nanog mailing list archives

Re: New DNS vulnerability: political overreach


From: Tom Beecher via NANOG <nanog () lists nanog org>
Date: Tue, 28 Jul 2026 13:36:53 -0400


Again, this was a takedown at the registry, i.e., Verisign, not the
registrar.  To avoid this sort of action, you’d have to use a top-level
domain operated by a company outside of the US, e.g., a ccTLD not in
US/PR/AS/GU/VI/MP/(UM) or one of the new gTLDs not operated by a company
subject to US jurisdiction (I’m too lazy to look that up).  Of course,
going that route will probably result in your customers getting confused
because you don’t have a .COM domain name and, of course, you’d be subject
to the legal jurisdiction of the country the TLD is operated in.


Yes, s/registrar/registry/ in my message.

But beyond that, yes. This has been true since 2012 when the DOJ first
started performing domain seizures. A non-US entity only had to really pay
attention to US federal law; If you weren't doing anything with your domain
that might run afoul there, you were pretty safe that your domain wouldn't
be seized.  ( Acknowledging here that the justifications for this action
have been expanding since 2012, which is Not Great either. )

Now, if this Texas action sticks as precedent, any **alleged** violation of
ANY US law ( federal / state / local / territorial) allows a court to issue
an order to take your domain down if it's from a US registry. Which of
course opens the door to non-US registries doing the same things (if they
aren't already), and everything just gets more fragmented and stupid.

I applaud all the legal professionals who fight to prevent this stupidity.
Truly underappreciated.

On Tue, Jul 28, 2026 at 11:57 AM David Conrad <drc () virtualized org> wrote:

On Jul 28, 2026, at 9:32 PM, Tom Beecher via NANOG <nanog () lists nanog org>
wrote:
Getting back to the technical issue though, all these things do is
reinforce the thought that if you are using a domain for commercial
purposes , you probably want to strongly consider one managed by a non-US
registrar if possible,

Again, this was a takedown at the registry, i.e., Verisign, not the
registrar.  To avoid this sort of action, you’d have to use a top-level
domain operated by a company outside of the US, e.g., a ccTLD not in
US/PR/AS/GU/VI/MP/(UM) or one of the new gTLDs not operated by a company
subject to US jurisdiction (I’m too lazy to look that up).  Of course,
going that route will probably result in your customers getting confused
because you don’t have a .COM domain name and, of course, you’d be subject
to the legal jurisdiction of the country the TLD is operated in.

Regards,
-drc


_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/Q5LO2PJCJ52CV3FPQKFQ6VDUTJEPHXVU/

Current thread: