Tomorrow's GNSO council meeting, DNS Abuse Small Team recommendations approval
Shiva Upadhyay
shiva.upadhyay at YAHOO.COM
Fri Aug 15 17:53:56 EEST 2025
Dear Farzaneh and colleagues,
Thank you for sharing your draft statement and for raising these concerns in such a thoughtful way. I fully respect the emphasis on due process and registrant rights, which are central to any credible DNS abuse framework. However, I would like to humbly offer a different perspective on the question of associated domain checks.
In practice, DNS abuse, particularly phishing, malware distribution, and botnet activity, rarely occurs in isolation. Abusive actors often rely on clusters of domains, rapidly shifting activity to bypass takedowns. Associated domain checks provide an important technical signal that allows registrars and registries to detect these patterns and intervene effectively. Without this tool, enforcement becomes fragmented and reactive, enabling bad actors to outpace mitigation efforts.
I share the concern that any enforcement mechanism must be applied proportionately, with transparency and safeguards. But I would argue that these are implementation issues rather than reasons to reject the concept outright. Associated domain checks do not inherently imply arbitrary enforcement; rather, they serve as part of a broader, multi-factor review process. With safeguards such as registrant notification, appeal mechanisms, and transparency reporting, we can achieve both goals: effective DNS abuse mitigation and protection of registrant rights.
>From my perspective, to rule out associated domain checks entirely risks weakening our collective ability to combat abuse at scale. A more constructive way forward may be to endorse their inclusion while explicitly conditioning their use on due process guarantees.
With that in mind, I would respectfully propose the following alternative statement for consideration:
“NCSG approves the DNS Abuse Small Team Report. We acknowledge that associated domain checks are an important tool in identifying patterns of abuse, especially in clustered infrastructure. However, we emphasize that their use must be coupled with clear safeguards—registrant notification, transparency, and meaningful opportunities for redress—to ensure fairness, proportionality, and accountability. DNS abuse mitigation should protect both internet users and registrants, and we support developing implementation frameworks that strike this balance.”
Thanks & Regards,
Shiva Upadhyay On Thursday 14 August, 2025 at 04:17:19 pm IST, Manju <manju4icann at gmail.com> wrote:
+1 to the statement. Thank you so much, Farzi!
Best,Manju
On Thu, Aug 14, 2025 at 18:12 Johan Helsingius <00001963cc94b85a-dmarc-request at listserv.syr.edu> wrote:
I fully support this.
Julf
On 14/08/2025 01:18, farzaneh badii wrote:
> Hi all,
>
> As we mentioned during the PC meeting, we are planning to vote on
> approving the small team recommendations on DNS abuse. There were three
> recommendations that were prioritized, two of which seem to be
> interesting to investigate. But we (as discussed on this mailing list)
> had grave concerns about the associated domain check. Here is the small
> team report: https://gnso.icann.org/sites/default/files/policy/2025/
> draft/dns-abuse-small-team-report-04aug25-en.pdf <https://
> gnso.icann.org/sites/default/files/policy/2025/draft/dns-abuse-small-
> team-report-04aug25-en.pdf>
> So tomorrow I will vote for adoption of small team's DNS abuse
> recommendation but I am planning to read this statement:
>
> "NCSG approves the DNS Abuse Small Team Report. However, we wish to
> formally record our concern regarding the inclusion of /associated
> domain checks/ as a potential DNS abuse mitigation measure.
>
> While we support effective and proportionate approaches to combating DNS
> abuse, we have consistently emphasized the need for due process at both
> the registration, detection and enforcement stages. Associated domain
> checks risk enabling overly broad or arbitrary enforcement—particularly
> if implemented without robust safeguards to ensure registrants are
> informed, have a meaningful opportunity to respond, and are protected
> from collateral harm.
>
> Such measures could lead to disproportionate take-down and suspensions
> and the targeting of legitimate registrants through bulk association-
> based criteria, undermining fairness, transparency, and accountability.
> We are also disappointed that due process and access to remedy have not
> been prioritized by other stakeholders in this work. Domain name
> registrants are not inherently criminals, and DNS abuse mitigation
> measures should reflect that presumption.
>
> We therefore cannot support the inclusion of associated domain checks
> unless and until clear, transparent, and consistently applied due
> process mechanisms are in place."
>
>
>
> Farzaneh
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20250815/105e6d20/attachment.htm>
More information about the Ncsg-discuss
mailing list