# Policies, legal and procedures

# Abuse and complaints policy in Openprovider

## Question

How does Openprovider handle complaints and abuse notifications about domain names?

## Answer

### General note

First of all, be aware that Openprovider, as a domain-only provider and not providing any content, hosting or e-mail services, are not in a position to judge the contents of a website. For that reason, our normal procedure is that we inform our reseller and the domain holder, but will not suspend the domain names without an official WIPO decision or court order (see below).

Unfortunately we cannot guarantee that our reseller will respond to the complainant.

### Informal complaints

As long as there is no court order, WIPO decision or other formal decision, disputes and complaints about a domain name are primarily handled between the domain holder and his or her direct provider. If the whois shows no contact information of the domain holder, you can send a message to one of the domain contacts through our [contact form](https://contact-form.registrar.eu/). Trusted senders can also send an e-mail to abuse@openprovider.com.

If that is not possible for any reason, the complainant can contact Openprovider's abuse department; see our article on [reporting abuse](https://openprovider.help/books/domains/page/reporting-abuse) for further information. We will promptly contact our customer about the issue and ask him to solve it. If this does not succeed, we will escalate the complaint and cooperate to find a suitable solution.

This solution will always be based on the contracts with and policies of the respective registry. If a solution is implemented without involvement of our customer (reseller), additional proof of identification of the registrant is required.

We use the Zendesk ticketing system for tracking abuse notifications. Each submitted report is automatically assigned a ticket number which the complainant receives in a copy of his message. Each complaint is tagged with specific labels for analysis purposes.

### Court order, WIPO and similar organisations

In case of a formal court order, [WIPO case or similar situation](https://www.icann.org/resources/pages/providers-6d-2012-02-25-en), Openprovider will temporarily lock the domain against any modifications by moving it to a special account. This does not imply any changes to the domain name: the domain data will remain the same and the domain will remain functional, it just cannot be altered for the duration of the proceeding.

Depending on the outcome of the case, we will implement the decision or move the domain back into our reseller's management:

- If the outcome is in favor of the complainant, Openprovider is required to implement the decision on the domain name and we will do so within 5 calendar days. This can be an update to the domain data (including change of registrant), provisioning of the authorization code, unlocking of the domain name or deletion of the domain.
- If the outcome is in favor of the domain registrant, we will return the domain under management of our reseller again without altering any data.

### Renew and restore

For the duration of the complaint, not only the registrant (through our reseller), but also the complainant can ask for renewal or reactivation of the domain name. If you are the complainant, please contact us in such a case.

### UDRP

In general, Openprovider follows the Uniform Domainname Resolution Policy or UDRP.  
You can find all details about this policy on [ICANN's website](https://www.icann.org/resources/pages/help/dndr/udrp-en).

# Abuse investigation by registries

A wide range of registries perform their own analysis on potentially abusive domain names. This can be based on publicly available blacklists or other reporters. In most cases, found domains are reported by the registry and we report them to our resellers. However, in some cases the registry suspends domain names without informing us. If you suspect a legitimate domain name from being suspended by the registry without reason, please contact us.

In most cases, domain names are suspended (they do not resolve anymore) and not deleted, so the domain can still be renewed and will not be lost.

## Radix Registry's proactive analysis

Registry Radix (managing extensions like .online, .site, .website and .tech) also performs "Proactive analysis". Proactive analysis is a process through which suspicious domains are identified based on various parameters and are proactively suspended to ensure the domain is disabled before an abuse activity is conducted or before severe damage is caused. The parameters are various variables ranging from keywords (e.g. trademark names) in the domain name, the registration pattern to registrant information, associated nameserver, similarity between the current and historic registrations, and many more.

In case of a suspended Radix domain, after solving the issue (or if a domain is flagged as a false positive), the registrant can submit an unsuspension request through [https://radix.website/report-abuse](https://radix.website/report-abuse) with a reasoning and/or the purpose of registration. Radix shall review the request and if found valid, the domain shall be considered for unsuspension.

# Corona and domain names

The corona pandemic impacts the world and unfortunately some persons are misusing this pandemic for their own gain. Many governments and registries adopt special procedures around domains that are related to corona, mostly based on keywords in the domain name (corona, covid, facemask, ...). If you register such domain, you may find that the delegation on the internet is delayed, or the registry asks the registrant for more information.

