<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>Manju wrote: </p>
<p><<The change from domain name security threat to DNS Abuse
was actually an<br>
effort of the SCCI to tighten the scope, not the contrary. The
general<br>
agreement within the SCCI was that "domain name security threat"
can be<br>
interpreted to have a broader remit that is beyond GNSO's mission
and<br>
scope, which prompted the change to 'DNS Abuse' as narrowly
defined in the<br>
contract.>></p>
<p><font color="#0000ff">That makes sense, and thank you. But I
think we need a footnote to tie "DNS Abuse within scope for the
GNSO" to a definition and this would be easily done as a
footnote. Does this work Manju, Julf and Tapani?</font></p>
<div class="moz-cite-prefix">
<pre wrap="" class="moz-quote-pre"></pre>
<blockquote type="cite" style="color: #007cff;">
<pre wrap="" class="moz-quote-pre"> Indicator 1: The GNSO has demonstrated meaningful activity towards
mitigating DNS Abuse and security threats relating to
domain names that are in scope for the GNSO.<font
color="#0000ff"><b>[1]</b></font>
</pre>
</blockquote>
<br>
</div>
<div class="moz-cite-prefix"><font color="#0000ff"><b>Where </b></font><font
color="#0000ff" style="white-space: pre-wrap;"><b>[1] is the footnote with the title & link of the ICANN document that defines the scope of "DNS Abuse within the scope for the GNSO" (and ICANN as a whole), namely, Phishing, Pharming, Malware, Botnets, and Spam as a delivery mechanism for the other four. (I don't have the doc and link handy, but I'm guessing you and staff do.) </b>With a footnote leading to a clear document laying out the definition of "DNS Abuse... in scope for the GNSO," then everyone can learn the definition, even if they do not know it and this writing serves present readers... and future ones. Great discussion!</font></div>
<div class="moz-cite-prefix"><font color="#0000ff"
style="white-space: pre-wrap;">
</font></div>
<div class="moz-cite-prefix"><font color="#0000ff"
style="white-space: pre-wrap;">Best, Kathy</font></div>
<div class="moz-cite-prefix"><font color="#0000ff"
style="white-space: pre-wrap;">
</font></div>
<div class="moz-cite-prefix">On 6/18/2026 2:07 PM, Johan Helsingius
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:a65f295d-7278-49b5-b3bb-53bd791a8986@Julf.com">All,
<br>
<br>
In light of this clarification from Manju, I would be inclined to
<br>
approve the proposed wording change. If any of you disagree
<br>
strongly, please speak up.
<br>
<br>
Julf
<br>
<br>
<br>
On 18/06/2026 10:16 am, Manju wrote:
<br>
<blockquote type="cite">Hi all,
<br>
<br>
Thank you for the questions.
<br>
<br>
Before answering them, please allow me to provide more context
on what we're doing in the SCCI with the Continuous Improvement
Program Pilot and what the criteria and indicators are for.
<br>
<br>
The Continuous Improvement Program (CIP) is ICANN's evolution of
its traditional Organizational Reviews, which previously
assessed how well Supporting Organizations, Advisory Committees,
and the Nominating Committee fulfilled their purpose, structure,
and accountability.
<br>
<br>
The CIP rests on five shared principles covering purpose,
structural effectiveness, operational efficiency,
accountability, and collaboration. Each CIP assessment cycle
runs up to three years and moves through three phases:
<br>
<br>
* Assessment and Prioritization (data collection and
identifying
<br>
improvement areas),
<br>
* Improvements (implementing changes), and
<br>
* Reporting (publishing results for public comment). <br>
As the body in GNSO that's responsible for continuous
improvement, SCCI has been following the CIP framework and
principles to develop the criteria and indicators for future
assessment and improvements. You can find the full set of
criteria and indicators here: https://
docs.google.com/document/d/1UoqrIjNArJFztNZ1Z9htTHCEIhJvIf2PNGLXgE_5HC0/
edit?tab=t.0#heading=h.49smw22t8kla
<a class="moz-txt-link-rfc2396E" href="https://docs.google.com/document/d/1UoqrIjNArJFztNZ1Z9htTHCEIhJvIf2PNGLXgE_5HC0/edit?tab=t.0#heading=h.49smw22t8kla"><https://docs.google.com/document/
d/1UoqrIjNArJFztNZ1Z9htTHCEIhJvIf2PNGLXgE_5HC0/edit?
tab=t.0#heading=h.49smw22t8kla></a>
<br>
<br>
*Note: Please refrain from commenting on the Google Doc as we're
currently only allowing the SCCI members to comment.*
<br>
*
<br>
*
<br>
In short, we are now developing criteria and indicators for
future data collection. And after collecting the data, we will
assess it against the indicators and criteria, evaluating
whether there is room for improvement.
