What the ICANN Registrar Accreditation Agreement Requires

The Internet Corporation for Assigned Names and Numbers grants registrars the right to sell domain names under a formal contract called the Registrar Accreditation Agreement, or RAA. That contract is detailed, and most registrar customers never read it — but it sets out obligations that are directly relevant to the safety of the broader domain ecosystem.

Among the most consequential requirements are those around abuse response. Under the RAA, an accredited registrar is obligated to maintain an abuse point of contact, to respond to abuse reports in a reasonable and timely manner, and to take action against domains used for phishing, malware distribution, and other forms of DNS abuse. These are not aspirational guidelines. They are contractual terms, and failure to comply gives ICANN grounds for enforcement action.

The agreement also requires registrars to maintain accurate WHOIS data, to comply with domain suspension requests from law enforcement under specific conditions, and to cooperate with ICANN's compliance staff during audits. When a registrar fails across multiple of these obligations simultaneously, the result is a formal notice of breach.

The Specific Violations That Trigger a Formal Breach Notice

Not every compliance failure rises to the level of a formal breach notice. ICANN's compliance staff typically begins with informal outreach and advisory communications. A breach notice is issued when a registrar has received that outreach and failed to remediate — or when the violations are severe enough that informal engagement is clearly insufficient.

The violations that most commonly appear in breach notices involve DNS abuse response failures: specifically, evidence that the registrar was hosting or facilitating phishing domains, malware sites, or fraudulent registrations and was not acting on abuse reports. A registrar that has a significant proportion of its registered domains flagged by independent abuse databases, and that cannot demonstrate a functioning abuse response process, is the archetypal candidate for a breach notice.

Secondary violations often accompany the primary abuse failures. WHOIS data accuracy problems — where registrant information is missing, falsified, or systematically incomplete — compound the abuse-response issue because investigators cannot contact domain owners or verify identity. The combination of non-functioning abuse response and degraded WHOIS accuracy is a pattern ICANN's compliance team takes seriously.

The documented ICANN breach findings from the Round 3 investigation provide a detailed look at how the specific violations mapped to RAA requirements in one well-documented case.

What a 21-Day Cure Period Actually Means in Practice

When ICANN issues a breach notice, it typically specifies a cure period — a window during which the registrar must remediate the identified violations before ICANN can proceed to escalation. Twenty-one days is a common cure period for abuse-response failures, though the specific timeline varies depending on the nature of the breach.

In theory, the cure period is an opportunity for genuine remediation: the registrar reviews its processes, implements functioning abuse response, clears the backlog of reported domains, and demonstrates compliance to ICANN's satisfaction. In practice, cure periods can be extended repeatedly through negotiation, compliance can be demonstrated through process changes that do not translate to actual outcomes, and "cured" status does not always mean the underlying culture of the registrar has changed.

For customers, the key question is not whether the breach notice was eventually resolved — it is how long the cure period dragged on, what ICANN's public record shows about the remediation, and whether independent abuse databases show the flagged activity actually decreased after the cure was certified. A registrar that achieves technical compliance while its IP ranges remain heavily represented in phishing abuse databases has not meaningfully reformed.

Case Study: A Registrar Cited for DNS Abuse Failure Within Months of Accreditation

One of the more striking recent examples in ICANN's enforcement record involves a registrar that signed its Registrar Accreditation Agreement in September 2024 and received a formal breach notice the following February — less than five months into its accreditation. As of the end of October 2024, the registrar had recorded zero legitimate .com domain registrations.

That last data point is significant. A registrar with no legitimate commercial activity in its first months of operation but already under ICANN scrutiny for DNS abuse failures is not a registrar that accidentally attracted criminal customers. The zero-legitimate-registrations figure, reported by DomainNameWire, suggests the registrar's customer base from the outset was drawn primarily from abuse-seeking users rather than ordinary businesses or individuals.

The cure period in this case extended well beyond the initial 21-day window — from the February 2025 breach notice to a resolution not achieved until March 2026. During that year-plus period, independent researchers tracked hundreds of phishing domains on the registrar's infrastructure remaining active. The registrar's own Trustpilot scores deteriorated from 4.9 to 3.4 as organic negative reviews from customers began to outpace the volume of apparent paid-review production.

Risks to Customers Whose Domains Are Registered With a Breached Registrar

If your domain is registered with a registrar currently under an ICANN breach notice, your practical exposure depends on the severity and trajectory of the breach. In most cases, your domain continues to function normally — ICANN does not suspend customer domains as part of registrar enforcement action under ordinary circumstances. The risk is more subtle.

First, registrar instability carries continuity risk. A registrar that is in prolonged breach proceedings may lose its accreditation entirely, which would trigger a mandatory transfer of all registered domains to another accredited registrar. That process is managed by ICANN and should not result in domain loss, but it can create administrative disruption and uncertainty during the transition period.

Second, shared infrastructure risk applies. If your registrar is also acting as a hosting provider — as many modern registrars do — and that hosting infrastructure has high concentrations of abuse activity, the IP reputation consequences described earlier in this series apply to your hosted services.

Third, and perhaps most importantly, a registrar in breach proceedings may be allocating its compliance resources to managing the ICANN process rather than to normal customer service operations. Support quality, WHOIS accuracy, and routine administrative tasks can deteriorate during periods of enforcement scrutiny.

How to Evaluate Whether to Migrate Your Domains

The decision to migrate domains away from a breached registrar involves a straightforward cost-benefit assessment. Domain transfers carry a small financial cost, require you to unlock the domain and obtain an authorization code, and involve a brief transition period during which changes to DNS records may be slower to process. These are manageable inconveniences.

Against those costs, weigh the nature of the breach, its duration, the registrar's trajectory since the breach was issued, and whether the registrar's independent abuse scores have improved. If a registrar received a breach notice, resolved it within the cure period, and shows a meaningfully cleaner abuse profile in independent databases since then, migration may not be necessary. If the breach dragged on for over a year while the registrar's IP ranges remained consistently flagged for hosting active phishing domains, the case for migration is much stronger.

ICANN maintains a public registrar directory with compliance history. Independent tools like PhishDestroy and HostDean publish registrar-level abuse scoring. Cross-referencing those sources takes less than 15 minutes per registrar and provides a factual basis for the migration decision that goes beyond headline news.