CertaDNS
Skip to lesson

Reporting Abuse · lesson 2 of 2

When nobody answers

After this lesson you can

Escalate an ignored report through the routes that exist, and know when to stop.

Assumes you have read The first message.

A meaningful share of well-written reports get no reply. The routes that exist are limited, and knowing which ones are real saves a week of writing to people who will not answer.

The escalation ladder

StepRouteRealistic?
1Follow up once, referencing the original, after two business daysYes. Queues lose things, and a polite follow-up frequently works.
2Move to the next party in the chain — host to registrar, or the reverseYes. This is the main escalation and should have been started in parallel anyway.
3The registrar’s own upstream, if they are a resellerSometimes. The RDAP record names the sponsoring registrar, which may not be who you wrote to.
4The registry for that TLDSometimes, for their own policy breaches. Weeks.
5ICANN complaint, for gTLD registrars ignoring abuse obligationsSlow, and it creates a record that matters for repeat offenders.
6Blocklist submissions and browser safe-browsing reportsYes, and it should happen early rather than as an escalation.

Step 6 belongs at the start

Reporting to browser safe-browsing services and phishing blocklists does not remove the site, and it interrupts the campaign — a browser interstitial stops most victims. It requires nobody’s cooperation, takes a minute, and works while every other route is still in a queue.

On detection, in parallel:
   1. capture evidence
   2. report to the host
   3. report to the registrar
   4. submit to safe-browsing and blocklists   <- do not wait

Step 4 has the shortest path to protecting people
and the least dependency on anyone answering.

Knowing when to stop

  • When the campaign is over. A domain that stopped serving content two weeks ago is not worth further escalation.
  • When the host is deliberately unresponsive. Some providers do not act, by business model. Recognise them and route around via the registrar and the blocklists.
  • When the domain matters enough for UDRP, which is a different process on a different timescale.
  • Record the outcome either way. A registrar that ignored three well-evidenced reports is a fact worth having next time, and worth having in an ICANN complaint.

The metric is duration, not resolution

A campaign interrupted by a browser warning on day one and taken down on day six is a better outcome than one taken down on day three with no interruption. Measure how long the site was effective, not how many takedowns were successful.

Last reviewed