<br>
<br>
What you were asked to review was one of the indicators, and as
it is a data point where we will be collecting data to assess
against, we in SCCI decided to word it open-ended enough to
allow the ease of data collection, while preventing scope creep
by adding wording such as 'in scope for GNSO'.
<br>
<br>
If you're interested in knowing more, I'd encourage you to
listen to the recordings of our ICANN86 session, where we
discussed this particular item in depth:
<a class="moz-txt-link-freetext" href="https://icann86.sched.com/event/2NQMw/gnso-scci-work">https://icann86.sched.com/event/2NQMw/gnso-scci-work</a>- session
<a class="moz-txt-link-rfc2396E" href="https://icann86.sched.com/event/2NQMw/gnso-scci-work-session"><https://icann86.sched.com/event/2NQMw/gnso-scci-work-session></a>
<br>
<br>
Hope this helps.
<br>
<br>
Best,
<br>
Manju
<br>
<br>
On Thu, Jun 18, 2026 at 3:34 PM Tapani Tarvainen
<00001e7f5908374c- <a class="moz-txt-link-abbreviated" href="mailto:dmarc-request@listserv.syr.edu">dmarc-request@listserv.syr.edu</a>
<a class="moz-txt-link-rfc2396E" href="mailto:00001e7f5908374c-dmarc-request@listserv.syr.edu"><mailto:00001e7f5908374c-dmarc-
request@listserv.syr.edu></a>> wrote:
<br>
<br>
Dear Manju,
<br>
<br>
Thank you for the explanation. Looking at the proposed text
again
<br>
it makes sense. But the language is a bit ambiguous:
<br>
<br>
> Indicator 1: The GNSO has demonstrated meaningful
activity
<br>
towards
<br>
> mitigating DNS Abuse and security
threats
<br>
relating to
<br>
> domain names that are in scope for
the GNSO.
<br>
<br>
Specifically, it's not clear if the qualification "that are
in scope..."
<br>
applies also to DNS Abuse and not only to security threats.
<br>
<br>
I'm not sure this matters here, but perhaps it would be
worth
<br>
thinking a moment if it could be clarified without making
the
<br>
text too cumbersome.
<br>
<br>
Tapani
<br>
<br>
<br>
On Jun 17 15:02, Manju (000020eb0920d952-dmarc-
<br>
<a class="moz-txt-link-abbreviated" href="mailto:request@LISTSERV.SYR.EDU">request@LISTSERV.SYR.EDU</a> <<a class="moz-txt-link-freetext" href="mailto:000020eb0920d952-dmarc">mailto:000020eb0920d952-dmarc</a>-
<br>
<a class="moz-txt-link-abbreviated" href="mailto:request@LISTSERV.SYR.EDU">request@LISTSERV.SYR.EDU</a>>) wrote:
<br>
>
<br>
> Hi all,
<br>
>
<br>
> Thank you very much for the discussion.
<br>
> As mentioned by Julf, I'm the chair of SCCI and have
to maintain
<br>
neutrality
<br>
> when it comes to the discussion of substance. However,
I believe I'm
<br>
> allowed to provide some context and clarification on
this issue.
<br>
>
<br>
> The change from domain name security threat to DNS
Abuse was
<br>
actually an
<br>
> effort of the SCCI to tighten the scope, not the
contrary. The
<br>
general
<br>
> agreement within the SCCI was that "domain name
security threat"
<br>
can be
<br>
> interpreted to have a broader remit that is beyond
GNSO's mission and
<br>
> scope, which prompted the change to 'DNS Abuse' as
narrowly
<br>
defined in the
<br>
> contract.
<br>
>
<br>
> One of the examples that can be understood as
'combating domain name
<br>
> security threat', as shared during our SCCI working
session in
<br>
Seville, is
<br>
> the Internationalized Domain Names PDP, which
regulates the variant
<br>
> management of IDNs. By this example, it should be
clear that
<br>
domain name
<br>
> security threat actually has a broader scope than DNS
abuse, the
<br>
latter of
<br>
> which is narrowly defined and codified in contract.
<br>
>
<br>
> Hope this helps.
