Tomorrow's GNSO council meeting, DNS Abuse Small Team recommendations approval

Shiva Upadhyay shiva.upadhyay at YAHOO.COM
Sun Aug 17 05:53:20 EEST 2025


 
Hi Farzaneh,

Thanks for the thoughtful follow-up and for keeping this discussion grounded in rights and due process. I respect the decision NCSG reached and the values behind it. I’d like to offer a different view on how we might reconcile those values with the operational need to address clustered DNS abuse, and suggest a path that narrows the risks you flagged.

On overbroad blocking/collateral damage
Totally agreed, this is the core hazard. The answer, in my view, is scoping and proportionality, not abandoning the tool:
   
   -    
Treat “association” as a multi-factor signal, not a single shared attribute. Require at least two strong links (e.g., common registrant/payment + corroborated abuse pattern), followed by human review.

   -    
Default to least-intrusive mitigation: warn/lock, then sinkhole or narrowly disable the specific abusive label; reserve full suspension for persistent/confirmed cases.

   -    
Document the decision path (what signals, what review, what action) so good actors caught in the net can be restored quickly.



On transparency and remedy for end users/registrants
I share the concern that opacity erodes trust. We can fix that with a process:

   
   -    
Notice & reasons to the registrant (and, where feasible, a public-facing explanation page for blocked labels).

   -    
A fast, simple appeals channel with defined SLAs and a presumption of restoration when evidence shows error or remediation.

   -    
Aggregate transparency: periodic stats on flagged associations, actions taken, reversals, and error rates.



On chilling effects on speech and service availability
A narrowly defined, reactive associated-check (triggered only after confirmed abuse) with public criteria is far less likely to chill speech than broad, preemptive monitoring. Publishing what counts as “association,” and requiring human validation before action, helps creators and service operators understand the rules and avoid self-censorship.



On disproportionate impact on at-risk communities
Fully agreed that vague “association” can be misused. Guardrails can and should include:

   
   -    
A human-rights impact assessment before adoption; periodic review after.

   -    
A bright-line focus on technical DNS abuse (malware/phishing/botnets), not content adjudication.

   -    
Independent review for escalated cases and consistent, extraterritorial application so rules can’t be weaponized locally.


Concrete safeguards (what I’d support in writing)
   
   -    
Tight, published definition of “association” (multi-factor, evidence-based).

   -    
Human review before enforcement; machines flag, people decide.

   -    
Proportional, stepwise response (warn → restrict changes → sinkhole → suspend as last resort).

   -    
Mandatory notice, reasons, and an easy appeal with clear timelines.

   -    
Public metrics and periodic audits (including error-rate reporting).

   -    
HRIAs and a clear carve-out from content policing.

   -    
Sunset/review clause to refine or retire the tool if the harms outweigh the benefits.


If helpful, here’s compromise language I’d be comfortable supporting. If we have already voted, then please keep it as a future reference:
“NCSG reaffirms that registrant and end-user rights, including freedom of expression and access to information, must anchor any DNS abuse response. We recognize that coordinated abuse frequently relies on clusters of domains and infrastructure. Investigating associated domains may be considered only within a narrowly defined, evidence-based and transparent framework that includes: (i) multi-factor association criteria and human validation; (ii) proportional, least-intrusive remedies; (iii) timely notice and accessible appeals; (iv) public reporting and independent review; and (v) a prior human-rights impact assessment. Absent these safeguards, we do not support deployment. With them, the aim is a balanced system that protects internet users while safeguarding legitimate speech and registrants.”

I appreciate the dialogue and am very open to refining the safeguards above. My goal is the same as yours: a rights-respecting approach that actually dismantles abusive infrastructure without collateral damage.

Warm Regards,Shiva Upadhyay    On Saturday 16 August, 2025 at 06:18:29 am IST, farzaneh badii <farzaneh.badii at gmail.com> wrote:  
 
 Hi Shiva,
Thank you very much and for your constructive feedback. We had a discussion about this on the list a few weeks back and members agreed to withdraw our support from the associated domain check. The statement tried to capture that discussion and generally NCSG's longstanding values and was read out yesterday so unfortunately we can't incorporate your changes but this is an ongoing conversation. Also we didn't withdraw support from the report as a whole but withdrew our support from this recommendation to investigate.
Our concern with associated domain checks is not limited to domain name registrants. This mechanism can also significantly impact end users’ rights, particularly freedom of expression and access to information. Overbroad blocking of “associated” domains risks removing lawful websites and services, cutting off important sources of information and tools that users rely on. Because these determinations are often opaque, affected users typically receive no notice and have no way to challenge a mistake. In practice, such measures can disproportionately affect marginalized communities and independent media, especially in environments with weak rule of law, where “association” may be used as a pretext for censorship.
Please see the examples below: 
1. Overbroad blocking leading to collateral damage
   
   - If a domain is flagged as “associated” with abuse, entire domains or subdomains can be suspended or blocked.
   - This can remove lawful content and services hosted alongside or under the same infrastructure, preventing end users from accessing information or tools they rely on.

Example:
A shared hosting provider has hundreds of legitimate small business websites. If one is compromised and associated domain checks link others incorrectly, the entire set could be disabled.




