No takedown on complaint alone · We collect one email, nothing else · Data out only on a Panamanian court order · Paid in crypto
Search a domain

Abuse policy · official policy of 8 October 2026

Abuse policy: no takedown on complaint alone, strict exceptions

A complaint alone never takes a domain down: we need a decision from a Panamanian court. Four exceptions are written openly — phishing, malware, botnets, child sexual abuse material and fraud that takes money from victims — and anyone can report them, with no account.

Last updated: · 11 min read

Quick answer

What is Sealname's abuse policy?

No takedown on complaint alone: at Sealname, a private domain name registration service paid in crypto, a complaint about copyright, defamation, politics or from a competitor does not get a domain suspended; we need a decision from a Panamanian court (foreign judgments must first be recognised in Panama). The strict exceptions are phishing, malware, botnets, child sexual abuse material, and fraud that takes money from victims (fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand, sale of stolen data): report them to [email protected], no account needed.

Abuse desk at a glance

Address[email protected]
Who can reportAnyone: victims, security teams, registries, researchers, authorities. No account, no login
AcknowledgementYes: an automatic acknowledgement with a reference number
Phishing (incl. pharming), malware, botnetsSuspension, acted on within 24 hours of a well-documented report
Child sexual abuse material (CSAM)Suspension immediately, and the URLs are reported to NCMEC
Fraud that takes money from victimsSuspension, acted on within 24 hours of a well-documented report: fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand, sale of stolen data
Copyright, defamation, political or competitor complaintsNo takedown on complaint alone: a decision from a Panamanian court is needed (foreign judgments must first be recognised in Panama)
Usual action on the exceptionsSuspension of the domain; the other domains of the same account are checked
Trademark disputesUDRP or URS, as ICANN requires of every registrar
BasisOfficial policy of 8 October 2026; ICANN Registrar Accreditation Agreement §3.18, as amended on 5 April 2024

What is the policy, in four lines?

This is the official policy of DomaineGoat LLC, decided on 8 October 2026.

  1. No takedown on complaint alone. A complaint about copyright, defamation, politics or from a competitor does not get a domain suspended. We need a decision from a Panamanian court (foreign judgments must first be recognised in Panama).
  2. Your data only goes out on a Panamanian court order. No foreign lawyer, private company or foreign government gets it without Panamanian legal process — except urgent requests that ICANN rules require registrars to answer: an imminent threat to life, serious bodily injury, critical infrastructure, or child exploitation. See the disclosure policy.
  3. No ID, no KYC — only a verified email, kept private. Paid in crypto, privacy included.
  4. Strict exceptions, written openly. Phishing, malware, botnets, child sexual abuse material, and fraud that takes money from victims (fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand, sale of stolen data) lead to suspension on a well-documented report.

Trademark disputes follow the UDRP, because ICANN requires it of every registrar: see UDRP and disputes.

Who can report abuse, and how?

Anyone can report abuse of a domain registered with Sealname. You do not need an account, a login or a form. Send an email to [email protected].

Plain-text email is fine, and no special format is required. Reports from security tools and threat-intelligence feeds are welcome, as long as each one names the domain, the URL, the time and the evidence. Write in English if you can.

To check that a domain is registered with us, look up its registrar on lookup.icann.org. If another registrar is shown, report the domain to that registrar instead.

What should an abuse report include?

A report we can act on quickly contains:

  1. The domain name or names.
  2. The exact URLs. You can write them in a safe form, such as hxxp://example[.]com/login.
  3. The type of abuse: phishing, malware, botnet or CSAM.
  4. Evidence: screenshots, full email headers for phishing emails, malware hashes or a sandbox report.
  5. Timestamps with a time zone, ideally UTC: when you saw the abuse, and whether it is still live.
  6. A way to reach you, if you want to answer our questions.

Never attach malware or child sexual abuse material. Send a hash, a link to an analysis or the URL only.

Which abuse leads to suspension, and how fast?

Five kinds, and only these: phishing, malware, botnets, child sexual abuse material and fraud that takes money from victims. Phishing, malware and botnets are the DNS abuse that ICANN's 2024 amendments to the Registrar Accreditation Agreement (§3.18) require every registrar to act on promptly; pharming counts as phishing, and spam counts only when it spreads one of them. Child sexual abuse material is treated as an emergency. Fraud that takes money from victims is treated like phishing: a well-documented report leads to suspension.

