[Ncsg-discuss] SCCI Criteria 4 - “domain name security threats”
Johan Helsingius
00001963cc94b85a-dmarc-request at LISTSERV.SYR.EDU
Wed Jun 17 13:47:56 EEST 2026
Thank you for the clarification, Manju!
Julf
On 17/06/2026 9:02 am, Manju wrote:
> Hi all,
>
> Thank you very much for the discussion.
> As mentioned by Julf, I'm the chair of SCCI and have to maintain
> neutrality when it comes to the discussion of substance. However, I
> believe I'm allowed to provide some context and clarification on this
> issue.
>
> The change from domain name security threat to DNS Abuse was actually an
> effort of the SCCI to tighten the scope, not the contrary. The general
> agreement within the SCCI was that "domain name security threat" can be
> interpreted to have a broader remit that is beyond GNSO's mission and
> scope, which prompted the change to 'DNS Abuse' as narrowly defined in
> the contract.
>
> One of the examples that can be understood as 'combating domain name
> security threat', as shared during our SCCI working session in Seville,
> is the Internationalized Domain Names PDP, which regulates the variant
> management of IDNs. By this example, it should be clear that domain name
> security threat actually has a broader scope than DNS abuse, the latter
> of which is narrowly defined and codified in contract.
>
> Hope this helps.
>
> Best,
> Manju
>
> On Tue, Jun 16, 2026 at 8:36 PM farzaneh badii <00001deb507b73c5-dmarc-
> request at listserv.syr.edu <mailto:00001deb507b73c5-dmarc-
> request at listserv.syr.edu>> wrote:
>
> Hi Julf
>
> I agree and we tried really hard in our public comments to mention
> the security threat and not frame it as DNS abuse, but the CPH and
> others were really keen on adding DNS abuse at the time. Maybe we
> can clarify that DNS abuse as narrowly defined in RAAs.
>
>
>
> Farzaneh
>
>
> On Tue, Jun 16, 2026 at 10:22 AM 鄭嘉逸 Chia I Cheng
> <00001edb87ceea84-dmarc-request at listserv.syr.edu
> <mailto:00001edb87ceea84-dmarc-request at listserv.syr.edu>> wrote:
>
>
> Hi all,
>
> I'm broadly aligned with the direction of the discussion, but I
> think it's worth pausing to consider why this proposed change is
> being raised within the SCCI framework specifically — that
> context seems important to how we shape our response.
>
> On the substantive question: is excluding "DNS Abuse" altogether
> actually to our advantage? If the term can be held to a narrow,
> operationally precise definition — one explicitly grounded in
> user rights and human rights principles — we may end up with
> more meaningful control over how it is applied than a rejection
> would give us.
>
> Best,
>
> Chia-I
>
> *寄件者: *NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU
> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>> 代表 NPC SVG
> <0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU
> <mailto:0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU>>
> *日期: *星期二, 2026年6月16日 清晨6:12
> *收件者: *NCSG-DISCUSS at LISTSERV.SYR.EDU <mailto:NCSG-
> DISCUSS at LISTSERV.SYR.EDU> <NCSG-DISCUSS at LISTSERV.SYR.EDU
> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>>
> *主旨: *Re: SCCI Criteria 4 - “domain name security threats”
>
> Like Abbas and Julf , I also believe the use of the term DNS
> abuse broadens the indicator into an area unsuitable for the
> GNSO council for reasons described below.
>
> RD
>
> On Mon, Jun 15, 2026, 3:08 PM <0000222a86a53d44-dmarc-
> request at listserv.syr.edu <mailto:0000222a86a53d44-dmarc-
> request at listserv.syr.edu>> wrote:
>
> Julf, I agree with the analysis by Abbas. Explicitly
> Including “DNS abuse” broadens the indicator into an area
> unsuitable for the GNSO Council for the reasons he describes.
>
> In terms of a statement, we can perhaps relate something
> like “the ICANN community has reached general consensus
> around a narrow set of DNS security threats (phishing,
> malware, botnets, pharming, and spam as a delivery
> mechanism). However, there has not been universal
> stakeholder consensus on the broader conceptual definition
> of DNS Abuse or on where the boundary lies between DNS abuse
> and content abuse. Therefore, since the term DNS abuse” can
> mean different things to different stakeholders, even within
> the narrow threats mentioned, by including "DNS abuse" as an
> indicator for evaluating the performance of the GNSO council
> risks creating unclear, and potentially unrealistic,
> expectations for achieving the stated criteria, to say
> nothing of the opportunity for debate regarding whether or
> not the criteria has been met.”
>
> I hope this helps.
