Skip to main content
Guidance

Good security practice for domain registrars

Principles to reduce the prevalence of malicious and abusive domain registrations.

Page 2 of 5

1. Put in place security controls at customer registration

Having security controls in place when a customer registers a domain helps prevent the registration of misleading or fraudulent domains in the first place. Efficient and effective checks should take into account cost and user experience, while also making it more difficult to obtain domains to use for abuse.

Different types of domain registrar may have different relationships with their customers. In cases where a registrar is able to establish a high level of trust with each customer, it is good practice to use checks at customer registration to defend against domain name abuse. For the large volume or more automated retail sale of domains, this approach may not be suitable, and other measures to prevent abuse should be used.

‘Know your customer’ checks

Aim: To help prevent accounts being registered for abuse, while maintaining usability for legitimate users.

You should verify that the information a customer provides, such as source IP address, email address, phone number or payment information is valid and not previously known to be used in fraud or abuse. You can do this by:

  • verifying that the contact information a customer provides is accessible to the customer (referred to by ICANN as ‘operational verification’), for example by sending a numeric code to input, before you allow a domain to be registered
  • ensuring that the information a customer provides is checked against available threat intelligence as part of the anti-fraud and abuse checks during registration
  • checking customer details against your own and third-party threat intelligence, and carrying out additional reviews on flagged transactions and accounts

If you use an external payment provider that doesn’t provide full customer details, you should take action to understand their verification processes and carry out additional checks if required. The NetBeacon Institute has an example workflow to incorporate anti-fraud and abuse checks into domain registrations. 

By following this process, verification can be part of a set of automated checks that takes into account different factors, including payment method, and the domain a customer intends to register. The results can then be used to calculate a score which allows either automatic acceptance, denial or further review.

 

Published

Reviewed

Version

1.0