DNS abuse

Harmful use of domain name A readable internet name made of labels separated by dots. Full definition of domain name or the DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS. Since 5 April 2024, ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN's gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD contracts define it as malware Harmful software, often spread or controlled using domain names. Full definition of malware, botnet A network of infected computers controlled by an attacker. Full definition of botnet, phishing Impersonating a trusted party to steal data, often with look-alike domains. Full definition of phishing, pharming Redirecting users to fake sites even when they type the right domain. Full definition of pharming, and spam Unwanted bulk messages, which count as DNS abuse only when used to deliver other abuse. Full definition of spam used to deliver those. registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry and registrar A company that registers domain names for customers with the registry. Full definition of registrar must act promptly on well-evidenced reports. Other groups use wider definitions.

category
Security and abuse

Updated on 4 min read

DNS abuse is the use of domain names to harm people: spreading harmful software, controlling hacked computers or tricking people into giving away passwords. In ICANN’s contracts with the companies that run and sell generic domains, it has a narrow, fixed meaning, and those companies must act on good evidence of it. What a website says or sells is a separate matter.

What DNS abuse is

Broadly, DNS abuse is any harmful use of domain names or the DNS. Since 5 April 2024, ICANN’s gTLD contracts, the RAA Registrar Accreditation Agreement The contract between ICANN and each accredited registrar. Full definition of RAA and the Registry Agreement The contract between ICANN and a gTLD registry operator. Full definition of Registry Agreement, define it as five harms, using definitions from the SSAC Security and Stability Advisory Committee ICANN's expert committee on security and stability of naming and addressing. Full definition of SSAC report SAC 115.

The industry drew up the list first. Registries and registrars launched the voluntary Framework to Address Abuse A voluntary industry pledge that defined DNS abuse and when registries and registrars act. Full definition of Framework to Address Abuse in October 2019 with the same five categories; as of October 2026 it has 48 signatories. The ICANN Board ICANN's board of directors, which adopts policies and approves key decisions. Full definition of ICANN Board approved the contract changes on 21 January 2024.

ICANN keeps the definition narrow to stay within its remit. Some ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD, which ICANN’s contracts do not bind, also count fraud and scams.

The five types in ICANN’s definition

  • Malware: harmful software run without the user’s consent.
  • Botnets: networks of infected computers that a remote attacker controls, often through command and control domains.
  • Phishing: tricking victims into revealing passwords or other sensitive data through look-alike messages or copycat websites.
  • Pharming: sending users to fraudulent sites by hijacking or poisoning DNS answers. Phishing tricks the person; pharming changes the DNS.
  • Spam: unsolicited bulk email, counted only when it delivers one of the other four.

fast flux Rapidly rotating the IP addresses behind a domain to hide and protect malicious servers. Full definition of fast flux and DGA domain generation algorithm Malware code that generates many domain names so infected machines can find their controller. Full definition of DGA are techniques that serve these harms, not separate categories.

DNS abuse versus content abuse

ICANN’s Bylaws forbid it to regulate the content that services using domain names carry, and the 2024 amendments deliberately left website content out. Counterfeit goods or illegal speech on a working website are content abuse. General fraud, such as cryptocurrency scams, is also outside the contractual definition. Besides, registries and registrars cannot remove a single page; they can only act on the whole domain.

The Framework still names four kinds of content where a registry or registrar should act without a court order: CSAM child sexual abuse material Child sexual abuse material, a type of illegal content registries and registrars act on directly. Full definition of CSAM, illegal online sale of opioids, human trafficking, and specific and credible incitements to violence. The IWF Internet Watch Foundation A British charity that reports child sexual abuse material, including to registries and registrars. Full definition of IWF, a hotline based in the United Kingdom, works to get CSAM removed; as of October 2026, registries and registrars can receive its alerts at no cost.

Malicious versus compromised domains

A maliciously registered domain was registered to cause harm. A compromised domain belongs to an innocent registrant The person or organization that holds a domain name registration. Full definition of registrant whose website or account was hacked. Suspending it would also cut off the legitimate site, its email and every subdomain A name created under a registered domain, like shop.example.com. Full definition of subdomain, so ICANN says suspension may not be the right step.

Two cases from ICANN’s guidance, shown with reserved name A name a registry withholds from normal registration, by rule or by its own choice. Full definition of reserved name:

  • A phishing link posing as a bank leads to bank-login.example, registered five days earlier. The registrar suspends it with clientHold A registrar status that stops a domain from working in the DNS. Full definition of clientHold within two business days.
  • A phishing page sits on city.autobrand.example, a subdomain of a car dealer’s three-year-old domain. Within three business days, the registrar asks the registrant to remove it by a set date.

These timelines are illustrations, not deadlines.

What registries and registrars must do

For gTLDs, since 5 April 2024:

  1. Registrars publish an abuse email address or web form on their homepage, with no login, and confirm each report.
  2. Registries publish an abuse contact The published contact where registrars and registries receive abuse reports. Full definition of abuse contact, including a postal address.
  3. With actionable evidence The level of proof that obliges a registry or registrar to act on DNS abuse. Full definition of actionable evidence, enough to decide reasonably that a name is used for DNS abuse, the registrar must promptly act to stop or disrupt it, weighing collateral damage. The registry must at least refer the case to the registrar, or act directly.
  4. No fixed deadline defines “promptly”, and no one has to break applicable law.

After reporting to the registrar and waiting a reasonable time, a reporter may complain to ICANN Contractual Compliance The ICANN team that enforces registry and registrar contracts. Full definition of ICANN Contractual Compliance. An uncured notice of breach can lead to suspension or termination of the contract. As of October 2026, ICANN reports nearly 530 investigations between 5 April 2024 and 5 April 2026, more than 480 of them resolved: about 66 percent led to action that stopped the abuse and another 8 percent to steps that disrupted it. Over 25,000 domains were mitigated, and four DNS abuse notices of breach were issued.

On 11 December 2025 the GNSO Generic Names Supporting Organization The ICANN body that develops policy for generic top-level domains. Full definition of GNSO Council started two PDP Policy Development Process ICANN's formal process for creating new policy. Full definition of PDP: the first, on associated domain checks, closed public comment An open period when anyone can comment on ICANN drafts. Full definition of public comment on its Initial Report on 28 September 2026; the second had not convened as of October 2026. Neither has added obligations.

In the European Union, NIS2 Directive on measures for a high common level of cybersecurity across the Union A European Union cybersecurity directive with rules on accurate domain registration data. Full definition of NIS2 requires EU countries, through their national laws (due by 17 October 2024), to make TLD top-level domain The last part of a domain name, after the final dot. Full definition of TLD registries and registration Obtaining the right to use a domain name for a set period. Full definition of registration providers, ccTLDs included, keep accurate, verified registration data The information kept about a domain and its owner. Full definition of registration data and answer access requests within 72 hours; as of October 2026, national laws vary. The directive mentions DNS abuse only as a reason for these duties; it neither defines it nor requires takedown Action that stops a harmful domain from working, such as suspension. Full definition of takedown.

How abuse is measured

Most figures come from reputation blocklist A published list of domains or IP addresses to block for spam, phishing or malware. Full definition of blocklist. A listed domain has been reported, not proven abusive, so counts are at best an upper limit.

As of October 2026, ICANN Domain Metrica ICANN's platform measuring reported abuse across registries and registrars, successor to Domain Abuse Activity Reporting. Full definition of ICANN Domain Metrica tracks phishing, malware and botnet command and control, but not general spam, by TLD and by registrar. In September 2026 it added Time to Mitigation, an estimate of how long a reported domain keeps working.

Sources