<br>
>
<br>
> Best,
<br>
> Manju
<br>
>
<br>
> On Tue, Jun 16, 2026 at 8:36 PM farzaneh badii <
<br>
> <a class="moz-txt-link-abbreviated" href="mailto:00001deb507b73c5-dmarc-request@listserv.syr.edu">00001deb507b73c5-dmarc-request@listserv.syr.edu</a>
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:00001deb507b73c5-dmarc-request@listserv.syr.edu"><mailto:00001deb507b73c5-dmarc-request@listserv.syr.edu></a>>
wrote:
<br>
>
<br>
> > Hi Julf
<br>
> >
<br>
> > I agree and we tried really hard in our public
comments to
<br>
mention the
<br>
> > security threat and not frame it as DNS abuse,
but the CPH and
<br>
others were
<br>
> > really keen on adding DNS abuse at the time.
Maybe we can
<br>
clarify that DNS
<br>
> > abuse as narrowly defined in RAAs.
<br>
> >
<br>
> >
<br>
> >
<br>
> > Farzaneh
<br>
> >
<br>
> >
<br>
> > On Tue, Jun 16, 2026 at 10:22 AM 鄭嘉逸 Chia I Cheng
<
<br>
> > <a class="moz-txt-link-abbreviated" href="mailto:00001edb87ceea84-dmarc-request@listserv.syr.edu">00001edb87ceea84-dmarc-request@listserv.syr.edu</a>
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:00001edb87ceea84-dmarc-request@listserv.syr.edu"><mailto:00001edb87ceea84-dmarc-request@listserv.syr.edu></a>>
wrote:
<br>
> >
<br>
> >>
<br>
> >> Hi all,
<br>
> >>
<br>
> >> I'm broadly aligned with the direction of the
discussion, but
<br>
I think
<br>
> >> it's worth pausing to consider why this
proposed change is
<br>
being raised
<br>
> >> within the SCCI framework specifically — that
context seems
<br>
important to
<br>
> >> how we shape our response.
<br>
> >>
<br>
> >> On the substantive question: is excluding
"DNS Abuse"
<br>
altogether actually
<br>
> >> to our advantage? If the term can be held to
a narrow,
<br>
operationally
<br>
> >> precise definition — one explicitly grounded
in user rights
<br>
and human
<br>
> >> rights principles — we may end up with more
meaningful control
<br>
over how it
<br>
> >> is applied than a rejection would give us.
<br>
> >> Best,
<br>
> >>
<br>
> >> Chia-I
<br>
> >>
<br>
> >> *寄件者: *NCSG-Discuss
<<a class="moz-txt-link-abbreviated" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU"><mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU></a>> 代表 NPC SVG
<
<br>
> >>
<a class="moz-txt-link-abbreviated" href="mailto:0000220936dcebb1-dmarc-request@LISTSERV.SYR.EDU">0000220936dcebb1-dmarc-request@LISTSERV.SYR.EDU</a>
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:0000220936dcebb1-dmarc-request@LISTSERV.SYR.EDU"><mailto:0000220936dcebb1-dmarc-request@LISTSERV.SYR.EDU></a>>
<br>
> >> *日期: *星期二, 2026年6月16日 清晨6:12
<br>
> >> *收件者: *NCSG-DISCUSS@LISTSERV.SYR.EDU
<<a class="moz-txt-link-freetext" href="mailto:NCSG">mailto:NCSG</a>-
<br>
<a class="moz-txt-link-abbreviated" href="mailto:DISCUSS@LISTSERV.SYR.EDU">DISCUSS@LISTSERV.SYR.EDU</a>>
<<a class="moz-txt-link-abbreviated" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU"><mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU></a>>
<br>
> >> *主旨: *Re: SCCI Criteria 4 - “domain name
security threats”
<br>
> >>
<br>
> >> Like Abbas and Julf , I also believe the use
of the term DNS abuse
<br>
> >> broadens the indicator into an area
unsuitable for the GNSO
<br>
council for
<br>
> >> reasons described below.
<br>
> >>
<br>
> >> RD
<br>
> >>
<br>
> >> On Mon, Jun 15, 2026, 3:08 PM <
<br>
> >>
<a class="moz-txt-link-abbreviated" href="mailto:0000222a86a53d44-dmarc-request@listserv.syr.edu">0000222a86a53d44-dmarc-request@listserv.syr.edu</a>
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:0000222a86a53d44-dmarc-request@listserv.syr.edu"><mailto:0000222a86a53d44-dmarc-request@listserv.syr.edu></a>>
wrote:
<br>
> >>
<br>
> >> Julf, I agree with the analysis by Abbas.
Explicitly Including
<br>
“DNS
<br>
> >> abuse” broadens the indicator into an area
unsuitable for the
<br>
GNSO Council
<br>
> >> for the reasons he describes.
