Data suggests reducing the 15-day verification deadline causes more harm than good.

In a new analysis, Tucows examined whether shortening the period registrants have to verify their contact information would reduce DNS abuse. The study concludes that tightening the window would likely disrupt legitimate domain holders while producing only a marginal decrease in abuse.
Under the current process, registrants have 15 days—usually by clicking a confirmation link sent by email—to verify their contact details. Domains that remain unverified after that period are suspended.
Some stakeholders have proposed cutting that 15-day window significantly or even requiring verification before a domain becomes active. To test the idea, Tucows analyzed verification behavior at one of its wholesale registrars (the company owns Enom, OpenSRS, and Ascio).
The findings show a clear pattern: almost half of registrants verify their domains the same day they register them. About 25% fail to verify within the deadline and are suspended. The remaining quarter verify after the first day but before the 15-day cutoff, with noticeable spikes in confirmations on the days reminder emails were sent.
Those results imply that any reduction in the verification period would likely cause inappropriate suspensions for many legitimate users—people who have already launched websites or set up email services that would be interrupted. Faster site deployment tools, including AI-driven builders, make quick setup more common, increasing the likelihood of disruption if the window is shortened.
Importantly, Tucows also found that more than 95% of domains later flagged for abuse had been verified by their registrants. Verification in this context means only that the registrant had a reachable email address and clicked a confirmation link; it does not demonstrate good intent or prevent misuse.
Given these results, the verification requirement appears to offer little protection against abuse while creating potential downsides. It can inconvenience legitimate registrants and may open another vector for phishing attacks aimed at domain owners. Based on Tucows’ analysis, keeping or tightening the email-confirmation requirement is unlikely to be an effective deterrent, and policymakers should carefully weigh the benefits against the harms before making changes to the verification policy.