DNS Abuse Response: From Detection to Enforcement PhishDestroy Research. Version 1.0. Published 2 August 2026. Direct answer. The defensible policy problem is not that the domain-name system has no abuse rules, nor that every malicious report should trigger an automatic suspension. It is that evidence, notification, mitigation and appeal are measured inconsistently across different actors. This paper proposes a common, auditable evidence-to-action protocol: preserve provenance; record comparable timestamps; separate malicious registrations from compromised services; assess collateral impact; apply proportionate response targets; publish outcomes; and provide rapid reversal. The architecture is a hypothesis to pilot, not a claim of settled law or proven global effectiveness. Directly supported by an official document or published study. A reproducible calculation whose inputs are assumptions, not market averages. A design offered for consultation, testing and revision. Research question, scope and standard of proof The question is narrower than “who failed?”: which observable delays between validated evidence and proportionate action are preventable, and which intervention reduces victim harm without creating unacceptable false positives or collateral damage? The scope is the contracted gTLD ecosystem: registrants, resellers, registrars, registries and ICANN's contractual compliance function. Hosting providers, CDNs, browsers, payment services, advertising platforms, national CERTs and law enforcement are included only where they affect the evidence or response chain. Country-code TLDs have different governance and are not assumed to be subject to ICANN's gTLD contracts. Claims this paper does not make It does not treat ICANN as a government regulator or law-enforcement body. ICANN is a nonprofit, multistakeholder technical coordinator and a contractual counterparty with compliance functions. It does not claim that 60–85% of global fraud loss occurs after detection. That percentage requires a disclosed incident-level dataset and remains a hypothesis. It does not claim that the entire domain namespace can be governed or rendered for $100 per month. A narrow ingest-and-triage prototype can run on commodity infrastructure; production enforcement cannot. It does not claim a universal 21-day takedown SLA. Current contractual language generally requires prompt and appropriate mitigation; specific timelines vary by report and process. It does not presume that serverHold is always the correct remedy. Registry-level suspension can affect mail, subdomains and legitimate users and may persist in caches until TTL expiry. The proposal is falsifiable. A pilot can compare treatment and control cohorts on time-to-triage, time-to-mitigation, victim-loss proxies, recurrence, false positives, reversal time and collateral impact. What the primary sources establish ICANN's first six-month enforcement report under the 2024 amendments recorded 192 investigations, more than 2,700 suspended domains, more than 350 disabled phishing pages and two Notices of Breach. Those figures do not prove that present controls are sufficient, but they rule out the absolute claim that the system takes no action. Why response latency remains a legitimate research target Some phishing campaigns operate on a timescale of hours or days. Bijmans et al. reported an average observed lifetime of 45 hours and a median of 24 hours for 1,288 phishing domains in one 2021 study. A 2026 study of newly registered phishing domains reported a highly skewed distribution: for 14,112 domains with measurable lifetimes, the mean was 8.6 days and the median one day. Neither sample can be generalized to every threat class, but both show why a process measured only in business days may miss short-lived campaigns. The curve visualizes the scenario in Section 4; it is not observed market data. Horizontal placement compresses long intervals for readability. Source: reproducible model with disclosed inputs. A shorter domain lifetime does not automatically equal prevented financial loss. Attackers may migrate, use compromised sites, change delivery channels or cash out before detection. The causal effect must be measured, not inferred from takedown speed alone. Campaign economics as a reproducible scenario The economically relevant asset is often not the registration fee but the traffic, creative, infrastructure and trust accumulated around a domain. That intuition is plausible; its magnitude varies by campaign. The calculator below therefore exposes every input instead of presenting a hypothetical result as an observed average. Measuring preventable harm without inventing precision “Loss after detection” can become a useful outcome only if detection, delivery and harm are defined consistently. A blacklist timestamp is not proof that the registrar received actionable evidence. A wallet transaction is not automatically attributable to one domain. A domain becoming unreachable does not identify which actor caused the change. Minimum event schema The numerator and denominator must use the same attribution rule. Results should report the cohort, confidence interval, right-censoring, missing sources, duplicate-victim handling and sensitivity to the observation window. The label “preventable” should be reserved for a causal design or, at minimum, a matched comparison — not every event after notice. The earlier article's 60–85% estimate should be treated as an empirical hypothesis until an incident-level dataset, selection criteria and uncertainty analysis are published. This paper does not use it as a finding. The institutional map: capability is distributed No single actor sees or controls the full incident. The registrar knows the registrant relationship; the registry controls registry-set domain status; the host and CDN control content delivery; browsers and security vendors control warnings; payment