ICANN Issues Breach Notice to Joker.com

ICANN Cracks Down: Major Registrars Face Breach Notices Over Whois Accuracy Failures

img 2698 1

The Internet Corporation For Assigned Names and Numbers (ICANN), the global multi-stakeholder organization responsible for coordinating the internet’s naming systems, has taken a firm stance on Whois data accuracy. In a move that underscores its commitment to maintaining the integrity of domain name registration, ICANN recently issued breach notices to two significant domain name registrars: Joker.com and Beijing Innovative Linkage Technology Ltd, operating as DNS.com.cn. These notices serve as a stark warning that their accreditation to operate as domain registrars may be at risk due to alleged failures in enforcing Whois data accuracy policies.

Understanding Whois Data and Its Critical Importance

At the heart of this dispute lies the Whois database, a publicly accessible directory containing information about domain name registrants. This data typically includes the registrant’s name, organization, address, email, and phone number, along with administrative and technical contacts. For decades, Whois has been an indispensable tool for various stakeholders, serving multiple crucial functions within the internet ecosystem.

Why Whois Accuracy Matters

The accuracy of Whois data is paramount for several reasons:

  • Combating Cybercrime: Law enforcement agencies, cybersecurity experts, and anti-spam organizations rely on accurate Whois information to identify and contact domain owners responsible for malicious activities such as phishing, malware distribution, and spam campaigns. Without accurate data, tracking down perpetrators becomes significantly more challenging, hindering efforts to protect internet users.
  • Protecting Intellectual Property: Brand owners and intellectual property rights holders depend on Whois data to identify and contact individuals or entities engaging in trademark infringement, cybersquatting, or other forms of online brand abuse. Accurate information facilitates legal action and resolution of disputes.
  • Ensuring Accountability: Whois data promotes accountability among domain registrants. Knowing that verifiable contact information is publicly available encourages responsible behavior and deters misuse of domain names.
  • Facilitating Technical Support and Communication: Accurate contact details enable quick resolution of technical issues, network problems, and security vulnerabilities associated with domain names. It also allows legitimate inquiries and communications to reach the correct parties.

ICANN’s Registrar Accreditation Agreement (RAA), a binding contract signed by all accredited registrars, explicitly mandates the collection and maintenance of accurate Whois data. Registrars are contractually obligated to take reasonable steps to investigate and correct inaccuracies reported to them, ensuring the reliability of this vital public resource.

The Escalation: From Notices of Concern to Breach

The journey leading to the breach notices began earlier in the year. In May, both Joker.com and DNS.com.cn received “notices of concern” from ICANN. These initial notices indicated that the registrars were not adequately responding to and addressing reported instances of inaccurate Whois data. Such notices typically serve as an early warning, providing registrars an opportunity to rectify the identified shortcomings before more severe actions are taken.

However, despite these preliminary warnings, ICANN remained unsatisfied with the progress made by both registrars. By September 30, the issues had not been resolved to ICANN’s satisfaction, leading to the formal issuance of notices of breach of contract. This escalation signifies a serious contractual violation, potentially carrying severe consequences for the registrars involved.

The scale of operation for these two registrars highlights the significance of ICANN’s action. Joker.com manages a substantial portfolio of approximately 600,000 domain names, while DNS.com.cn oversees around 300,000. Any regulatory action affecting registrars of this size has widespread implications for a considerable number of domain holders and the broader internet infrastructure.

Upon receiving the breach notices, Joker.com and DNS.com.cn were given a 15-day window to remedy the identified contractual breaches. Failure to do so within this timeframe could lead to further, more stringent actions by ICANN, including the ultimate sanction of losing their registrar accreditation.

Joker.com’s Defense: A Question of Interpretation and Action

Just two days after receiving the breach notice, on October 2, Jan Legenhausen of Joker.com promptly responded to ICANN via email. His message conveyed a readiness to comply while also expressing a degree of confusion regarding the specific nature of the problem.

We are ready to take whatever action is necessary to sort this out – though we _really_ do not understand what the effective problem is. For us, it looks more like an uncertainty about the last words of 3.67.8 (“…steps to correct that inaccuracy”).

Please let me add some facts about the supporting documents/domains (“breaches”?) you sent with this notice – our impression is, that 100% of the mentioned incidents have been handled correctly by Joker.com.

Since you still seem to consider them as “evidence of breach”, I suspect that you do not agree with our method of “disabling a domain”?

This is something we explicitly asked Khalil Rasheed some time ago, when you started this discussion: Is putting a domain on “hold” (=moving out of the zone) appropriate or not, in case a whois entry is verified as wrong? We never got an indication from ICANN about this…

If my assumption is correct, this would mean that in case we change our method of “disabling a domain because of false whois data” could probably solve this issue…

Otherwise we really depend on advise what else could be done.

