10/06/2026 | Press release | Distributed by Public on 10/06/2026 10:06
Evidence-based policy development depends not only on having data, but also on having transparent and reproducible methods for analyzing it. As the ICANN community continues its work on the GNSO-initiated Domain Name System (DNS) Abuse Mitigation Policy Development Process (PDP) 1, one important question is how domain names associated with those known to be engaged in DNS Abuse can be identified using available data.
To help address this question, ICANN has today announced the release of a new report, Associated Domain Analysis Using Public Data, in its Office of the Chief Technology Officer (OCTO) publication series. ICANN's research provides technical groundwork that can help inform the community's consideration of this question by documenting a transparent and reproducible approach to identifying such associations.
The report highlights the potential value of associated domain analysis using only publicly available technical registration and DNS infrastructure data to support efforts to mitigate DNS Abuse. The methodology does not rely on registrant contact information, payment data, or account-holder identifiers. The OCTO study found that more than half (56.4 percent) of the reported maliciously registered generic top-level domain names (gTLDs) included in the study sample had at least one associated domain.
For ICANN, DNS Abuse is defined as botnets, malware, phishing, pharming, and spam (when used as a vector for any of those specific abuses). The practice of rapidly registering high volumes of domain names has previously been observed in connection with large-scale DNS Abuse campaigns. Using a set of multiple overlapping techniques, the OCTO report establishes a baseline methodology for the identification of associated domain name registrations. The methodology may be used in future for reporting, as well as to support the proactive identification of domains that may be at high risk of abuse.
ICANN plans to continue this line of research, including further work to validate the results, minimize data processing delays, and distribute output to relevant ICANN stakeholders.
This follow-up work will build on the methodology established in this report and provide additional empirical evidence that may be useful to the community as its work on associated domain checks progresses.
For a complete list of titles in the OCTO Publications series, please see the OCTO publication page. If you have questions or would like to comment on one of the reports, please send an email to [email protected].