ICANN has terminated the accreditation of two domain registrars in quick succession, citing unresolved compliance failures and escalating DNS abuse concerns. The decisions reflect heightened scrutiny of registrar obligations under the Registrar Accreditation Agreement (RAA), particularly in handling abuse reports and maintaining operational standards.
What happened
Trustname.com, operated by Estonia-based Fewmoretaps OU, will lose its ICANN accreditation effective 11 September. The termination follows four formal breach notices issued within a 78-day period, the most recent on 26 August. ICANN determined that Trustname failed to act promptly on phishing and other DNS abuse reports, violating RAA Sections 3.18.1 and 3.18.2. While the registrar acknowledged shortcomings and introduced remediation measures beginning in February, ICANN concluded these efforts were insufficient. Data from ICANN’s Domain Metrica showed the median percentage of Trustname-sponsored domains reported for phishing rising from approximately 0.7% in January to 10% in August, despite ongoing remediation attempts.
Separately, IPIP Inc. will lose its accreditation on 13 September after failing to cure an 5 August breach notice. The violations included non-compliance with Registration Data Access Protocol (RDAP) requirements, missed registration-data escrow deposits, unpaid accreditation fees, and the absence of a mechanism for disclosing non-public registration data. ICANN’s records indicate repeated unsuccessful attempts to contact IPIP, including unanswered emails and unreachable telephone contacts.
For both registrars, ICANN will use its De-Accredited Registrar Transition Procedure to transfer managed domains to qualified accredited registrars. The total number of domains affected was not disclosed in the termination notices.
A third registrar, Beijing Zihai Technology Co., Ltd., received a breach notice on 26 August but remains accredited pending further review.
- Trustname.com received four breach notices between 10 June and 26 August 2026
- Phishing reports among Trustname-sponsored domains rose from ~0.7% in January to ~10% in August
- IPIP Inc. failed to comply with RDAP, escrow, and fee obligations
- Both terminations take effect in September 2026
- ICANN will oversee domain transfers for affected registrants
Why it matters
The terminations signal ICANN’s willingness to enforce contractual obligations more aggressively, particularly in areas directly impacting end-user security. DNS abuse has become a focal point for regulators and industry groups, with phishing and malware domains increasingly tied to financial fraud and identity theft. Registrars that fail to mitigate such abuse risk not only reputational damage but also operational disruptions for their customers, who may face sudden domain transfers or service interruptions.
The cases also highlight the challenges of cross-border compliance. Trustname.com, based in Estonia, and IPIP Inc., whose jurisdiction was not specified in the termination notices, both faced difficulties meeting ICANN’s requirements despite multiple opportunities to remedy violations. The lack of consistent enforcement mechanisms across jurisdictions has long been a point of contention in the domain industry, and these terminations may prompt calls for clearer global standards.
What to watch
Registrars and resellers should review their abuse-handling procedures and RDAP compliance to avoid similar enforcement actions. ICANN’s Domain Metrica data, which tracks abuse trends, may see increased adoption as a benchmarking tool. Meanwhile, the transition of domains from de-accredited registrars could test ICANN’s transfer protocols, particularly if the volume of affected domains is substantial. Beijing Zihai Technology’s ongoing breach proceeding may also provide further insight into ICANN’s enforcement thresholds.
- Audit your registrar’s abuse response times and RDAP compliance to preempt enforcement risks
- Prepare contingency plans for domain transfers if your registrar faces accreditation issues
- Monitor ICANN’s Domain Metrica for abuse trends among your registrar’s portfolio
Companies mentioned
Automated pipeline · Domains
Synthesized from 1 industry feed on 31 Aug 2026. Passed independent editor verification (score 92/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 2 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers ICANN terminating registrars for DNS abuse and compliance failures.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers ICANN terminating registrars for DNS abuse and compliance failures.
- Writing the article — Draft created article_id=486 slug=icann-terminates-two-registrars-over-dns-abuse-failures
-
Editor review — Approved
- Score: 92/100
- Factual grounding: The draft states 'the most recent [breach notice] on 26 August' for Trustname.com, but the source specifies the termination notice was issued on 27 August, one day after the fourth breach notice (26 August). The 26 August date is correct for the breach notice, but the phrasing could imply the termination was on 26 August, which is not supported by the source.
- Style compliance: The 'Key facts' block includes '~0.7%' and '~10%' for phishing reports, but the source uses 'about 0.7%' and 'about 10%'. While the approximation is correct, the symbol '~' is not verbatim from the source and could be standardized to 'about' for consistency.
- Style compliance: The draft uses '78-day period' in the body and 'between 10 June and 26 August 2026' in the Key facts block. The source specifies '78 days' between the first and fourth breach notices (10 June to 26 August). While the calculation is correct, the phrasing in the body could explicitly state the period (e.g., 'within a 78-day period (10 June to 26 August)') to avoid ambiguity.
- Audience relevance and notability: The draft does not explicitly state the total number of domains affected by the terminations, as the source notes this was not disclosed. While this is not a material omission, it could be clarified in the body (e.g., 'The total number of domains affected was not disclosed in the termination notices.').
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Rejected library image #140: The candidate depicts the GoDaddy headquarters exterior, which is unrelated to ICANN or domain registrars. The alt text is incorrect (mentions GoDaddy instead of ICANN), and the photo does not illustrate the article topic of ICANN terminating registrars over DNS abuse failures.
- Assigning hero image — Rejected library image #5: The provided candidate (index 0) is unrelated to the article topic. The alt text describes a prohibition sign in Japanese, and the query mentions a generic office workspace, which does not align with the context of ICANN terminating registrars over DNS abuse failures. No candidate meets the minimum relevance threshold of 70.
- Assigning hero image — Reused library image reused image #47
- Linking related stories — Linked 3 relations from 420 candidates
- Publishing — Published icann-terminates-two-registrars-over-dns-abuse-failures
- Mastodon — Posted https://mstdn.social/@hostingpaper/117191395325751911




Discussion · coming soon
Be the first to join the thread when community discussion launches.