Public Comment

Public Comment is a vital part of our multistakeholder model. It provides a mechanism for stakeholders to have their opinions and recommendations formally and publicly documented. It is an opportunity for the ICANN community to effect change and improve policies and operations.

Contenido disponible solo en los siguientes idiomas

  • English

Name: Alexander Urbelis
Date: 17 Oct 2025
Affiliation: Ethereum Name Service (ENS) Labs
Other Comments

Public Comments by ENS Labs, Ltd

Ethereum Name Service (ENS) Labs supports ICANN proceeding with a Policy Development Process (PDP) on DNS Abuse Mitigation and offers the following comments on the Preliminary Issue Report.

ENS Labs is a non-profit organization that combats and tracks DNS abuse on a daily basis targeting its users with increasingly sophisticated attacks involving credentials harvesting, digital asset wallet drainers, and other forms of malicious impersonation. As such, ENS Labs is acutely aware of both the temporal and technical limitations of reporting DNS Abuse, the narrow scope of legal process such as the UDRP, and the increasingly scarce resources of law enforcement.  At the DNS‑OARC meeting on 8 October 2025 in Stockholm, we presented research detailing a campaign in which a single threat actor operated over 2,200 malicious domains targeting decentralized finance and Web3 users. We would be pleased to share those findings with ICANN staff.

DNS abuse continues to evolve with increasing velocity and volume.  The current ICANN mechanisms to address abuse are largely reactive – triggered only after harm occurs. While mechanisms such as the UDRP or Compliance complaints are valuable, they impose significant cost and logistical burdens on victims and address abuse only in a post hoc, fragmented, case-by-case fashion. ICANN needs a proactive, coordinated framework for prevention and mitigation.

Focus on Phase 0: Preventative Measures

ENS recommends that the PDP prioritize Phase 0, “Preventative Measures,” as identified in the Preliminary Issue Report. While the Report notes that not all such measures may suit consensus policy, ENS urges ICANN to codify as many as possible within Consensus Policy rather than relegating them to “best practices.”  Without binding policy, contracted parties lack accountability for prevention. In our experience, threat actors readily exploit registrars and jurisdictions with limited enforcement; the absence of universal preventative standards perpetuates this vulnerability.

To increase the likelihood of catching malicious activity early:

•  Technical indicators suggesting a domain is likely malicious should prompt interim action – without requiring victims to supply “actionable evidence” such as screenshots or phishing samples.

•  A domain that is prima facie malicious (based on defined criteria) should trigger registrar intervention.

•  Cybersecurity researchers and other trusted reporters should be able to  report domains via zone file analysis that match known threat actor tactics, techniques, and procedures (TTPs).

•  Registrars could temporarily place such domains on clientHold status, pending a registrant counter-notice.

A simple due process structure such as this mirrors the takedown process of the DMCA and ensures legitimate registrants retain simple recourse while protecting the broader Internet community from repeat offenders.

Scope of the PDP

ENS supports inclusion of Unrestricted API Access and Associated Domain Checks as Phase 0 priorities but strongly recommends adding “Coordinated Mitigation of DGA-Based Botnet Domains.” Although such botnet events are less frequent, their scale and impact justify consensus-level procedures for coordinated response. Even where cross-community coordination (e.g., with law enforcement) is required, embedding responsibilities in Consensus Policy would provide clarity, speed, and consistency. Standardized response workflows within ICANN’s remit would ensure that countermeasures are timely, integrated, and effective.

* * *

As an organization that is committed to the responsible integration of Web3 with the traditional DNS, ENS Labs appreciates ICANN’s consideration of these comments in preparing the Final Issue Report on the PDP for DNS Abuse Mitigation. We remain available to discuss at ICANN's convenience.


Sincerely yours,

Alexander Urbelis

General Counsel

ENS Labs, Ltd.


Summary of Attachment


Summary of Submission

The Ethereum Name Service (ENS) Labs’ public comment supports ICANN’s proposal to initiate a Policy Development Process (PDP) on DNS Abuse Mitigation, urging a more proactive and coordinated approach to combat DNS abuse. Drawing from its experience monitoring digital‑asset–focused impersonation and phishing campaigns—including a recent study of over 2,200 malicious domains—ENS highlights the limits of current reactive tools like the UDRP and compliance complaints. The submission recommends prioritizing “Phase 0: Preventative Measures,” calling on ICANN to integrate these standards into binding consensus policy rather than non‑mandatory best practices to ensure accountability among registrars and discourage exploitation of weak enforcement jurisdictions.