Domain Registrars Plead for Data as WHOIS Verification Requirements Lead to Widespread Website Suspensions
The digital landscape is currently grappling with a significant challenge that has left over a million websites in limbo: mandatory WHOIS verification requirements. For nearly a year, major domain name registrars have been tasked with verifying specific elements of domain name WHOIS information, a mandate that, while seemingly straightforward, has proven to be anything but. This policy, intended to bolster internet security and curb illicit activities, has instead resulted in widespread domain suspensions, causing considerable disruption for legitimate website owners and sparking intense debate within the internet governance community.

The Flawed Reality of Simple Verification
In theory, the current verification process appears elegantly simple: upon a new domain registration or a change to WHOIS records, the registrar dispatches an email to the WHOIS contact, requesting a click to confirm the details. This mechanism was designed to ensure the accuracy and validity of registrant information, a cornerstone for accountability in the online world. However, the practical application has exposed critical flaws.
The reality is starkly different from the theoretical ideal. Many domain owners either do not receive these crucial verification emails or overlook them amidst a deluge of other digital communications. This oversight, whether due to spam filters, outdated contact information, or simple human error, carries severe consequences. Over one million domain names have been suspended globally because their owners failed to complete this seemingly minor verification step. Each suspension translates directly into a broken website, rendering businesses inoperable, silencing personal blogs, and severing vital online connections.
The repercussions extend beyond mere inconvenience. For small businesses, a suspended website can mean lost revenue, damaged customer trust, and a significant setback to their online presence. For larger entities, it can lead to reputational damage and operational paralysis. The internet, a backbone of modern commerce and communication, becomes unreliable when such a fundamental element as domain ownership can lead to unexpected outages.
Registrars’ Urgent Plea for Evidenced-Based Policy
The domain name registrars, on the front lines of implementing these policies, have become increasingly vocal in their appeals to ICANN (the Internet Corporation for Assigned Names and Numbers). Their central argument revolves around the need for empirical data: they are desperately seeking evidence from law enforcement agencies to demonstrate the tangible benefits of these stringent verification requirements. How, they ask, is this policy effectively aiding in the fight against online crime? Is the quantifiable benefit significant enough to justify the collateral damage of suspending over a million legitimate domain names?
This issue reached a boiling point at the recent ICANN meeting in Los Angeles, particularly amidst discussions of potentially escalating verification demands. The prospect of even stricter measures has heightened the alarm within the registrar community, prompting a renewed and more insistent call for accountability and data-driven policymaking.
The Looming Specter of Cross-Field Validation
A particularly concerning development discussed at the meeting was the potential introduction of “cross-field validation.” This advanced verification step would require registrars not only to confirm an email address but also to verify the accuracy of other WHOIS data, such as physical addresses. While seemingly a logical step towards more robust data, its implementation presents formidable challenges.
Verifying physical addresses is inherently complex, even within a single, well-documented country like the United States. When scaled globally, the task becomes exponentially more difficult, fraught with issues related to diverse addressing formats, privacy regulations, data availability, and the sheer administrative burden. The implications are clear: cross-field validation would inevitably lead to an even greater number of domain suspensions as registrars struggle to validate details across myriad international jurisdictions. Furthermore, the increased operational complexity and data acquisition costs would almost certainly translate into significantly higher domain registration fees, impacting users and businesses worldwide.
The fundamental question remains: what measurable good will such an onerous and costly system achieve? Without concrete evidence that these measures effectively deter criminals, the industry fears they are merely creating bureaucratic hurdles for legitimate users while failing to address the core problem of online abuse.
A Dialogue of Disconnect: ICANN, Registrars, and Law Enforcement
During the Registrar Stakeholders Group meeting with ICANN’s board, the frustration of the registrars was palpable. James Bladel, VP of Policy at GoDaddy, directly challenged the board regarding the status of the data they had been promised from law enforcement. He specifically recalled a commitment made a year prior, expecting statistical analysis to be ready by the London meeting.
Akram Attalah, President of ICANN’s Global Domains Division, attempted to assuage fears, stating, “…We are not going to try to impose things that are not feasible; nobody wins. So let’s continue the dialogue and see how we can progress it.” However, this emphasis on “continued dialogue” missed the registrars’ point entirely. They weren’t asking for more discussion; they were demanding concrete data.
Bladel pressed further: “…I’m sorry. I was specifically asking: Have we requested a statistical analysis of any kind from law enforcement as we were committed to one year ago last summer, that it would be ready by London. So what’s the status of that request?”
Attalah’s response was a revelation of the policy’s underlying weakness: “I don’t know of any requests of law enforcement. Law enforcement is not somebody that we can go call and ask them to do this for us. But we could try to approach a few members of law enforcement that we negotiated with and see if they are willing to do that. But I am not very optimistic about this.” This admission starkly highlighted the disconnect between policy creation and its purported effectiveness.
