Abuse and sanctions policy
How abuse of a name, an address or the network is reported, who acts first, which sanctions can follow and who decides them, and how a decision is challenged.
What this policy covers
GOpenCDR (names) and GOpenCNR (addresses and the network) share one case system, run in GOpenCSR. A report about a name, an address or prefix, or an ASN opens a case there, and every case runs the same way whichever product holds its subject: the holder is told and acts first, and Tier 0 steps in when it does not. This policy sets out that route, the sanctions at the end of it, and how a decision is challenged.
What counts as abuse is defined by the acceptable use policies: GOpenCSR's for accounts and the shared services, GOpenCNR's for addresses and the network, and GOpenCDR's for names. This policy applies together with them and with each product's terms. It adds no kind of abuse of its own.
"We" is Gelhaus Solutions, which operates the three services and holds the Tier 0 role. The "holder" is the person or organisation that holds the name, the address space or the ASN a report is about.
How to report
- By email to abuse@gplatform.org.
- Through the report form at
csr.gplatform.org. It takes a name, an address or prefix, or an ASN, and checks that the registries hold it before it opens a case. - To the holder directly, through its abuse relay address. Every holder has one, published with its resources, in the form
abuse+<handle>@relay.csr.gplatform.org. The relay forwards your message without showing you the holder's own address. It accepts up to 20 messages an hour from one sender and evidence of up to 20 MB, and it keeps a log of the sender address and the outcome of each delivery for 12 months.
Reports about a GOpenCDR name may also go to the address and the report form that GOpenCDR's acceptable use policy gives. They reach the same case system.
Anyone may report, with or without an account. Report in good faith: a knowingly false report breaches GOpenCSR's acceptable use policy.
What a report needs
- What it is about: the name, the address or prefix, or the ASN. A name or an address that neither registry holds is not ours to act on, and we say so.
- What is happening: the kind of abuse, what you saw and when, with times in UTC where you have them.
- What shows it: logs, headers, screenshots or samples.
- How to reach you: an email address, and whether the holder may contact you through the relay. It may only if you agree.
We acknowledge every report within 24 hours, with a case number and a link to follow the case.
Who learns who you are
Your identity is not passed to the holder unless you agree or the law requires it. The holder sees what was reported and the evidence. It can write to you through the relay only if you said it may.
The holder acts first
Every case starts with the holder. The case notice goes to the holder's abuse relay address and appears in its account, where the holder can answer, send its own evidence and say what it has done. A holder keeps its relay address delivering to someone who acts on what arrives.
The holder has 48 hours to act, or 12 hours where the abuse is an active attack: active phishing, malware being served, scanning, or a leak that is live. If the holder has not acted when that time runs out, Tier 0 steps in. If the holder answers, Tier 0 reviews the answer and the evidence before it takes any step.
Names
For a GOpenCDR name, the case follows the route of GOpenCDR's acceptable use policy, inside this case system and with that policy's own times: the operator of the name's TLD acts first, and Tier 0's root abuse desk steps in when it does not, acting on the name itself in a TLD that Gelhaus Solutions hosts, or escalating against a self-hosted TLD under its TLD operator agreement.
The measures for names are GOpenCDR's: a name can be put on hold, locked, suspended or deleted, as GOpenCDR's terms describe. A hold is used rather than a deletion wherever a hold stops the harm.
The sanctions ladder for addresses and the network
When Tier 0 steps in on a GOpenCNR case, it has five steps, in this order:
- Warning. The holder is warned in the case.
- Reduced max-prefix. The hubs accept fewer prefixes from the holder than its usual limit.
- Routes suppressed at the hubs. The hubs stop carrying the holder's routes.
- Depeered from all Tier 0 nodes. Every node Tier 0 operates ends its sessions with the holder.
- Allocation reclaimed. The holder's address space is taken back, and reclaimed space is handled as the GOpenCNR terms describe.
Each step lasts at least 7 days before the next, so that a holder always has time to put things right. Only an emergency suspension, below, acts faster. Every step is an action in the case: the holder is told when it applies and why. Each step is a Tier 0 decision, confirmed with a passkey and taken under four-eyes.
