DomainTools Fights Back: Appeals Landmark Injunction Over .NZ Whois Data Collection
A pivotal legal battle is unfolding in the world of internet governance and cybersecurity. DomainTools, a prominent provider of Whois data and security intelligence services, is vigorously appealing a preliminary injunction. This injunction was brought against it by the .NZ registry, Domain Name Commission Limited (DNCL), concerning DomainTools’ ongoing practice of collecting and publishing .NZ Whois data. The outcome of this case could set a significant precedent for how online terms of service are enforced, the accessibility of crucial internet data, and the evolving landscape of digital privacy.
![]()
The dispute began in June 2018 when DNCL initiated legal action against DomainTools. At the heart of DNCL’s complaint was the assertion that DomainTools’ methods of gathering and disseminating .NZ Whois information constituted a direct violation of DNCL’s established terms of service. These terms, according to DNCL, were explicitly provided with every Port 43 Whois query result originating from the .NZ registry. The registry maintained that by continuing to collect and publish this data, DomainTools was knowingly contravening the conditions set forth for accessing their database.
The Crucial Role of Whois Data in Cybersecurity and Transparency
To fully grasp the implications of this legal struggle, it’s essential to understand the significance of Whois data. Whois is a protocol that allows users to query databases to find out who owns a domain name or an IP address. Historically, Whois records provided crucial details such as the registrant’s name, address, email, and phone number, alongside administrative and technical contacts. This information has long been an indispensable tool for network administrators, law enforcement, and, critically, cybersecurity professionals.
For cybersecurity services like DomainTools, Whois data serves as a cornerstone for threat intelligence, incident response, and forensic analysis. By analyzing patterns in domain registrations, identifying common registrants linked to malicious activity, and tracking changes in ownership, these services can detect and mitigate cyber threats more effectively. Without access to comprehensive Whois data, the ability to trace the origin of phishing attacks, malware distribution, and other online abuses would be severely hampered, making the internet a more dangerous place for users and organizations alike.
However, the utility of Whois data is continually balanced against increasing concerns over individual privacy. With regulations like the General Data Protection Regulation (GDPR) coming into effect, the public availability of personal registrant information has been significantly restricted in many jurisdictions. This tension between transparency (for security and accountability) and privacy (for individual rights) is a central theme underlying many contemporary debates about internet governance, and it directly informs the arguments being made in the DomainTools vs. DNCL case.
The Genesis of the Legal Challenge: DNCL’s Stance
Domain Name Commission Limited (DNCL) operates as the official registry for .NZ domain names. In this capacity, DNCL is responsible for managing the registration system, ensuring the stability and security of the .NZ namespace, and setting policies that govern how its data is accessed and used. DNCL’s lawsuit against DomainTools aimed to protect what it considered its proprietary data and enforce its terms of service.
DNCL’s core argument was straightforward: by accessing and compiling .NZ Whois data, DomainTools was essentially scraping information in defiance of explicit usage policies. These policies, presented with each Whois query, prohibited mass collection and redistribution of the data. DNCL contended that DomainTools’ actions not only breached a contractual agreement but also potentially undermined the registry’s ability to manage its data and ensure privacy for .NZ registrants. The registry sought to prevent further unauthorized data collection and compel DomainTools to remove previously published records.
The Preliminary Injunction: A Temporary Setback for DomainTools
Following DNCL’s initial lawsuit, a Federal District judge ultimately granted a preliminary injunction against DomainTools. This was a significant early victory for DNCL. The injunction mandated that DomainTools immediately cease the collection of any new .NZ Whois records and, critically, remove all previously published .NZ Whois records from its databases for the duration of the lawsuit.
A preliminary injunction is a temporary order issued by a court before the final judgment in a case. Its purpose is to prevent irreparable harm to one party while the litigation proceeds. For DomainTools, this injunction represented a direct challenge to a core part of its business model. The immediate removal of vast quantities of .NZ Whois data not only impacted its historical datasets but also its ongoing ability to provide comprehensive threat intelligence and investigative services to its global clientele, potentially affecting countless cybersecurity investigations reliant on this specific domain information.
DomainTools’ Appeal: Challenging “Browsewrap” Agreements
Unwilling to accept the preliminary injunction, DomainTools promptly appealed the decision to the Ninth Circuit Court of Appeals. In its opening brief, DomainTools laid out a robust legal challenge, primarily focusing on the enforceability of DNCL’s terms of service.