Although each registry has its own details, the following are the most common actions:

- Registries may **delay delegation** in the zone file of corona related domain names. That means that a domain name is not immediately available on the internet.
- Registries may **ask the registrant** to confirm their data, for example by uploading proof of identity.
- Registries may **check domain names** that are corona related and send a "notice and takedown" request to the registrar. We will suspend the domain names in such cases if no sufficient response is received.
- Registries may **delete domain names** that they flag as abusive.

  
In general, if you have registered a domain name that can be related to corona and that domain name is not activated as usual, first check the details (legitimacy) of the registrant, your own e-mail and ask your customer / registrant to check his e-mail to see if there was a request for further information on the domain name. If not and the domain name does still not resolve after 48 hours, you can contact us for more information.

# Escalation procedure  - Token request of a domain (reseller)

## Question:

Which actions are expected from the reseller by an escalation of the domain owner?

## Answer:

When the domain owner contacts Openprovider requesting the authorization code of a domain or any other change regarding one of the domains the reseller has under his account,. Openprovider will contact the reseller.   
  
Openprovider, as an ICANN-accredited registrar , is **obliged** to generate the authorization code or apply any changes within **5 working days** if the owner of the domain requests it.   
  
Before that, Openprovider will ask the reseller to contact the domain owner to handle the request. In case the reseller does not respond, Openprovider has to generate the codes for the end customer.  
  
Therefore, Openprovider will contact the reseller to inform him about what is going on; if no answer is given, we will apply the requested changes within **5 working days**.   
Keep in mind that ICANN and the registry rules, as well as our Terms and Conditions, place the registrant above the reseller when it comes to deciding what is done to a domain name and what is not.  
  
**For example,** an unpaid invoice is **not** a valid reason to decline an update or a reset of the authorization code.

# Escalation procedure - External .nl domain

## Question

How to start an escalation process in case the current registrar of a .nl domain does not provide a transfer code?

## Answer

Openprovider can start an escalation procedure when the owner of a .nl domain wants to retrieve their transfer code (also referred to as authorization code / token) , but has trouble to receive this from the current registrar. A reason can be that the company is bankrupt, does not respond, or in case of conflict.

SIDN provides a procedure to start an escalation process, in which the current registrar gets 5 working-days to resolve the issue himself or, in case the issue is not resolved in 5 days, SIDN will verify the owner and provide the transfer code.

The following documents are required (by email to support) to start this process:

**If the registrant is a natural person:**

- a copy of the identity document of the registrant
- proof of ownership (available [here](https://www.sidn.nl/en/requesting-registrant-details), more information available in our [.nl article](https://openprovider.help/books/domains/page/nl) (Transfer &gt; Proof of ownership))
- proof that the registrant first requested the code at the current registrar (for example an e-mail)
- proof that the registrant wants to transfer the domain name to Openprovider (for example, an e-mail)

  
**If the registrant is a legal person (company):**

- a business registration document from the Chamber of Commerce (not older than six months) from the registrant
- a copy of the identity document of the person authorised according to the business registration document
- proof that the registrant first requested the code at the current registrar (for example an e-mail)
- a proof that this registrant wants to move the domain name to Openprovider (for example an e-mail)

### Domain in quarantine

In case the domain itself is not active, but already in quarantine, a different process can be used.

Please follow the steps in [this article](https://openprovider.help/books/domains/page/escalation-procedure-external-transfer-from-quarantine-available-for-nl-and-be) if the domain is currently in quarantine.

# Escalation procedure - External transfer from quarantine | Available for .nl and .be

The Registry for .nl (SIDN) and the Registry for .be (DNSBelgium) offer the option to transfer and restore a domain which is currently in quarantine at a different registrar.   
  
This has been implemented in the RCP for **.be** domains.  
This is a manual process via the support department for **.nl** domains - <support@openprovider.com>   
  
The costs for the transfer + restore is € 75 (per domain, excl VAT)

<span>Requirements for a .be transfer from quarantine:</span>

- the domain name
- a valid authorization code (can be requested at the [Registry](https://www.dnsbelgium.be/en))
- the handles (owner, admin, tech, billing) matching the current whois details
- nameservers
- approval of the fee in the control panel via the checkbox
- The request can be submitted via the transfer page in the control panel and will be processed realtime.

