Submit a Support Ticket
Corporate

Domain Responsibilities

A plain-language summary of the rights and obligations of domain name registrants under ICANN's 2009 Registrar Accreditation Agreement (RAA).

1. Background and Purpose

This page provides a plain-language summary of the rights and obligations of registrants ("Registered Name Holders") under ICANN's 2009 Registrar Accreditation Agreement (the "RAA"). The text is based on the ICANN document prepared with the contributions of the joint working group of the GNSO Council and the At-Large Advisory Committee and through consultations with registrars.

To register a domain name, a Registered Name Holder must use the services of a Registrar accredited by ICANN. For an organization to obtain ICANN accreditation, it must sign a contract with ICANN called the RAA. The RAA and the related ICANN policies establish various rights and obligations for the Registered Name Holder.

The summaries herein are provided for informational purposes only; they do not replace or modify the actual texts of the RAA, the relevant specifications or the policies. The binding documents are the original texts of the relevant agreements and policies.

2. Relevant RAA Provisions

Because the RAA is a contract between ICANN and the Registrar, no one — including the Registered Name Holder — may sue ICANN or the Registrar on the grounds that the RAA has been breached.

Registrars may not claim that they can provide privileged or superior access to any TLD over other organizations.

Certain obligations of the Registrar depend on the Registered Name Holder fulfilling its responsibilities, in particular the payment of registration fees, the submission of the required data, and the accurate and timely updating of such data. The Registrar is also obliged to notify the Registered Name Holder of matters such as the expiration of the registration period, the use of personal data, the escrow of data for names registered under a privacy/proxy service, and the fees applicable to the recovery of names.

3. Data Submission to the Registry Operator

For each registered name within each TLD, the Registrar must submit certain data points to the Registry Operator (Registry):

  • The registered name itself (m.3.2.1.1),
  • The IP addresses of the primary and secondary name servers (m.3.2.1.2),
  • The corresponding names of those name servers (m.3.2.1.3),
  • The identity of the Registrar, unless generated automatically by the registration system (m.3.2.1.4),
  • The expiration date of the registration, unless generated automatically by the registration system (m.3.2.1.5),
  • Any other data requested by the Registry Operator (m.3.2.1.6).

The information relating to the name servers (m.3.2.1.2–3) is generally provided by the Registered Name Holder. If the Registered Name Holder updates this data, the Registrar must transmit the update to the Registry Operator within five (5) days.

4. WHOIS Data

Registrars are obliged to provide an interactive web page that is publicly accessible and freely searchable, together with a port 43 WHOIS service. The RAA sets out the data points that must be provided in response to a query:

  • The registered name (m.3.3.1.1),
  • The names of the primary and secondary name servers (m.3.3.1.2),
  • The identity of the Registrar (m.3.3.1.3),
  • The original creation date of the registration (m.3.3.1.4),
  • The expiration date of the registration (m.3.3.1.5),
  • The name and postal address of the Registered Name Holder (m.3.3.1.6),
  • The name, postal address, e-mail address, telephone number and (where available) fax number of the technical contact (m.3.3.1.7),
  • The name, postal address, e-mail address, telephone number and (where available) fax number of the administrative contact (m.3.3.1.8).

This data is referred to as "WHOIS data". The Registered Name Holder is obliged to keep the WHOIS data up to date; upon receiving an update, the Registrar updates the WHOIS record "immediately". The Registrar may outsource the maintenance of the public query function.

The RAA may permit the provision of bulk access to WHOIS data for third parties. In connection with bulk access or the public query function, the Registrar must restrict high-volume queries and uses such as marketing and mass promotion as specified in the RAA. If the query function is outsourced, the same restrictions must be applied to the contractor.

5. Communication and Record Keeping

Registrars must keep records of all correspondence with Registered Name Holders and of the information submitted to Registry Operators.

6. Data Escrow, Privacy and Proxy Services

The Registrar must maintain a database containing the WHOIS data of all names registered under its accreditation and all data it submits to the Registry Operator. This database must also include, for each name, the name and (where available) the postal address, e-mail address, telephone number and fax number of the billing contact.

