
Registrar Accountability
Every abuse report we send is logged. This page turns that log into a scoreboard: how long each registrar takes to act, how many escalations it takes, and how many malicious domains stay live on their watch. The numbers are computed deterministically from raw data — the categories are derived from the numbers, not from us.
The illusion of security — how registrars profit from the abuse they ignore
On paper, every registrar is bound by its ICANN agreement to investigate and act on abuse. In practice that agreement is a dead letter — window dressing over a business model built on willful blindness. In this project’s entire history we have not seen ICANN apply a single meaningful sanction against a negligent registrar, while the registrar keeps collecting its fee on every domain it sells — the malicious ones included. A registrar may decide it knows better than VirusTotal and the wider infosec community and leave a flagged domain up. Fine — but then the loss that lands on the next victim is the registrar’s to answer for, not the victim’s.
Mass negligence
Valid, evidence-backed abuse reports are systematically ignored, buried, or met with an automated non-reply.
Indisputable proof, ignored
Domains flagged by VirusTotal and independent infosec labs stay live while abuse desks stall or go silent.
Profitable delays
Malware and possibly phishing stay online for weeks — every extra day is a paying customer the registrar won’t cut off.
Someone pays for the miss
Override the evidence and the outcome is yours to own. “There were no reports” no longer works — every notice here is logged, timestamped and exportable on demand.
We don’t persecute domains or registrars. Nothing here runs on a timer — and until this year we had no way to re-report at all. The first notice goes out at detection; we escalate only after independently re-confirming a domain is still live and dangerous, and only a very small share ever gets that far. Even under that restraint, this is the record: not incompetence, but tacit complicity — and it is fully exportable, every email, every date. Everything below is the receipts.
Public by design — every report carried a disclosure notice
Every abuse report we send carries an explicit notice to the recipient: its contents — including the exact date and time it was sent and the full body of the request — may and will be made available to the public. This page contains only emails that carried that notice, and the same notice is published in our open-source DestroyList repository. The data is ours, disclosure was declared in every message, and we are fully within our rights to publish it.
Some registrars behave as though their internal policies override ICANN’s requirements and national law — as if possibly phishing and fraud are “permitted” for as long as they personally choose not to act. We document this publicly so anyone can see the plain truth: these threats persist not because they went unnoticed, but because the responsible provider decided to do nothing.
Any victim has the right to know how many times a registrar was warned about the domain that harmed them — and how many times it could have prevented the loss. That record is now public: this page and its full dataset are open-source under the MIT license on GitHub, free for anyone to verify, cite, or build on.
Requesting the record
DestroyList is an independent, non-commercial, open-source project. Anyone may look up how many abuse reports we sent for a specific domain — but only through public channels, so access is equal for everyone:
Methodology — how these numbers are computed
Registrars ranked by (in)action
| Registrar | Domains | Reports | Suspended | Never suspended | Verdict |
|---|---|---|---|---|---|
| Loading accountability data… | |||||
Fairness safeguards. IANA #1910 and free hosts (Vercel, GitHub, Netlify and similar) are excluded on purpose — they are free services, not paid registrars, and it is not their job to cover for a registrar that refuses its own. Their abuse forms usually work better and faster, and we still report to them by hand when a registrar fails; scoreboarding them here would be unfair. Registrars with fewer than 10 reported domains are omitted to avoid small-sample distortion. Response medians are computed only over domains with a confirmed takedown; still-active domains are counted separately and never averaged in. Every claim is reproducible from the hashed dataset IANA #1086.