ICANN's new rules for domain registrants require you to verify an email address
iwantmyname.com
iwantmyname.com
Link: http://www.icann.org/en/resources/registrars/raa/approved-wi...
You can thank the law enforcement lobby and ICANN wanting to keep them happy. All of us registrars fought hard against it for a number of obvious reasons, but they went forward with it anyway.
Almost all registrars will be on the new contract soon if they already aren't because ICANN made it a requirement to be able to sell the new GTLDs. This is now going to be a normal part of owning a domain name.
Also, the verification checks only need to be done after you initially submit your contact details or after you attempt to change them, so it shouldn't be too much of an issue.
The big problem that registrars face is that law enforcement want us, the registrars, to verify phone numbers and addresses too, which is going to push up costs quite a bit, even if we find ways of doing so without having to actually phone people.
It's going to suck.
Verifying addresses sounds like a real pain though. I imagine they'd want a scan of some ID or something else just as silly. Hopefully ICANN can push back on LE.
Thankfully, the new requirements for gTLDs aren't quite that onerous: we have to contact them to validate phone numbers and emails (which can mostly be automated), and we only have to ensure that the address provided is valid. That said, the costs involved in address verification aren't small, and we're hedging potential savings in avoiding fraudulent customers against the additional costs involved.
ICANN can't push back against the LEAs though: this stuff is now in the contract, so we're all stuck with it.
That is 200 verification emails, which now need to be pressed or whoops, no more working web shop, email!, and internal API will stop working and so on. Remember that broken DNS will cause emails to bounce rather than being resent later by the mail server.
Example 2: A company is changing name/owner, and in middle of all this need to register new domain name. Whoops, forgot to activate in all that?
Example 3: technical contact is on vacation.
Of course, if your registrar doesn't manage contacts as separate objects from domains (and some don't), they yeah, you'll end up getting a boatload of verification emails.
You'll also start finding a bunch of registrars doing email address checks to ensure deliverability before any registrations or contact updates are performed: this is for the customer's good and the registrar's good.
Registrars have to make a best effort to contact the customer by email. That means that if the email does bounce initially (due to DNS issues, full mailbox, &c.), it's up to the registrar to try again until the grace period expires.
Your second one isn't correct: if your contact has already been verified, there's no need to verified again. It's only if the contact is new or updated that verification needs to be done.
In the third case, you should be using roles, not individuals. Mail aliases were invented for a reason: no one person should be receiving these emails, so it's really your own tough luck if you're a business and you're not ensuring that there's somebody always able to receive and process the emails. Moreover, verification happens when a contact is created or updated, so it should be an address with somebody immediately able to process the verification request.
As far as my ability to write authoritatively on the subject goes, I'm the development lead for a registrar, and implemented most of our domain management system myself.
The verification and validation requirements the LEAs pushed down our throats are still crazy, even if they're not as bad now as what they were initially looking for.
Yeah, because there's absolutely no way to have an anonymous email address... /s But seriously, what does law enforcement think this will accomplish? I could see ICANN wanting to cut down on squatters or other domain delinquents, but for tracking down criminals this seems pointless. If anyone has theories or info on what they hope to accomplish I'd be interested.
Here is the applicable rules. As nitinag pointed out this only is for registrar's who have signed the 2013 RAA. Registrars still under the 2009 RAA are not bound by this. (At some point they will have to sign the new RAA and they will right away if they want to sell (as was pointed out) the new f TLDs.
http://www.icann.org/en/resources/registrars/raa/approved-wi...
While I can't speak for what other registrars will be doing these ICANN policies in the past tend to leave plenty of wiggle room and the ability to game the system (by registrars) if they want to.
Specifically:
"In either case, if Registrar does not receive an affirmative response from the Registered Name Holder, Registrar shall either verify the applicable contact information manually or suspend the registration, until such time as Registrar has verified the applicable contact information. If Registrar does not receive an affirmative response from the Account Holder, Registrar shall verify the applicable contact information manually, but is not required to suspend any registration."
Verify: the email address of the Registered Name Holder (and, if different, the Account Holder) by sending an email requiring an affirmative response through a tool-based authentication method such as providing a unique code that must be returned in a manner designated by the Registrar, or
the telephone number of the Registered Name Holder (and, if different, the Account Holder) by either (A) calling or sending an SMS to the Registered Name Holder's telephone number providing a unique code that must be returned in a manner designated by the Registrar, or (B) calling the Registered Name Holder's telephone number and requiring the Registered Name Holder to provide a unique code that was sent to the Registered Name Holder via web, email or postal mail.