<span>Requirements for a .nl transfer from quarantine:</span>

Add the following details in the email:

- the domain name
- the handles (owner, admin, tech, billing) matching the current whois details
- nameservers
- awareness and approval of the fee
- proof that the registrant wants to transfer the domain name to Openprovider (for example, an e-mail)
- proof of ownership (available [here](https://www.sidn.nl/en/requesting-registrant-details), more information available in our [.nl article](https://openprovider.help/books/domains/page/nl) (Transfer &gt; Proof of ownership))
- identification documents:
    - **If the registrant is a natural person:**
        - a copy of the identity document of the registrant
    - **If the registrant is a legal person (company):**
        - a business registration document from the Chamber of Commerce (not older than six months) from the registrant
        - a copy of the identity document of the person authorised according to the business registration document

# Escalation procedure - Internal transfer from quarantaine

## Question

How to transfer a domain which is currently in quarantine (redemption period) at a different Openprovider reseller?

## Answer

When a domain name is in quarantine (redemptionPeriod), there is an option to restore that domain name via another Openprovider reseller if the current provider can or does not assist. A reason can be that the company is bankrupt, does not respond or in case of conflict. This process can be started on explicit request from the legitimate domain owner only.

To start this process, please send an e-mail to <support@openprovider.com> containing the following information:

- your Openprovider reseller ID
- a copy of the identity document of the registrant
- in case of a legal entity: a business registration document from the Chamber of Commerce (not older than six months) from the registrant. (The identity card provided needs to match the person mentioned in the registration document.)
- proof that the registrant first requested the restore at the current provider (for example an e-mail)
- proof that the registrant wants you to initiate the transfer (for example, an e-mail)
- confirmation of the involved costs.

The process:

- Openprovider validates the request and the provided documentation.
- If the request is valid, the deleted domain will be transferred to the account of the requesting reseller
- The domain will restored and renewed. The following costs are charged to the account of the new reseller: the restore and renewal fee based on the extension plus € 25,- administrative fee
- Openprovider informs the previous and new reseller about the transfer
- We intend to complete your request within one business day

***Notes:***

- *The procedure mentioned below is only valid when a domain is in soft / hard quarantine. When a domain has the status "pending delete" this option is not available: the domain cannot be restored anymore*
- *If the domain name is currently active, a different [procedure](https://openprovider.help/books/domains/page/escalation-procedure-token-request-of-a-domain-registrant) is followed to request the transfercode*
- *If the domain name is a .nl or .be domain and in quarantine at a different registrar, follow this [article](https://openprovider.help/books/domains/page/escalation-procedure-external-nl-domain)*

# Escalation procedure - Token request of a domain (registrant)

## Question

How to receive a domain authorisation code if the reseller doesn't respond to one's request?

## Answer

Openprovider will start an escalation procedure when the owner of a domain want to retrieve their authorisation code.  
  
<span>Openprovider</span>, as registrar, is obliged to generate the authorisation code of the domain or to apply any changes in the current contacts if the owner of the domain requests it. Therefore Openprovider need to confirm that the person contacting Openprovider speaks in name of the owner of the domain. Before this escalation procedure can start <span>Openprovider</span> need:

1. **Copy of id card**   
    (If the domain is registered on a company name we should receive a Chamber of Commerce letter)
2. **Invoice of the domain**
3. **Please note :** THIS POINT IS ONLY APPLICABLE FOR ***.nl*** DOMAINS***.* Proof of ownership** (available [here](https://www.sidn.nl/en/requesting-registrant-details), more information available in our [.nl article](https://openprovider.help/books/domains/page/nl) (Transfer &gt; Proof of ownership))
4. **Please note :** THIS POINT IS ONLY APPLICABLE FOR **INDIAN** CUSTOMERS ***.* a.** ID Proof of the Domain Owner (PAN / Aadhar / Driving License / Passport) **b.** If the domain is registered in the name of a company / organization, please submit us either Company Registration Certificate / GST Registration Certificate / Certificate of Incorporation (if applies).

These documents should be send to Openprovider, using the form "***I am a domain owner***" on the following page" [https://www.openprovider.com/company/contact-us/contact-support](https://www.openprovider.com/company/contact-us/contact-support)

When Openprovider has received the escalation from the domain owner Openprovider will first contact the reseller where the domain is administrated to inform about where the escalation is about, Openprovider will ask the reseller to proceed with the request of the domain owner. In case the reseller does not collaborate send us a reply **after 5 working days.** Openprovider will provide the authorisation code by email on which the domain is registered or apply the desired changes in the contact details.

