Editorial mirrorBrand mentions redacted to public IDs. Hover to inspect. Everything else is theatre.How it works
THE ENABLERS REGISTRYRegistrar accountability archive
Archive LiveRead-only public record · No ads · No tracking
Case file folder with redacted documents and confidential investigation report.
CASE / REGISTRAR ACCOUNTABILITY

Registrar Accountability — Who Acts on Abuse Reports

The Enablers Registry·Editorial mirror·/registrar-accountability/

Public record copy. Brand names withheld, public accreditation numbers preserved. If the body below says “we”, that means the original publisher, not this mirror. TER only preserves, redacts, and re-contextualizes.

Registrar Accountability

Every abuse report we send is logged. This page turns that log into a scoreboard: how long each registrar takes to act, how many escalations it takes, and how many malicious domains stay live on their watch. The numbers are computed deterministically from raw data — the categories are derived from the numbers, not from us.

The illusion of security — how registrars profit from the abuse they ignore

On paper, every registrar is bound by its ICANN agreement to investigate and act on abuse. In practice that agreement is a dead letter — window dressing over a business model built on willful blindness. In this project’s entire history we have not seen ICANN apply a single meaningful sanction against a negligent registrar, while the registrar keeps collecting its fee on every domain it sells — the malicious ones included. A registrar may decide it knows better than VirusTotal and the wider infosec community and leave a flagged domain up. Fine — but then the loss that lands on the next victim is the registrar’s to answer for, not the victim’s.

Mass negligence

Valid, evidence-backed abuse reports are systematically ignored, buried, or met with an automated non-reply.

Indisputable proof, ignored

Domains flagged by VirusTotal and independent infosec labs stay live while abuse desks stall or go silent.

Profitable delays

Malware and possibly phishing stay online for weeks — every extra day is a paying customer the registrar won’t cut off.

Someone pays for the miss

Override the evidence and the outcome is yours to own. “There were no reports” no longer works — every notice here is logged, timestamped and exportable on demand.

We don’t persecute domains or registrars. Nothing here runs on a timer — and until this year we had no way to re-report at all. The first notice goes out at detection; we escalate only after independently re-confirming a domain is still live and dangerous, and only a very small share ever gets that far. Even under that restraint, this is the record: not incompetence, but tacit complicity — and it is fully exportable, every email, every date. Everything below is the receipts.

Negligent Slow Responsive Insufficient sample
Methodology — how these numbers are computed

Registrars ranked by (in)action

Registrar Domains Reports Suspended Never suspended Verdict
Loading accountability data…

Fairness safeguards. IANA #1910 and free hosts (Vercel, GitHub, Netlify and similar) are excluded on purpose — they are free services, not paid registrars, and it is not their job to cover for a registrar that refuses its own. Their abuse forms usually work better and faster, and we still report to them by hand when a registrar fails; scoreboarding them here would be unfair. Registrars with fewer than 10 reported domains are omitted to avoid small-sample distortion. Response medians are computed only over domains with a confirmed takedown; still-active domains are counted separately and never averaged in. Every claim is reproducible from the hashed dataset IANA #1086.

Continue browsing the ledger

This page is the editorial mirror. Brand names are redacted to public IANA / business identifiers. Use the index to navigate other case files.

Open registrar ledger → All briefings