaxed overbreadth rules did not eliminate the requirement that the plaintiff himself suffer a distinct injury. Because Peterson lacked one, he could not carry the claims of absent anonymous registrants into federal court.
The appellate result therefore did not validate the federal interpretation on constitutional merits. It affirmed the judgment because the chosen claimant’s public record defeated the threshold injury needed for adjudication. The policy remained operational, while the most important merits question was left for someone else.
The standing gap favoured an already implemented rule
The result created a standing gap between the people most capable of filing and the people most clearly injured. Peterson had the knowledge, resources and willingness to challenge the rule quickly. His own site, however, supplied the facts that allowed the appellate court to find no anonymity injury. People with stronger claims—whistleblowers, dissidents, abuse survivors, politically exposed speakers or others who had preserved a separation between identity and publication—were not before the court.
That gap has practical consequences. A policy can be challenged in two courts and later be described as “judicially tested” even though the appellate decision never addresses the merits. Institutions may treat the existence of litigation as validation, while the holding actually says only that this plaintiff was not entitled to the requested merits ruling.
The gap also interacts with irreversibility. A claimant must prove a concrete threat of publication, suspension or loss. Yet proving an anonymity injury may require supplying identity and risk evidence to a court. Protective orders, sealed declarations and pseudonymous proceedings can sometimes reduce that conflict, but access to them is not automatic, and Peterson’s published appellate record did not test such an arrangement. The claimant needs enough disclosure to establish standing without destroying the confidentiality the action seeks to preserve.
A stronger future record would require a still-anonymous beneficial user, a specific demand to replace the proxy record, evidence that publication or loss was imminent, and a remedy capable of preventing that event. Standing would open the courthouse door; it would not decide the underlying dispute.
What a still-anonymous registrant could have contested
A claimant who had not already linked legal identity and location to the domain could present an injury different from Peterson’s. Such a person could allege that continued use of the name was conditioned on public disclosure, that a registrar or registry had issued a concrete correction demand, that the threatened action was imminent, and that disclosure would expose the person to a specific speech, safety or retaliation risk. Whether that showing would satisfy Article III would remain a judicial question, but it would answer the factual weakness the Fourth Circuit identified.
On the merits, at least four disputes would remain.
The first would concern interpretation of the statement of work. The text required the name and address of the domain-name holder. A claimant could argue that an intermediary capable of accepting responsibility, maintaining contact data and relaying communications was the holder of record, while the beneficial user was a licensee. NTIA would answer that the person controlling and benefiting from the name was the holder whose data the registry had to possess and display. The Fourth Circuit did not resolve that contractual issue.
The second would concern clarification versus policy change. Proxy services had operated for years through registrar arrangements that included language about licensing use of a name. A claimant could argue that a categorical prohibition altered the legal effect of an established practice and required a more formal process. The government would rely on the original data-field requirements, the distinction between registrar and holder, and the APA’s contract-related exception. The appellate court did not choose between those accounts.
The third would concern the fit between public disclosure and the stated objectives. Confidential registry access may assist eligibility verification, lawful investigation and continuity. Universal public publication is a separate measure. A court reaching the First Amendment merits would need to identify the burden, the nature of the government-administered resource, the relationship between domain registration and speech, the degree of tailoring, and the availability of less exposing alternatives. The district court supplied one answer on Peterson’s record. The Fourth Circuit did not adopt it as the basis for affirmance.
The fourth would concern case-specific procedure. Even if NTIA had authority to require the actual user’s data, an affected person could ask how the registration was classified, whether the scan was accurate, whether a recognised exception applied, what evidence could rebut the match and whether publication or loss should occur before review. A procedural complaint would still need a cause of action, standing and an available remedy. The institutional absence of an appeal does not itself create federal jurisdiction. It does, however, identify the point at which review access may fail to become redress.