<br>
> >>
<br>
> >>
<br>
> >>
<br>
> >> In terms of a statement, we can perhaps
relate something like
<br>
“the ICANN
<br>
> >> community has reached general consensus
around a narrow set of
<br>
DNS security
<br>
> >> threats (phishing, malware, botnets,
pharming, and spam as a
<br>
delivery
<br>
> >> mechanism). However, there has not been
universal stakeholder
<br>
consensus on
<br>
> >> the broader conceptual definition of DNS
Abuse or on where the
<br>
boundary
<br>
> >> lies between DNS abuse and content abuse.
Therefore, since the
<br>
term DNS
<br>
> >> abuse” can mean different things to different
stakeholders,
<br>
even within the
<br>
> >> narrow threats mentioned, by including "DNS
abuse" as an
<br>
indicator for
<br>
> >> evaluating the performance of the GNSO
council risks creating
<br>
unclear, and
<br>
> >> potentially unrealistic, expectations for
achieving the stated
<br>
criteria, to
<br>
> >> say nothing of the opportunity for debate
regarding whether or
<br>
not the
<br>
> >> criteria has been met.”
<br>
> >>
<br>
> >>
<br>
> >>
<br>
> >> I hope this helps.
<br>
> >>
<br>
> >>
<br>
> >>
<br>
> >> Ken
<br>
> >>
<br>
> >>
<br>
> >>
<br>
> >> *From:* NCSG-Discuss
<<a class="moz-txt-link-abbreviated" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU"><mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU></a>> *On Behalf
Of *Abbas
<br>
> >> Sibai
<br>
> >> *Sent:* Monday, June 15, 2026 9:33 AM
<br>
> >> *To:* <a class="moz-txt-link-abbreviated" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>
<<a class="moz-txt-link-freetext" href="mailto:NCSG">mailto:NCSG</a>-
<br>
<a class="moz-txt-link-abbreviated" href="mailto:DISCUSS@LISTSERV.SYR.EDU">DISCUSS@LISTSERV.SYR.EDU</a>>
<br>
> >> *Subject:* Re: SCCI Criteria 4 - “domain name
security threats”
<br>
> >>
<br>
> >>
<br>
> >>
<br>
> >> Hi Julf,
<br>
> >>
<br>
> >> Thanks for flagging this. As an individual
member of the NCUC, I
<br>
> >> completely share your concerns. Specifically
inserting the
<br>
term "DNS Abuse"
<br>
> >> into the GNSO Continuous Improvement Program
framework is a
<br>
major red flag
<br>
> >> that we definitely need to push back against
during the
<br>
upcoming call on
<br>
> >> Wednesday, 1 July 2026.
<br>
> >>
<br>
> >> From our constituency’s perspective, my
understanding is that
<br>
there are
<br>
> >> two distinct "cans of worms" this proposal
opens up:
<br>
> >>
<br>
> >> - *Mission Creep and Content Regulation:*
Broadening the
<br>
text to
<br>
> >> explicitly name "DNS Abuse" risks shifting
the GNSO's focus
<br>
from core
<br>
> >> technical layer infrastructure toward
content regulation.
<br>
What I
<br>
> >> understood is that the NCUC has a
long-standing commitment to
<br>
> >> fiercely protecting freedom of expression
and digital
<br>
rights. If the
<br>
> >> indicators explicitly target "DNS Abuse"
rather than
<br>
strictly defined
<br>
> >> security threats, it invites outside
pressure on the GNSO
<br>
to police website
<br>
> >> content, a precedent that directly
undermines our core
<br>
mission and
<br>
> >> human rights principles.
<br>
> >> - *Disproportionality and Human Rights
Impacts:* I also
<br>
understood
<br>
> >> that NCUC has consistently advocated that
any policy
<br>
intervention
<br>
> >> addressing domain security must be narrow,
proportionate,
<br>
and strictly
<br>
> >> scoped. Tying the evaluation of the GNSO's
performance to
<br>
broad and
<br>
> >> subjective perceptions of "DNS Abuse"
(especially via a
<br>
survey indicator)
<br>
> >> creates an incentive to pass sweeping,
reactive policies.
<br>
This places
<br>
> >> innocent registrants at risk of collective
or automated
<br>
domain suspensions
<br>
> >> without adequate due process or Human
Rights Impact
<br>
Assessments (HRIAs).