# How to Request Access to Non-Public WHOIS Data (NPRD)

## <span>Overview</span>

<span>For privacy and data-protection reasons, personal information in domain registration data is no longer publicly visible in WHOIS lookups.</span>

Openprovider, as an ICANN-accredited registrar, may disclose limited non-public registration data to third parties who can demonstrate a legitimate and proportionate interest, in accordance with:

- The ICANN Registration Data Policy (RDP);
- Article 6(1)(f) of the General Data Protection Regulation (GDPR) (legitimate interest basis); and
- Other applicable data-protection and privacy laws.

<span>Every request is individually assessed to ensure that the legitimate interests of the requester do not override the privacy rights of the data subject.</span>

**Please note:** Disclosures for domain names using Whois Privacy Protection (WPP) or other proxy services are handled separately under the Specification on Privacy and Proxy Registrations (P/P Specification) of the ICANN Registrar Accreditation Agreement (RAA).

## <span>Who Can Submit a Request?</span>

<span>Any third party—including individuals, companies, or public authorities—may submit a request if they can demonstrate a legitimate interest.</span>

<span>Typical valid reasons include:</span>

<div id="bkmrk-purpose-examples-law"><div><figure><table><thead><tr><th><span>Purpose</span></th><th><span>Examples</span></th></tr></thead><tbody><tr><td><span>Law enforcement</span></td><td><span>Investigation of fraud, cybercrime, or misuse</span></td></tr><tr><td><span>Intellectual-property enforcement</span></td><td><span>Trademark or copyright infringement</span></td></tr><tr><td><span>DNS abuse mitigation</span></td><td><span>Phishing, malware, spam, or fraud cases</span></td></tr><tr><td><span>Legal proceedings</span></td><td><span>Where registration data is required as evidence</span></td></tr></tbody></table>

</figure></div></div><span>Requests for commercial, marketing, or data-collection purposes will not be accepted.</span>

## <span>Step-by-Step: How to Submit a Request</span>

### <span>Step 1: Review Eligibility</span>

<span>Before starting, ensure:</span>

- <span>You have a clear legal or legitimate reason to access the data.</span>
- <span>You have exhausted less-intrusive alternatives (e.g., public WHOIS lookup, dispute resolution, or abuse report).</span>

> <span>**If those options are sufficient, an NPRD request is unnecessary.**</span>

### <span>Step 2: Prepare Your Information</span>

<span>You’ll need the following before submission:</span>

1. <span>Exact domain name(s) under review</span>
2. <span>Your details (organization, name, email)</span>
3. <span>Proof of representation or authority</span>
    
    
    - <span>e.g., Power of Attorney, or a statement confirming you act on your own behalf</span>
4. <span>Requested data</span>
    
    
    - <span>Specify which contact fields (e.g., registrant name, email) you seek</span>
5. <span>Case summary</span>
    
    
    - <span>Legal basis (GDPR article, statute, or other law)</span>
    - <span>Description of the issue</span>
    - <span>Explanation of necessity and proportionality</span>
6. <span>Supporting documents</span>
    
    
    - <span>e.g., trademark certificates, infringement evidence, or court documents</span>
    - <span>Combine all supporting files into a single ZIP (max 10 MB)</span>

### <span>Step 3: Submit the Form</span>

<span>Go to: </span>[<span>Openprovider Contact Form</span>](https://www.openprovider.com/company/contact-us)  
<span>and scroll to the section “Request the Disclosure of Personal Data.”</span>

<figure id="bkmrk-">![embedded-image-0wbxtyje.png](https://openprovider.help/uploads/images/gallery/2026-08/embedded-image-0wbxtyje.png)</figure><span>Fill in all required fields in the form:</span>

<div id="bkmrk-section-description-"><div><figure><table><thead><tr><th><span>Section</span></th><th><span>Description</span></th></tr></thead><tbody><tr><td><span>01. Requestor</span></td><td><span>Provide organization details and upload proof of authority</span></td></tr><tr><td><span>02. Scope of Request</span></td><td><span>Enter the domain(s) and specify which data you’re requesting</span></td></tr><tr><td><span>03. Case Summary</span></td><td><span>Describe the case, cite relevant law, and attach supporting evidence</span></td></tr><tr><td><span>04. Declaration</span></td><td><span>Confirm good-faith purpose, lawful processing, and data-deletion commitment</span></td></tr></tbody></table>

</figure></div></div><span>Click Submit once complete.</span>

### Step 4: Evaluation and Response

**Acknowledgment:** You’ll receive confirmation that your request was received.

**Internal Review (≤ 30 days):** Openprovider assesses your documentation and legal basis.

**Outcome:**

- *Approved* → Only the specific data elements requested and justified will be disclosed. No additional information will be shared beyond the scope of your request.
- *Denied* → If your request doesn’t meet the criteria or lacks sufficient justification.