Weekly scans turned interpretation into repeatable enforcement
The later implementation record shows how the policy moved beyond one registrar and one lawsuit. In a 2007 State of the Space report hosted by NTIA, NeuStar said it performed regular weekly scans of the entire usTLD database for evidence of proxy or anonymous registrations. In an accompanying written-policy submission, it described such registrations as compliance violations and said a registrar found offering them would be notified of breach.
Those documents are contractor submissions, not independent audits. They prove that NeuStar represented the process in those terms. They do not establish the scan’s precision, the identity of every data source, the number of human reviewers, the rate at which classifications were reversed, or whether registrars and customers had a formal appeal. Nor do they show that every beneficial user’s identity was independently verified after a match.
Even with those limits, the reports reveal the administrative mechanism. Contract language defined the prohibited condition. The central database allowed the registry to search across registrars. A suspected pattern generated a compliance classification. The registrar then faced notice and possible contractual consequences. The system did not depend on a member of the public filing a complaint about each registration.
Registry-wide scanning also redistributed error costs. The registry had an incentive to reduce undetected proxy arrangements and demonstrate compliance with its federal customer. A registrar had an incentive to cure quickly to protect accreditation. A beneficial user bore the cost of explaining why a record was legitimate, securing another arrangement or seeking a court order under deadline. Unless the contract required an independent review and a hold, no actor in that chain necessarily had a strong incentive to investigate a difficult false positive before changing the record.
The public record does not disclose enough to judge whether false positives were common. It does disclose enough to reject the idea that the rule remained a merely textual policy. Weekly registry-wide review made the interpretation repeatable and scalable. The contract had become an enforcement system.
The missing remedy sat between the scan and the lawsuit
The formal availability of federal litigation did not supply a complete operational appeal. Peterson reached the district court and the Fourth Circuit, but the temporary-restraint request became moot when implementation proceeded, the preliminary injunction was denied, and the appeal ended more than a year after the existing-record deadline without a merits decision.
A meaningful provider-side remedy would have required several elements that are not documented in the public record: notice of the precise fields or patterns producing the match; the policy clause invoked; a defined opportunity to submit contrary evidence; a decision-maker able to reverse the classification; a deadline; and a continuity rule preventing publication, deletion or registrar sanctions while the challenge was timely pending.
The distinction between an operational ability and a legal entitlement is important. NTIA could have directed its contractor to pause. NeuStar and the registrar had technical abilities to maintain, lock or alter records. A federal court could have entered an injunction. None of those capacities amounted to an automatic right held by a customer. Without a contractual or judicial command, the institutions controlling the system remained free to continue implementation.
That is the difference between review access and an enforceable remedy. Filing a complaint can produce a record. Filing a lawsuit can produce institutional scrutiny. Redress requires an authorised actor to stop the threatened change, correct the classification and restore the prior state. In a disclosure dispute, restoration after the fact is especially weak because information copied from a public registry cannot reliably be recalled.
A counterfactual has to separate knowledge from publication
A serious alternative cannot assume that privacy should defeat every registry objective. It must test whether the government could obtain reliable identity, nexus, reachability and lawful access without making every beneficial user’s direct details public by default.
The first component would be a confidential verified-beneficial-user record. The registry, or a contractually accountable verification provider, would hold the legal identity, contact details and evidence of United States nexus. Verification would have defined standards: acceptable documents or electronic evidence, freshness rules, change controls, audit logs and procedures for correction. The public record would not display those details by default. This is a proposed architecture, not a claim about the assurance performed in Peterson’s case.
The second component would be an accredited public relay. The public registration record would identify the intermediary and provide functioning postal and electronic channels. Contracts would impose forwarding deadlines, uptime obligations, escalation procedures and sanctions for repeated failure. A relay that did not reliably reach the user would be a compliance problem. Reachability would become measurable rather than assumed.
The third component would be written classification notice. When a registry scan identified a suspected proxy or anonymous registration, the registrar and beneficial user would receive the basis of the match, the policy clause, the requested correction and the evidence needed to challenge it. A bare statement of noncompliance would be inadequate because the affected person cannot correct or rebut an unknown error.
