Abuse Reporting & Handling Policy


Abuse Reporting & Handling Policy

This Abuse Reporting & Handling Policy describes how NICENIC INTERNATIONAL GROUP CO., LIMITED ("NiceNIC") receives, investigates, tracks, and responds to reports of abuse involving domain names sponsored by NiceNIC or other NiceNIC services.

1. Purpose

NiceNIC is an ICANN-accredited registrar and maintains abuse-reporting and abuse-handling procedures to meet applicable contractual, registry, legal, security, and service obligations.

An abuse report is an allegation or signal requiring review. Submission of a report does not, by itself, establish that a customer or domain has violated NiceNIC policy, ICANN requirements, registry rules, or applicable law.

NiceNIC seeks to handle reports promptly, fairly, based on available evidence, and with measures proportionate to the circumstances.

2. Official Abuse Reporting Channels

Abuse involving a domain name or NiceNIC service should be submitted through one of NiceNIC's official abuse channels:

Online abuse report:
https://nicenic.com/reportabuse.php

Abuse email:
[email protected]

The abuse-reporting mechanism is intended to be accessible without requiring the reporter to hold a NiceNIC customer account.

General customer support, social media, forum messages, or unrelated business contacts are not the preferred channels for abuse reports and may be redirected to the official abuse process.

NiceNIC may nevertheless review or act on credible information received through another channel where required by law, appropriate for security, necessary to protect users, or necessary to satisfy ICANN or registry obligations.

3. Information to Include

A report should contain enough information to allow NiceNIC to identify the affected resource and evaluate the allegation.

Depending on the issue, useful information may include:

  • the affected domain name;
  • the complete abusive URL where applicable;
  • the category of alleged abuse;
  • a clear description of the activity;
  • screenshots;
  • full email headers and message content for email-related abuse;
  • timestamps and time zone;
  • relevant IP addresses;
  • security or firewall logs;
  • malware, phishing, or threat-intelligence evidence;
  • payment receipts or transaction evidence for fraud reports;
  • the legitimate brand or service being impersonated where relevant;
  • legal documents or rights evidence where relevant; and
  • the reporter's contact details for follow-up.

Reporters should avoid submitting unnecessary personal data, passwords, authentication codes, private keys, or unrelated confidential information.

4. Confirmation of Receipt

For reports submitted through the official abuse mechanism, NiceNIC will provide a confirmation of receipt sufficient to identify the submission in accordance with applicable ICANN requirements.

Where required by the applicable Registrar Accreditation Agreement, the confirmation will identify at least:

  • NiceNIC as the registrar;
  • the reported Registered Name or Registered Names; and
  • the date the report was submitted.

A confirmation of receipt is not a determination that the allegation is valid.

5. Initial Review and Classification

NiceNIC may review:

  • whether NiceNIC is the sponsoring registrar or relevant service provider;
  • whether the reported activity remains active;
  • the nature of the allegation;
  • the quality and relevance of the evidence;
  • whether the issue constitutes DNS Abuse for purposes of NiceNIC's ICANN registrar obligations;
  • whether the domain appears to have been maliciously registered or instead appears to be a legitimate domain that has been compromised;
  • whether the issue is principally associated with hosting, email, a subdomain, a third-party platform, or another provider;
  • whether the report concerns trademark/copyright rights rather than DNS Abuse;
  • applicable registry rules;
  • applicable law, legal process, or court orders; and
  • any other reasonably available information relevant to the investigation.

6. DNS Abuse

For gTLDs subject to NiceNIC's ICANN registrar obligations, "DNS Abuse" has the meaning specified by the then-current ICANN Registrar Accreditation Agreement and related ICANN requirements.

As of the Effective Date of this Policy, the contractual DNS Abuse categories are:

  • malware;
  • botnets;
  • phishing;
  • pharming; and
  • spam when spam serves as a delivery mechanism for one or more of the other specified forms of DNS Abuse.

Other harmful or illegal conduct may still violate NiceNIC policy or applicable law even if it does not fall within the ICANN contractual definition of DNS Abuse.

7. Actionable Evidence and Investigation

NiceNIC will take reasonable and prompt steps to investigate abuse reports as required by applicable registrar obligations.

Evidence is considered in context. A report does not need to use any particular commercial threat feed or reporting format to be considered.

Where information submitted by a reporter is incomplete, NiceNIC may:

  • review information reasonably available to NiceNIC;
  • request additional relevant evidence;
  • inspect the reported URL or other relevant public resource where safe and appropriate;
  • review account, nameserver, DNS, registration, or service information available to NiceNIC; or
  • contact another relevant service provider or registry where appropriate.

NiceNIC will not require irrelevant evidence merely to delay handling of an otherwise actionable report.

8. Required Mitigation for DNS Abuse

When NiceNIC has actionable evidence that a gTLD Registered Name sponsored by NiceNIC is being used for DNS Abuse, NiceNIC will promptly take mitigation action that is reasonably necessary to stop or otherwise disrupt the Registered Name from being used for that DNS Abuse, as required by the applicable ICANN Registrar Accreditation Agreement.