and wallet providers can interrupt transfers; authorities can compel preservation or seizure. ICANN writes and enforces contracts in the gTLD ecosystem but does not operate a universal EPP control plane. Observe content, infrastructure and victim indicators; preserve provenance. Can remove content or access rapidly, often without changing the domain. Reviews abuse, contacts the registrant and can set client-side status. Controls registry-set EPP status and the TLD zone delegation. Investigates contracted-party compliance; does not adjudicate every fraud case. Coordinate response and use jurisdiction-specific legal powers. The design implication is orchestration, not centralization. A common case identifier and evidence envelope should let each actor record what it saw, what authority it used and what outcome it produced, while keeping legal responsibility with the actor that takes the action. The 2024 contractual baseline — and what it does not specify The April 2024 global amendments to the Registrar Accreditation Agreement and Base Registry Agreement created express obligations to mitigate DNS Abuse. Registrars must act promptly when they have actionable evidence that a sponsored name is being used for DNS Abuse. Registry operators must act promptly where they reasonably determine, based on actionable evidence, that a registered name is being used for DNS Abuse. In both cases the appropriate measure depends on context, severity and collateral harm. Three timelines that are often conflated This flexibility has benefits: a compromised university domain should not be handled like a newly registered single-purpose phishing domain. The accountability problem is that “prompt” and “appropriate” are difficult to compare without published timestamps, case categories and outcome codes. The proposal below adds measurement and review without pretending that one deadline fits every case. The boundary problem: phishing is covered; some financial deception may not be Phishing is explicitly within the contractual definition of DNS Abuse. The harder boundary concerns sites that deceive users under an original name rather than impersonating an identifiable third party: some fake investment platforms, fraudulent stores, recovery scams and wallet-signature schemes. Depending on facts, these may be treated as website-content abuse, consumer fraud or another legal category rather than contractual DNS Abuse. Verified Financial Harm Abuse (VFHA): documented use of a domain to obtain funds, payment credentials, private keys or seed phrases through deception, regardless of brand impersonation. VFHA is not current ICANN terminology and does not itself create contractual authority. A policy consultation could ask whether a narrowly evidenced category like VFHA belongs in future contracts, a cross-sector referral framework, or national law. Expansion should require a precise harm test, reliable evidence, proportional remedies, jurisdictional review and appeal. Vague “scam” labels are insufficient. What a $100/month prototype can — and cannot — buy A commodity server can ingest a defined set of zone-file diffs, Certificate Transparency events and open feeds, normalize strings, compute hashes and prioritize candidates. That is a useful engineering benchmark. It is not “complete monitoring of the Internet.” In Q2 2026, Verisign reported 401.6 million registrations across all TLDs; CZDS covers participating gTLD zone files rather than all TLDs, and CT covers publicly logged certificates rather than every active domain. Widths are logarithmic to keep small values visible. Prototype and programme values are planning assumptions, not vendor quotations. ICANN operations funding is shown only as institutional scale; the categories are not equivalent budgets. Proposed Verified Abuse Response Framework The proposed framework is a reference architecture, not an automatic global kill switch. It standardizes the case envelope, decision record and timestamps while allowing the authorized operator to choose the least disruptive effective action. Collect reports and observations; hash raw artifacts; synchronize clocks. Record origin, method, handling history and source dependencies. Reproduce the harmful behavior and distinguish independent evidence. Classify malicious registration, compromised service, shared hosting and criticality. Assign the responsible actor, target time and least disruptive effective remedy. Publish outcome metadata, measure impact and support rapid reversal. Evidence tiers Single feed, lexical match or reputation claim. Suitable for observation, never sufficient alone for suspension. Timestamped capture showing credential theft, malware delivery or a deceptive transaction path. At least two genuinely independent sources or one reproducible technical proof plus ownership/context checks. Authority, affected service, brand owner or validated victim evidence, with privacy-safe chain of custody. Three feeds that copy the same upstream blacklist are one source, not three. The provenance graph must expose shared origin, synchronization and vendor re-publication. A minimal evidence envelope and interoperable API The API should create a verifiable case, not issue a suspension command. Decision authority remains with the registrar, registry, host, platform or competent authority. Every state transition is signed and appended to the audit log. A successful response returns a case ID, the receiving actor, evidence tier, completeness errors, target review time and a public transparency URL. It must not promise a specific remedy before a competent actor evaluates authority and collateral impact. Proposed response targets, not universal takedown deadlines Service-level objectives should separate acknowledgement, triage, decision and effective mitigation. This makes performance measurable without assuming that suspension is always the right outcome. These