The fourth component would be a continuity hold. A timely challenge would preserve DNS resolution and prevent involuntary publication, deletion or transfer while a defined review took place, subject to a narrow emergency exception. The hold would be short, recorded and unavailable to delay unrelated abuse proceedings. Its purpose would be to keep the remedy from becoming meaningless before adjudication.
The fifth component would be an independent appeal. The reviewer would not be the same compliance unit that generated the match. It would have power to confirm, reverse or narrow the classification, order correction of the record, lift or extend the hold and issue reasons. Aggregate match, reversal and timing data could be published without exposing customer identities.
Measured against the government’s asserted objectives, this model would perform differently across functions. For accuracy, a confidential verified record could be more reliable than a public field populated by a user who fears exposure. For the United States nexus requirement, verification could directly test citizenship, residence, incorporation or bona fide presence rather than infer eligibility from a public address. For technical incidents, a service-level relay and an authenticated emergency channel could provide rapid contact. For law enforcement, lawful requests could reach the verified file without depending on informal goodwill. For registrar failure, escrow and transfer controls could preserve continuity.
The counterfactual would not satisfy an objective of universal public identification. If the policy purpose is that every member of the public should know the beneficial user of a national namespace, confidential verification is not a substitute. That is why the asserted objectives must be disaggregated. Fraud control, technical reachability, nexus verification, lawful access and public attribution are different functions. Calling all of them “accuracy” conceals the choice about who may see the data.
The alternative also creates new risks. A confidential identity repository becomes a valuable breach target. Verification may exclude people who lack conventional documents. Relay providers may fail or obstruct. Emergency access may expand beyond genuine emergencies. Appeals may slow enforcement and invite tactical claims. Those costs require minimisation, security controls, access logging, independent audit, sanctions for misuse and time-limited review. Privacy by intermediation is not accountability unless the intermediary is itself governed.
The institutional advantage is reversibility. The registry retains the ability to know the beneficial user and enforce eligibility, while the user receives notice and a decision before public exposure or loss of the name. Error is addressed inside the control chain rather than shifted immediately to a customer seeking emergency federal relief.
What the case establishes—and what it does not
The record supports a bounded conclusion about power. NTIA’s control of the .us contract allowed it to define the required holder data and direct the registry contractor. NeuStar translated that interpretation into registrar-facing obligations, deadlines, compliance notices and later reported weekly scans. Registrars held the customer relationship and submitted the data, but their access to the namespace depended on upstream compliance. The beneficial user had speech and privacy interests without an equivalent ability to preserve the disputed record.
The case also establishes that judicial review can end without constitutional validation. The district court addressed the First Amendment and APA arguments. The Fourth Circuit affirmed because Peterson lacked a personal injury after publicly identifying himself. It expressly left open whether the disclosure requirement could injure a person whose speech depended on anonymity. Describing that judgment as an appellate merits endorsement would be inaccurate.
Several source limits remain material. The standalone NTIA instruction that first declared proxy use noncompliant is not in the public source set used here, although the litigation documents identify and describe it. The record contains conflicting years for the deadline to end new proxy services. The later contractor reports disclose weekly scans but not the criteria, error rate, review log or independent audit. The sources do not establish that Peterson’s domain was cancelled by the government, that Domains By Proxy was ordered by a court to identify him, or that any provider completed an independent identity-verification audit.
Those limits narrow the durable lesson. This is not a general history of WHOIS and not proof that every public registration-data rule is lawful or unlawful. It is a case about how a field definition in a sovereign ccTLD procurement contract became registry law in practice. Consultation shaped the specification. Contract administration selected the interpretation. Registry control made it scalable. Registrar incentives made it effective. A user reached court but did not obtain an appellate merits decision or an interim continuity guarantee.
Accountability begins beyond publication of the rule. It requires a clear account of who can classify the record, who can stop implementation, what evidence can reverse the match, and how continuity or confidentiality will be restored. In .us, the contract answered the first question with force. The public record is much less complete on the others.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