The appropriate action depends on the circumstances, including:

  • the type of DNS Abuse;
  • the cause and severity of the harm;
  • whether the activity is active;
  • whether the domain appears maliciously registered or compromised;
  • the technical role of the domain;
  • the likely effectiveness of registrar-level action; and
  • the risk of collateral damage to legitimate users or services.

9. Proportionate Mitigation

Possible actions may include, where appropriate and permitted:

  • requesting remediation;
  • requiring the customer or reseller to remove or disable the abusive activity;
  • applying a registrar lock;
  • applying clientHold or another registrar status;
  • restricting DNS or other NiceNIC-provided functionality;
  • restricting email, hosting, API, or account access;
  • referring the matter to the relevant hosting provider, registry, or other infrastructure provider;
  • preserving relevant records;
  • suspending an affected service;
  • terminating a service or account for serious or repeated violations; or
  • taking another measure reasonably necessary to address the abuse.

NiceNIC is not required to apply the same mitigation measure in every case.

10. Compromised Domains and Collateral Damage

A legitimate domain may be abused without the registrant's knowledge because of compromised hosting, credentials, content-management software, DNS settings, or another security failure.

Where reasonably practicable, NiceNIC will consider the risk of collateral damage before applying domain-level suspension.

For a compromised legitimate domain, requesting rapid remediation or applying a narrower mitigation may be more appropriate than immediate suspension if the narrower action is sufficient to stop or disrupt the abuse.

This does not prevent immediate suspension or another stronger measure where the circumstances, severity, continuing harm, legal requirements, or security risk justify it.

11. Maliciously Registered Domains

Where available evidence indicates that a domain was registered or is controlled primarily for phishing, malware, credential theft, botnet activity, pharming, or another serious abusive purpose, faster domain-level mitigation may be appropriate.

NiceNIC is not required to provide advance notice where doing so would materially increase the risk of harm, enable evasion, frustrate a mandatory requirement, or undermine effective mitigation.

12. Non-DNS Illegal Activity

Illegal Activity and DNS Abuse are not identical concepts.

Reports concerning fraud, unlawful goods or services, threats, impersonation, illegal content, sanctions, or other conduct may be handled under applicable law, NiceNIC's Terms of Service & Acceptable Use Policy, registry rules, court orders, or other relevant requirements even where the conduct does not meet the ICANN contractual definition of DNS Abuse.

The legal and technical role of NiceNIC will be considered when determining what action, if any, is appropriate.

13. Trademark and Domain-Name Rights Complaints

Trademark infringement or a dispute over rights in a domain name is not automatically DNS Abuse.

Where the principal dispute concerns who has rights to the domain name, the appropriate mechanism may include:

  • the Uniform Domain Name Dispute Resolution Policy (UDRP);
  • the Uniform Rapid Suspension System (URS);
  • a ccTLD-specific dispute policy; or
  • a court of competent jurisdiction.

NiceNIC does not decide the merits of UDRP or URS disputes.

If evidence also demonstrates phishing, credential theft, malware, or another form of DNS Abuse, NiceNIC may separately handle the DNS Abuse aspect.

14. Copyright Complaints

Copyright complaints are reviewed separately from DNS Abuse unless the reported activity also involves qualifying DNS Abuse or another basis for registrar-level action.

NiceNIC may request information reasonably necessary to identify the copyrighted work, allegedly infringing material, complainant, authority to act, and other information required by the applicable complaint process.

A copyright complaint does not automatically result in suspension of a domain name.

15. Child Sexual Abuse Material and Child Exploitation

Reports concerning suspected child sexual abuse material or child exploitation are treated as high-risk matters and escalated without unnecessary delay.

NiceNIC may preserve relevant records, restrict an affected service, and cooperate with appropriate authorities, registries, hosting providers, or other relevant entities as required or permitted by law.

Reporters should not unnecessarily copy, download, or redistribute suspected illegal child-abuse material when submitting a report.

16. Hosting and Third-Party Infrastructure

A registrar controls domain-registration functions but may not control the website files, application, mail server, or hosting environment associated with the domain.

Where abusive content is hosted by a third party, reporting the activity to the hosting provider or other infrastructure provider may allow more targeted removal.

NiceNIC may nevertheless take registrar-level action where required or appropriate under applicable obligations.

17. Reseller-Sponsored Customers

A domain may have been purchased through a NiceNIC reseller while NiceNIC remains the sponsoring registrar.

NiceNIC may coordinate with the reseller during an abuse investigation, but delegation to a reseller does not eliminate NiceNIC's applicable ICANN registrar obligations.

NiceNIC may contact the Registered Name Holder or other customer directly where reasonably necessary for abuse mitigation, security, legal compliance, mandatory notices, or protection of registrant rights.