are pilot targets. The correct values should be derived from observed threat lifetimes, staffing, error cost and legal constraints, then published with attainment distributions rather than a single average. Safety, due process, privacy and failure modes Fast response without safeguards can amplify bad data into censorship, commercial sabotage or infrastructure outages. A legitimate architecture therefore treats false positives and collateral harm as first-class security failures. Minimum due-process guarantees Reason code, evidence tier and responsible decision-maker are recorded for every restrictive action. A registrant can obtain a privacy-safe statement of reasons and submit counter-evidence. Urgent appeals are reviewed by a person who did not make the original decision. Reversal propagates through the same signed channel as the original action. Aggregate error and restoration statistics are public; sensitive evidence remains access-controlled. From a “toxicity score” to an accountable Response Quality Index A public registrar score can improve accountability, but naïve rankings are distorted by portfolio size, feed coverage, customer mix and whether domains were maliciously registered or later compromised. A score must never justify collective blocking of all customers of a registrar. If a composite is required for governance, weights should be set before evaluation, sensitivity-tested and backtested against held-out cases. Results should be stratified by TLD, registrar size, threat class and evidence source. The output is an accountability signal — not an automated domain verdict. A tiered Public Abuse Transparency Database A transparency registry can eliminate disputes over whether a notice existed, when it was delivered and what action followed. Publishing every artifact, however, could expose victims, personal data, investigative methods and live exploit paths. The solution is tiered access. Case ID, indicator, broad category, key timestamps, evidence tier, actor roles, outcome code, appeal state and hashes of sealed artifacts. Reproducible technical evidence, contact channel, collateral context and preservation instructions. Victim data, financial attribution, active-investigation material and unredacted chain of custody. Each update is append-only, timestamped and signed. Corrections do not erase history; they add a superseding record. Public search should obey retention rules, prevent bulk victim discovery and offer redress for inaccurate personal data. A six-month pilot with a pre-registered evaluation A useful pilot should be small enough to govern and large enough to test the causal chain. Suggested scope: three volunteer registrars, two registry operators, one hosting/CDN partner, two independent research feeds and a qualified appeal panel. The study protocol and outcome definitions should be registered before cases are assigned. Define categories, authorities, evidence tiers, privacy impact assessment and stop conditions. Measure baseline timestamps and outcomes without changing response behavior. Introduce signed provenance, de-duplication and collateral classification. Randomize eligible cases or use a stepped-wedge rollout; monitor errors daily. Conduct restoration drills, red-team malicious reports and audit access controls. Publish effect sizes, confidence intervals, missingness, adverse events, costs and replication materials. Primary pilot outcomes Median and 90th-percentile time from validated evidence to effective mitigation. Difference in attributable post-notice harm or a pre-specified victim-exposure proxy. False-positive rate, wrongful-action severity and median restoration time. Recurrence at the same registrant, infrastructure cluster and campaign level. Direct operational cost per validated case and per effective mitigation. Scale only if the pilot shows materially faster effective mitigation without exceeding pre-registered limits for false positives, privacy incidents, appeal delay or collateral service disruption. Conclusions and testable recommendations DNS abuse response is neither a purely technical filter nor a problem one institution can solve by itself. Existing 2024 contracts established meaningful mitigation duties, but they leave substantial discretion over evidence, timing and remedy. That discretion is necessary for proportionality; without comparable records, it also makes performance difficult to evaluate. Standardize the evidence envelope. Adopt common provenance, timestamp and outcome fields across reporters, registrars, registries and infrastructure providers. Measure stages separately. Publish acknowledgement, triage, decision, mitigation and appeal times by threat class and evidence tier. Distinguish malicious registration from compromise. Prefer path/account remediation for compromised legitimate services and reserve domain-wide measures for cases where they are proportionate. Pilot response targets. Test hour-scale objectives for high-confidence, single-purpose malicious registrations rather than declaring a universal deadline. Publish privacy-safe accountability data. Use a tiered transparency registry with signed histories and restricted evidence. Evaluate causal impact. Do not equate faster suspension with saved money until a pre-registered study measures victim-impact outcomes and displacement. The strongest constructive claim is therefore modest but actionable: the ecosystem can make response latency, evidence quality, error and harm measurable now. Once measured, faster and safer interventions can be tested against a baseline. If the intervention fails, the same data will show why. If it succeeds, the evidence — rather than rhetoric — can support contractual or policy change. The earlier investigation presents a deliberately adversarial accountability argument. This whitepaper narrows or supersedes its broad claims where primary sources support more precise wording.