Average review time: up to 30 calendar days.

**Response Delivery:** Once the review is complete, Openprovider will provide its response —including any approved data disclosure— through its secure Zendesk ticketing system. Verified requestors will receive an email with notifications and responses via this secure ticket channel.

## <span>Data-Handling Obligations</span>

<span>By submitting a request, you declare that:</span>

- <span>The data will be processed only for the purpose described</span>
- <span>It will be securely deleted within 30 days</span>
- <span>It will not be transferred or shared unlawfully</span>
- <span>False or misleading requests may result in liability or refusal of future requests</span>

## <span>Contact &amp; Support</span>

<span>If you have questions or need help preparing your submission:</span>

- <span>Visit: </span>[<span>https://www.openprovider.com/company/contact-us</span>](https://www.openprovider.com/company/contact-us)
- <span>Choose: **“Request the Disclosure of Personal Data”** under the contact form options.</span>
- <span>Or open a **Support Ticket** from your Openprovider account.</span>

## <span>References</span>

- [ICANN's Registration Data Policy](https://www.icann.org/en/contracted-parties/consensus-policies/registration-data-policy)
- [<span>GDPR Article 6(1)(f): Legitimate Interest Basis</span>](https://www.edpb.europa.eu/system/files/2024-10/edpb_guidelines_202401_legitimateinterest_en.pdf)
- [<span>ICANN Temporary Specification for gTLD Registration Data</span>](https://www.icann.org/en/contracted-parties/generic-top-level-domains/temporary-specification-for-gtld-registration-data-01-01-2020-en)

# How to act if someone else registers a domain with your trademark?

## Question

How to act if someone else registers a domain name with your trademark name?

## Answer

Most registries do not scan domain names against known trademarks. In other words: everybody can register a domain name, even microsoft.com or google.nl if it wasn't already taken. If this happens to your or your customer's trademark and damage is done, there are three methods to deal with this: the domain dispute policies URS and UDRP, and a formal complaint to a court.

### URS and UDRP

The [Uniform Rapid Suspension](https://openprovider.help/books/domains/page/urs-procedure-uniform-rapid-suspension-system) (URS) and [Uniform Domain Name Dispute Resolution Policy](https://www.icann.org/resources/pages/help/dndr/udrp-en) (UDRP) have a lot of overlap, but also differences. URS is the smaller and faster variant of UDRP, introduced with the launch of the new gTLDs in 2013.

Both types define three prerequisites that must all be met to make a complaint valid:

- <span>the registered domain is **identical or confusingly similar** to the trademark</span>
- <span>the registrant has **no legitimate right or interest** to the domain name</span>
- <span>the domain name was registered and is **used in bad faith** (includes 'just for selling to trademark holder', domain hijacking, ...)</span>

**<span>If not all three prerequisites are met, URS and UDRP are no option.</span>**

<span>The common parts of URS and UDRP are, that a complaint is filed and an arbitration committee reviews the complaint. This leads to an outcome. However, while UDRP can force a domain to be transferred to the complainant, URS can only lead to suspension of the domain name.</span>

<span>This table lists the most important differences between URS and UDRP:</span>

<table id="bkmrk-urs-udrp-supported-e"><tbody><tr><td>**URS**</td><td>**UDRP**</td></tr><tr><td>**Supported extensions**</td><td>- New gTLDs
- Some legacy gTLDs
- A few ccTLDs

</td><td>- All gTLDs
- [various ccTLDs](https://www.wipo.int/amc/en/domains/cctld/)

</td></tr><tr><td>**Eligibility**</td><td>Registered trademarks only</td><td>Also common-law trademarks</td></tr><tr><td>**Price (depends on provider)**</td><td>Cheaper</td><td>More expensive</td></tr><tr><td>**Resolution**</td><td>Suspension of domain only</td><td>Transfer or cancellation of domain</td></tr><tr><td>**Speed**</td><td>Faster (few weeks)</td><td>Slower (few months)</td></tr><tr><td>**Deliverables**</td><td>Full proof of lack of legitimate interest and bad faith</td><td>Report likeliness of lack of legitimate interest and bad faith</td></tr></tbody></table>

### Regular court

If URS and UDRP cannot be used, for example because the domain owner is not using the domain in bad faith, the trademark holder may refer to his or her local court. Whether or not this will be successful depends on too many variables to describe here: the coverage of the trademark, the jurisdiction of the domain owner, the contents of the website... We advise to contact a legal advisor.