18. Reports from Law Enforcement and Qualifying Authorities

NiceNIC maintains the dedicated abuse point of contact required by the applicable ICANN Registrar Accreditation Agreement for qualifying reports of Illegal Activity from law-enforcement, consumer-protection, quasi-governmental, or other qualifying governmental authorities.

Where the applicable Registrar Accreditation Agreement requires it, a well-founded report submitted through the dedicated authority contact will be reviewed within twenty-four (24) hours by a person empowered to take necessary and appropriate action.

NiceNIC is not required to take action that would contravene applicable law.

NiceNIC may authenticate the identity, authority, jurisdiction, and legal basis of a governmental request where appropriate.

19. Court Orders and Binding Legal Process

NiceNIC may act in response to:

  • a valid court order;
  • binding governmental process;
  • a mandatory registry instruction;
  • a UDRP or URS requirement;
  • an ICANN contractual requirement; or
  • another legal obligation applicable to NiceNIC.

Where legally permitted and appropriate, NiceNIC may seek clarification or legal review of an overbroad, invalid, or unclear request.

20. Notice to the Customer

Where circumstances permit, NiceNIC may notify a customer or reseller of the allegation and provide an opportunity to remediate.

Advance notice may be omitted where:

  • immediate mitigation is reasonably necessary;
  • evidence indicates an intentionally malicious registration;
  • notice could enable evasion or destruction of evidence;
  • a court, authority, registry, ICANN requirement, or law restricts notice;
  • a serious security or child-safety risk exists; or
  • delay would materially increase harm.

21. Restoration and Review

Where a domain or service was restricted because of abuse or security concerns, NiceNIC may review a request for restoration after:

  • the abusive activity has been removed;
  • a compromised website or account has been secured;
  • relevant credentials have been reset;
  • required security updates have been applied;
  • corrected technical information has been provided;
  • the original evidence has become outdated or was shown to be incorrect; or
  • another appropriate remediation has been completed.

Restoration is not guaranteed where a continuing legal, registry, ICANN, security, dispute, or abuse basis requires the restriction to remain.

22. Customer Review / Appeal

A customer affected by a discretionary NiceNIC abuse action may request review through NiceNIC's support channel.

The request should identify:

  • the affected domain or service;
  • the relevant NiceNIC case or notice;
  • the remediation completed;
  • evidence that the reported activity has ceased;
  • evidence of compromise where relevant; and
  • any information showing that the original report was inaccurate, outdated, or misclassified.

A review request does not suspend a court order, registry requirement, UDRP/URS action, ICANN obligation, or other mandatory restriction.

23. Reporter Follow-Up

NiceNIC may communicate with a reporter to request relevant additional information or confirm that a case has been received or reviewed.

Privacy, security, law, and customer confidentiality may limit the information NiceNIC can disclose concerning:

  • internal investigation methods;
  • customer identity;
  • non-public Registration Data;
  • account information;
  • law-enforcement communications;
  • security controls; or
  • specific internal actions.

Absence of detailed disclosure to a reporter does not mean a report was ignored.

24. Duplicate, Automated, or Abusive Reports

NiceNIC may consolidate duplicate reports concerning the same issue.

NiceNIC may apply reasonable controls to abusive, misleading, clearly irrelevant, or technically harmful submissions.

Such controls will not be used to prevent legitimate reporters from submitting abuse reports through the required channel.

25. Recordkeeping

NiceNIC documents the receipt of and response to abuse reports as required by the applicable ICANN Registrar Accreditation Agreement and other applicable obligations.

Records are retained for the period required by the applicable Registrar Accreditation Agreement, subject to applicable law.

NiceNIC may provide required records to ICANN Contractual Compliance upon proper request.

26. Privacy

Personal data submitted in an abuse report is handled under the NiceNIC Privacy Policy and applicable law.

NiceNIC may disclose information where reasonably necessary to investigate abuse, coordinate mitigation, comply with ICANN or registry requirements, protect users or systems, establish or defend legal claims, or comply with law.

27. No Automatic Finding of Liability

A report, registrar restriction, security action, or temporary mitigation measure is not necessarily a final legal finding that the Registered Name Holder committed unlawful conduct.

NiceNIC may take precautionary or contractual action based on the evidence and obligations applicable at the time.

28. Applicable Policies and Priority

This Policy should be read with:

  • the NiceNIC Terms of Service & Acceptable Use Policy;
  • the Domain Name Registration Service Agreement;
  • the NiceNIC Privacy Policy;
  • the Domain Transfer Policy;
  • UDRP and URS policies where applicable;
  • applicable registry policies; and
  • applicable law.

Where a mandatory ICANN, registry, court, governmental, or legal requirement conflicts with this Policy, the mandatory requirement controls to the extent of the conflict.

29. Changes

NiceNIC may update this Policy to reflect changes in law, ICANN requirements, registry rules, abuse patterns, security practices, or NiceNIC services.

Changes required by law, ICANN, or a registry may take effect when required.