In either case, if Registrar does not receive an affirmative response from the Registered Name Holder, Registrar shall either verify the applicable contact information manually or suspend the registration, until such time as Registrar has verified the applicable contact information. If Registrar does not receive an affirmative response from the Account Holder, Registrar shall verify the applicable contact information manually, but is not required to suspend any registration. ====================
So there are other methods that ICANN outlines in order to verify the account holder information to activate the domain, not _just_ an email address like the article states.
But which one?
I get plenty of emails in my whois-listed mailbox that purport to be from my registrar. Guess how many are genuine.
Also, consider using your registrar's WHOIS privacy service, if they provide one: your registrar only has to ensure the details you provided are genuine, and those can be masked in WHOIS.
For example, NameCheap' WhoisGuard service has an option to rotate the email address every 30 days. If I subscribe to a service like that, will I have to verify the randomly generated address every time it is rotated?
Right now, they only ask for confirmation once a year regardless of whether there has been any change of contact info. But OP makes it look like I'll have to verify my email address every time it changes, and one of the main features of WhoisGuard is that the email address in my whois changes all the time.
If I tell NameCheap/WhoisGuard to rotate my email every day (probably overkill, but it's possible), will I wake up every morning to find a new confirmation link in my inbox?
As far as I know, the address confirmations are for your real address details. Namecheap isn't asking you to confirm the whoisguard details, and presumably the new provisions will function the same way.
Those were basically a way to nudge name holders to ensure the details they provided were correct to minimise the chances to people lodging WHOIS inaccuracy complaints with registrars or directly with ICANN. See here: http://www.icann.org/en/resources/compliance/complaints/regi...
What's changed is that the Law Enforcement Agencies have pushed to make registrars be proactive in checking that any contact information is accurate rather than reactive in response to complaints. It's likely going to push up domain costs quite a bit. Here's what registrars on the 2013 RAA are required to do: http://www.icann.org/en/resources/registrars/raa/approved-wi...
It looks like verifying a contact email address, which is nothing new and a routine with most registrars anyways.
Oh, and you bought that domain with a credit card.
Namecheap actually accepts Bitcoin[0], but yes - the way they are currently implemented and used, TLD domain names are not at all anonymous.
[0] https://www.namecheap.com/support/payment-options/bitcoin.as...
You know, for turrursm.
Some, but not most, vendors do require more extensive address information on file.
- http://support.godaddy.com/help/article/8948/verifying-conta...
- http://www.hover.com/blog/icann-registrant-verification-is-c...
- http://blog.dnsimple.com/2013/12/new-rules-for-domain-regist...
Edit. This seems to be a more legal-like explanation of the relevant rules from a registrar called enom. http://www.comprotex.com/icann.html
It states that for certain types of changes/new contact details, there will be a verification email sent, with a link you have to click.
That doesn't involve giving your real identity to anyone.
I am very disappointed in the cultural trend over the last few decades that makes a third-party entity, usually a government, the final arbiter over who someone is. If I want to be a certain name in person, and "logfromblammo" on HN, or another pseudonym somewhere else, I question the motives of anyone who wants to undermine that separation. I think it is a fundamental human right to decide who you are, and the ability to separate your social circles by the identity you use is essential to privacy and free discourse.
Several of the positions I hold as an on-line personality--religion, political views, spectator sport preferences--could be used against me in my job or hometown. An atheist anarchist that doesn't even like football is just one step away from social assassination in my physical location. If I cannot establish a separate and distinct identity to discuss such things in another venue, I cannot be free of the social prejudices of my neighbors, ever.
So I believe your assertion is incorrect. Real name policies promote self-censorship for everyone who is not blessed enough to live in a socially tolerant locale. I am content for logfromblammo to have a separate karma rating than my in-person name, and for it to be a discardable on-line identity. That arrangement can certainly be abused, but making that abuse impossible hurts far more than it helps.
Best regards,
John Doe Jr.
___
P.S. ¹) Some people will likely to be unable to use their "real" name with such policies. http://www.kalzumeus.com/2010/06/17/falsehoods-programmers-b...
As soon as they register a new domain with a registrar under the 2013 RAA or if they update their contact details, they'll be forced to validate them.
These verifications don't show up out of the blue. They're only for when you create or modify a domain registration. If you change your domain records less than an hour before going off-grid for an extended vacation, you deserve the consequences.
As wtallis wrote, this only applies when you initially register a domain or modify the contact details associated with a domain. While registrars are required to re-validate contact details, they only need to email you to notify you that you should check that your contact details are still accurate, which they currently have to do already. Of course, if the email bounces... but if that's the case then you've seriously screwed up.