---
id: "dns-abuse"
kind: "glossary-term"
title: "DNS abuse"
language: "en"
category: "Security and abuse"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/dns-abuse/"
translations:
  es: "https://tldlog.com/es/glosario/uso-indebido-dns/"
  de: "https://tldlog.com/de/glossar/dns-missbrauch/"
  fr: "https://tldlog.com/fr/glossaire/utilisation-malveillante-dns/"
  it: "https://tldlog.com/it/glossario/abuso-dns/"
  pt-BR: "https://tldlog.com/pt/glossario/abuso-dns/"
  ru: "https://tldlog.com/ru/glossariy/zloupotreblenie-dns/"
  zh-Hans: "https://tldlog.com/zh/cihui/dns-lanyong/"
---

# DNS abuse

Harmful use of domain names or the DNS. Since 5 April 2024, ICANN's gTLD contracts define it as malware, botnets, phishing, pharming, and spam used to deliver those. Registries and registrars must act promptly on well-evidenced reports. Other groups use wider definitions.

DNS abuse is the use of domain names to harm people: spreading harmful software, controlling hacked computers or tricking people into giving away passwords. In ICANN's contracts with the companies that run and sell generic domains, it has a narrow, fixed meaning, and those companies must act on good evidence of it. What a website says or sells is a separate matter.

## What DNS abuse is

Broadly, DNS abuse is any harmful use of domain names or the DNS. Since 5 April 2024, ICANN's gTLD contracts, the RAA and the Registry Agreement, define it as five harms, using definitions from the SSAC report SAC 115.

The industry drew up the list first. Registries and registrars launched the voluntary Framework to Address Abuse in October 2019 with the same five categories; as of October 2026 it has 48 signatories. The ICANN Board approved the contract changes on 21 January 2024.

ICANN keeps the definition narrow to stay within its remit. Some ccTLDs, which ICANN's contracts do not bind, also count fraud and scams.

## The five types in ICANN's definition

- **Malware:** harmful software run without the user's consent.
- **Botnets:** networks of infected computers that a remote attacker controls, often through command and control domains.
- **Phishing:** tricking victims into revealing passwords or other sensitive data through look-alike messages or copycat websites.
- **Pharming:** sending users to fraudulent sites by hijacking or poisoning DNS answers. Phishing tricks the person; pharming changes the DNS.
- **Spam:** unsolicited bulk email, counted only when it delivers one of the other four.

Fast flux and DGAs are techniques that serve these harms, not separate categories.

## DNS abuse versus content abuse

ICANN's Bylaws forbid it to regulate the content that services using domain names carry, and the 2024 amendments deliberately left website content out. Counterfeit goods or illegal speech on a working website are content abuse. General fraud, such as cryptocurrency scams, is also outside the contractual definition. Besides, registries and registrars cannot remove a single page; they can only act on the whole domain.

The Framework still names four kinds of content where a registry or registrar should act without a court order: CSAM, illegal online sale of opioids, human trafficking, and specific and credible incitements to violence. The IWF, a hotline based in the United Kingdom, works to get CSAM removed; as of October 2026, registries and registrars can receive its alerts at no cost.

## Malicious versus compromised domains

A maliciously registered domain was registered to cause harm. A compromised domain belongs to an innocent registrant whose website or account was hacked. Suspending it would also cut off the legitimate site, its email and every subdomain, so ICANN says suspension may not be the right step.

Two cases from ICANN's guidance, shown with reserved names:

- A phishing link posing as a bank leads to bank-login.example, registered five days earlier. The registrar suspends it with clientHold within two business days.
- A phishing page sits on city.autobrand.example, a subdomain of a car dealer's three-year-old domain. Within three business days, the registrar asks the registrant to remove it by a set date.

These timelines are illustrations, not deadlines.

## What registries and registrars must do

For gTLDs, since 5 April 2024:

1. **Registrars** publish an abuse email address or web form on their homepage, with no login, and confirm each report.
2. **Registries** publish an abuse contact, including a postal address.
3. **With actionable evidence**, enough to decide reasonably that a name is used for DNS abuse, the registrar must promptly act to stop or disrupt it, weighing collateral damage. The registry must at least refer the case to the registrar, or act directly.
4. **No fixed deadline** defines "promptly", and no one has to break applicable law.

After reporting to the registrar and waiting a reasonable time, a reporter may complain to ICANN Contractual Compliance. An uncured notice of breach can lead to suspension or termination of the contract. As of October 2026, ICANN reports nearly 530 investigations between 5 April 2024 and 5 April 2026, more than 480 of them resolved: about 66 percent led to action that stopped the abuse and another 8 percent to steps that disrupted it. Over 25,000 domains were mitigated, and four DNS abuse notices of breach were issued.

On 11 December 2025 the GNSO Council started two PDPs: the first, on associated domain checks, closed public comment on its Initial Report on 28 September 2026; the second had not convened as of October 2026. Neither has added obligations.

In the European Union, NIS2 requires EU countries, through their national laws (due by 17 October 2024), to make TLD registries and registration providers, ccTLDs included, keep accurate, verified registration data and answer access requests within 72 hours; as of October 2026, national laws vary. The directive mentions DNS abuse only as a reason for these duties; it neither defines it nor requires takedowns.

## How abuse is measured

Most figures come from reputation blocklists. A listed domain has been reported, not proven abusive, so counts are at best an upper limit.

As of October 2026, ICANN Domain Metrica tracks phishing, malware and botnet command and control, but not general spam, by TLD and by registrar. In September 2026 it added Time to Mitigation, an estimate of how long a reported domain keeps working.

## Sources

- [Advisory: Compliance With DNS Abuse Obligations in the Registrar Accreditation Agreement and the Registry Agreement](https://www.icann.org/en/contracted-parties/advisories/documents/advisory-compliance-with-dns-abuse-obligations-in-the-registrar-accreditation-agreement-and-the-registry-agreement-05-02-2024-en)
- [Two Years of Enforcing DNS Abuse Mitigation Requirements: Progress & Next Steps](https://www.icann.org/en/blogs/details/two-years-of-enforcing-dns-abuse-mitigation-requirements-progress-next-steps-02-06-2026-en)
- [Framework to Address Abuse (website and PDF)](https://dnsabuseframework.org/)

## related terms

- [phishing](https://tldlog.com/glossary/phishing/)
- [malware](https://tldlog.com/glossary/malware/)
- [botnet](https://tldlog.com/glossary/botnet/)
- [pharming](https://tldlog.com/glossary/pharming/)
