Build1 publisher2 min readPublished
Associated Domain Checks would make a registrar look past the domain in the complaint
A working group inside ICANN is drafting an obligation that would reach other domains tied to a confirmed abusive one. What triggers the check, and whether it runs before the first suspension, is unsettled.
The Engineer · Build desk

What happened
- Since April 2024 the Registrar Accreditation Agreement has required a registrar to investigate the domain named in an abuse complaint and mitigate that one domain if the evidence holds up.
- ICANN's DNS Abuse Small Team called the gap between closing one report and stopping an operation the highest-priority target when it scoped the community's policy work in late 2025.
- The GNSO Council adopted a working group charter for Associated Domain Checks in January 2026, and the group held four dedicated sessions at ICANN85 in Mumbai and four more at ICANN86 in Seville.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint The enforcement record counts domains and not operators, so the community is setting a threshold without a public measure of how much campaign infrastructure the current rule leaves standing.
- decision The ordering question decides whether the associated check delays suspension of a confirmed phishing domain in order to cover the portfolio behind it.
- exposure A shared registrar account becomes a liability for organisations that never received a complaint, because that is how brand-defense and inherited domains are usually held.
- precedent If the check ships near its current scope, the unit evaluated when abuse is found becomes the registrant account. Later obligations will be drafted against that unit.
ICANN Compliance's two-year enforcement report describes more than one domain per report. It counts more than 480 resolved investigations, roughly two thirds of them ending in direct registrar action [4]. That is about 320 investigations, and against them sit more than 25,000 mitigated domains [5][16]. If those mitigations came out of those investigations, the average action covered about 78 domains [16]. The report does not say how many of the 25,000 belonged to the same operator [6].
Batching, then, already happens somewhere in practice. Under the current rule, going looking for it is up to the registrar. Since April 2024 the Registrar Accreditation Agreement has scoped the duty to the domain named in the complaint, with suspension the usual remedy and a lighter disruption measure for domains that were compromised instead of registered for the purpose [1][3].
Associated Domain Checks would change the object of that duty. According to the dev.to account published by ntctech, the direction under discussion has a registrar, once a domain under its management is confirmed engaged in abuse, check other domains associated through defined signals and evaluate whether those domains warrant further action [11]. Which signals count and what evaluation obliges set what that costs to run. The signals in the abuse pattern the group is aiming at are a shared account, a shared registrant contact, or another identifying marker across dozens or hundreds of domains registered in bursts [7].
Ordering is the operational question, and it is open [12]. Require the associated check before mitigation of the confirmed domain, and the time to suspend a live phishing site becomes a function of how many domains share that account. Allow it afterwards, and the operator keeps the window it has now, cycling to the next disposable name [7].
The risk runs in the other direction as well. Working group members raised guilt by association directly: a framework built too loosely could sweep in a registrant's unrelated, legitimate domains on the strength of a shared account [13]. Enterprise footprints are assembled from brand-defense registrations, regional and country-code variants, and domains inherited through subsidiaries and acquisitions, and the account argues the check's assumption was not built around structures like that [15].
This is all draft. Thirteen months separate the charter from the working group's target for its Initial Report, February 2027 [14][17]. The threshold that triggers a check is still unsettled [12].
What to watch
- Whether the Initial Report sets one confirmed abusive domain as the trigger or requires corroborating evidence first.
- Whether the draft text places the associated check before or after mitigation of the originally reported domain.
- Whether the group defines the signal list narrowly, and in particular whether a shared registrar account alone qualifies.