My comments to ICANN regarding their proposed changes to the UDRP and URS

You have until Monday, August 10, 2026 (23:59 UTC) to tell ICANN what you think. Do not miss this deadline. Submit comments here. There will likely be no further opportunity to comment on these changes.

I’ve completed my company’s comments to ICANN regarding their proposed changes to the UDRP and URS. These lopsided changes harm domain name registrants, and do not even faithfully apply the recommendations of the prior policy working groups.

The documents out for public comment are  misaligned with the underlying policy recommendations, to the further detriment of registrants’ fundamental rights to due process. ICANN takes every opportunity to hollow out the rights of domain name owners, especially when few are paying attention. The capture of the process is evident, given that the deviations from the policy recommendations are not random, but overwhelmingly go in favour of IGOs (like WIPO, OECD, etc.) and against registrants. The policy recommendations themselves were already unbalanced, and we expressed our opposition repeatedly. But, the implementation of the recommendations is even worse than the policies that the ICANN Board approved.

You can read my company’s full submission in the PDF below (105 pages!), or via ICANN’s public comment forum.

LEAP-ICANN-IGO-2026August9-comments-FINAL.pdf

I sounded the alarm about the serious defects on Friday’s blog post. I also made an AI-generated podcast earlier today that’s a fairly good overview of why the topic is important to registrants.

Below is a quick summary of the submission, as posted to the ICANN comment forum. The 105-page PDF submission is relatively dense and technical, and is intended to be precise for all the (mostly) lawyers reviewing the submissions within ICANN’s processes.

If you agree with our concerns, feel free to submit your own comment endorsing our submission. Or, if you need more time to study the issues, you should ask ICANN to extend the comment period, perhaps until the end of the summer.

Kudos to Ron Jackson of DNJournal for submitting a comment already.


Our position: the draft documents are not aligned with the policy recommendations the ICANN Board adopted in April 2023, and they are not close to it.

We identify 32 numbered changes needed across the three documents — 15 to the UDRP materials, 11 to the URS materials, 6 to the Policy Guidance — plus 11 further points about the process. The number matters less than the direction. Almost without exception, where the adopted recommendations gave a domain name registrant a protection, the drafts remove it, narrow it, or defer it to documents that have not been written; where the adopted recommendations gave intergovernmental organisations something, the drafts deliver it in full and sometimes add to it. A pattern that runs so consistently one way deserves an explanation.

One example, in plain language. The Board adopted a rule that a registrant who takes a dispute to court keeps the domain name while the case is heard. The drafts omit it. A registrant who exercises the very right the Board preserved would lose the name before any judge examines the case — and once a name has passed to an organisation that can assert immunity from national courts, recovering it is, in practice, extremely difficult.

The package is also incomplete. Which arbitration institutions will hear these cases, under what rules, and at what cost are all left blank. The community is being asked to approve a system whose operative content does not yet exist.

We therefore ask ICANN to extend this comment period. It falls across the northern-hemisphere summer; the material is long and technical; and the volume of defects that one outside reviewer found in a few weeks suggests the detailed review that should already have taken place has not. We encourage others — registrars, non-commercial users, and individual registrants — to read the drafts and file comments. Ensuring alignment is ICANN’s obligation rather than the community’s, but on this record it will not happen unless people say so.

AI-generated podcast on the ICANN comment period regarding changes to the UDRP and URS

Monday is the deadline to submit comments to ICANN regarding the changes to the UDRP and URS in relations to IGOs, which harm the fundamental rights of domain name owners, that I discussed in Friday’s blog post.

I’m still working on my lengthy submission (over 100 pages long now), as the ICANN materials are replete with serious issues that harm registrants and I want to be as thorough as I can in the limited time available.

While I work on it further, I fed the latest draft into Google’s NotebookLM AI tool, and it generated a relatively high quality podcast summarizing some of the issues.

Since my written submission will be quite technical and dense, folks might find the less technical AI-generated podcast to be more accessible as a general introduction to the issues. If you feel that more time is needed to study this issue, I encourage you to ask ICANN to extend the deadline to the end of summer, via their public comment tool.

RED ALERT: ICANN’s Draft IGO Rules Would Transfer Your Domain Name Even While You’re Suing In Court

You have until Monday, August 10, 2026 (23:59 UTC) to tell ICANN what you think. Do not miss this deadline. Submit comments here. There will likely be no further opportunity to comment on these changes.

