registration data accuracy
How correct and usable the contact details in a domain record are. registrant The person or organization that holds a domain name registration. Full definition of registrant must give true data and keep it up to date, and gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD registrar A company that registers domain names for customers with the registry. Full definition of registrar must check parts of it. Wrong data can lead to suspension or cancellation. How to measure accuracy now that most data is hidden is still debated.
- category
- Registration data and privacy
Registration data accuracy is whether the contact details behind a domain name A readable internet name made of labels separated by dots. Full definition of domain name are true, complete and working. The holder must give correct details and keep them current, and the registrar must check some of them. Wrong details can cost the holder the domain.
What registration data accuracy means
For generic top-level domains (gTLDs), the duty comes from ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN’s RAA Registrar Accreditation Agreement The contract between ICANN and each accredited registrar. Full definition of RAA (RAA). The registrant must give “accurate and reliable contact details”. As of October 2026, they must correct them within seven days of any change.
There is no single definition beyond these rules. In the ICANN community, some argue that being able to reach the registrant is enough, while others want identity checks too.
Why accuracy matters
Correct details let the registrar and others reach the holder about technical problems, transfers, disputes and abuse. The European Union’s NIS2 Directive on measures for a high common level of cybersecurity across the Union A European Union cybersecurity directive with rules on accurate domain registration data. Full definition of NIS2 directive links accuracy to the security and stability of the DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS.
Since the GDPR General Data Protection Regulation The European Union data protection law that led to hiding personal data in WHOIS. Full definition of GDPR, most personal data is hidden from public lookups. ICANN says the duties did not change, but errors became harder for outsiders to spot. Hidden data is not the same as wrong data.
Verification checks and reminders
As of October 2026, the RAA’s WHOIS Accuracy Program Specification The section of the registrar contract that sets how registrant contact details must be checked. Full definition of WHOIS Accuracy Program Specification (formerly the WHOIS Accuracy Program Specification) sets two checks for gTLD registrars:
- Validation: the email address, phone number and postal address are correctly formatted, the postal address for its country.
- Verification: the registrant confirms the email address or the phone number, for example by returning a unique code.
Both happen within 15 days of a new registration Obtaining the right to use a domain name for a set period. Full definition of registration, an incoming transfer or a change of registrant A change of a domain's owner details, with confirmation steps. Full definition of change of registrant, and within 15 calendar days of any change to the contact details. Identical data already verified need not be checked again unless there is reason to doubt it. A bounced email forces a new verification.
The RDRP Registration Data Reminder Policy The ICANN policy requiring registrars to remind registrants yearly to check their registration data. Full definition of RDRP (RDRP) adds a yearly prompt. Before each anniversary of the creation date, the registrar shows the registrant the current data and warns that false contact information can lead to cancellation. If everything is correct, no action is needed. The updated policy, formerly the WHOIS Data Reminder Policy, had to be implemented by 21 August 2025.
Registrars must also investigate inaccuracies reported by anyone and take reasonable steps to correct them.
What happens if your data is wrong
If the registrant of example.com ignores the verification email, on day 16 the registrar must verify the data by hand or suspend the domain until it is verified.
Wilfully false data, a wilful failure to update, or no reply for more than 15 days to the registrar’s questions about accuracy is a material breach of the registration agreement. The registrar must then terminate or suspend the name, or place it on clientHold A registrar status that stops a domain from working in the DNS. Full definition of clientHold and clientTransferProhibited A registrar status that blocks transfers to another registrar. Full definition of clientTransferProhibited until the data is validated. The website and email can stop working.
Anyone can report suspected wrong data to ICANN Contractual Compliance The ICANN team that enforces registry and registrar contracts. Full definition of ICANN Contractual Compliance, with evidence such as a bounced email. Valid complaints go to the registrar, which must investigate. Most investigated cases ended with the name suspended or cancelled: 79% from January 2017 to May 2018, and 69% from June 2018 to December 2020.
Measuring accuracy and the policy debate
ICANN’s WHOIS ARS WHOIS Accuracy Reporting System A paused ICANN project that sampled WHOIS records to measure their accuracy. Full definition of WHOIS ARS (ARS) tested records drawn from samples of 10,000 to 12,000 and reported every six months from December 2015 to June 2018. It measured whether data was well formed and whether it worked, never whether the person was who they claimed to be. In the last cycle, 56% of domains passed all operability tests, though 98% of records had at least one working email address or phone number. ICANN paused it after the GDPR, and as of October 2026 it has not restarted.
The GNSO Generic Names Supporting Organization The ICANN body that develops policy for generic top-level domains. Full definition of GNSO Council set up the Registration Data Accuracy Scoping Team A GNSO group that studied registration data accuracy from 2021, paused, and was formally ended in 2025. Full definition of Registration Data Accuracy Scoping Team in July 2021. In September 2022 the team proposed a registrar survey and a registrar audit. The work was paused in November 2022, and in September 2024 the Council deferred the two proposals for six more months.
In 2025 the Council approved four recommendations from a small Council team: re-examine validation and verification, create education materials for registrants, mark names suspended for wrong data in their records, and discontinue the Scoping Team’s work. The first cites the INFERMAL Inferential Analysis of Maliciously Registered Domains An ICANN-funded study of which registration features attract malicious domain registrations. Full definition of INFERMAL, which reported 70% fewer malicious registrations where contact details were checked before or during registration. The small team did not endorse the study’s methods or conclusions.
EU rules: NIS2 and ccTLDs
ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD are not bound by the RAA. In the European Union, Article 28 of NIS2 requires TLD top-level domain The last part of a domain name, after the final dot. Full definition of TLD registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry and registrars to keep accurate and complete data, including the registrant’s name, email and phone, and to publish their verification procedures; a recital adds that at least one means of contact should be verified. Member states had to apply it through national law from 18 October 2024, so details differ by country.
For .eu, EURid The nonprofit registry that runs .eu under contract with the European Commission. Full definition of EURid published a Registration Data Verification Policy in October 2024 under Belgium’s NIS2 law. A name flagged as possibly linked to abuse is suspended at once and reactivated only after its data is verified; if not verified within a set time, it is withdrawn and released for registration.
For .es, Spain’s national plan for .es names makes the applicant An organization that has applied to ICANN to run a new gTLD. Full definition of applicant responsible for the truth and accuracy of their data and requires immediate updates. Red.es The Spanish public body that manages the .es domain through its unit Dominios.es. Full definition of Red.es does not verify data at registration; it checks afterwards, including on reports from public bodies. As of October 2026, the registrar, holder and administrative contact get 15 calendar days to fix the data while the name keeps working. Then Red.es opens a special cancellation procedure: the holder has 30 calendar days to respond, and the name stops working after the first 10. Holders unsure of their position should ask their registrar, Red.es or a lawyer.
Sources
- Registrar Accreditation Agreement, opens another website in a new tab
- ICANN Organization Enforcement of Registration Data Accuracy Obligations Before and After GDPR, opens another website in a new tab
- GNSO Council Accuracy Small Team Summary, opens another website in a new tab
- EURid: Data quality, opens another website in a new tab
- Dominios.es: Cancela un dominio, opens another website in a new tab