Skip to main content
Evidence · Not Opinion · Updated Daily

Registrar Accountability

Listen to this article
0:00 / --:--

Every abuse report we send is logged. This page turns that log into a scoreboard: how long each registrar takes to act, how many escalations it takes, and how many malicious domains stay live on their watch. The numbers are computed deterministically from raw data — the categories are derived from the numbers, not from us.

The illusion of security — how registrars profit from the abuse they ignore

On paper, every registrar is bound by its ICANN agreement to investigate and act on abuse. In practice that agreement is a dead letter — window dressing over a business model built on willful blindness. In this project’s entire history we have not seen ICANN apply a single meaningful sanction against a negligent registrar, while the registrar keeps collecting its fee on every domain it sells — the malicious ones included. A registrar may decide it knows better than VirusTotal and the wider infosec community and leave a flagged domain up. Fine — but then the loss that lands on the next victim is the registrar’s to answer for, not the victim’s.

Mass negligence

Valid, evidence-backed abuse reports are systematically ignored, buried, or met with an automated non-reply.

Indisputable proof, ignored

Domains flagged by VirusTotal and independent infosec labs stay live while abuse desks stall or go silent.

Profitable delays

Malware and phishing stay online for weeks — every extra day is a paying customer the registrar won’t cut off.

Someone pays for the miss

Override the evidence and the outcome is yours to own. “There were no reports” no longer works — every notice here is logged, timestamped and exportable on demand.

We don’t persecute domains or registrars. Nothing here runs on a timer — and until this year we had no way to re-report at all. The first notice goes out at detection; we escalate only after independently re-confirming a domain is still live and dangerous, and only a very small share ever gets that far. Even under that restraint, this is the record: not incompetence, but tacit complicity — and it is fully exportable, every email, every date. Everything below is the receipts.

Negligent Slow Responsive Insufficient sample
Methodology — how these numbers are computed

Registrars ranked by (in)action

Registrar Domains Reports Suspended Never suspended Verdict
Loading accountability data…

Fairness safeguards. Cloudflare and free hosts (Vercel, GitHub, Netlify and similar) are excluded on purpose — they are free services, not paid registrars, and it is not their job to cover for a registrar that refuses its own. Their abuse forms usually work better and faster, and we still report to them by hand when a registrar fails; scoreboarding them here would be unfair. Registrars with fewer than 10 reported domains are omitted to avoid small-sample distortion. Response medians are computed only over domains with a confirmed takedown; still-active domains are counted separately and never averaged in. Every claim is reproducible from the hashed dataset above.