Categories and target times

CategoryExamplesTarget timeUsual action
PhishingFake login or payment pages; lookalikes of banks, payment services or governments; pharming (DNS redirection to a fraudulent site)Acted on within 24 hours of a well-documented reportSuspension
MalwareDomains that host or spread malicious softwareActed on within 24 hours of a well-documented reportSuspension
BotnetsCommand-and-control domains of a botnetActed on within 24 hours of a well-documented reportSuspension
Child sexual abuse material (CSAM)Any such material, on the domain or reached through itActed on immediately, and the URLs are reported to NCMECSuspension
Fraud that takes money from victimsFake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand, sale of stolen dataActed on within 24 hours of a well-documented reportSuspension
SpamOnly when it carries phishing, malware or botnet linksHandled as the abuse it spreadsSuspension when confirmed
Copyright, defamation, political or competitor complaintsClaims about the content of a site or the conduct of its ownerAnswered within 2 business daysNo takedown without a decision from a Panamanian court
Trademark disputesA domain name that may infringe a trademarkAs the UDRP or URS setsLock, then the panel's decision

Target times run from a well-documented report. A report that lacks evidence starts the clock when the missing details arrive.

What happens after you report abuse?

Each report goes through the same five steps.

  1. Acknowledgement

    You receive an automatic acknowledgement with a reference number. Use that reference if you send more evidence.

  2. Review

    We check the evidence: the URL, the screenshots, the headers and public reputation lists. If a detail is missing, we ask for it.

  3. Action

    When phishing, malware, a botnet, CSAM or fraud that takes money from victims is confirmed, we suspend the domain, so it stops resolving. CSAM is acted on immediately, and the URLs are reported to NCMEC. Any other complaint is answered with the route to a court.

  4. Associated domains

    We check the other domains of the same account, because abusive domains are often registered in batches.

  5. Count

    The case is closed under its reference and counted in the quarterly transparency report.

Why does Sealname check the other domains of an account?

Because abuse rarely comes alone. Interisle's Phishing Landscape 2025 found that 77% of phishing domains were registered maliciously, and 37% through bulk registrations. When one domain of an account is confirmed as abusive, the others deserve a look.

We can link the domains of one account through its account number, even without ID or KYC. In January 2026, the ICANN community (GNSO) started a policy process on such "associated domain checks", as reported by Spamhaus in April 2026.

Why doesn't a complaint alone take a domain down?

Because a complaint is one side of a dispute, and a registrar is not a judge. This is the first line of our policy: no takedown on complaint alone. It covers disputes about content.

  • Copyright complaints need a decision from a Panamanian court (foreign judgments must first be recognised in Panama). You can also contact the hosting provider of the site.
  • Defamation and other claims about content need a decision from a Panamanian court.
  • Political complaints, whoever sends them, need a decision from a Panamanian court.
  • Complaints from competitors, such as claims of unfair practices, need a decision from a Panamanian court.
  • Trademark disputes follow the UDRP or the URS, because ICANN requires it of every registrar: see UDRP and disputes.

Fraud is different: a fake shop, an investment or crypto scam, a wallet drainer, an impersonation of a bank or brand or the sale of stolen data takes money from victims, so a well-documented report leads to suspension, as for phishing. We answer every other complaint and explain the route. Customer data goes out only on a Panamanian court order (or on an urgent request under ICANN rules): see the disclosure policy and the law enforcement page.

Why does a privacy service need fast abuse handling?

Because privacy must not become a shelter for abuse. A DNSRF analysis found privacy or proxy services on 65% of 414,218 abuse-listed domains. An ICANN-funded study, reported by PCWorld, showed that banks also use such services. Privacy is legitimate, so the handling of real abuse has to be real.

ICANN enforces this. In the first six months of the 2024 amendments, it opened 192 investigations, and more than 2,700 domains were suspended.

