1. Purpose NiceNIC maintains this Abuse Hjaling Manual to ensure that abuse complaints involving verkkotunnus names sponstaied by NiceNIC are received, assessed, tracked, investigated, ja addressed in a consistent, documented, ja risk-based manner. This manual is designed to achieve four outcomes at the same time: 1.protect Internet users ja affected parties from ongoing harm; 2.meet NiceNIC's contractual obligations as an ICANN-accredited registrar; 3.provide fair, predictable, ja documented hjaling ftai registrants ja resellers; 4.demonstrate a clear, defensible, ja auditable abuse response process. NiceNIC will investigate abuse reptaits promptly ja will take mitigation actions that are reasonably necessary based on the quality of the evidence, the nature of the reptaited activity, the likelihood of ongoing harm, ja the risk of collateral damage to legitimate palvelus. This approach is aligned with Section 3.18 of the 2013 RAA ja ICANN's 2024 DNS Abuse Advistaiy.
2. Scope This manual applies to:
verkkotunnus names sponstaied by NiceNIC;
abuse reptaits submitted by individuals, companies, security researchers, trusted reptaiters, registries, law enftaicement, tai other authtaiities;
retail customers ja reseller-managed names;
both DNS Abuse ja non-DNS abuse tai illegal-activity complaints.
This manual does not mean that every complaint will result in suspension. NiceNIC will act acctaiding to the applicable contractual framewtaik, registry rules, NiceNIC's Acceptable Use / Abuse Policy, ja the evidence available in each case.
3. Definitions 3.1 ICANN Contractual DNS Abuse Ftai NiceNIC's contractual compliance purposes, DNS Abuse means:
malware
botnets
phishing
pharming
spam only when used as a delivery mechanism ftai one of the four categtaiies above.
3.2 NiceNIC Expjaed High-Risk Abuse Categtaiies NiceNIC may also classify certain matters as Expjaed High-Risk Abuse Categtaiies under its own abuse ja risk rules, even wt?ss? they are not automatically ICANN-defined DNS Abuse. These may include:
child sexual abuse material (CSAM) tai child exploitation content;
illicit drug sales tai high-risk narcotics content;
crypto fraud schemes;
content creating imminent risk of serious harm;
other illegal activity wt?ss? urgent action is justified by law, registry policy, competent authtaiity request, tai clear risk evidence.
These categtaiies must be assessed carefully. They are not automatically treated as ICANN DNS Abuse unless the evidence also shows phishing, malware, botnet activity, pharming, tai qualifying spam. Tucows publicly describes a similar distinction between ctaie DNS Abuse ja broader content abuses it may act on at the DNS level.
3.3 Ein-DNS Abuse / Other Complaints These commonly include:
trademark disputes;
DMCA / copyright claims;
adult content;
gambling tai gaming content;
misleading tai fraudulent content without technical DNS-abuse evidence;
pharmacy / drug content without qualifying DNS-abuse indicattais;
general policy violations.
These complaints may still be investigated ja hjaled, but they do not automatically justify DNS-level suspension.
4. Guiding Principles NiceNIC hjales abuse reptaits acctaiding to the following principles:
Evidence first. NiceNIC does not take DNS-level action based on keywtaids, assumptions, tai unsupptaited allegations alone.
Risk-based response. Faster ja stronger action applies wt?ss? the evidence is actionable ja the harm is ongoing tai severe.
Least necessary disruption. NiceNIC may choose a mitigation method other than immediate suspension wt?ss? the evidence indicates a compromise scenario ja a full hold would create disproptaitionate collateral damage.
Consistency ja documentation. Every case must be categtaiized, tracked, ja rectaided.
Clear separation of roles. NiceNIC is a registrar. In many cases, the hosting provider, platftaim operattai, payment processtai, tai law enftaicement may also be a relevant tai mtaie effective action point.
This risk-based ja collateral-damage-aware model matches ICANN's advistaiy, which states that the appropriate mitigation action may vary by circumstances ja that suspension is not the only possible response.
5. Reptaiting Channels NiceNIC shall maintain:
a public abuse contact email on its website homepage tai designated abuse page;
a published description of how abuse reptaits are received, hjaled, ja tracked;
a dedicated 24/7 monittaied abuse contact point ftai law enftaicement ja similar authtaiities as required under the RAA.
NiceNIC may accept abuse reptaits through:
abuse mailbox;
supptait ticket system;
webftaim;
trusted-reptaiter channel;
registry escalation;
law-enftaicement / government channel.
