What TrustName’s Termination Tells Us About DNS Abuse Enforcement

,  / October 01,2026

ICANN terminated Trustname.com’s accreditation on 27 August 2026, effective 11 September 2026, ending months of attempts to get the “bulletproof” registrar to action abuse reports for phishing. Termination means Trustname can no longer register gTLD domain names and existing registrations will be transitioned to another registrar. 

Why it matters: It’s one of the clearest tests of the 2024 DNS Abuse amendments. This is the first termination on the basis of DNS Abuse; it shows the amendments have teeth, and that ICANN Compliance is willing and able to terminate registrars on DNS Abuse grounds.

What happened?

To register generic Top Level Domains (gTLDs) a registrar needs to be accredited with ICANN and is allocated an IANA ID (a unique identifier). They also need to comply with the Registrar Accreditation Agreement (RAA). Section 3.18 of the RAA requires registrars to promptly act on well-evidenced DNS Abuse reports (e.g. phishing, malware and botnets). These requirements were introduced in 2024.

ICANN’s Compliance team enforces those contracts globally. Most of the time, we don’t see what is happening; Compliance works with operators to improve practices. In the most extreme cases, where engagement with the operator is unsuccessful, we see external signs. Previously these were breach notices regarding registrars and registries’ compliance with the DNS Abuse amendments. Now we see the first DNS Abuse related termination.

Fewmoretaps OU d/b/a Trustname.com (IANA#4318) (“Trustname”) was accredited as a registrar in 2023. In 2026, they received four breach notices from ICANN Compliance within 78 days — the most ICANN has issued to one registrar under these rules. ICANN terminated Trustname on two separate grounds: missed cure deadline, and four breaches within 12 months (the threshold is three).

Trustname marketed itself as a “bulletproof” registrar. According to their website, they applied a “Golden Principle of Self-Doubt”: erring toward the registrant, communicating with customers before acting, and letting registrants who seriously violated its rules transfer their domain elsewhere rather than lose it outright.

According to the breach notices, Trustname domains impersonated banks and a government tax agency. It didn’t act for weeks, and only after ICANN stepped in.

Importantly, ICANN followed through and enforced the contracts to the point of termination, effective 11 September 2026. A termination of accreditation means Trustname can no longer sell any gTLD domains. This includes the legacy TLDs such as .org, .com, .net, but also .top, .icu, .qpon, and any new gTLDs created in the future (a “next round” is currently underway).

Trustname’s existing registrations will be transferred under ICANN’s De-Accredited Registrar Transition Procedure. ICANN identifies a “gaining registrar” (either one Trustname proposes, or one selected through a competitive process) and bulk-transfers all affected gTLD registrations to them. Registrants keep their domains at no extra cost, with no change to expiration dates; the gaining registrar then contacts affected customers with instructions for managing their names going forward. Registrants can transfer elsewhere afterward, though the gaining registrar may deny outbound transfers for the first 60 days.

Enforcement is targeted, and it’s changing registrar behaviour 

From the indicators of enforcement we can see publicly, we know that ICANN has issued the following relevant breach notices:

Registrars

Registries 

Many of the registrars that received breach notices had already been showing up consistently in NetBeacon MAP’s public high-abuse tables beforehand. Aceville ranked in the top 5 for malicious domains per 100,000 Domains Under Management (DUM) for at least sixth months running before its September 2024 notice. When Ultahost received a breach notice in February 2025, they were unredacted in our public reporting with 20% of their new registrations being maliciously registered. Trustname first appeared unredacted in July 2026 with 820 malicious domains per 100,000 DUM, the second highest in the table. 

This indicates compliance has appropriately focused on registrars and TLDs with a high volume of maliciously registered domains used for phishing and malware. The current contracts don’t set any expectations on the amount of malicious registrations, only around the requirement to mitigate promptly. 

From the perspective of harm reduction, it’s reassuring to see a focus on registrars with high relative volumes of malicious registrations.

We measure mitigation in two places: NetBeacon Reporter has a strict mitigation measurement, looking for the application of clientHold and serverHold on domains that pass through the reporting conduit. NetBeacon MAP has a more holistic measurement of whether or not the harm has stopped, which we’re now working to attribute to specific actors.

We haven’t published attributed mitigation data for NetBeacon MAP yet. We’ve been working carefully to make sure we get this right. Accurately measuring malicious abuse is hard. Measuring mitigation is even harder. Correctly attributing it is crucial, and incredibly complex.

NetBeacon Reporter provides an interesting operational case study here. Anyone can report abuse through the conduit, so the quality can be varied and is likely to include at least some false positives. However, when we look at registrar behaviours prior and post breach notices, we see something fascinating.

Example Registrar 

Observing the EPP status of clientHold allows us to confidently attribute mitigation action to the registrar. The clientHold EPP status is set by a registrar and makes the domain non-functional; the registry equivalent is serverHold. Looking for these statuses is therefore a strict indication of mitigation attribution.

This chart tracks the use of clientHold and serverHold in the lead up to the breach notice of one registrar. We show three months before, and 11 months afterwards – broken down into weeks. The upper chart shows the percentage of mitigation under each category: clientHold, serverHold, no mitigation within 7 days, and ‘other mitigation’. We only began measuring other mitigation recently so it’s not present throughout the whole data set. The bar chart below shows the volume of raw domains flowing through NetBeacon Reporter for that registrar. 

Registrar A: Weekly abuse reports in NetBeacon Reporter and mitigation response (- 12 weeks before breach, and +45 weeks after)

In the three months in the lead up to the breach notice, this registrar’s application of clientHold moves between 14-31%. The number of cases per week typically fluctuates between 50-100. They experience an increase shortly before the breach, hitting 322 cases on the week of the breach notice. This volume stays high for approximately 19 weeks post breach before settling into a lower number per week. 

Around the time of the breach notice we see an interesting jump in the percentage of domains being met with clientHold, this sits around 80-90% for some time. The amount of abuse drops again in terms of raw volume, and clientHold fluctuates between 50-80%. 

One can reasonably conclude that the ICANN breach notice had the effect of changing this registrar’s behavior when it comes to DNS Abuse mitigation. 

Putting all of this together, it seems to indicate that ICANN Compliance’s enforcement of the DNS Abuse amendments is working. Interventions from ICANN Compliance can change registrar behaviour, and operators who consistently avoid their obligations can expect to have their accreditations terminated. 

What’s next? 

The policy landscape is set to change again, moving from a reactive mitigation requirement to additional expectations around unearthing related malicious domains, and a focus on applying friction for high volume registrations tools. The first of these changes (Associated Domain Check – “PDP 1”)  is out for consultation, you can read the NetBeacon submission here. 

Another DNS Abuse related PDP (“PDP 2”) is set to start shortly, aimed at creating friction for high volume registration tools, focusing more on the prevention of DNS Abuse.

We look forward to seeing the next developments and publishing more data in due course. 

Note: The mitigation measurements described here are also available for providers of reports to view on the domains they submit for free through NetBeacon Reporter. https://netbeacon.org/report-abuse/