>
> Ken
>
> *From:* NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU
> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>> *On Behalf Of *Abbas
> Sibai
> *Sent:* Monday, June 15, 2026 9:33 AM
> *To:* NCSG-DISCUSS at LISTSERV.SYR.EDU <mailto:NCSG-
> DISCUSS at LISTSERV.SYR.EDU>
> *Subject:* Re: SCCI Criteria 4 - “domain name security threats”
>
> Hi Julf,
>
> Thanks for flagging this. As an individual member of the
> NCUC, I completely share your concerns. Specifically
> inserting the term "DNS Abuse" into the GNSO Continuous
> Improvement Program framework is a major red flag that we
> definitely need to push back against during the upcoming
> call on Wednesday, 1 July 2026.
>
> From our constituency’s perspective, my understanding is
> that there are two distinct "cans of worms" this proposal
> opens up:
>
> * *Mission Creep and Content Regulation:* Broadening the
> text to explicitly name "DNS Abuse" risks shifting the
> GNSO's focus from core technical layer infrastructure
> toward content regulation. What I understood is that the
> NCUC has a long-standing commitment to fiercely
> protecting freedom of expression and digital rights. If
> the indicators explicitly target "DNS Abuse" rather than
> strictly defined security threats, it invites outside
> pressure on the GNSO to police website content, a
> precedent that directly undermines our core mission and
> human rights principles.
> * *Disproportionality and Human Rights Impacts:* I also
> understood that NCUC has consistently advocated that
> any policy intervention addressing domain security must
> be narrow, proportionate, and strictly scoped. Tying the
> evaluation of the GNSO's performance to broad and
> subjective perceptions of "DNS Abuse" (especially via a
> survey indicator) creates an incentive to pass sweeping,
> reactive policies. This places innocent registrants at
> risk of collective or automated domain suspensions
> without adequate due process or Human Rights Impact
> Assessments (HRIAs).
>
> The original text, focusing strictly on "mitigating domain
> name security threats," keeps the evaluation grounded within
> the GNSO's technical and contractual scope. The proposed
> revision unnecessarily complicates it and opens the door to
> over-policing at the registry/registrar level.
>
> I fully support our leadership taking a strong stance
> against this text on Wednesday. Please let me know if you
> need any assistance with drafting a formal statement or if
> there are specific points you want supported during the call.
>
>
> Warm Regards,
>
> *Abbas Sibai*
> *Policy & Advocacy Specialist*
>
> +9613824725 <tel:+9613824725>
>
>
>
> *|*
>
>
>
> https://www.linkedin.com/in/abbas-sibai/ <https://
> www.linkedin.com/in/abbas-sibai/>
>
>
>
> On Mon, Jun 15, 2026 at 12:28 PM Johan Helsingius
> <00001963cc94b85a-dmarc-request at listserv.syr.edu
> <mailto:00001963cc94b85a-dmarc-request at listserv.syr.edu>> wrote:
>
> Hi all,
>
> I am the NCSG representative to the Standing Committee on
> Continuous
> Improvement (SCCI) that is formulating the Continuous
> Improvement
> Program framework. The SCCI is chaired by Manju, another
> NCSG:er, but
> as chair she has to remain neutral.
>
> The work until now has been developing the Criteria and
> Indicators
> that will be used to judge how well the GNSO processes are
> working.
>
> We have made good progress under the very capable leadership
> of Manju,
> and most issues haven't been very controversial, but I want
> to flag
> the current issue where we probably want to speak up against
> the current
> proposal.
>
> The issue is Criteria 4, "The GNSO actively combats domain name
> security threats", where there is a proposal to change the draft
> text from:
>
> Indicator 1: The GNSO has demonstrated meaningful
> activity towards
> mitigating domain name security threats.
>
> Indicator 2: 66% of surveyed respondents agree that
> the GNSO
> combats domain name security threats.
>
> to:
>
> Indicator 1: The GNSO has demonstrated meaningful
> activity towards
> mitigating DNS Abuse and security threats
> relating to
> domain names that are in scope for the GNSO.
>
>
> Indicator 2: 66% of surveyed respondents agree that
> the GNSO has
> demonstrated meaningful activity towards
> mitigating
> DNS Abuse and security threats relating
> to domain
> names that are in scope for the GNSO.
>
> While we probably are OK with mitigating domain name
> security threats,
> specifically mentioning DNS Abuse opens up some cans of worms.
>
> We will have a chance to present our views at the next SCCI
> call on
> Wednesday, 1 July 2026, so I welcome your comments/opinions.
>
> Julf
>
More information about the Ncsg-discuss
mailing list