---
id: "raa"
kind: "glossary-term"
title: "RAA"
language: "en"
category: "Governance and policy"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/raa/"
translations:
  es: "https://tldlog.com/es/glosario/raa/"
  de: "https://tldlog.com/de/glossar/raa/"
  fr: "https://tldlog.com/fr/glossaire/raa/"
  it: "https://tldlog.com/it/glossario/raa/"
  pt-BR: "https://tldlog.com/pt/glossario/raa/"
  ru: "https://tldlog.com/ru/glossariy/raa/"
  zh-Hans: "https://tldlog.com/zh/cihui/raa/"
---

# RAA

Registrar Accreditation Agreement

The contract between ICANN and each accredited registrar. It sets duties such as handling registration data, responding to abuse reports, following ICANN policies and passing key terms on to resellers. Breaking it can lead to loss of accreditation.

The Registrar Accreditation Agreement (RAA) is the contract a company signs with ICANN to sell generic domain names such as .com. It sets what registrars owe their customers and the wider Internet, and what ICANN can do when they fail. It does not apply to country domains such as .es.

## What the RAA is

The RAA is a standard contract between ICANN and each registrar it accredits. Signing it gives the company the right to register and renew names in gTLD registries.

The form is still called the "2013 RAA", but its text has been amended. As of October 2026, new agreements use the version the ICANN Board approved on 21 January 2024, and existing registrars received the same changes through a global amendment effective 5 April 2024. An earlier amendment, effective 7 August 2023, moved public registration data to RDAP and ended the WHOIS obligations on 28 January 2025.

The agreement renews for five-year periods, and only its English text is binding. As of October 2026, amendments negotiated with registrars need the approval of registrars holding 90% of the names under management, and of the ICANN Board. The 2024 amendment, on DNS abuse, does not cover website content or access to registration data.

## What it requires from registrars

As of October 2026, the duties fall into six groups.

- **Policies.** Follow all ICANN consensus policies, present and future, and the UDRP.
- **Registration data.** Publish it free of charge through RDAP and verify contact details: if the registrant does not confirm them within 15 calendar days, verify them manually or suspend the name. Keep records for two years after the agreement ends, and deposit a copy of the data in escrow.
- **Abuse reports.** Publish an abuse email address or web form on, or easily reached from, the home page, confirm receipt to the reporter and investigate promptly. Keep a contact for law enforcement that is monitored 24 hours a day, and review well-founded reports within 24 hours.
- **DNS abuse.** Since 5 April 2024, a registrar with actionable evidence that a name it sponsors is used for malware, botnets, phishing, pharming or spam that delivers them must promptly take the mitigation actions reasonably necessary to stop or disrupt it. The right action depends on the harm and the risk of collateral damage; it is not always a suspension.
- **Resellers.** Sign written agreements that pass on the RAA terms. The registrar stays responsible for the service.
- **Fees and reporting.** Pay yearly and variable fees (the contract caps the yearly fee at US$4,000), file a compliance certificate within 20 days of each year end, accept audits, and tell ICANN within seven days of any unauthorized access to registration data.

## Protections it gives registrants

Registrars and resellers must publish or link to the Registrants' Benefits and Responsibilities Specification. It entitles registrants to a registration agreement they can review and download at any time; to know who their registrar is, its prices and terms, and how to complain, transfer, renew and restore names; and to be free of false advertising, deceptive notices and hidden fees.

Other clauses help too. A reseller must name the sponsoring registrar when asked. Registrars send renewal reminders, and a name that is not renewed is normally cancelled at the latest by the end of the auto-renew grace period.

In return, registrants must give accurate data, update it within seven days of any change and answer the registrar's inquiries within 15 days; otherwise the name may be suspended or cancelled.

The registrant does not sign the RAA. Its contract is the registration agreement with the registrar or reseller, which must include the RAA's minimum terms. Problems go first to the registrar, then to ICANN Contractual Compliance.

## How it is enforced and what happens on breach

ICANN Contractual Compliance acts on complaints sent through its web forms, on its own monitoring and on audits. It first tries to resolve issues informally: most complaint types get three notices with five business days each, and this phase is not published.

If that fails, ICANN sends a breach notice, which is published. If the registrar does not cure the breach within 21 days, ICANN can terminate the agreement on 15 days' written notice, during which the registrar can start arbitration. ICANN can also suspend the registrar's ability to create names or accept inbound transfers for up to 12 months. Three fundamental and material breaches within 12 months, or conduct that endangers the stability of the Internet, are also grounds for termination.

An example: someone reports phishing on example.net through a registrar's abuse form. The registrar must confirm receipt, naming itself, the domain and the date of the report, and act if the evidence is actionable. If it ignores the report, the reporter can complain to ICANN, which starts with informal notices and can move to a breach notice.

## RAA, Registry Agreement and registry-registrar agreements compared

These are three separate contracts:

- **RAA:** between ICANN and a registrar; renewed every five years.
- **Registry Agreement:** between ICANN and a gTLD registry operator; the base agreement runs for ten years.
- **RRA:** between a registry and each registrar that sells its names. The base Registry Agreement requires registries to sell only through ICANN-accredited registrars, give them all non-discriminatory access and use one uniform RRA for all its registrars. Material changes need ICANN's approval and at least 15 days' notice to registrars.

The registries and registrars bound by ICANN contracts are the contracted parties. Their DNS abuse duties differ: a registrar must act to stop or disrupt the abuse, while a registry must at least refer the case to the sponsoring registrar or act itself.

## Sources

- [2013 Registrar Accreditation Agreement (version approved 21 January 2024)](https://itp.cdn.icann.org/en/files/accredited-registrars/registrar-accreditation-agreement-21jan24-en.htm)
- [Advisory: Compliance With DNS Abuse Obligations in the Registrar Accreditation Agreement and the Registry Agreement](https://www.icann.org/en/contracted-parties/advisories/documents/advisory-compliance-with-dns-abuse-obligations-in-the-registrar-accreditation-agreement-and-the-registry-agreement-05-02-2024-en)
- [Contractual Compliance FAQs (ICANN)](https://www.icann.org/resources/pages/faqs-84-2012-02-25-en)
- [Base gTLD Registry Agreement (approved 21 January 2024)](https://itp.cdn.icann.org/en/files/registry-agreements/base-registry-agreement-21-01-2024-en.pdf)

## related terms

- [ICANN accreditation](https://tldlog.com/glossary/accreditation/)
- [registrar](https://tldlog.com/glossary/registrar/)
- [Registry Agreement](https://tldlog.com/glossary/registry-agreement/)
- [ICANN Contractual Compliance](https://tldlog.com/glossary/icann-contractual-compliance/)
