DNS Abuse: Exploring Both Sides of the Issue
A balanced perspective on the challenges and responsibilities surrounding DNS abuse.

The fight against online scams, spam, and malware distribution is a shared goal within the domain name industry. No one wants to see domain names and websites used for malicious purposes. However, the question of who bears the primary responsibility for policing the internet and combating these abuses remains a complex and often contentious issue. How much effort should domain registrars and registries be required to expend in rooting out malicious activity? What are the potential consequences for legitimate websites caught in the crossfire?
In this discussion, we delve into these critical questions, exploring the multifaceted nature of DNS abuse and the challenges involved in effectively addressing it. Our guest, Jothan Frakes, brings a wealth of experience to the table. With three decades immersed in the DNS space, Jothan has witnessed this ongoing debate unfold over time. He possesses a deep understanding of both sides of the equation, offering valuable insights into why ICANN (the Internet Corporation for Assigned Names and Numbers) and its contracted parties often find themselves at the forefront of efforts to clean up the mess.
DNS abuse is a broad term encompassing various malicious activities that exploit the Domain Name System (DNS). These activities can range from phishing attacks designed to steal sensitive information to the distribution of malware and the hosting of fraudulent or misleading content. The consequences of DNS abuse can be severe, impacting individuals, businesses, and the overall integrity of the internet ecosystem.
One of the key challenges in addressing DNS abuse is the sheer scale of the problem. The internet is a vast and dynamic environment, with millions of domain names registered and countless websites launched every day. Monitoring and identifying malicious activity across this vast landscape requires significant resources and expertise.
Furthermore, the actors behind DNS abuse are often sophisticated and resourceful, constantly evolving their tactics to evade detection. They may use techniques such as domain fronting, fast flux DNS, and bulletproof hosting to conceal their activities and make it more difficult to track them down.
The debate over who should be responsible for policing DNS abuse often revolves around the roles and responsibilities of various stakeholders in the domain name industry. Registrars, the companies that sell domain names, are often seen as the first line of defense against abuse. They have the ability to suspend or terminate domain names that are found to be involved in malicious activity.
Registries, the organizations that manage top-level domains (TLDs) such as .com and .org, also play a crucial role in combating DNS abuse. They can implement policies and procedures to prevent the registration of domains for malicious purposes and to address abuse that occurs within their TLDs.
ICANN, as the organization responsible for coordinating the global DNS, plays a central role in setting policies and standards related to DNS abuse. ICANN works with registrars, registries, and other stakeholders to develop and implement measures to combat malicious activity and protect the integrity of the DNS.
However, the question of how much responsibility should be placed on these various stakeholders is a subject of ongoing debate. Some argue that registrars and registries have a moral and ethical obligation to actively police their platforms and prevent abuse. They believe that these entities are in the best position to identify and address malicious activity, and that they should be held accountable for failing to do so.
Others argue that placing too much responsibility on registrars and registries could lead to unintended consequences. They fear that these entities might become overly cautious and begin suspending or terminating domain names based on unsubstantiated allegations of abuse. This could have a chilling effect on free speech and innovation, and could harm legitimate businesses that rely on their domain names to operate online.
Another concern is the potential for collateral damage to legitimate websites. In some cases, efforts to combat DNS abuse can inadvertently affect innocent parties. For example, a registrar might suspend a domain name that is being used for both legitimate and malicious purposes, effectively shutting down the entire website.
Striking a balance between combating DNS abuse and protecting the rights of legitimate website owners is a complex and delicate task. It requires a collaborative approach involving all stakeholders in the domain name industry, as well as a clear understanding of the potential consequences of different actions.
The role of technology in combating DNS abuse is also crucial. There are a variety of tools and technologies that can be used to detect and prevent malicious activity, such as machine learning algorithms, threat intelligence feeds, and domain reputation systems.
However, technology alone is not enough to solve the problem. It is also essential to have clear policies and procedures in place, as well as effective communication and collaboration between different stakeholders. This includes sharing information about known threats, coordinating responses to incidents, and working together to develop best practices for combating DNS abuse.
Addressing DNS abuse is an ongoing challenge that requires a multifaceted approach. It is a shared responsibility that must be embraced by all stakeholders in the domain name industry. By working together, we can create a safer and more secure online environment for everyone.
In addition to the discussion on DNS abuse, this episode also touches on topics such as a personal takedown story, common legal mistakes made in the domain name industry, and Radix’s impressive year. These diverse topics offer a well-rounded perspective on the challenges and opportunities facing the domain name community.
Resources Mentioned:
- Anti-Phishing Working Group: An industry association focused on eliminating fraud and identity theft resulting from phishing, pharming, email spoofing, malware, and other forms of online deception.
- Mail, Mobile and Messaging Anti-Abuse Working Group: A collaborative effort to combat spam, malware, and other forms of abuse across email, mobile, and messaging platforms.
- DNS Abuse Institute: An organization dedicated to researching and addressing DNS abuse through education, collaboration, and advocacy.
- Internet & Jurisdiction: A global multistakeholder organization addressing the tension between the cross-border internet and national laws.
- ICANN Registrar Stakeholder Group: A group representing the interests of registrars within the ICANN ecosystem.
- ICANN Registry Stakeholder Group: A group representing the interests of registries within the ICANN ecosystem.
- Internet Infrastructure Coalition: An organization advocating for policies that support the growth and innovation of the internet infrastructure.
- Domain Name Association: An industry association representing domain name registries, registrars, and resellers.
- Jothan Frakes: The personal website of Jothan Frakes, a leading expert in the DNS space.
Sponsor: Sav.com no-fee backorders
Podcast: Play in new window | Download (Duration: 38:32 — 30.9MB) | Embed
Subscribe: Email | RSS
Subscribe via Apple Podcasts to listen to the Domain Name Wire podcast on your iPhone or iPad, or click play above or download to begin listening. (Listen to previous podcasts here.)