# Abuse policy: no takedown on complaint alone, strict exceptions

> Sealname abuse policy: no takedown on complaint alone. Phishing, malware, botnets, CSAM and fraud on victims are suspended. Report to abuse@sealname.com.

- URL: https://sealname.com/abuse/
- Last updated: 2026-10-08
- Publisher: Sealname (https://sealname.com)

A complaint alone never takes a domain down: we need a decision from a Panamanian court. Four exceptions are written openly — phishing, malware, botnets, child sexual abuse material and fraud that takes money from victims — and anyone can report them, with no account.

**Quick answer — What is Sealname's abuse policy?**

**No takedown on complaint alone**: at **Sealname**, a private domain name registration service paid in crypto, a complaint about copyright, defamation, politics or from a competitor does not get a domain suspended; we need a decision from a Panamanian court (foreign judgments must first be recognised in Panama). The strict exceptions are phishing, malware, botnets, child sexual abuse material, and fraud that takes money from victims (fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand, sale of stolen data): report them to **abuse@sealname.com**, no account needed.

## Abuse desk at a glance

| Attribute | Value |
| --- | --- |
| Address | abuse@sealname.com |
| Who can report | Anyone: victims, security teams, registries, researchers, authorities. No account, no login |
| Acknowledgement | Yes: an automatic acknowledgement with a reference number |
| Phishing (incl. pharming), malware, botnets | Suspension, acted on within 24 hours of a well-documented report |
| Child sexual abuse material (CSAM) | Suspension immediately, and the URLs are reported to NCMEC |
| Fraud that takes money from victims | Suspension, acted on within 24 hours of a well-documented report: fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand, sale of stolen data |
| Copyright, defamation, political or competitor complaints | No takedown on complaint alone: a decision from a Panamanian court is needed (foreign judgments must first be recognised in Panama) |
| Usual action on the exceptions | Suspension of the domain; the other domains of the same account are checked |
| Trademark disputes | UDRP or URS, as ICANN requires of every registrar |
| Basis | Official policy of 8 October 2026; ICANN Registrar Accreditation Agreement §3.18, as amended on 5 April 2024 |

## What is the policy, in four lines?

This is the official policy of DomaineGoat LLC, decided on 8 October 2026.

1. **No takedown on complaint alone.** A complaint about copyright, defamation, politics or from a competitor does not get a domain suspended. We need a decision from a Panamanian court (foreign judgments must first be recognised in Panama).
2. **Your data only goes out on a Panamanian court order.** No foreign lawyer, private company or foreign government gets it without Panamanian legal process — except urgent requests that ICANN rules require registrars to answer: an imminent threat to life, serious bodily injury, critical infrastructure, or child exploitation. See the [disclosure policy](https://sealname.com/disclosure-policy/).
3. **No ID, no KYC** — only a verified email, kept private. Paid in crypto, privacy included.
4. **Strict exceptions, written openly.** Phishing, malware, botnets, child sexual abuse material, and fraud that takes money from victims (fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand, sale of stolen data) lead to suspension on a well-documented report.

Trademark disputes follow the UDRP, because ICANN requires it of every registrar: see [UDRP and disputes](https://sealname.com/udrp-and-disputes/).

## Who can report abuse, and how?

Anyone can report abuse of a domain registered with Sealname. You do not need an account, a login or a form. Send an email to **abuse@sealname.com**.

Plain-text email is fine, and no special format is required. Reports from security tools and threat-intelligence feeds are welcome, as long as each one names the domain, the URL, the time and the evidence. Write in English if you can.

To check that a domain is registered with us, look up its registrar on [lookup.icann.org](https://lookup.icann.org/en). If another registrar is shown, report the domain to that registrar instead.

## What should an abuse report include?

A report we can act on quickly contains:

1. **The domain name** or names.
2. **The exact URLs.** You can write them in a safe form, such as hxxp://example[.]com/login.
3. **The type of abuse**: phishing, malware, botnet or CSAM.
4. **Evidence**: screenshots, full email headers for phishing emails, malware hashes or a sandbox report.
5. **Timestamps with a time zone**, ideally UTC: when you saw the abuse, and whether it is still live.
6. **A way to reach you**, if you want to answer our questions.

Never attach malware or child sexual abuse material. Send a hash, a link to an analysis or the URL only.

## Which abuse leads to suspension, and how fast?

Five kinds, and only these: phishing, malware, botnets, child sexual abuse material and fraud that takes money from victims. Phishing, malware and botnets are the DNS abuse that ICANN's 2024 amendments to the Registrar Accreditation Agreement (§3.18) require every registrar to act on promptly; pharming counts as phishing, and spam counts only when it spreads one of them. Child sexual abuse material is treated as an emergency. Fraud that takes money from victims is treated like phishing: a well-documented report leads to suspension.