A Registered Name Holder may wish to limit the personal information displayed in a WHOIS query. To do so, the name can be registered through a privacy service (personal information is concealed and is most often replaced by the service's information) or a proxy service may be used (in which case the Registered Name Holder is the proxy service, which licenses the right of use to the customer).

When a name is registered under a privacy/proxy service, the Registrar must do one of two things: (1) include in the database the name, postal address, e-mail address and telephone number provided by the customer even where privacy/proxy is used; or (2) display a notice to the customer, when selecting the privacy/proxy service, that their data is not escrowed. Where the customer's data is not escrowed, only the contact details of the privacy/proxy service are escrowed; in that case, in the event of the bankruptcy or failure of the Registrar or Registry Operator, future notifications can only be sent to the contact information in the database.

7. Registrar's Business Dealings with the Registered Name Holder

The RAA imposes a number of obligations on the Registrar's business dealings.

The Registrar may not activate a name without receiving reasonable assurance from the Registered Name Holder that the registration fee will be paid.

If the Registered Name Holder does not consent to renewal, the Registrar may cancel the registration at the end of the current term. If the Registered Name Holder has not consented to renewal, the name must be deleted from the Registry Operator's database within 45 days of the end of the registration term.

This right of cancellation/deletion is not absolute. RAA m.3.7.5.1 sets out a list of "exceptional circumstances"; where these exist, the Registrar may renew the name even without the Registered Name Holder's consent (e.g. where the name is the subject of a UDRP proceeding, a court order, a bankruptcy proceeding or a billing dispute). In such cases, a record of the reason for renewal must be kept.

The Registrar must notify every new Registered Name Holder of the deletion and auto-renewal policies, and must seek to inform Registered Name Holders when these policies change. These policies, together with the fees to be charged for the recovery of a name during the "Redemption Grace Period" (the 30-day period during which the name is in "Pending Delete" status with the Registry Operator), must be displayed on the websites where registration/renewal takes place.

If, at the time of deletion or expiration, the name is the subject of a UDRP dispute, the UDRP complainant has the right to renew (or, if deleted, to restore) the name. If the complainant renews/restores the name, the Registrar must place the name in HOLD or LOCK status and update the WHOIS information to indicate that the name is the subject of a dispute. RAA m.3.7.5.7 grants the original Registered Name Holder the right to recover or renew the name if the UDRP complaint is terminated without a decision or resolved in favor of the original registrant.

8. Registrar / Registered Name Holder Agreement

Registrars must enter into an electronic or paper registration agreement with all Registered Name Holders. Under the RAA (m.3.7.7.1–12), this agreement must at least include the following:

  • The Registered Name Holder must provide "accurate and reliable contact information" and must "promptly correct and update" it throughout the registration term. The required information: full name, postal address, e-mail address, telephone number, and fax number where available; in the case of an organization, association or company, the name of the person authorized for contact and the data in m.3.3.1.2, 3.3.1.7 and 3.3.1.8 (m.3.7.7.1).
  • If the Registered Name Holder willfully provides inaccurate or unreliable information, willfully fails to update the information promptly, or fails to respond to the Registrar's accuracy inquiry within fifteen (15) days, it will be deemed to have materially breached the agreement and the registration may be cancelled.
  • The person registered as the Registered Name Holder is obliged to provide full contact information and is the official record holder. If a person registers a name and leaves it to another's use (e.g. a web designer registering it on behalf of a client) and this "third party" is not a party to the agreement, the Registered Name Holder will be liable for harm caused by the third party's wrongful use unless it discloses the user's identity and current contact information, provided it has been presented with "reasonable evidence of actionable harm".
  • The Registrar must inform the Registered Name Holder how its data will be used, with whom it will be shared, how the data can be accessed and updated, and must indicate which data is required and which is voluntary. The Registered Name Holder must consent to these data processing terms.
  • If the Registered Name Holder provides the Registrar with personal data belonging to a "third party" who is not a party to the agreement, it must confirm that it has made the same notifications to and obtained the same consents from such persons.
  • The Registrar may process the data only for the stated purposes and agrees to take reasonable precautions to protect the data from "loss, misuse, unauthorized access or disclosure, alteration or destruction".
  • The Registered Name Holder represents that, to its knowledge, the registration or use of the name does not infringe the legal rights of third parties (e.g. trademark or copyright).
  • In a dispute relating to the use of the name, the Registered Name Holder submits to the jurisdiction of at least one of the following: the courts of the Registrar's domicile or the courts of its own "domicile".
  • The Registered Name Holder agrees that the registration may be "suspended, cancelled or transferred" for the reasons set out in m.3.7.7.11 (e.g. where an ICANN policy/specification so requires, or to correct registration errors or resolve disputes). For example, an administrative panel under the UDRP may decide to suspend, transfer or cancel the name.
  • The Registered Name Holder agrees to "indemnify and hold harmless" the Registry Operator and its directors, employees and agents against all claims, damages, liabilities and expenses (including reasonable attorneys' fees) arising out of the registration.