###   
Trademark Protection Services

Exactly for this kind of situations, a couple of providers offer trademark protection services like DPML and TREx. That prevents the trademark holder from defensively registering a lot of domain names, and protects against non-trademark holders registering the domains. More information is available in our [knowledge base](https://openprovider.help/books/domains/page/what-are-the-advantages-of-protected-marks-lists-dpml-uni-eps-and-adultblock).

# NIC.NI Registry Policy Changes Affecting .NI Domains

## <span>Overview</span>

The NIC.NI registry has announced a reorganization of its operations to align with new national legal requirements in Nicaragua. As a result, new restrictions and validation procedures have been implemented for the registration and renewal of .ni domain names.

These changes are mandatory and apply to all registrars and domain holders without exception.

##   
<span>Key Changes from NIC.NI</span>

1\. **Compliance with Cybercrime Law (Ley N° 1042 - LEY ESPECIAL DE CIBERDELITOS)**

All .ni domain names must comply with the provisions of Nicaragua's Cybercrime Law. Domains associated with content or activities that are prohibited under this law cannot be registered or renewed.  
  
2\. **Prohibited Content Categories**

NIC.NI will not permit the registration or renewal of domains that are related to:

- **Online gambling services** (e.g., casinos, betting sites)
- **Adult content** (e.g., pornography, explicit content platforms)

Domains falling under these categories will be automatically rejected.

3\. **Registry-Led Validation Process**

NIC.NI will conduct manual validation checks on all domain applications to ensure compliance with their new policies.

- This process is now a required step for both new registrations and renewals.
- Delays may occur due to processing times. Validation may take several weeks or more.
- Approval is at the sole discretion of the NIC.NI registry.

## <span>What You Need to Do</span>

- Review your current .ni domains to ensure they comply with the new requirements.
- When registering or renewing a .ni domain, allow extra time for the validation process.
- Avoid submitting domains related to prohibited categories, as they will be rejected.
- If you are unsure about compliance, consult a legal advisor familiar with Nicaraguan cybercrime law.

# New DNSbelgium Registrant Verification Process

From 1st March 2022, dnsBelgium will implement in production a new registrant verification process.  
This process is really simple, and it will ensure the ownership of the domains:

1. Domain is registered by a private individual (by default, in *pendingCreate*);
2. The registrant will receive an email from dnsBelgium with a link to validate the owner data;
3. Once the data is validated, the domain will be active.
4. For company registrations, a company contact can go through verification.

- To validate the registrant information for **Belgian** private individuals, the registry is using the service “**itsme**” or “**eID card reader**”.
- To validate the registrant information for **Dutch** private individuals, the registry is using the service “**itsme**” or “**iDIN**”.
- For registrants outside *The Netherlands* or *Belgium*, the registrants will have to validate their identity using **Onfido**.

The registry created a video to explain the full process: [https://www.tryout.dnsbelgium.be/en/verification](https://www.tryout.dnsbelgium.be/en/verification)

<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="allowfullscreen" frameborder="0" height="315" src="https://www.youtube.com/embed/sxRdt0HYPAI?si=VvdqFNDlBf7yjupZ" title="YouTube video player" width="560"></iframe>

# URS procedure (Uniform Rapid Suspension System)

## Question

What is the *Uniform Rapid Suspension* (URS) procedure?

## Answer

URS ('Uniform Rapid Suspension System') is a fast complaint procedure which is based on the existing UDRP ('Uniform Domainname Resolution Policy') but has a lower-cost and faster path to relief for rights holders in the most clear-cut cases of infringement. Most generic TLDs (like .com, .london and .email) support URS. A clear description of the procedures is in the attached [*URS procedures.pdf*](https://support.openprovider.eu/hc/article_attachments/205378518/URS_procedures.pdf) file, extended information in *[URS rules.pdf](https://support.openprovider.eu/hc/article_attachments/205378498/URS_rules.pdf)* and [*URS technical requirements.pdf*](https://support.openprovider.eu/hc/article_attachments/205378508/URS_technical_requirements.pdf). Full information can be found on [ICANN's website](http://newgtlds.icann.org/en/applicants/urs).

