RAA

Registrar Accreditation Agreement

The contract between ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN and each accredited registrar A company that registers domain names for customers with the registry. Full definition of registrar. It sets duties such as handling registration data The information kept about a domain and its owner. Full definition of registration data, responding to abuse report A notice telling a registrar, registry or host that a domain is being used for harm. Full definition of abuse report, following ICANN policies and passing key terms on to reseller A business that sells domains using another registrar's accreditation. Full definition of reseller. Breaking it can lead to loss of accreditation.

category
Governance and policy

Updated on 4 min read

The Registrar Accreditation Agreement (RAA) is the contract a company signs with ICANN to sell generic domain name A readable internet name made of labels separated by dots. Full definition of domain name such as .com. It sets what registrars owe their customers and the wider Internet, and what ICANN can do when they fail. It does not apply to country domains such as .es.

What the RAA is

The RAA is a standard contract between ICANN and each registrar it accredits. Signing it gives the company the right to register and renew names in gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry.

The form is still called the “2013 RAA”, but its text has been amended. As of October 2026, new agreements use the version the ICANN Board ICANN's board of directors, which adopts policies and approves key decisions. Full definition of ICANN Board approved on 21 January 2024, and existing registrars received the same changes through a global amendment effective 5 April 2024. An earlier amendment, effective 7 August 2023, moved public registration data to RDAP Registration Data Access Protocol The modern protocol for looking up domain registration data, replacing WHOIS. Full definition of RDAP and ended the WHOIS The legacy lookup service for domain registration data, now replaced by RDAP for gTLDs. Full definition of WHOIS obligations on 28 January 2025.

The agreement renews for five-year periods, and only its English text is binding. As of October 2026, amendments negotiated with registrars need the approval of registrars holding 90% of the names under management, and of the ICANN Board. The 2024 amendment, on DNS abuse Harmful use of domains, defined in ICANN contracts as five specific threats. Full definition of DNS abuse, does not cover website content or access to registration data.

What it requires from registrars

As of October 2026, the duties fall into six groups.

  • Policies. Follow all consensus policy An ICANN community rule that gTLD registries and registrars must follow. Full definition of consensus policy, present and future, and the UDRP Uniform Domain-Name Dispute-Resolution Policy ICANN's out-of-court process for trademark disputes over domain names. Full definition of UDRP.
  • Registration data. Publish it free of charge through RDAP and verify contact details: if the registrant The person or organization that holds a domain name registration. Full definition of registrant does not confirm them within 15 calendar days, verify them manually or suspend the name. Keep records for two years after the agreement ends, and deposit a copy of the data in escrow A neutral service holding payment until a domain is transferred. Full definition of escrow.
  • Abuse reports. Publish an abuse email address or web form on, or easily reached from, the home page, confirm receipt to the reporter and investigate promptly. Keep a contact for law enforcement that is monitored 24 hours a day, and review well-founded reports within 24 hours.
  • DNS abuse. Since 5 April 2024, a registrar with actionable evidence The level of proof that obliges a registry or registrar to act on DNS abuse. Full definition of actionable evidence that a name it sponsors is used for malware Harmful software, often spread or controlled using domain names. Full definition of malware, botnet A network of infected computers controlled by an attacker. Full definition of botnet, phishing Impersonating a trusted party to steal data, often with look-alike domains. Full definition of phishing, pharming Redirecting users to fake sites even when they type the right domain. Full definition of pharming or spam Unwanted bulk messages, which count as DNS abuse only when used to deliver other abuse. Full definition of spam that delivers them must promptly take the mitigation actions The steps a registry or registrar takes to stop or disrupt abuse of a domain. Full definition of mitigation actions reasonably necessary to stop or disrupt it. The right action depends on the harm and the risk of collateral damage; it is not always a suspension.
  • Resellers. Sign written agreements that pass on the RAA terms. The registrar stays responsible for the service.
  • Fees and reporting. Pay yearly and variable fees (the contract caps the yearly fee at US$4,000), file a compliance certificate within 20 days of each year end, accept audits, and tell ICANN within seven days of any unauthorized access to registration data.

Protections it gives registrants

Registrars and resellers must publish or link to the Registrants’ Benefits and Responsibilities Specification. It entitles registrants to a registration Obtaining the right to use a domain name for a set period. Full definition of registration agreement they can review and download at any time; to know who their registrar is, its prices and terms, and how to complain, transfer, renew and restore Bringing a deleted domain back during the redemption grace period. Full definition of restore names; and to be free of false advertising, deceptive notices and hidden fees.

Other clauses help too. A reseller must name the sponsoring registrar when asked. Registrars send renewal Paying to extend a domain registration for more time. Full definition of renewal reminders, and a name that is not renewed is normally cancelled at the latest by the end of the auto-renew grace period A period after expiry when an auto-renewed domain can still be renewed or canceled. Full definition of auto-renew grace period.

In return, registrants must give accurate data, update it within seven days of any change and answer the registrar’s inquiries within 15 days; otherwise the name may be suspended or cancelled.

The registrant does not sign the RAA. Its contract is the registration agreement with the registrar or reseller, which must include the RAA’s minimum terms. Problems go first to the registrar, then to ICANN Contractual Compliance The ICANN team that enforces registry and registrar contracts. Full definition of ICANN Contractual Compliance.

How it is enforced and what happens on breach

ICANN Contractual Compliance acts on complaints sent through its web forms, on its own monitoring and on audits. It first tries to resolve issues informally: most complaint types get three notices with five business days each, and this phase is not published.

If that fails, ICANN sends a breach notice A published ICANN letter telling a registrar or registry that it has broken its contract. Full definition of breach notice, which is published. If the registrar does not cure the breach within 21 days, ICANN can terminate the agreement on 15 days’ written notice, during which the registrar can start arbitration. ICANN can also suspend the registrar’s ability to create names or accept inbound transfers for up to 12 months. Three fundamental and material breaches within 12 months, or conduct that endangers the stability of the Internet, are also grounds for termination.

An example: someone reports phishing on example.net through a registrar’s abuse form. The registrar must confirm receipt, naming itself, the domain and the date of the report, and act if the evidence is actionable. If it ignores the report, the reporter can complain to ICANN, which starts with informal notices and can move to a breach notice.

RAA, Registry Agreement and registry-registrar agreements compared

These are three separate contracts:

  • RAA: between ICANN and a registrar; renewed every five years.
  • Registry Agreement The contract between ICANN and a gTLD registry operator. Full definition of Registry Agreement: between ICANN and a gTLD registry operator The organization that holds the contract or mandate for a TLD and sets its rules. Full definition of registry operator; the base agreement runs for ten years.
  • RRA Registry-Registrar Agreement The contract between a registry and a registrar that sells its domains. Full definition of RRA: between a registry and each registrar that sells its names. The base Registry Agreement requires registries to sell only through ICANN-accredited registrars, give them all non-discriminatory access and use one uniform RRA for all its registrars. Material changes need ICANN’s approval and at least 15 days’ notice to registrars.

The registries and registrars bound by ICANN contracts are the contracted parties The gTLD registries and registrars that hold contracts with ICANN. Full definition of contracted parties. Their DNS abuse duties differ: a registrar must act to stop or disrupt the abuse, while a registry must at least refer the case to the sponsoring registrar or act itself.

Sources