2. Lack of transparency and remedy for affected users
   
   - End users generally aren’t notified when a site they visit is blocked due to an associated domain determination.
   - There’s no accessible appeals process for them, even if the information they sought was lawful and important.
   - This lack of remedy erodes trust and leaves users without a path to challenge mistaken or excessive enforcement.




3. Chilling effect on speech and service availability
   
   - Content creators and service providers may self-censor or avoid certain infrastructure for fear of being linked to an abusive actor through automated association.
   - This indirectly limits diversity of content and services available to the public.




4. Disproportionate impact on marginalized or at-risk communities
   
   - In countries with poor press freedom or weak rule of law, “association” can be used as a pretext to suppress independent media, activist groups, or opposition voices.
   - Automated checks make it easier to justify blocking them without a specific, substantiated abuse case.

I would like to also caution us against supporting "proactive" measures before doing human rights impact assessment and having the remedy in place. 




Best regards, 

Farzaneh 

On Fri, Aug 15, 2025 at 6:54 PM Shiva Upadhyay <0000055b426785d6-dmarc-request at listserv.syr.edu> wrote:

 
Dear Farzaneh and colleagues,

Thank you for sharing your draft statement and for raising these concerns in such a thoughtful way. I fully respect the emphasis on due process and registrant rights, which are central to any credible DNS abuse framework. However, I would like to humbly offer a different perspective on the question of associated domain checks.

In practice, DNS abuse, particularly phishing, malware distribution, and botnet activity, rarely occurs in isolation. Abusive actors often rely on clusters of domains, rapidly shifting activity to bypass takedowns. Associated domain checks provide an important technical signal that allows registrars and registries to detect these patterns and intervene effectively. Without this tool, enforcement becomes fragmented and reactive, enabling bad actors to outpace mitigation efforts.

I share the concern that any enforcement mechanism must be applied proportionately, with transparency and safeguards. But I would argue that these are implementation issues rather than reasons to reject the concept outright. Associated domain checks do not inherently imply arbitrary enforcement; rather, they serve as part of a broader, multi-factor review process. With safeguards such as registrant notification, appeal mechanisms, and transparency reporting, we can achieve both goals: effective DNS abuse mitigation and protection of registrant rights.

>From my perspective, to rule out associated domain checks entirely risks weakening our collective ability to combat abuse at scale. A more constructive way forward may be to endorse their inclusion while explicitly conditioning their use on due process guarantees.

With that in mind, I would respectfully propose the following alternative statement for consideration:

“NCSG approves the DNS Abuse Small Team Report. We acknowledge that associated domain checks are an important tool in identifying patterns of abuse, especially in clustered infrastructure. However, we emphasize that their use must be coupled with clear safeguards—registrant notification, transparency, and meaningful opportunities for redress—to ensure fairness, proportionality, and accountability. DNS abuse mitigation should protect both internet users and registrants, and we support developing implementation frameworks that strike this balance.”

Thanks & Regards,
Shiva Upadhyay    On Thursday 14 August, 2025 at 04:17:19 pm IST, Manju <manju4icann at gmail.com> wrote:  
 
 +1 to the statement. Thank you so much, Farzi!
Best,Manju
On Thu, Aug 14, 2025 at 18:12 Johan Helsingius <00001963cc94b85a-dmarc-request at listserv.syr.edu> wrote:

I fully support this.

        Julf


On 14/08/2025 01:18, farzaneh badii wrote:
> Hi all,
> 
> As we mentioned during the PC meeting, we are planning to vote on 
> approving the small team recommendations on DNS abuse. There were three 
> recommendations that were prioritized, two of which seem to be 
> interesting to investigate. But we (as discussed on this mailing list) 
> had grave concerns about the associated domain check. Here is the small 
> team report: https://gnso.icann.org/sites/default/files/policy/2025/ 
> draft/dns-abuse-small-team-report-04aug25-en.pdf <https:// 
> gnso.icann.org/sites/default/files/policy/2025/draft/dns-abuse-small- 
> team-report-04aug25-en.pdf>
>   So tomorrow I will vote for adoption of small team's DNS abuse 
> recommendation but I am planning to read this statement:
> 
> "NCSG approves the DNS Abuse Small Team Report. However, we wish to 
> formally record our concern regarding the inclusion of /associated 
> domain checks/ as a potential DNS abuse mitigation measure.
> 
> While we support effective and proportionate approaches to combating DNS 
> abuse, we have consistently emphasized the need for due process at both 
> the registration, detection and enforcement stages. Associated domain 
> checks risk enabling overly broad or arbitrary enforcement—particularly 
> if implemented without robust safeguards to ensure registrants are 
> informed, have a meaningful opportunity to respond, and are protected 
> from collateral harm.
> 
> Such measures could lead to disproportionate take-down and suspensions 
> and the targeting of legitimate registrants through bulk association- 
> based criteria, undermining fairness, transparency, and accountability. 
> We are also disappointed that due process and access to remedy have not 
> been prioritized by other stakeholders in this work. Domain name 
> registrants are not inherently criminals, and DNS abuse mitigation 
> measures should reflect that presumption.
> 
> We therefore cannot support the inclusion of associated domain checks 
> unless and until clear, transparent, and consistently applied due 
> process mechanisms are in place."
> 
> 
> 
> Farzaneh

  
  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20250817/af814904/attachment.htm>


More information about the Ncsg-discuss mailing list