9. Verification of Contact Information

The relevant specifications/policies may impose on the Registrar the obligation to verify contact information at initial registration and to re-verify it at specified intervals.

When notified that a name's contact information is inaccurate, the Registrar must take "reasonable steps" to verify the information, and must take action to correct any inaccuracies it becomes aware of (even if no one reports them). It must also maintain a valid e-mail and postal address of its own and publish it on its website.

10. Reseller Arrangements

The RAA imposes obligations on the Registrar's work with third-party Resellers. The Registrar must include the following in its Reseller agreements: the prohibition on the Reseller claiming to be accredited by ICANN; the requirement that the Reseller's registration agreements contain all the provisions the Registrar is required to have in its own agreement; the publication of the required ICANN links; and the identification of the responsible registrar.

If a customer uses the Reseller's privacy/proxy service, the Reseller must do one of three things: (1) transmit the customer's identity and contact information to the Registrar; (2) place this information in escrow; or (3) display a notice to the customer that their information is not escrowed. The Registrar is also obliged to take compliance and enforcement action against any Reseller that breaches the required provisions.

11. Other Policies and Specifications

Restored Names Accuracy Policy: When a Registrar restores a name (from the Redemption Grace Period) that was deleted because inaccurate contact data was provided or inquiries were not answered, the name must remain in "Registrar Hold" status until the Registered Name Holder provides current and accurate WHOIS information.

UDRP (Uniform Domain Name Dispute Resolution Policy): In addition to the undertaking in the RAA, the UDRP also requires an undertaking that the name has not been registered for an unlawful purpose and will not be used contrary to applicable laws. The UDRP also subjects the Registered Name Holder to a mandatory administrative proceeding conducted before an ICANN-approved dispute resolution service provider. This mandatory administrative proceeding does not prevent the pursuit of a separate judicial remedy for the same or similar conduct.

Inter-Registrar Transfer Policy: The Registered Name Holder has the right to transfer its domain name registration between registrars, and the policy sets out the response times for a transfer request. The right of transfer is not absolute; there may be conditions such as time limits from the date of creation/previous transfer and the provision of the necessary authorization/documents. The current Registrar may deny a transfer only in the following circumstances:

  • Evidence of fraud,
  • A UDRP proceeding,
  • An order of a court of competent jurisdiction,
  • A reasonable dispute over the identity of the Registered Name Holder or administrative contact,
  • Non-payment of fees for a previous period (including credit card charge-backs) — in such cases the name must be placed in "Registrar Hold" status before the denial,
  • An express written objection to the transfer from the Transfer Contact (via e-mail, fax, document or other voluntary opt-in methods),
  • The name already being in "lock" status (provided a reasonable and accessible method is offered to remove the lock),
  • The transfer being requested within 60 days of the creation date in the record,
  • Less than 60 days (or a shorter period to be determined) having elapsed since the name was transferred.

12. Notes

  1. Additional information about the lifecycle of a typical gTLD name and its post-expiration statuses can be found in the relevant ICANN resources.
  2. The technical names of the domain name statuses come from community-based RFC drafts. While a name is in one of these statuses, it cannot be deleted or modified; for any change, the Registrar must change the status.
  3. There are many ways to "infringe the legal rights" of others; applicants who are concerned that registration or use may infringe another's rights are encouraged to obtain independent legal advice.
  4. There may be other forums that can adjudicate a dispute regarding the use of a name; however, these are not specified in the RAA.

Last updated: June 2026