DomainTools’ central argument revolves around the classification of DNCL’s agreement as a “browsewrap” agreement. In legal terms, a browsewrap agreement is a contract entered into when a user merely navigates a website or uses a service, with the assumption that continued use signifies acceptance of the terms, even if those terms are not explicitly presented or agreed to via a checkbox or similar affirmative action. This contrasts sharply with a “clickwrap” agreement, where users must actively click a button or check a box indicating their consent to the terms before proceeding. Courts generally view clickwrap agreements as much more likely to be enforceable due to the explicit nature of user consent.
DomainTools contends that because DNCL’s terms were merely included with each Whois result – without requiring an affirmative action from the querying party to agree – they should not be considered binding. The company highlighted that even the lower court acknowledged the inherent challenges in enforcing browsewrap agreements, stating that they are typically not enforceable unless “the user has actual or constructive knowledge of the [terms of use].” However, the lower court had concluded that DomainTools’ repeated Whois queries established sufficient knowledge.
The Nuances of Automated Access and Intent
This is where DomainTools introduces a critical distinction. The company argues that the lower court’s reasoning regarding “sufficient knowledge” should not apply in its case because all of DomainTools’ Whois queries were “conducted by an automated program on a dedicated computer-to-computer channel acting without human intervention.” This means that unlike a human user who might encounter and consciously (or semi-consciously) disregard terms of service while browsing, DomainTools’ system was an automated process, designed to retrieve data efficiently, not to parse and agree to legal texts.
Furthermore, DomainTools asserted that the specific wording of DNCL’s terms themselves did not clearly indicate that DomainTools’ type of data use—i.e., mass collection and subsequent publication for cybersecurity analysis—constituted a violation. This argument delves into the interpretation of contractual language and whether the terms were sufficiently clear and unambiguous to inform an automated system, or even a human operator setting up such a system, of the prohibited actions. If the terms were vague or open to multiple interpretations, DomainTools could argue that it did not knowingly or intentionally violate them. This becomes particularly relevant given the global nature of internet data and the varying legal interpretations across jurisdictions.
Weighing the Impacts: Customers vs. Registrant Privacy
Beyond the technical legal arguments surrounding browsewrap agreements and automated systems, DomainTools has also urged the appellate court to consider the broader practical implications of the preliminary injunction. Specifically, the company wants the court to weigh the significant negative impact on its global customer base against the perceived impact on .NZ registrants whose information might be published.
DomainTools’ services are utilized by thousands of cybersecurity professionals, government agencies, and enterprises worldwide for critical threat intelligence. An injunction preventing the collection and publication of Whois data from a specific top-level domain (TLD) like .NZ could create a dangerous blind spot in their intelligence feeds, potentially hindering the detection and neutralization of cyber threats originating from or routed through .NZ domains. The company argues that the harm to cybersecurity efforts, and by extension, to global internet users, far outweighs the privacy concerns of individual .NZ registrants, especially given the increasingly anonymized nature of Whois data post-GDPR. This argument introduces a public interest dimension to the legal proceedings, framing the decision not just as a corporate dispute but as one with wide-ranging implications for digital safety and security.
Broader Implications for Internet Governance and Data Access
The DomainTools vs. DNCL case is more than just a localized legal battle; it carries significant implications for the future of internet governance, data access, and the legal framework surrounding online agreements globally. If DomainTools’ appeal is successful, it could establish a precedent that makes it more challenging for registries worldwide to enforce browsewrap agreements, particularly against automated systems. This could embolden other data service providers and researchers to access and utilize publicly available internet data without explicit consent mechanisms.
Conversely, if the injunction is upheld, it could empower domain name registries to exert greater control over their Whois databases, potentially leading to a further fragmentation of Whois data accessibility. This fragmentation could pose substantial challenges for cybersecurity researchers who rely on comprehensive, centralized data to identify and track malicious actors across different TLDs. As global discussions continue regarding the future of Whois data in a post-GDPR world, this case adds another layer of complexity, highlighting the ongoing tension between data privacy regulations and the operational needs of internet security and research communities. The Ninth Circuit Court of Appeals’ decision will undoubtedly be closely watched by stakeholders across the entire internet ecosystem.