ICANN board member Mike Silber then adopted a defensive stance, asserting, “…Law enforcement is not a single entity that you can go to and say, ‘Please deliver the stats.’ It’s a loose affiliation of law enforcement agencies from a variety of countries who operate in different manners.” While this is true, Jeff Eckhaus of Rightside later pointed out the apparent contradiction: “law enforcement” seemed to function as a unified group when they initially made their demands for the WHOIS verification policies.
The Elusive “Position Document” and Finger-Pointing
In a somewhat ironic turn, Silber then requested a “position document” from the registrars that could be presented to law enforcement agencies. He claimed to have “asked twice for the registrars to please give us a position paper that we can start with.” This led to a testy exchange between Silber and ICANN CEO Elliot Noss, with Silber reiterating his defensive position: “Where is the papers? When you guys have asked for other things, I have seen the documents, the letters, the correspondence. Where is it? You were supposed to do that for me last time.”
However, the registrars dispute the timeline and nature of this request. Industry participants indicate that if such a paper was requested, it was certainly not a prominent part of the recent registrar/board meetings in Singapore or London, where the primary demand from registrars was for ICANN to secure data from law enforcement, not to produce more documents themselves. During the Singapore meeting, Silber himself had acknowledged ICANN’s inability to *force* law enforcement to provide data, stating, “Whether they will give us specific metrics in time for London, well, that’s up to them. We can only request it and encourage it.” This suggests a consistent pattern of registrars requesting data from law enforcement via ICANN, rather than being asked to provide a position paper to justify their own stance.
Chairman Crocker’s Candid Insights: The Lack of Relevant Metrics
Chairman Crocker, notably, appears to align with the registrars’ perspective on this issue. He shared his past interactions with law enforcement officials when they were formulating these demands, recounting his consistent questioning:
… I had somewhat regular interactions with some of the law enforcement people ‐‐ I asked the question: And how will we know that this is going to have an effect? What are the metrics, or how do you know? No good answers coming back.
Now we’ve instituted them, and now we’ve seen statistics come about, the measurable harm that is being done to the ‐‐ to us, the good guys, if you will. And, again, we ask the question: How can we tell? And I’ve tried to have sensible conversations at multiple points with various people in law enforcement…
…And the other quite straightforward, pragmatic response that I got in a more recent discussion is they don’t keep statistics that relate to the questions that we’re asking. You cannot go and get crime breakdowns from the FBI or from others that tell you exactly which ones were because of abuse of domain names and so forth.
Crocker’s candid account cuts through the rhetoric and lays bare the central truth: the very data needed to justify these policies simply doesn’t exist within law enforcement’s standard statistical frameworks. They don’t track crime specifically in a way that links it directly to WHOIS data inaccuracies, making it impossible to prove the efficacy of verification mandates.
The Core Problem: Ineffective Measures and Collateral Damage to Legitimate Users
And therein lies the fundamental truth that registrars, board members, and even some law enforcement officials quietly acknowledge: merely having someone verify their email address or physical address is highly unlikely to significantly reduce serious online crime. Professional criminals are adept at circumventing such basic hurdles. They can easily acquire free, disposable email addresses and phone numbers. They are skilled at looking up valid physical addresses online, or even creating fictitious ones, making address verification a trivial obstacle at best.
The current verification schemes, therefore, largely amount to what critics call “security theater” – a set of actions taken to make people *feel* secure, without actually providing a substantial increase in security. The tragic irony is that the only individuals genuinely harmed by these well-intentioned but ultimately misguided policies are the innocent bystanders: legitimate website owners, small businesses, and individuals who rely on the internet for their livelihoods and communication. They are the ones who face domain suspensions, website downtime, and the administrative burden of navigating an increasingly complex and unforgiving system.
Moving Forward: Towards Smarter, Evidence-Based Solutions
The ongoing saga of WHOIS verification underscores a critical need for re-evaluation within internet governance. Instead of continuing with policies that lack demonstrable effectiveness and impose significant harm on legitimate users, there must be a shift towards smarter, evidence-based solutions. This requires genuine collaboration between ICANN, registrars, and law enforcement – not a dialogue of disconnect, but a concerted effort to identify and implement measures that genuinely combat abuse without penalizing the vast majority of law-abiding internet users.
Future policies should focus on actionable data, leveraging technology for targeted abuse prevention, and fostering an environment of trust and accountability. This means exploring alternatives that don’t rely on blanket, cumbersome verification methods but instead target malicious actors more precisely. The goal should be to enhance the security and integrity of the domain name system while preserving its accessibility and utility for everyone. Without a commitment to empirical evidence and a willingness to adapt policies based on real-world impact, the internet risks becoming a less reliable and more frustrating place for its users.