Joker.com’s response highlighted a key point of contention: their methodology for addressing inaccurate Whois data. Legenhausen suggested that Joker.com had consistently disabled domains with verified false Whois entries, effectively putting them “on hold” or “moving them out of the zone.” He indicated that they believed this action constituted a correct handling of the incidents and sought clarification on whether ICANN disagreed with this specific method. The registrar implied a lack of clear guidance from ICANN on the precise steps required to “correct that inaccuracy,” as stipulated in Section 3.7.8 of the RAA.

ICANN’s Clarification: Beyond Deactivation to Correction

ICANN’s Director of Contractual Compliance, Stacy Burnette, provided a swift response to Joker.com, seeking to clarify ICANN’s expectations and requirements. Her reply acknowledged Joker.com’s proactive deactivation of the domains referenced in the breach letter but also underlined the critical distinction between deactivation and actual correction of Whois data.

Thank you for your prompt response on 2 October 2008 indicating that you have deactivated the domains referenced in our breach letter to Joker.com on 30 September 2008. Depending on the circumstances, deactivating a name as you have done could be an appropriate action in response to a Whois data inaccuracy claim.

Your email does not, however, identify the steps you took to investigate and attempt to correct the inaccurate Whois data. We further note that the Whois data concerning the domains referenced in the breach letter are still inaccurate.

If you can demonstrate that you took reasonable steps to investigate the Whois data inaccuracy claims we will forgo the monthly reporting request and consider this matter closed

Burnette’s email confirmed that while deactivating a domain can be an appropriate initial step, it is not the complete solution required by the RAA. The core issue, as highlighted by ICANN, was the registrars’ failure to demonstrate that they had taken “reasonable steps to investigate and attempt to correct” the inaccurate Whois data. Simply putting a domain on hold, while preventing its active use, does not resolve the underlying problem of the inaccurate data remaining within the Whois system or address the fundamental requirement to correct it. ICANN explicitly noted that the Whois data for the implicated domains remained inaccurate, underscoring the incompleteness of Joker.com’s actions.

Crucially, ICANN offered a clear path to resolution: if Joker.com could provide evidence of having undertaken reasonable investigative efforts and attempts to correct the Whois data inaccuracies, ICANN would be willing to close the matter and waive the requirement for monthly reporting. This demonstrates ICANN’s objective to enforce compliance rather than simply levy penalties, providing registrars with an opportunity to align with contractual obligations.

Broader Implications for the Domain Name Industry

This incident between ICANN and registrars like Joker.com and DNS.com.cn carries significant implications for the entire domain name ecosystem. For the involved registrars, the threat of losing accreditation is existential. Such a loss would mean they could no longer register new domains or manage existing ones, effectively shutting down a core part of their business and forcing the transfer of their entire domain portfolio to other accredited registrars.

For domain holders, repeated issues with Whois accuracy enforcement by their registrar could lead to disruptions in service, loss of domain control, or even legal complications if their data is incorrect or unverified. It underscores the importance for domain registrants to ensure their Whois information is always current and accurate.

More broadly, this case reaffirms ICANN’s commitment to its contractual compliance framework and its role in upholding the standards necessary for a functional and secure internet. By taking action against large registrars, ICANN sends a strong message to all accredited registrars about the seriousness of Whois accuracy requirements. This enforcement also feeds into the ongoing global discussions surrounding Whois data, particularly in light of evolving privacy regulations like GDPR, which have introduced complexities regarding the collection and public display of personal data in Whois records. ICANN continues to navigate the delicate balance between privacy concerns and the imperative for accessible and accurate data for legitimate purposes.

Conclusion: Ensuring a Reliable Internet Foundation

The breach notices issued by ICANN to Joker.com and DNS.com.cn highlight the critical importance of Whois data accuracy in maintaining a trustworthy and secure internet. While registrars play a vital role in managing domain registrations, they are equally responsible for adhering to the contractual obligations set forth by ICANN, particularly concerning the integrity of registrant data.

This case serves as a powerful reminder that “disabling a domain” is often only a partial solution; the full requirement extends to actively investigating and attempting to correct the underlying Whois inaccuracies. ICANN’s clear communication of its expectations provides a necessary framework for registrars to operate within, ensuring that the Whois database remains a reliable resource for security, law enforcement, and intellectual property protection.

As the internet continues to evolve, the demand for transparency and accountability in domain registration remains unwavering. ICANN’s proactive enforcement actions are essential steps in upholding these principles, ultimately contributing to a more stable, secure, and reliable global internet for everyone.