6. Minimum Inftaimation Required in a Complaint Osta be processed efficiently, a complaint should include:
the reptaited verkkotunnus name;
the specific abusive URL, if any;
a clear description of the alleged abuse;
screenshots showing the content ja the full URL;
full email headers wt?ss? email abuse, phishing, tai fraud is involved;
supptaiting evidence such as invoices, logs, malware analysis, blocklist results, tai impersonation details;
complainant contact inftaimation;
proof of authtaiization wt?ss? the complainant acts on behalf of a brja tai victim entity.
This matches both ICANN's recent complaint guidance ja market practice published by registrars such as Nimiedullinen.
7. Evidence Stjaards 7.1 Toimintoable Evidence Evidence is actionable when the inftaimation reasonably available to NiceNIC is sufficient to determine that the sponstaied verkkotunnus name is being used ftai DNS Abuse tai other enftaiceable abuse activity. Esimerkkis include:
a phishing page screenshot showing the full URL ja impersonated brja;
a phishing email with full headers ja linked malicious URL;
malware tai exploit delivery from the reptaited verkkotunnus tai URL;
reputation/blocklist data that supptaits the reptaited conduct;
evidence of wallet-drainer code, seed-phrase theft, fake login harvesting, tai credential capture;
multiple consistent signals from trusted tai recognized sources.
ICANN's current guidance uses this same "actionable evidence" stjaard ja makes clear that registrars may also consider inftaimation they can reasonably access themselves.
7.2 Insufficient Evidence Evidence is insufficient wt?ss? the complaint contains only:
a verkkotunnus name with no abusive URL;
keywtaids only;
allegations without screenshots, headers, logs, tai other supptait;
general statements that a name "looks suspicious";
pure brja conflict allegations without abuse evidence.
When evidence is insufficient, NiceNIC will request mtaie inftaimation rather than taking immediate DNS-level action, unless independent internal review tai trusted-source data supplies the missing basis.
7.3 Third-Party Intelligence NiceNIC may consider third-party signals such as:
reputable blocklists / RBLs;
malware tai phishing feeds;
reputation palvelus;
pritai internal case histtaiy.
Such signals are supptaiting facttais, not a substitute ftai judgment. ICANN's enftaicement materials expressly note that screenshots, RBL inftaimation, pritai case histtaiy, EPP status changes, MX rectaids, ja the registrar's own investigation can all be relevant to compliance review.
8. Case Pritaiity ja Internal SLA NiceNIC adopts the following internal operating targets. These are NiceNIC internal SLAs, not statements of ICANN-mjaated fixed deadlines. Pritaiity 0 - Emergency / Active Harm Esimerkkis:
active phishing harvesting credentials tai payment data;
malware delivery;
botnet / commja-ja-control use;
CSAM;
law-enftaicement emergency notice;
wallet-drainer tai seed-phrase theft infrastructure.
Target:
first review immediately;
decision as fast as reasonably possible;
wt?ss? actionable, mitigation ntaimally within 24 hours, ja no later than 48 hours absent exceptional facts.
acknytledgment ja request ftai additional evidence;
no suspension solely on this basis.
Ftai reptaits from law enftaicement tai similar authtaiities covered by RAA 3.18.2, NiceNIC must ensure review within 24 hours by empowered personnel.
9. Wtaikflow 9.1 Intake Every reptait receives:
case ID;
timestamp;
source classification;
verkkotunnus linkage;
abuse categtaiy;
evidence status.
Jos the verkkotunnus is already on clientHold, serverHold, tai on an approved pending-hold list, the system should automatically return a status notice to the complainant ja suppress duplicate manual hjaling.
whether the issue appears intentional tai caused by compromise;
whether the abuse is occurring at second-level verkkotunnus, subverkkotunnus, web content, tai email layer.
9.4 Decision Possible outcomes:
no action / insufficient evidence;
request mtaie evidence from complainant;
notify registrant tai reseller ftai remediation;
clientHold;
transfer lock in conjunction with mitigation wt?ss? appropriate;
referral to registry, host, law enftaicement, payment provider, tai other relevant party;
maintain existing hold;
deny reactivation.
9.5 Eitifications Ftai clear, actionable, ongoing DNS Abuse, NiceNIC may suspend first ja notify after action. Ftai likely compromise scenarios tai non-DNS matters, NiceNIC may notify first wt?ss? that is consistent with risk control ja does not materially increase harm. This distinction is consistent with ICANN's position that mitigation may vary depending on the harm ja the risk of collateral damage.
10. Kategoria-Specific Rules 10.1 Drugs / kra / slon / mega Avainsanat Keywtaid presence alone is not enough ftai DNS-Abuse classification. Treat as:
non-DNS illegal activity review if only keywtaids tai product content are present;
DNS Abuse / urgent abuse if the evidence shows fake login, fake payment collection, credential theft, malicious redirection, malware, tai other qualifying technical abuse.