### Categories and target times

| Category | Examples | Target time | Usual action |
| --- | --- | --- | --- |
| Phishing | Fake login or payment pages; lookalikes of banks, payment services or governments; pharming (DNS redirection to a fraudulent site) | Acted on within 24 hours of a well-documented report | Suspension |
| Malware | Domains that host or spread malicious software | Acted on within 24 hours of a well-documented report | Suspension |
| Botnets | Command-and-control domains of a botnet | Acted on within 24 hours of a well-documented report | Suspension |
| Child sexual abuse material (CSAM) | Any such material, on the domain or reached through it | Acted on immediately, and the URLs are reported to NCMEC | Suspension |
| Fraud that takes money from victims | Fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand, sale of stolen data | Acted on within 24 hours of a well-documented report | Suspension |
| Spam | Only when it carries phishing, malware or botnet links | Handled as the abuse it spreads | Suspension when confirmed |
| Copyright, defamation, political or competitor complaints | Claims about the content of a site or the conduct of its owner | Answered within 2 business days | No takedown without a decision from a Panamanian court |
| Trademark disputes | A domain name that may infringe a trademark | As the UDRP or URS sets | Lock, then the panel's decision |

Target times run from a well-documented report. A report that lacks evidence starts the clock when the missing details arrive.

## What happens after you report abuse?

Each report goes through the same five steps.

1. **Acknowledgement** — You receive an automatic acknowledgement with a reference number. Use that reference if you send more evidence.
2. **Review** — We check the evidence: the URL, the screenshots, the headers and public reputation lists. If a detail is missing, we ask for it.
3. **Action** — When phishing, malware, a botnet, CSAM or fraud that takes money from victims is confirmed, we suspend the domain, so it stops resolving. CSAM is acted on immediately, and the URLs are reported to NCMEC. Any other complaint is answered with the route to a court.
4. **Associated domains** — We check the other domains of the same account, because abusive domains are often registered in batches.
5. **Count** — The case is closed under its reference and counted in the quarterly transparency report.

## Why does Sealname check the other domains of an account?

Because abuse rarely comes alone. Interisle's Phishing Landscape 2025 found that 77% of phishing domains were registered maliciously, and 37% through bulk registrations. When one domain of an account is confirmed as abusive, the others deserve a look.

We can link the domains of one account through its account number, even without ID or KYC. In January 2026, the ICANN community (GNSO) started a policy process on such "associated domain checks", as reported by Spamhaus in April 2026.

## Why doesn't a complaint alone take a domain down?

Because a complaint is one side of a dispute, and a registrar is not a judge. This is the first line of our policy: **no takedown on complaint alone**. It covers disputes about content.

- **Copyright** complaints need a decision from a Panamanian court (foreign judgments must first be recognised in Panama). You can also contact the hosting provider of the site.
- **Defamation** and other claims about content need a decision from a Panamanian court.
- **Political** complaints, whoever sends them, need a decision from a Panamanian court.
- **Complaints from competitors**, such as claims of unfair practices, need a decision from a Panamanian court.
- **Trademark** disputes follow the UDRP or the URS, because ICANN requires it of every registrar: see [UDRP and disputes](https://sealname.com/udrp-and-disputes/).

Fraud is different: a fake shop, an investment or crypto scam, a wallet drainer, an impersonation of a bank or brand or the sale of stolen data takes money from victims, so a well-documented report leads to suspension, as for phishing. We answer every other complaint and explain the route. Customer data goes out only on a Panamanian court order (or on an urgent request under ICANN rules): see the [disclosure policy](https://sealname.com/disclosure-policy/) and the [law enforcement page](https://sealname.com/law-enforcement/).

## Why does a privacy service need fast abuse handling?

Because privacy must not become a shelter for abuse. A DNSRF analysis found privacy or proxy services on 65% of 414,218 abuse-listed domains. An ICANN-funded study, reported by PCWorld, showed that banks also use such services. Privacy is legitimate, so the handling of real abuse has to be real.

ICANN enforces this. In the first six months of the 2024 amendments, it opened 192 investigations, and more than 2,700 domains were suspended.

Trustname, a registrar that promised its customers protection from takedowns (Domain Name Wire, 10 June 2026), is the counter-example. ICANN sent it a termination notice on 27 August 2026, effective 11 September 2026. The notice cited breaches of RAA §3.18.1 and §3.18.2, after 4 breach notices in 78 days. Its median phishing rate rose from about 0.7% to about 10% between January and August 2026, per ICANN Domain Metrica. A registrar that loses its accreditation puts every customer's domain at risk: refusing takedowns on complaint alone only works if real abuse is handled.

## What happens with false or bad-faith reports?

A report alone never suspends a domain: we act on evidence, and only for the strict exceptions. A report that is knowingly false, or that tries to use the abuse desk to settle a business or content dispute, is closed without action.

A customer whose domain was suspended can ask why and appeal by writing to support@sealname.com. The [acceptable use policy](https://sealname.com/acceptable-use-policy/) explains the appeal. An abuse report never leads us to reveal the customer's data: that needs a Panamanian court order, as the [disclosure policy](https://sealname.com/disclosure-policy/) explains.

