GOpenCDR acceptable use policy
What a GOpenCDR name may not be used for, what counts as DNS abuse, and how a report moves from the TLD to the root.
What this covers
This policy applies to every name registered in a GOpenCDR TLD, every account and API key, every mirror, and the resolvers we run. You accept it together with the GOpenCDR terms. It adds to the acceptable use section of the general terms rather than replacing it.
A TLD may publish stricter rules of its own for names in it. It may not relax these.
What a name may not be used for
Do not use a GOpenCDR name, account or service for any of the following:
- Phishing: deceiving people into handing over credentials, payment details or other personal data, including by imitating a brand, a bank or an authority.
- Malware: distributing malicious software, or hosting it, or pointing people at it.
- Botnets: commanding or controlling compromised machines, including through generated names or fast-changing records.
- Pharming: sending people who meant to reach one site to another, including by hijacking DNS or poisoning caches.
- Spam that delivers any of the above, and unsolicited bulk messages sent from a GOpenCDR name or advertising one.
- Infringement: using a name in a way that infringes somebody else's trademark, name or other rights, or registering it in bad faith to sell it to the rights holder, to block them or to disrupt their business. Who is entitled to a name is settled under the name dispute policy, not here.
- Anything unlawful under the law that applies to you or to us. Child sexual abuse material is always reported to the authorities.
How the service itself may not be used
- Do not attack, overload or test GOpenCDR's infrastructure except as the security and disclosure policy allows.
- Do not use the resolvers we run against anybody else: no amplification, no reflection, and no flooding of other people's servers through them.
- Do not try to make a GOpenCDR name answer in place of a name in the IANA namespace, or to get around the checks that prevent it.
- Do not register names in bulk to hold them, trade them or keep them from people who want them. Free names are for use.
- Do not harvest registration data or zone data, and do not use zone data for anything other than resolving names. Mirrors that receive zone files are bound by the mirror operator terms.
- Do not open accounts to get around a restriction or a suspension.
What is not our business
We act on DNS abuse and on binding orders. We do not act on content somebody dislikes, on disagreement, on criticism of anybody, including of us, or on lawful speech. The DNS is not where content is judged: a report that a website under a GOpenCDR name says something objectionable is answered with exactly that. Unlawful content belongs with whoever hosts it, and where a court or an authority orders us to act on the name, we act.
How abuse is handled
The TLD acts first, and the root steps in when it does not.
- Report. Anyone may report abuse, by email to egelhaus@ennogelhaus.de with "Abuse" in the subject line, or through the report form in the GOpenCDR portal. Name the domain, say what is happening and include what shows it. We acknowledge every report within 24 hours.
- The TLD acts first. We pass the report to the TLD operator, who has 48 hours to act, or 12 hours where phishing or malware is active.
- The root steps in. If the TLD has not acted in that time, the root abuse desk acts on the name itself in a hosted TLD. For a self-hosted TLD it escalates under the TLD operator agreement, which can end in the TLD's delegation being suspended if it keeps failing to act.
- Emergencies. Where people are at immediate risk, for example from an active phishing campaign, the root may act at once and tell the TLD straight afterwards.
- Every action is notified and can be appealed. The registrant receives a statement of reasons and may appeal as the GOpenCDR terms describe. Every action is recorded in the transparency log.
- Measures are proportionate. A hold is used rather than a deletion wherever a hold stops the harm, and a restriction is lifted once the abuse has stopped and its cause has been dealt with.
A reporter's identity is not passed to the registrant unless the reporter agrees or the law requires it.
Requests from courts and authorities
We act on orders and requests from courts and authorities only where they come with valid legal process from a competent authority. The registrant is told unless the law forbids it. Every request and its outcome is counted in a transparency report published every six months. Requests for registrant data follow the registration data disclosure policy.
Consequences
Breaking this policy can lead to a name being held, locked, suspended or deleted, to API keys being revoked, and, where the breach is serious or repeated, to the account being closed. A TLD operator that keeps failing to act on abuse in its TLD answers for it under its own agreement.