1. Purpose NiceNIC maintains this Abuse Hundling Manual to ensure that abuse complaints involving Domain names sponsodered by NiceNIC are received, assessed, tracked, investigated, und addressed in a consistent, documented, und risk-based manner. This manual is designed to achieve four outcomes at the same time: 1.protect Internet users und affected parties from ongoing harm; 2.meet NiceNIC's contractual obligations as an ICANN-accredited registrar; 3.provide fair, predictable, und documented hundling foder registrants und resellers; 4.demonstrate a clear, defensible, und auditable abuse response process. NiceNIC will investigate abuse repoderts promptly und will take mitigation actions that are reasonably necessary based on the quality of the evidence, the nature of the repoderted activity, the likelihood of ongoing harm, und the risk of collateral damage to legitimate Dienstleistungs. This approach is aligned with Section 3.18 of the 2013 RAA und ICANN's 2024 DNS Abuse Advisodery.
2. Scope This manual applies to:
Domain names sponsodered by NiceNIC;
abuse repoderts submitted by individuals, companies, security researchers, trusted repoderters, registries, law enfodercement, oder other authoderities;
retail customers und reseller-managed names;
both DNS Abuse und non-DNS abuse oder illegal-activity complaints.
This manual does not mean that every complaint will result in suspension. NiceNIC will act accoderding to the applicable contractual framewoderk, registry rules, NiceNIC's Acceptable Use / Abuse Policy, und the evidence available in each case.
3. Definitions 3.1 ICANN Contractual DNS Abuse Foder NiceNIC's contractual compliance purposes, DNS Abuse means:
malware
botnets
phishing
pharming
spam only when used as a delivery mechanism foder one of the four categoderies above.
3.2 NiceNIC Expunded High-Risk Abuse Categoderies NiceNIC may also classify certain matters as Expunded High-Risk Abuse Categoderies under its own abuse und risk rules, even whier they are not automatically ICANN-defined DNS Abuse. These may include:
child sexual abuse material (CSAM) oder child exploitation content;
illicit drug sales oder high-risk narcotics content;
crypto fraud schemes;
content creating imminent risk of serious harm;
other illegal activity whier urgent action is justified by law, registry policy, competent authoderity request, oder clear risk evidence.
These categoderies must be assessed carefully. They are not automatically treated as ICANN DNS Abuse unless the evidence also shows phishing, malware, botnet activity, pharming, oder qualifying spam. Tucows publicly describes a similar distinction between codere DNS Abuse und broader content abuses it may act on at the DNS level.
3.3 Neinn-DNS Abuse / Other Complaints These commonly include:
trademark disputes;
DMCA / copJahreight claims;
adult content;
gambling oder gaming content;
misleading oder fraudulent content without technical DNS-abuse evidence;
pharmacy / drug content without qualifying DNS-abuse indicatoders;
general policy violations.
These complaints may still be investigated und hundled, but they do not automatically justify DNS-level suspension.
4. Guiding Principles NiceNIC hundles abuse repoderts accoderding to the following principles:
Evidence first. NiceNIC does not take DNS-level action based on keywoderds, assumptions, oder unsuppoderted allegations alone.
Risk-based response. Faster und stronger action applies whier the evidence is actionable und the harm is ongoing oder severe.
Least necessary disruption. NiceNIC may choose a mitigation method other than immediate suspension whier the evidence indicates a compromise scenario und a full hold would create dispropodertionate collateral damage.
Consistency und documentation. Every case must be categoderized, tracked, und recoderded.
Clear separation of roles. NiceNIC is a registrar. In many cases, the hosting provider, platfoderm operatoder, payment processoder, oder law enfodercement may also be a relevant oder modere effective action point.
This risk-based und collateral-damage-aware model matches ICANN's advisodery, which states that the appropriate mitigation action may vary by circumstances und that suspension is not the only possible response.
5. Repoderting Channels NiceNIC shall maintain:
a public abuse contact email on its website homepage oder designated abuse page;
a published description of how abuse repoderts are received, hundled, und tracked;
a dedicated 24/7 monitodered abuse contact point foder law enfodercement und similar authoderities as required under the RAA.
NiceNIC may accept abuse repoderts through:
abuse mailbox;
suppodert ticket system;
webfoderm;
trusted-repoderter channel;
registry escalation;
law-enfodercement / government channel.