Trustname, a registrar that promised its customers protection from takedowns (Domain Name Wire, 10 June 2026), is the counter-example. ICANN sent it a termination notice on 27 August 2026, effective 11 September 2026. The notice cited breaches of RAA §3.18.1 and §3.18.2, after 4 breach notices in 78 days. Its median phishing rate rose from about 0.7% to about 10% between January and August 2026, per ICANN Domain Metrica. A registrar that loses its accreditation puts every customer's domain at risk: refusing takedowns on complaint alone only works if real abuse is handled.

What happens with false or bad-faith reports?

A report alone never suspends a domain: we act on evidence, and only for the strict exceptions. A report that is knowingly false, or that tries to use the abuse desk to settle a business or content dispute, is closed without action.

A customer whose domain was suspended can ask why and appeal by writing to [email protected]. The acceptable use policy explains the appeal. An abuse report never leads us to reveal the customer's data: that needs a Panamanian court order, as the disclosure policy explains.

Sealname sells private domains paid in crypto, with privacy included where the registry allows it. Prices are on the price list.

Abuse reports: FAQ

Do I need an account to report abuse?

No. Anyone can report abuse of a domain registered with Sealname, without an account, a login or a form. Send an email to [email protected] with the domain, the URLs, your evidence and timestamps. You receive an automatic acknowledgement with a reference number.

Will you tell me who owns the abusive domain?

No, an abuse report does not lead to disclosure. We act on the domain itself, by suspending it for phishing, malware, botnets, CSAM or fraud that takes money from victims. The owner's data goes out only on a Panamanian court order, to a UDRP or URS provider in a trademark dispute, or in an urgent case ICANN rules require, as the disclosure policy explains.

How fast does Sealname act on phishing?

Phishing, malware, botnets and fraud that takes money from victims are acted on within 24 hours of a well-documented report. A well-documented report names the domain and the URLs, and includes screenshots or headers and timestamps. If details are missing, we ask for them, and the target time starts when they arrive.

How do I report child sexual abuse material?

Email [email protected] with the URL only, never the material itself. Put "CSAM" in the subject. Reports of child sexual abuse material are acted on immediately, and the URLs are reported to NCMEC. The domain is suspended, and we check the other domains of the same account. No account is needed to report.

Not on a complaint alone. Copyright, defamation, political and competitor complaints need a decision from a Panamanian court (foreign judgments must first be recognised in Panama); we answer each complaint and explain that route. Content complaints can also go to the hosting provider. Trademark disputes go through the UDRP or the URS, as ICANN requires. Fraud that takes money from victims is different: it is suspended like phishing.

Do you check the other domains of an abusive customer?

Yes. When a domain is confirmed as abusive, we check the other domains of the same account. Interisle found that 37% of phishing domains in its 2025 study came from bulk registrations, so abuse often comes in batches. We link the domains through the account number, even without ID or KYC.

Will my report appear in the transparency report?

Yes, as a count, never with your name. The quarterly transparency report counts abuse reports by category, the share confirmed, the median time to action and the suspensions. The first report will be published in January 2027. It never publishes your evidence or your email.

Customer data goes out only on a Panamanian court order (or on an urgent request under ICANN rules): a copy goes to [email protected] with the subject "Legal request". Foreign police go through Panamanian legal process. Reports of phishing, malware, botnets, CSAM or fraud that takes money from victims need no order: the domain is suspended. Our law enforcement page explains the route.

Sources (8)
  1. 2024 global amendments to the RAA and RA: DNS abuse obligations — ICANN (5 April 2024)
  2. ICANN's DNS Abuse Mitigation Program: key updates from 2024 — ICANN (10 December 2024)
  3. Notice of termination of the Registrar Accreditation Agreement (Trustname) — ICANN (27 August 2026)
  4. ICANN sends breach notice to Trustname — Domain Name Wire (10 June 2026)
  5. Phishing Landscape 2025 — Interisle Consulting Group (2025)
  6. Privacy/proxy services: a safe haven for cybercriminals? — DNS Research Federation (checked 8 October 2026)
  7. Exposing hidden domain registrations could hurt innocent users more than criminals — PCWorld (checked 8 October 2026)
  8. Domain Reputation Update, October 2025 to March 2026 — Spamhaus (April 2026)

Report abuse to [email protected]

No account needed. Read the rules every customer accepts, and what we publish each quarter.

.com $12.99/year · privacy included · no KYC

Search a domain