A case climbs the ladder only as far as the abuse requires. Once the abuse has stopped and its cause has been dealt with, the case closes, and any measure short of reclamation is lifted.
Names and addresses together
A holder may hold names in GOpenCDR and addresses in GOpenCNR. Where the abuse calls for it, a sanction may cover a holder's names and addresses together: a step on the network can come with a measure on the holder's names, and the other way round. That is a Tier 0 decision under four-eyes. The statement of reasons says so, and each measure stays within what the documents of its own product allow for the resource concerned.
Emergency suspension
Where a case cannot wait for the holder or for the ladder, Tier 0 may suspend at once under its emergency power, but only in the cases in which the general terms of service let us act first: child sexual abuse material, a threat to life or limb, malware or phishing, a compromised account, an attack on our systems or on others, a match on a sanctions list, and a binding order of a court or an authority. The emergency power has these limits:
- It only suspends or tightens. It never loosens anything.
- It applies at once, and the holder is told at once. The statement of reasons reaches the holder no later than when the suspension takes effect, unless the law forbids telling it, and the holder is heard afterwards.
- It lapses after 90 days unless it is reaffirmed, and after one year at the latest.
- It is published in the transparency log, flagged as an emergency for good, and reviewed afterwards.
For names, GOpenCDR's acceptable use policy lets the root act at once where people are at immediate risk. That is this same power, with the same limits, and it too is used only in the cases listed above.
What runs automatically, and what a person decides
A person takes every decision to sanction a holder. Automated checks, such as a blocklist match, a failed probe, or an alert from GOpenCNR's route collector about a hijack, a leak or an invalid route, find candidates for a case and never decide on their own.
A few things run automatically, because they follow from a rule rather than from a judgement about anyone:
- A leaking closed prefix is cut by the hub at once. When a member leaks closed routes, the hubs drop that member's closed routes and sessions on their own, and nobody has to confirm the cut. A case opens and the holder is told.
- Routes the registry does not support are refused. The hubs' filters are generated from the registry, and a route without a route object, or one that fails RPKI or ASPA validation, is refused. Every refusal is counted and shown to the member.
- A flapping session is held: six flaps in 15 minutes hold a session for 15 minutes.
- A sanctions-list match places holds until Tier 0 clears or confirms it, as described below: an automated decision, in which a person reviews every match.
- The steps after a missed reconfirmation follow on the dates GOpenCNR's terms set. For names, the steps after an unconfirmed address and the withdrawal of a name that comes to exist in the IANA root follow GOpenCDR's terms.
None of these is a step of the ladder.
Flow sampling in a case
GOpenCNR's hubs keep counters, not records of traffic. Inside an open case, and only there, Tier 0 may sample the traffic of the reported source to establish what is happening:
- for at most 7 days, and never outside an open case;
- one packet in 1,000;
- recording source, destination, port and size, and never content;
- with the sampling logged in the case.
The samples are deleted when the case closes. What they showed stays with the case as its findings. How this fits the secrecy of telecommunications is set out in GOpenCNR and the secrecy of telecommunications.
Content
Tier 0 does not police content, at the DNS layer or at the network layer. It does not inspect or filter what members send, host or publish.
- Addresses and the network. A holder is responsible for what it hosts. A report of unlawful content goes through the case system to the holder, as it would reach any host from its upstream provider, and a holder that ignores a well-founded report can be sanctioned as any upstream provider would act against a host.
- Names. GOpenCDR does not judge content at the DNS layer, as its acceptable use policy says. A name is not restricted because of what a website under it says.
- Orders. Where a court or a competent authority orders us to act on a name, an address or prefix, or an ASN, we act, as the authority request policy sets out.
Child sexual abuse material is always reported to the police or the Bundeskriminalamt, with what we hold about it that is not telecommunications traffic data. Traffic data are passed on only under a legal order.
