AWS is not offering Austria's TLD .at for registration
forums.aws.amazon.com
forums.aws.amazon.com
When we migrated DNS to route53 in early 2019 we discussed moving registration as well. That conversation took about two minutes and ended in a hard no.
Our registrar is MarkMonitor who specializes in large portfolios.
I’ve got a dedicated account rep. We know each other well. We talk often, not just domains but college sports, etc.
I need something I email my guy and it gets done.
Registering a .es domain requires a scan of my drivers license. He handles that.
Transferring in .am domains during a recent merger required an authorization letter, on letterhead, signed by a corporate officer.
We don’t have any .at but I’d put 20 quatloos on there being some sort of requirement that AWS can’t just drop into a web interface, combined with the fact you don’t really have phone support until you qualify for Enterprise Support.
My primary role is near what you’d call Cloud Architect, domains and DNS are a side gig that ended up in my lap. Being disappointed in how AWS does something is sort of a theme in my life.
In this particular case however I’d bet the issue is with the AT registry wanting something.
If AWS were to say what the problem was then people might be a bit happier to wait?
Drives me nuts, but all companies do this rather than giving a direct answer.
Except when they aren't, which is what I'm talking about. And you could say the same thing about the marketing speak.
If you ask a question on Stackoverflow, a lot of people will give you the answer they know, regardless of the question you asked.
If I ask "how do I do this with x?" The answer "Generally in this language we do it with y. Will that work?" is a proper answer
If I ask "why does x panic?" The answer isn't, "do y." The answer is an insight to the programming language/operating system in question, but people just can't resist, and it is exactly like the marketing speak mentioned here.
...But saying "we have all these other things that you've already told us you're aware of" is where things start to get passive aggressive.
Maybe it’s different inside the EU compared to outside of it, but I have a few .es domains and I didn’t have to provide a scan of any ID to reg them, I did have to provide the ID’s number.
Now it might be that the ID number might be more easily queryable between EU states removing the need of a scan compared to counties, I’ve never looked into it. But it’s still a piece of information MM can just hold on to and handle when required for you.
I’m just sharing my own experiences with .es tlds, one thing I will say having a 3rd party like MM monitoring and handling your .es domains is they are now responsible for renewing them, if you miss the emails about your domain expiring because auto-renew failed due to an expired card and you fail to renew in time there is little to no grace time compared to other tlds. That one almost bit me on the arse once :-(
If you lose the domain, you lose everything (email, web, services, etc.), possibly permanently, with no option to migrate without losing your domain, branding, SEO position, etc.
e.g.
* Your server got hacked, and your entire account gets blocked
* You get a shock bill from AWS, and lose access to the account because the account is unpaid.
* Also it allows your hosting provider to hold you ransom to payment or you lose everything
Someone less directly versed in the intricacies of registries and registrars and service providers might take longer to assert rights, deploy governance machinery, and achieve the same result, but the existential finality described above would be better painted as a time-consuming and Byzantine inconvenience.
I read domain registration horror stories with a pinch of salt. Not just because the sector is (like cryptocurrencies) riddled with scammers and shysters and liars and con-artists, but also because even the most Kafkesque fuckups I’ve seen ultimately started with incompetence, inexperience, arrogance, or negligence (usually omitted in the telling) on the part of the apparent victim.
Country code registries have their own, and many apparent registrars are actually reselling Tucows or OpenSRS, both of whom have compliance teams that create significant leverage over resellers.
However, communicating them with them concisely and unambiguously requires care and understanding. Obtaining a result from the people who execute these processes means encoding requests in terms of their incentives rather than your own. Many people find that hard to do, especially people burdened by their own overwhelming sense of entitlement. This is of course advice for anyone engaging with an external bureaucracy, and the best way to internalise it, is to have run one.
A few months later, I wanted to transfer them elsewhere, but quickly realized that the auth codes in the AWS interface had expired, with no way to renew them. I didn't have a support subscription since I only used the AWS account for these 4 domains + Route 53 and I wasn't about to pay Amazon 30$/month to get them to fix their own mistakes.