Sealname sells private domains paid in crypto, with privacy included where the registry allows it. Prices are on the [price list](https://sealname.com/pricing/).

## Abuse reports: FAQ

### Do I need an account to report abuse?

No. Anyone can report abuse of a domain registered with Sealname, without an account, a login or a form. Send an email to abuse@sealname.com with the domain, the URLs, your evidence and timestamps. You receive an automatic acknowledgement with a reference number.

### Will you tell me who owns the abusive domain?

No, an abuse report does not lead to disclosure. We act on the domain itself, by suspending it for phishing, malware, botnets, CSAM or fraud that takes money from victims. The owner's data goes out only on a Panamanian court order, to a UDRP or URS provider in a trademark dispute, or in an urgent case ICANN rules require, as the [disclosure policy](https://sealname.com/disclosure-policy/) explains.

### How fast does Sealname act on phishing?

Phishing, malware, botnets and fraud that takes money from victims are acted on within 24 hours of a well-documented report. A well-documented report names the domain and the URLs, and includes screenshots or headers and timestamps. If details are missing, we ask for them, and the target time starts when they arrive.

### How do I report child sexual abuse material?

Email abuse@sealname.com with the URL only, never the material itself. Put "CSAM" in the subject. Reports of child sexual abuse material are acted on immediately, and the URLs are reported to NCMEC. The domain is suspended, and we check the other domains of the same account. No account is needed to report.

### Will you take a domain down for copyright or defamation?

Not on a complaint alone. Copyright, defamation, political and competitor complaints need a decision from a Panamanian court (foreign judgments must first be recognised in Panama); we answer each complaint and explain that route. Content complaints can also go to the hosting provider. Trademark disputes go through the UDRP or the URS, as ICANN requires. Fraud that takes money from victims is different: it is suspended like phishing.

### Do you check the other domains of an abusive customer?

Yes. When a domain is confirmed as abusive, we check the other domains of the same account. Interisle found that 37% of phishing domains in its 2025 study came from bulk registrations, so abuse often comes in batches. We link the domains through the account number, even without ID or KYC.

### Will my report appear in the transparency report?

Yes, as a count, never with your name. The quarterly [transparency report](https://sealname.com/transparency/) counts abuse reports by category, the share confirmed, the median time to action and the suspensions. The first report will be published in January 2027. It never publishes your evidence or your email.

### I am a police officer. Where do I send a legal request?

Customer data goes out only on a Panamanian court order (or on an urgent request under ICANN rules): a copy goes to abuse@sealname.com with the subject "Legal request". Foreign police go through Panamanian legal process. Reports of phishing, malware, botnets, CSAM or fraud that takes money from victims need no order: the domain is suspended. Our [law enforcement page](https://sealname.com/law-enforcement/) explains the route.

## Sources

1. [2024 global amendments to the RAA and RA: DNS abuse obligations](https://www.icann.org/resources/pages/global-amendment-2024-en) — ICANN (5 April 2024)
2. [ICANN's DNS Abuse Mitigation Program: key updates from 2024](https://www.icann.org/en/blogs/details/icanns-dns-abuse-mitigation-program-key-updates-from-2024-10-12-2024-en) — ICANN (10 December 2024)
3. [Notice of termination of the Registrar Accreditation Agreement (Trustname)](https://www.icann.org/uploads/compliance_notice/attachment/1367/hedlund-to-nestsiarovich-27aug26.pdf) — ICANN (27 August 2026)
4. [ICANN sends breach notice to Trustname](https://domainnamewire.com/2026/06/10/icann-sends-breach-notice-to-trustname/) — Domain Name Wire (10 June 2026)
5. [Phishing Landscape 2025](https://interisle.net/PhishingLandscape2025) — Interisle Consulting Group (2025)
6. [Privacy/proxy services: a safe haven for cybercriminals?](https://dnsrf.org/blog/privacy-proxy-services---a-safe-haven-for-cybercriminals-) — DNS Research Federation (checked 8 October 2026)
7. [Exposing hidden domain registrations could hurt innocent users more than criminals](https://www.pcworld.com/article/439970/exposing-hidden-domain-registrations-could-hurt-innocent-users-more-than-criminals.html) — PCWorld (checked 8 October 2026)
8. [Domain Reputation Update, October 2025 to March 2026](https://content.spamhaus.org/cafc21f6-5e93-4881-99f5-544a65d017c5.pdf) — Spamhaus (April 2026)

**Report abuse to abuse@sealname.com** No account needed. Read the rules every customer accepts, and what we publish each quarter. [Acceptable use policy](https://sealname.com/acceptable-use-policy/) · [Transparency report](https://sealname.com/transparency/)

---

Sealname: Sealname registers private domain names paid in crypto (BTC, USDT, USDC, ETH, SOL, LTC): privacy-first, we collect one email, nothing else — no ID, no KYC, no logs. WHOIS privacy included; a .com costs $12.99/year.