Long-time readers of this blog know that I’ve spent more than a decade fighting ICANN’s repeated attempts to carve out special privileges for intergovernmental organizations (IGOs) at the expense of the fundamental rights of domain name registrants. I was a member of the original working group (2014–2018) that reached consensus against replacing the courts with arbitration. I was then shut out of the captured “EPDP” that reversed that outcome, and shut out again from the closed-door Implementation Review Team (IRT) that has now produced the draft rules ICANN published for public comment on June 30, 2026.

I’ve been digging through the draft implementation documents line by line, comparing them against the policy recommendations the ICANN Board actually adopted on April 30, 2023. I’ll have much more to say about what I found (there’s a lot), but one defect is so serious — and so indefensible — that it deserves its own RED ALERT post.

Continue reading “RED ALERT: ICANN’s Draft IGO Rules Would Transfer Your Domain Name Even While You’re Suing In Court”

My Comments To The ICANN Board Regarding The Transfer Policy Final Report

The turd polishers at ICANN have produced yet another highly polished turd of a report regarding domain name transfer policy, that is open for public comments until 23:59 UTC time on Monday June 16, 2025 (i.e. less than 24 hours from the time of this blog post). The report is being voted upon by the ICANN Board, so this is really the final opportunity to go “on the record” with your input (which will in all likelihood be completely ignored, but some of us still choose to submit comments regardless).

Our complete submission is now visible on ICANN’s website here, or you can read the main 19 page PDF here.

For a small taste of the contents of the document, here’s the “Conclusion” section from the final page of the PDF:

The analysis presented herein underscores that the “push-based” transfer system and enhanced WHOIS transparency within the Losing FOA are not merely incremental improvements but represent fundamental shifts necessary for establishing robust domain name security and ensuring comprehensive registrant protection in the evolving digital landscape. These proposals address inherent vulnerabilities in the current transfer policy that the Transfer Policy Review Working Group’s Final Report has, regrettably, failed to adequately address.

The working group’s dismissal of the push-based system due to a stated preference for “incremental change” and perceived workload reveals a systemic bias within ICANN policy development towards minor adjustments over truly transformative ideas. This incrementalist approach inherently limits ICANN’s capacity to achieve optimal security and fulfill its mandate, highlighting the critical need for Board intervention. Furthermore, the dominance of registrars within this working group and the referral of critical proposals to “Tech Ops,” which is not a true multistakeholder forum, point to a fundamental challenge within ICANN’s multistakeholder model regarding the perceived balance of power and influence. The Board’s decision on this report will therefore signal its commitment not only to domain transfer security but also to the integrity of genuine multistakeholder engagement and registrant representation, thereby impacting ICANN’s overall legitimacy and accountability.

Therefore, it is strongly urged that the ICANN Board reject the Transfer Policy Review Working Group’s Final Report in its current form. The Board should instead mandate further work by a truly multistakeholder body, with explicit instructions to thoroughly evaluate and prioritize the push-based transfer system and the enhanced WHOIS transparency proposal within the Losing GOA. This decisive action would demonstrate a commitment to innovation and prioritize registrant security over incrementalism or the vested interests of specific contracted parties. By taking such a course, the ICANN Board would not only address critical security deficiencies but also reaffirm its dedication to its core mission and the principles of a balanced, accountable multistakeholder model.

My Comments to ICANN Opposing the 2024 .COM Renewal

The public comment period regarding the .COM renewal ends today (November 5, 2024). ICANN routinely ignores public input, and I expect that will continue with this comment period.

Regardless, I’ve submitted a comment opposing to the .COM renewal, in order to be on the record. You can also read it here (PDF).

Continue reading “My Comments to ICANN Opposing the 2024 .COM Renewal”

AI-generated Audio Podcast about ICANN IGO Issues and Domain Disputes

(if you’re having trouble using the media player, the MP3 is here)

In January 2023, I submitted extensive comments to ICANN, regarding IGO Issues and domain name disputes. There were 3 quite detailed PDFs in that submission (as there were other comment periods over the years), that many may not have read.