Sanctions-list matches
A person is screened by the legal name and country they give when they first become a holder of resources, as a GOpenCNR member or a GOpenCDR registrant, and an organisation by its verified name and country. Accounts that hold nothing are not screened. The name and country given for screening are seen only by Tier 0. Screening runs at that moment and every day at 03:00 UTC, against the EU consolidated financial sanctions list, and finds near matches as well as exact ones.
A match automatically places holds: no new names or addresses and no transfers out, while what the holder already has keeps working. A match when someone first becomes a holder places the same holds, so nothing can be obtained until the match is cleared.
These holds are an automated decision within the meaning of Art. 22 GDPR. It is permitted because it is necessary to perform the contract and is authorised by Union law, the EU sanctions regulations (Art. 22(2)(a) and (b) GDPR), and it comes with the safeguards of Art. 22(3) GDPR: a person at Tier 0 reviews every match, and the holder may obtain human intervention, express its view and contest the decision.
Tier 0 then either clears the match and records why, after which the same holder and list entry are not flagged again unless the entry changes, or confirms it under four-eyes. A confirmed match blocks the holder's names and addresses together and becomes a case under this policy.
Only the holder and Tier 0 know that a review exists. Anyone else sees only that the holder cannot be added right now. No screening outcome tied to a holder is written to the transparency log, and the transparency report carries counts only.
Statements of reasons
Every action in a case is notified to the holder with a statement of reasons, no later than when the action takes effect: what was done and to which resource, why, under which rule and on which facts, whether it followed a report or Tier 0's own findings, whether it ran automatically under a rule, how long it lasts, and how to challenge it. Where the law forbids telling the holder, it is told as soon as the law no longer does. Only in the cases listed under "Emergency suspension" does Tier 0 act before hearing the holder, and it hears the holder afterwards.
Appeals
The holder, as the party affected, may appeal any decision under this policy within six months of being told of it: from the case in its account, by replying to the notice, or by writing to contact@gplatform.org.
- Who decides. The appeal is heard by the Registry Council of the product whose resource the decision concerns: the GOpenCNR Registry Council for addresses and the network, the GOpenCDR Registry Council for names. A decision that covered names and addresses together is heard by each for its own part. The person who took the decision does not vote on the appeal.
- Accounts and posts. An appeal against restricting an account or removing a post goes to the Registry Council of the product where it happened: the product whose council the post was in, or where the conduct took place. The statement of reasons names it.
- While Tier 0 still holds the seats. Until people are elected to a product's Registry Council, Tier 0 reviews the appeal itself and says so in its answer.
- Meanwhile, a measure stays in place until the appeal is decided. An emergency suspension still lapses on its own terms.
- The answer gives reasons, and every appeal and its outcome is counted in the transparency report.
- The courts remain open to you whatever the outcome, before, during and after an appeal.
For a name, this is how the challenge described in GOpenCDR's terms is heard.
Who is named on a case
A case names the holder, the resources it concerns and the Tier 0 people who act in it. A holder that joined on an invitation was vouched for by a member or by Tier 0. For 12 months after it joins, its voucher is named on any case against it, so that vouching stays accountable. Being named does not make the voucher liable for what the holder does.
The record
- Every action taken in a case is recorded in the transparency log, the one log for GOpenCDR, GOpenCNR and GOpenCSR, except the outcome of a sanctions-list review, which is never written there. It holds identifiers and hashes, never an email address, a person's name or the IP address somebody connected from, and an entry cannot be removed.
- Every report, case, action, emergency suspension and appeal is counted in the joint transparency report for the three services, published every six months under the transparency report policy.
- A case is kept for 12 months after it closes, then deleted. Flow samples go when the case closes. What we process in a case, and why, is in the GOpenCSR privacy notice.
Points of contact
Abuse reports go to abuse@gplatform.org. For everything else, including questions about a case you are part of, write to contact@gplatform.org, which is also the single point of contact for authorities and for users under Arts. 11 and 12 of the Digital Services Act, in English or German.
Changes
This policy changes through the process the general terms of service set out: a material change is announced to your address at least six weeks before it takes effect. Every version is kept in the document archive.