Tomorrow's GNSO council meeting, DNS Abuse Small Team recommendations approval

farzaneh badii farzaneh.badii at GMAIL.COM
Fri Aug 15 19:47:43 EEST 2025


Hi Shiva,

Thank you very much and for your constructive feedback. We had a discussion
about this on the list a few weeks back and members agreed to withdraw our
support from the associated domain check. The statement tried to capture
that discussion and generally NCSG's longstanding values and was read out
yesterday so unfortunately we can't incorporate your changes but this is an
ongoing conversation. Also we didn't withdraw support from the report as a
whole but withdrew our support from this recommendation to investigate.

Our concern with associated domain checks is not limited to domain name
registrants. This mechanism can also significantly impact end users’
rights, particularly freedom of expression and access to information.
Overbroad blocking of “associated” domains risks removing lawful websites
and services, cutting off important sources of information and tools that
users rely on. Because these determinations are often opaque, affected
users typically receive no notice and have no way to challenge a mistake.
In practice, such measures can disproportionately affect marginalized
communities and independent media, especially in environments with weak
rule of law, where “association” may be used as a pretext for censorship.

Please see the examples below:

*1. Overbroad blocking leading to collateral damage*

   - If a domain is flagged as “associated” with abuse, entire domains or
   subdomains can be suspended or blocked.
   - This can remove lawful content and services hosted alongside or under
   the same infrastructure, preventing end users from accessing information or
   tools they rely on.

*Example:*
A shared hosting provider has hundreds of legitimate small business
websites. If one is compromised and associated domain checks link others
incorrectly, the entire set could be disabled.


*2. Lack of transparency and remedy for affected users*

   - End users generally aren’t notified when a site they visit is blocked
   due to an associated domain determination.
   - There’s no accessible appeals process for them, even if the
   information they sought was lawful and important.
   - This lack of remedy erodes trust and leaves users without a path to
   challenge mistaken or excessive enforcement.


*3. Chilling effect on speech and service availability*

   - Content creators and service providers may self-censor or avoid
   certain infrastructure for fear of being linked to an abusive actor through
   automated association.
   - This indirectly limits diversity of content and services available to
   the public.


*4. Disproportionate impact on marginalized or at-risk communities*

   - In countries with poor press freedom or weak rule of law,
   “association” can be used as a pretext to suppress independent media,
   activist groups, or opposition voices.
   - Automated checks make it easier to justify blocking them without a
   specific, substantiated abuse case.

I would like to also caution us against supporting "proactive" measures
before doing human rights impact assessment and having the remedy in place.


Best regards,

Farzaneh


On Fri, Aug 15, 2025 at 6:54 PM Shiva Upadhyay <
0000055b426785d6-dmarc-request at listserv.syr.edu> wrote:

> Dear Farzaneh and colleagues,
>
> Thank you for sharing your draft statement and for raising these concerns
> in such a thoughtful way. I fully respect the emphasis on due process and
> registrant rights, which are central to any credible DNS abuse framework.
> However, I would like to humbly offer a different perspective on the
> question of associated domain checks.
>
> In practice, DNS abuse, particularly phishing, malware distribution, and
> botnet activity, rarely occurs in isolation. Abusive actors often rely on
> clusters of domains, rapidly shifting activity to bypass takedowns.
> Associated domain checks provide an important technical signal that allows
> registrars and registries to detect these patterns and intervene
> effectively. Without this tool, enforcement becomes fragmented and
> reactive, enabling bad actors to outpace mitigation efforts.
>
> I share the concern that any enforcement mechanism must be applied
> proportionately, with transparency and safeguards. But I would argue that
> these are implementation issues rather than reasons to reject the concept
> outright. Associated domain checks do not inherently imply arbitrary
> enforcement; rather, they serve as part of a broader, multi-factor review
> process. With safeguards such as registrant notification, appeal
> mechanisms, and transparency reporting, we can achieve both goals:
> effective DNS abuse mitigation and protection of registrant rights.
>
> From my perspective, to rule out associated domain checks entirely risks
> weakening our collective ability to combat abuse at scale. A more
> constructive way forward may be to endorse their inclusion while explicitly
> conditioning their use on due process guarantees.
>
> With that in mind, I would respectfully propose the following alternative
> statement for consideration:
>
> “NCSG approves the DNS Abuse Small Team Report. We acknowledge that
> associated domain checks are an important tool in identifying patterns of
> abuse, especially in clustered infrastructure. However, we emphasize that
> their use must be coupled with clear safeguards—registrant notification,
> transparency, and meaningful opportunities for redress—to ensure fairness,
> proportionality, and accountability. DNS abuse mitigation should protect
> both internet users and registrants, and we support developing
> implementation frameworks that strike this balance.”
>
> Thanks & Regards,
>
> Shiva Upadhyay
> On Thursday 14 August, 2025 at 04:17:19 pm IST, Manju <
> manju4icann at gmail.com> wrote:
>
>
> +1 to the statement. Thank you so much, Farzi!
>
> Best,
> Manju
>
> On Thu, Aug 14, 2025 at 18:12 Johan Helsingius <
> 00001963cc94b85a-dmarc-request at listserv.syr.edu> wrote:
>
> I fully support this.
>
>         Julf
>
>
> On 14/08/2025 01:18, farzaneh badii wrote:
> > Hi all,
> >
> > As we mentioned during the PC meeting, we are planning to vote on
> > approving the small team recommendations on DNS abuse. There were three
> > recommendations that were prioritized, two of which seem to be
> > interesting to investigate. But we (as discussed on this mailing list)
> > had grave concerns about the associated domain check. Here is the small
> > team report: https://gnso.icann.org/sites/default/files/policy/2025/
> > draft/dns-abuse-small-team-report-04aug25-en.pdf <https://
> > gnso.icann.org/sites/default/files/policy/2025/draft/dns-abuse-small-
> > team-report-04aug25-en.pdf>
> >   So tomorrow I will vote for adoption of small team's DNS abuse
> > recommendation but I am planning to read this statement:
> >
> > "NCSG approves the DNS Abuse Small Team Report. However, we wish to
> > formally record our concern regarding the inclusion of /associated
> > domain checks/ as a potential DNS abuse mitigation measure.
> >
> > While we support effective and proportionate approaches to combating DNS
> > abuse, we have consistently emphasized the need for due process at both
> > the registration, detection and enforcement stages. Associated domain
> > checks risk enabling overly broad or arbitrary enforcement—particularly
> > if implemented without robust safeguards to ensure registrants are
> > informed, have a meaningful opportunity to respond, and are protected
> > from collateral harm.
> >
> > Such measures could lead to disproportionate take-down and suspensions
> > and the targeting of legitimate registrants through bulk association-
> > based criteria, undermining fairness, transparency, and accountability.
> > We are also disappointed that due process and access to remedy have not
> > been prioritized by other stakeholders in this work. Domain name
> > registrants are not inherently criminals, and DNS abuse mitigation
> > measures should reflect that presumption.
> >
> > We therefore cannot support the inclusion of associated domain checks
> > unless and until clear, transparent, and consistently applied due
> > process mechanisms are in place."
> >
> >
> >
> > Farzaneh
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20250815/43037cc8/attachment.htm>


More information about the Ncsg-discuss mailing list