Using the NotebookLM AI tool I mentioned in an earlier post today, that generated an excellent podcast regarding domain name transfer policy, I figured I’d let the AI summarize my IGO-related submissions. The result is the embedded audio in this blog post. It did a fairly good job of explaining things at a high-level, although it missed an important detail, namely that IGOs are able to assert immunity when they’re the defendant, and thus the “role reversal” gives them a big advantage (especially if they’re no longer agreeing to the mutual jurisdiction clause). I hope this piques the interest of those who’ve not followed this important issue, and causes them to dive deeper into the PDFs (which have more detailed arguments).

 

 

Push system for domain name transfers already in place for .co.uk!

Theo Develegas, the author of DomainGang, has a personal blog. He wrote about a .co.uk transfer today:

https://acro.net/blog/enom-end-of-an-era-the-fastest-domain-transfer-ever/

which noted:

What surprised me was the way .co.uk domains are transferred to another registrar, in this case Spaceship. After unlocking the domain, I went to Spaceship to begin the transfer out which required to copy an IPS tag into the domain’s record.

What is an IPS tag for domains, you may ask. It’s like a reverse authentication code: You get it from the registrar you move your .co.uk domain to and provide it to the registrar where the domain sits at.

The moment the IPS tag was updated at eNom the domain was no longer there. It was an instant change of registrar! All I had to do next was complete the transfer at Spaceship by submitting the request. The domain appeared in my account, once again instantly.

That’s the kind of “push” system  for domain name transfers that I’ve been advocating for more than 2 years at ICANN, for gTLD domain names like .com. It’s already in production. There’s no excuse now for ICANN not to adopt this, at least as a pilot project, for gTLD domain names.

 

AI-generated Audio Podcast about ICANN Transfer Policy

Prepare to be blown away! 

As regular readers of this blog will be aware, I’ve written extensively about proposed changes to the ICANN Transfer Policy.  Last week, I blogged about my 2024 submission to ICANN. It also mentioned my previous extensive submissions in 2022.

Today, I read about an interesting AI tool created by Google called NotebookLM which is able to summarize documents and even create audio podcasts. So, as an experiment, I uploaded my 2024 and 2022 ICANN submissions into NotebookLM, and here’s the result (7 minutes and 41 seconds in length).

(if you’re having trouble using the media player, the MP3 file is here)

Isn’t that simply incredible?

Continue reading “AI-generated Audio Podcast about ICANN Transfer Policy”

My 2024 Submission To ICANN Regarding Transfer Policy, ahead of September 30 deadline

ICANN has another public comment period regarding transfer policy. The deadline to submit comments is Monday September 30, 2024 at 23:59 UTC time.

My company’s submission can be read here. I focused on the lack of consideration of a “push” system of transfers, and lack of overall consideration of registrants’ input.

This isn’t the first time that ICANN has asked for input on transfer policy. My company submitted substantial comments in 2022 as well, which the captured working group, dominated by registrars, has not incorporated into its latest set of recommendations.

As this is likely the final opportunity to impact the working group’s final recommendations before they’re sent to the GNSO Council (despite being misleadingly labelled as an “Inital Report“, which I called out in my latest comments), now is the time to make a submission on this important topic which affects registrants.

Hopefully my company’s submission of today, and also from 2022, will help stimulate your own thinking, before you submit your own comments.

[For posterity and archival purposes, one can find a PDF version of my submitted comments here.]

 

Millions Of Sensitive US Military Emails Misdirected To Mali, Despite 2014 Warning From Me

In August 2014, I noticed a potential security vulnerability in relation to the .mil top-level domain, which is operated by the US military. As such, I reported the issue to CERT, describing the issue in sufficient detail that they could understand the problem.

Today, I learned via a tweet from Elliot Silver:

about the report in the Financial Times concerning millions of US military emails being misdirected, and quote-tweeted that I had reported the issue many years ago:

https://twitter.com/GeorgeKirikos/status/1680925062621216768

Elliot Silver later blogged about it, and it’s been reported on by many other news outlets.

You can read my August 6, 2014 CERT “Vulnerability Report” here (I had prudently saved a copy), and the confirmation was VRF#HYIXW4Z4. [The PDF is redacted, as it had contained my cell phone number, which I rarely disclose.]

Continue reading “Millions Of Sensitive US Military Emails Misdirected To Mali, Despite 2014 Warning From Me”