I naïvely tried contacting billing support (the only one you can contact for free, go figure) in the hope they could forward the bug report, but while they were very apologetic, there was nothing they could do.
So Amazon took my domains hostage for 6 months until they eventually figured out the bug on their own. Have not touched anything related to AWS ever since.
Big red flag!
This changed in 2015 and you can now register 2lds like company.nz or network.nz but AWS still hasn't updated their system. It means my employer has to have a 2nd registrar just for those domains. Nagging our TAM and asking other companies to do the same has had no effect.
Note that AWS use Ghandi.net for .nz registration (and many/most other TLS) and Ghandi do support .nz 2lds
Even large organizations struggle to do this with just one.
If Austria demands a valid Austrian ID number, Amazon would have to build an app to request this, validate it against the Austrian database, provide data security guarantees to the Austrian government for using this information, etc. If the barriers are higher than the demand Amazon will just say fuck it.
On the other hand, .com.au for example requires a valid Australian business registration number for domain registration.
ccTLDs are the Wild West. It's hard to generalize -- practically every ccTLD does something weird that makes it difficult to support, though.
A few examples of areas where ccTLDs behave significantly differently from gTLDs are:
• Many ccTLDs require registrants to have some form of personal or business presence in the country. The requirements for how the registrant must prove that presence can vary.
• Some ccTLDs have unusual processes surrounding domain expirations and renewals. For example, under some ccTLDs, domains always expire at the end of a month, rather than exactly a year after registration. Additionally, some ccTLDs restrict when domains can be renewed -- for example, .au domains can only be renewed within 90 days of their expiration, and .eu domains cannot be renewed within 5 days of expiration.
• Domain transfers can get weird as well. gTLDs have a standardized process for domain transfer authorization; ccTLDs often modify this system or replace it entirely.
Original Request from Feb 22, 2017. AWS person says it has been added as a feature request but no ETA. Occasional updates since then with people requesting and AWS saying "No ETA".
> .AT domains renew automatically. A domain must be cancelled 3 days before the expiry date to avoid renewal. ... If the reseller cannot reach the registrant, or if the registrant refuses to pay, refuses to sign the form, or claims not to have heard of the reseller, a Domain Withdrawal can be processed. To process this withdrawal, the reseller will have to contact OpenSRS support. They can state "I can not reach the registrant, please give the domain back to the registry". Once OpenSRS support processes the withdrawal the registry will no longer point the domain at OpenSRS. The registry will take over and contact the registrant. If the registrant is still unresponsive, the domain is deleted by the registry.
@AWS my 5cents: adding many more TLDs is one of the highest ROI investments you can make.
You'd of been fine to use AWS without route53, it's basically the standard. As discussed in this thread, separation of concerns is wise.
I have a .es (Spanish) domain, and it wasn't until quite recently that they stopped asking you to include your passport number or SSN in the WHOIS entry.
A number of registrars wouldn't let you buy the domain without residence in Spain either... Ended up going with a horrible registrar, and I transferred to Namecheap the moment they supported .es domains.
Domains, DNS, App/Web Hosting, Email (Domain and Transactional), File Storage, Version Control, Backups, Secrets Storage, Directory Services, Zero-Trust/VPN, etc. should be on different providers (or different accounts if an overlapping provider), whether the services are third-party or self-hosted or a mixture of both.
Would this service still provide value if all the others were down? Would all the others still provide value of this was down? If both answers are yes, separate, if both are no, don't, if the answers differ go with the flow.
There's definitely a fair bit of overhead for becoming a registrar of all gTLDs and ccTLDs (there is generally a different application needed for each ccTLD), and for smaller countries the overhead might not justify the number of registrations they expect to get.
I had a quick look at Cloudflare's offerings and it looks like they're only offering gTLDs but intend to expand their ccTLD list.
You can always manage any domain with Route53, but registrations are only supported for these TLDs.