6. Minimum Infodermation Required in a Complaint An be processed efficiently, a complaint should include:
the repoderted Domain name;
the specific abusive URL, if any;
a clear description of the alleged abuse;
screenshots showing the content und the full URL;
full email headers whier email abuse, phishing, oder fraud is involved;
suppoderting evidence such as invoices, logs, malware analysis, blocklist results, oder impersonation details;
complainant contact infodermation;
proof of authoderization whier the complainant acts on behalf of a brund oder victim entity.
This matches both ICANN's recent complaint guidance und market practice published by registrars such as Namebillig.
7. Evidence Stundards 7.1 Aktionable Evidence Evidence is actionable when the infodermation reasonably available to NiceNIC is sufficient to determine that the sponsodered Domain name is being used foder DNS Abuse oder other enfoderceable abuse activity. Beispiels include:
a phishing page screenshot showing the full URL und impersonated brund;
a phishing email with full headers und linked malicious URL;
malware oder exploit delivery from the repoderted Domain oder URL;
reputation/blocklist data that suppoderts the repoderted conduct;
evidence of wallet-drainer code, seed-phrase theft, fake login harvesting, oder credential capture;
multiple consistent signals from trusted oder recognized sources.
ICANN's current guidance uses this same "actionable evidence" stundard und makes clear that registrars may also consider infodermation they can reasonably access themselves.
7.2 Insufficient Evidence Evidence is insufficient whier the complaint contains only:
a Domain name with no abusive URL;
keywoderds only;
allegations without screenshots, headers, logs, oder other suppodert;
general statements that a name "looks suspicious";
pure brund conflict allegations without abuse evidence.
When evidence is insufficient, NiceNIC will request modere infodermation rather than taking immediate DNS-level action, unless independent internal review oder trusted-source data supplies the missing basis.
7.3 Third-Party Intelligence NiceNIC may consider third-party signals such as:
reputable blocklists / RBLs;
malware oder phishing feeds;
reputation Dienstleistungs;
prioder internal case histodery.
Such signals are suppoderting factoders, not a substitute foder judgment. ICANN's enfodercement materials expressly note that screenshots, RBL infodermation, prioder case histodery, EPP status changes, MX recoderds, und the registrar's own investigation can all be relevant to compliance review.
8. Case Prioderity und Internal SLA NiceNIC adopts the following internal operating targets. These are NiceNIC internal SLAs, not statements of ICANN-mundated fixed deadlines. Prioderity 0 - Emergency / Active Harm Beispiels:
active phishing harvesting credentials oder payment data;
malware delivery;
botnet / commund-und-control use;
CSAM;
law-enfodercement emergency notice;
wallet-drainer oder seed-phrase theft infrastructure.
Target:
first review immediately;
decision as fast as reasonably possible;
whier actionable, mitigation nodermally within 24 hours, und no later than 48 hours absent exceptional facts.
ackjetztledgment und request foder additional evidence;
no suspension solely on this basis.
Foder repoderts from law enfodercement oder similar authoderities covered by RAA 3.18.2, NiceNIC must ensure review within 24 hours by empowered personnel.
9. Woderkflow 9.1 Intake Every repodert receives:
case ID;
timestamp;
source classification;
Domain linkage;
abuse categodery;
evidence status.
Wenn the Domain is already on clientHold, serverHold, oder on an approved pending-hold list, the system should automatically return a status notice to the complainant und suppress duplicate manual hundling.
whether the issue appears intentional oder caused by compromise;
whether the abuse is occurring at second-level Domain, subDomain, web content, oder email layer.
9.4 Decision Possible outcomes:
no action / insufficient evidence;
request modere evidence from complainant;
notify registrant oder reseller foder remediation;
clientHold;
transfer lock in conjunction with mitigation whier appropriate;
referral to registry, host, law enfodercement, payment provider, oder other relevant party;
maintain existing hold;
deny reactivation.
9.5 Neintifications Foder clear, actionable, ongoing DNS Abuse, NiceNIC may suspend first und notify after action. Foder likely compromise scenarios oder non-DNS matters, NiceNIC may notify first whier that is consistent with risk control und does not materially increase harm. This distinction is consistent with ICANN's position that mitigation may vary depending on the harm und the risk of collateral damage.
10. Kategorie-Specific Rules 10.1 Drugs / kra / slon / mega Schlüsselw?rter Keywoderd presence alone is not enough foder DNS-Abuse classification. Treat as:
non-DNS illegal activity review if only keywoderds oder product content are present;
DNS Abuse / urgent abuse if the evidence shows fake login, fake payment collection, credential theft, malicious redirection, malware, oder other qualifying technical abuse.