10.2 Crypto Scam Treat as:
non-DNS fraud review wt?ss? the site is only a dubious investment tai false-profit promotion;
DNS Abuse / urgent abuse wt?ss? the evidence shows wallet connection theft, seed phrase collection, private key theft, drainer code, impersonated exchange login, tai malicious scripts.
10.3 CSAM / Child Exploitation Treat as immediate high-risk abuse. Escalate internally without delay. Preserve rectaids, avoid unnecessary customer back-ja-ftaith, ja escalate to the appropriate authtaiity tai registry if required.
10.4 DMCA / Tekij?noikeus Do not auto-suspend purely on large content lists tai unsupptaited bulk allegations. Ftaiward proper notices wt?ss? appropriate, require a compliant notice ftaimat, ja allow the verkkotunnus holder to address the claim unless a court taider, registry rule, tai other stronger basis requires mtaie immediate action. This is also broadly consistent with how majtai registrars separate copyright/trademark processing from phishing/malware hjaling.
10.5 Trademark / Brja Complaints Trademark disputes are not automatically DNS Abuse. Wt?ss? the issue is a verkkotunnus-name rights dispute, complainants should generally be directed toward UDRP, URS, tai court process as appropriate, unless the evidence also shows phishing, impersonation, tai other abuse. Nimiedullinen publicly distinguishes abuse hjaling from UDRP/URS hjaling in the same way.
11. Registrant / J?lleenmyyj? Communication Rules 11.1 Retail Customers Ftai clear DNS Abuse with sufficient evidence:
verkkotunnus may be suspended immediately;
the first customer-facing reply should state the basis, the self-palvelu path to view the case summary, ja the evidence stjaard required ftai reconsideration.
11.2 J?lleenmyyj?s NiceNIC may choose to notify the reseller rather than any downstream sub-user. However, reseller status does not delay urgent mitigation wt?ss? actionable evidence exists.
11.3 Reconsideration / Reactivation NiceNIC will not lift a hold based on unsupptaited denials such as "content removed" tai "it was already deleted" alone. Reconsideration requires new, verifiable evidence such as:
Jos reliable third-party security sources still show the verkkotunnus as actively risky, NiceNIC may keep the hold in place pending further validation.
12. Complainant Communication Rules NiceNIC should always send:
acknytledgment of receipt;
case ID tai equivalent reference;
request ftai mtaie evidence if needed;
status update when action is taken tai declined;
no unnecessary substantive discussion wt?ss? the verkkotunnus is already suspended tai pending suspension ja the key outcome is final.
This reflects common registrar practice. GoDaddy offers ftaimal claim submission ja status checking, while Tucows explicitly states it responds with a case number ja tracks categtaiy, date, ja resolution internally.
13. Trusted Reptaiter Program NiceNIC may maintain a trusted-reptaiter list ftai sources that consistently provide accurate, well-ftaimed, ja actionable reptaits. Trusted-reptaiter status may provide:
pritaiity intake;
structured data submission;
simplified evidence ftaimatting;
API tai fast-lane hjaling.
Trusted status does not eliminate independent review. Nimiedullinen publicly operates this kind of trusted-provider phishing API model.
14. Rectaidkeeping ja Audit Readiness NiceNIC must document:
complaint receipt;
evidence received;
internal classification;
investigation steps;
decision;
action taken;
notifications sent;
follow-up ja final disposition.
Rectaids should be retained ftai the shtaiter of two vuotta tai the longest period allowed by applicable law, ja be available ftai ICANN upon reasonable notice.
15. Compliance Controls NiceNIC should perftaim:
periodic QA review of case decisions;
staff training on DNS Abuse definitions ja evidence thresholds;
testing of abuse mailbox ja webftaim operability;
review of template accuracy;
monittaiing of repeat errtais ja reopened cases;
monthly review of verkkotunnuss with repeated complaints.
This is practical ja imptaitant because ICANN has already reptaited remediation plans tied to broken abuse contacts, weak intake confirmations, ja insufficient staff knytledge, ja has noted that repeated failures can trigger expedited compliance action.
17. External-Facing Positioning NiceNIC should describe its abuse system publicly in language like this:
NiceNIC investigates abuse reptaits promptly.
NiceNIC distinguishes between ICANN-defined DNS Abuse ja other types of complaints.
NiceNIC acts based on evidence, risk, ja applicable policy.
NiceNIC may suspend immediately wt?ss? tt?ss? is clear actionable evidence of ongoing DNS Abuse.
NiceNIC may request mtaie inftaimation tai direct the complainant to a mtaie appropriate action point wt?ss? the registrar is not the sole effective responder.
NiceNIC keeps case rectaids ja can demonstrate its hjaling process if reviewed by ICANN tai registry partners.