<br>
> >>
<br>
> >> The original text, focusing strictly on
"mitigating domain
<br>
name security
<br>
> >> threats," keeps the evaluation grounded
within the GNSO's
<br>
technical and
<br>
> >> contractual scope. The proposed revision
unnecessarily
<br>
complicates it and
<br>
> >> opens the door to over-policing at the
registry/registrar level.
<br>
> >>
<br>
> >> I fully support our leadership taking a
strong stance against
<br>
this text
<br>
> >> on Wednesday. Please let me know if you need
any assistance
<br>
with drafting a
<br>
> >> formal statement or if there are specific
points you want
<br>
supported during
<br>
> >> the call.
<br>
> >>
<br>
> >>
<br>
> >> Warm Regards,
<br>
> >>
<br>
> >> *Abbas Sibai*
<br>
> >> *Policy & Advocacy Specialist*
<br>
> >>
<br>
> >> +9613824725
<br>
> >>
<br>
> >> *|*
<br>
> >>
<br>
> >> <a class="moz-txt-link-freetext" href="https://www.linkedin.com/in/abbas-sibai/">https://www.linkedin.com/in/abbas-sibai/</a>
<https://
<br>
<a class="moz-txt-link-abbreviated" href="http://www.linkedin.com/in/abbas-sibai/">www.linkedin.com/in/abbas-sibai/</a>>
<br>
> >>
<br>
> >>
<br>
> >>
<br>
> >>
<br>
> >>
<br>
> >> On Mon, Jun 15, 2026 at 12:28 PM Johan
Helsingius <
<br>
> >>
<a class="moz-txt-link-abbreviated" href="mailto:00001963cc94b85a-dmarc-request@listserv.syr.edu">00001963cc94b85a-dmarc-request@listserv.syr.edu</a>
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:00001963cc94b85a-dmarc-request@listserv.syr.edu"><mailto:00001963cc94b85a-dmarc-request@listserv.syr.edu></a>>
wrote:
<br>
> >>
<br>
> >> Hi all,
<br>
> >>
<br>
> >> I am the NCSG representative to the Standing
Committee on
<br>
Continuous
<br>
> >> Improvement (SCCI) that is formulating the
Continuous Improvement
<br>
> >> Program framework. The SCCI is chaired by
Manju, another
<br>
NCSG:er, but
<br>
> >> as chair she has to remain neutral.
<br>
> >>
<br>
> >> The work until now has been developing the
Criteria and Indicators
<br>
> >> that will be used to judge how well the GNSO
processes are
<br>
working.
<br>
> >>
<br>
> >> We have made good progress under the very
capable leadership
<br>
of Manju,
<br>
> >> and most issues haven't been very
controversial, but I want to
<br>
flag
<br>
> >> the current issue where we probably want to
speak up against
<br>
the current
<br>
> >> proposal.
<br>
> >>
<br>
> >> The issue is Criteria 4, "The GNSO actively
combats domain name
<br>
> >> security threats", where there is a proposal
to change the draft
<br>
> >> text from:
<br>
> >>
<br>
> >> Indicator 1: The GNSO has demonstrated
meaningful
<br>
activity towards
<br>
> >> mitigating domain name
security threats.
<br>
> >>
<br>
> >> Indicator 2: 66% of surveyed
respondents agree that the GNSO
<br>
> >> combats domain name
security threats.
<br>
> >>
<br>
> >> to:
<br>
> >>
<br>
> >> Indicator 1: The GNSO has demonstrated
meaningful
<br>
activity towards
<br>
> >> mitigating DNS Abuse and
security threats
<br>
relating to
<br>
> >> domain names that are in
scope for the GNSO.
<br>
> >>
<br>
> >>
<br>
> >> Indicator 2: 66% of surveyed
respondents agree that the
<br>
GNSO has
<br>
> >> demonstrated meaningful
activity towards
<br>
mitigating
<br>
> >> DNS Abuse and security
threats relating to
<br>
domain
<br>
> >> names that are in scope
for the GNSO.
<br>
> >>
<br>
> >> While we probably are OK with mitigating
domain name security
<br>
threats,
<br>
> >> specifically mentioning DNS Abuse opens up
some cans of worms.
<br>
> >>
<br>
> >> We will have a chance to present our views at
the next SCCI
<br>
call on
<br>
> >> Wednesday, 1 July 2026, so I welcome your
comments/opinions.
<br>
> >>
<br>
> >> Julf
<br>
> >>
<br>
<br>
</blockquote>
</blockquote>
<pre class="moz-signature" cols="72">--
Kathy Kleiman
Past President, Domain Name Rights Coalition</pre>
</body>
</html>