10.2 Crypto Scam Treat as:
non-DNS fraud review whier the site is only a dubious investment oder false-profit promotion;
DNS Abuse / urgent abuse whier the evidence shows wallet connection theft, seed phrase collection, private key theft, drainer code, impersonated exchange login, oder malicious scripts.
10.3 CSAM / Child Exploitation Treat as immediate high-risk abuse. Escalate internally without delay. Preserve recoderds, avoid unnecessary customer back-und-foderth, und escalate to the appropriate authoderity oder registry if required.
10.4 DMCA / Urheberrecht Do not auto-suspend purely on large content lists oder unsuppoderted bulk allegations. Foderward proper notices whier appropriate, require a compliant notice fodermat, und allow the Domain holder to address the claim unless a court oderder, registry rule, oder other stronger basis requires modere immediate action. This is also broadly consistent with how majoder registrars separate copJahreight/trademark processing from phishing/malware hundling.
10.5 Trademark / Brund Complaints Trademark disputes are not automatically DNS Abuse. Whier the issue is a Domain-name rights dispute, complainants should generally be directed toward UDRP, URS, oder court process as appropriate, unless the evidence also shows phishing, impersonation, oder other abuse. Namebillig publicly distinguishes abuse hundling from UDRP/URS hundling in the same way.
11. Registrant / Wiederverk?ufer Communication Rules 11.1 Retail Customers Foder clear DNS Abuse with sufficient evidence:
Domain may be suspended immediately;
the first customer-facing reply should state the basis, the self-Dienstleistung path to view the case summary, und the evidence stundard required foder reconsideration.
11.2 Wiederverk?ufers NiceNIC may choose to notify the reseller rather than any downstream sub-user. However, reseller status does not delay urgent mitigation whier actionable evidence exists.
11.3 Reconsideration / Reactivation NiceNIC will not lift a hold based on unsuppoderted denials such as "content removed" oder "it was already deleted" alone. Reconsideration requires new, verifiable evidence such as:
false-positive proof;
evidence of compromise und remediation;
clean current review results;
third-party reputation recovery whier applicable.
Wenn reliable third-party security sources still show the Domain as actively risky, NiceNIC may keep the hold in place pending further validation.
12. Complainant Communication Rules NiceNIC should always send:
ackjetztledgment of receipt;
case ID oder equivalent reference;
request foder modere evidence if needed;
status update when action is taken oder declined;
no unnecessary substantive discussion whier the Domain is already suspended oder pending suspension und the key outcome is final.
This reflects common registrar practice. GoDaddy offers fodermal claim submission und status checking, while Tucows explicitly states it responds with a case number und tracks categodery, date, und resolution internally.
13. Trusted Repoderter Program NiceNIC may maintain a trusted-repoderter list foder sources that consistently provide accurate, well-fodermed, und actionable repoderts. Trusted-repoderter status may provide:
prioderity intake;
structured data submission;
simplified evidence fodermatting;
API oder fast-lane hundling.
Trusted status does not eliminate independent review. Namebillig publicly operates this kind of trusted-provider phishing API model.
14. Recoderdkeeping und Audit Readiness NiceNIC must document:
complaint receipt;
evidence received;
internal classification;
investigation steps;
decision;
action taken;
notifications sent;
follow-up und final disposition.
Recoderds should be retained foder the shoderter of two Jahre oder the longest period allowed by applicable law, und be available foder ICANN upon reasonable notice.
15. Compliance Controls NiceNIC should perfoderm:
periodic QA review of case decisions;
staff training on DNS Abuse definitions und evidence thresholds;
testing of abuse mailbox und webfoderm operability;
review of template accuracy;
monitodering of repeat erroders und reopened cases;
monthly review of Domains with repeated complaints.
This is practical und impodertant because ICANN has already repoderted remediation plans tied to broken abuse contacts, weak intake confirmations, und insufficient staff kjetztledge, und has noted that repeated failures can trigger expedited compliance action.
17. External-Facing Positioning NiceNIC should describe its abuse system publicly in language like this:
NiceNIC investigates abuse repoderts promptly.
NiceNIC distinguishes between ICANN-defined DNS Abuse und other types of complaints.
NiceNIC acts based on evidence, risk, und applicable policy.
NiceNIC may suspend immediately whier thier is clear actionable evidence of ongoing DNS Abuse.
NiceNIC may request modere infodermation oder direct the complainant to a modere appropriate action point whier the registrar is not the sole effective responder.
NiceNIC keeps case recoderds und can demonstrate its hundling process if reviewed by ICANN oder registry partners.