Public Comment

Public Comment is a vital part of our multistakeholder model. It provides a mechanism for stakeholders to have their opinions and recommendations formally and publicly documented. It is an opportunity for the ICANN community to effect change and improve policies and operations.

Name: Nick Wenban-Smith
Date: 15 Oct 2025
Affiliation: Nominet UK
Summary of Submission

According to official statistics from the UK government (Cybersecurity Breaches Survey 2024) half of UK businesses report having experienced some form of cyber security breach or attack in the previous 12 months. Phishing is cited as being by far the most common attack vector, followed by impersonation in emails or online, and viruses and other malware. Phishing is also commonly cited as the most common form of DNS Abuse, and increasing rapidly year on year.

It is therefore incumbent on domain name ecosystem participants, including the ICANN contracted parties, to prevent the registration of phishing domains, and to swiftly deactivate any which manage to get past registration systems.

We therefore agree with the Netbeacon White Paper that proportionate, risk-based friction in registration processes may be an effective measure for the reduction of abusive domains which are created and then used to conduct phishing campaigns. It is for this reason that all newly created domains in the .UK ccTLD are screened and algorithmically assessed for phishing risk. High risk registrations have a temporary server hold applied until we are satisfied that they are legitimate.

We view restricting API access to known legitimate parties as potentially a sensible consensus policy which could shut down what is currently an easy entry point for threat actors to register phishing domains at scale.

In a similar vein we already look for patterns in proven phishing domains, and at the registry level carry out associated-domain checks as outlined in the Preliminary Issue Report. We can report that associated-domain checking is a simple and effective measure to detect phishing domains.

We therefore strongly support both the proposed PDPs. They address matters which are already established practice in leading registry providers, and therefore should present obvious quick wins in the constant battle against DNS Abuse. We see no reason why they cannot run concurrently on an urgent basis.