Home / Blogs

Proxy-Privacy User Higher for Illicit Domains

Don't miss a thing – sign up for CircleID Weekly Wrap newsletter delivered to your inbox once a week.
Garth Bruen

WHOIS issues are looming large for the ICANN meeting next week, starting with an all-day WHOIS Policy Review on Sunday (background). WHOIS is a subject that has been the recent topic of a number of issues including a debacle over potentially disclosing the identities of compliance reporters to spammers and criminal domainers. For those unacquainted with the purpose of WHOIS, I would recommend Paul Vixie's excellent article.

One of the controversial sub-issues is privacy-proxy domain registrations which allow a registrant to replace their WHOIS details with the contact information a of privacy shield company. The privacy-proxy business is a nebulous world with no standards and little accountability. Supporters claim it protects victims and political activists from attacks and private citizens from getting spammed or scammed. Critics, like me, contend it is a loose system run on behalf of criminals and spammers. Additionally, the illicit use of privacy-proxy erodes the legitimate use. This is compounded by the fact that many privacy-proxy services are phantom companies themselves.

In September of last year ICANN released the results of a study estimating 18% usage of privacy-proxy services in the gTLD (full report). However, Knujon research has revealed that privacy-proxy usage is significantly higher among illicit domain registrations. We looked at two specific categories: spammed domains and illicit pharmacy domains. The conventional logic has always been that spammers and criminals would not waste money on privacy services, that they would simply falsify registration data or use "throw-away" free email addresses. We know this is not the case. One section of a report KnujOn will issue on Tuesday March 15th will show 33% usage of privacy-proxy registrations for domains advertised in spam and 39 to 51% usage among illicit pharmacy domains.

KnujOn studied 13,277 repeatedly spammed domains over six months and found that among the general population, most registrants used unmonitored or false yahoo.com, gmail.com, hotmail.com, and other free-email accounts in the registration. However, six out of the top ten spam registrations were through Registrar-sponsored privacy services. Also, 31 of the all the 152 registrant emails domains collected were privacy services.

For illicit pharmacy domains, the numbers are even more interesting. Once again gmail, yahoo, hotmail and aol "throw-aways" were most popular but 15 out of the top 20 contact emails used were at privacy services, most were the services offered by the sponsoring Registrar. Among the general population of 27,414 illicit pharmacy domains studied 39% used privacy-proxy. Within the 50th percentile there is 45% privacy usage, in the 25th percentile it is 48%. Among the top 50 contact email domains 51% were privacy services. The most used privacy services had 8,380 illicit pharmacies as customers.

For some, the question still remains, why pay for a privacy service when bogus WHOIS information is easy to use? There are a variety of reasons. First, it adds another layer of obfuscation to confound investigators. A separate KnujOn study found over 100 illicit pharmacy domains, that had the privacy service removed after complaints, had false WHOIS underneath. A second reason is that it provides additional cover for illicit registrants by creating an unaccountable phantom third party that is neither completely registrant nor Registrar. This is evidenced in multiple UDPRs where a brand owner eventually wins an infringing domain name through default but the true identity of the original owner is never revealed.

There are many more issues including which privacy services are compliant with the ICANN RAA and who owns the privacy services heavily used by illicit domainers. This will be detailed in our full report.

By Garth Bruen, Internet Fraud Analyst and Policy Developer. More blog posts from Garth Bruen can also be read here.

Related topics: Cybercrime, Cybersecurity, Cybersquatting, DNS, Domain Names, ICANN, Internet Governance, Law, Policy & Regulation, Privacy, Registry Services, Spam, Top-Level Domains, UDRP, Whois

 
   

Comments

To post comments, please login or create an account.

Related Blogs

Related News

Explore Topics

Dig Deeper

Verisign

Cybersecurity

Sponsored by Verisign
Afilias Mobile & Web Services

Mobile Internet

Sponsored by Afilias Mobile & Web Services
Afilias

DNS Security

Sponsored by Afilias

Promoted Posts

Now Is the Time for .eco

.eco launches globally at 16:00 UTC on April 25, 2017, when domains will be available on a first-come, first-serve basis. .eco is for businesses, non-profits and people committed to positive change for the planet. See list of registrars offering .eco more»

Boston Ivy Gets Competitive With Its TLDs, Offers Registrars New Wholesale Pricing

With a mission to make its top-level domains available to the broadest market possible, Boston Ivy has permanently reduced its registration, renewal and transfer prices for .Broker, .Forex, .Markets and .Trading. more»

Industry Updates – Sponsored Posts

Attacks Decrease by 23 Precent in 1st Quarter While Peak Attack Sizes Increase: DDoS Trends Report

UDRP: Better Late than Never - ICA Applauds WIPO for Removing Misguided 'Retroactive Bad Faith'

The Rise and Fall of the UDRP Theory of 'Retroactive Bad Faith'

.PRESS Supports Press Freedom Day for 3rd Consecutive Year

Leading Internet Associations Strengthen Cooperation

5 Afilias Top Level Domains Now Licensed for Sale in China

Radix Announces Largest New gTLD Sale with Casino.Online

2016 Year in Review: The Trending Keywords in .COM and .NET Domain Registrations

Global Domain Name Registrations Reach 329.3 Million, 2.3 Million Growth in Last Quarter of 2016

i2Coalition to Present Tucows CEO Elliot Noss With Internet Community Leadership Award

A Look at How the New .SPACE TLD Has Performed Over the Past 2 Years

Verisign Releases Q4 2016 DDoS Trends Report: 167% Increase in Average Peak Attack from 2015 to 2016

Michele Neylon Appointed Chair Elect of i2Coalition

Neustar to be Acquired by Private Investment Group Led by Golden Gate Capital

Startup League Reports from WebSummit, Lisbon

Verisign Q3 2016 DDoS Trends Report: User Datagram Protocol (UDP) Flood Attacks Continue to Dominate

2016 U.S. Election: An Internet Forecast

.SPACE Becomes the Choice of the First Ever Space Nation Asgardia

Government Guidance for Email Authentication Has Arrived in USA and UK

Afilias Chairman Jonathan Robinson Wins ICANN's 2016 Leadership Award at ICANN 57