A rights holder can file a complaint with one of the URS providers (currently just three: FORUM, ADNDRC and MFSD). This can be done if three pre-conditions are met (all of them, not just a sub-set):

- <span>the registered domain is **identical or confusingly similar** to the trademark</span>
- <span>the registrant has **no legitimate right or interest** to the domain name</span>
- <span>the domain name was registered and is **used in bad faith** (includes 'just for selling to trademark holder', domain hijacking, ...)</span>

### Process

- **<span>Filing, locking and informing</span>**
    - *<span>As an example, two PDF files that introduce a complaint to the registrar are attached to this article.</span>*
    - <span>The procedure starts with filing the complaint at a URS provider</span>
    - <span>A complaint can be filed for multiple domains together; if this number exceeds 15 domains, the respondent needs to pay a fee as well.</span>
    - <span>If the complaint is accepted, the registry is informed and the registry locks the domain ('server' locks). No modifications (including delete and transfer) can be done anymore.</span>
    - <span>As soon as domain is locked, the URS provider informs the registrar by e-mail and the registrant (from whois data) by postal mail, fax and e-mail. The complaint is translated by the URS provider into the registrant's language.</span>
- **<span>Responding</span>**
    - The registrant has 14 days (can be extended to maximum 21 days upon request) to respond electronically, in less than 2.500 words. The response should include:
        - <span>confirmation of registrant data</span>
        - <span>for each of the grounds of the complaint a specific admission or denial</span>
        - <span>any defense which contradicts the complainant's claims (examples of contradicting 'bad faith' are listed in *URS procedures.pdf* in 5.7, 5.8 and 5.9)</span>
        - <span>a statement that the contents are true and accurate</span>
- **<span>Decision</span>**
    - <span>An independent examiner examines the response and decides</span>
        - <span>If the decision is **in favor of the registrant**, the domain is unlocked again and returned to full control of the registrar and registrant</span>
        - <span>If the decision is **in favor of the complainant**, the domain is redirected to an informative page of the URS provider and remains locked by the registry. The original whois data (except for the nameservers) does not change.  
            The registrant has 6 months (can be extended to 12 months) to file an additional response and ask for a new examination.  
            </span>
- **<span>Domain lifecycle</span>**
    - <span>If the decision is in favor of the registrant, the domain is handled like every other domain. If the decision is in favor of the complainant however, the domain remains locked until the end of the registration period, after which the domain is deleted. The complainant can once request a one-year renewal of the domain name, which will be charged by Openprovider to the complainant. After this additional year ends, the domain will be deleted.</span>

As you can read in the above procedure, the domain name is just locked for changes and redirected to a landing page. At the end of its registration period the domain is deleted. The URS procedures do *not* lead to an order to transfer the domain to the complainant. If the complainant wants to get control over the domain name, he should file a regular UDRP complaint.

### <span>Where does Openprovider join the game?</span>

Openprovider is no party in the complaint and response processes. Apart from being informed as stakeholder of the domain name (the registrar), we only can follow up a request from the complainant to renew the domain for one more year.

# Abuse en Openprovider

*Este articulo describe cómo presentar una queja sobre un dominio. Teniendo en cuenta nuestro rol como registrador, nosotros informaremos al revendedor (reseller) pero no podemos juzgar el contenido o transferir el dominio a otro titular o registrador. Para esos casos, por favor lee nuestra [Política de quejas y abuse](https://dev-docs.op-staging.net/books/domains/page/abuse-and-complaints-policy-in-openprovider).*

**<span>Información para el reclamante</span>**

Si quieres informarnos de un caso de abuse puedes contactar con nosotros enviando un email a <abuse@openprovider.com>. Para que podamos actuar con más rapidez necesitamos que nos envíes el dominio fraudulento y una explicación detallada de lo que sucede con el dominio. Algunos ejemplos de abuse pueden ser:

\- Una tienda fraudulenta que vende productos falsos o que no envían los productos comprados.

\- Suplantación de identidad o de datos

\- Contenido prohibido o no permitido

\- Copyright

Es importante que nos envíes una queja clara y que incluyas tus datos de contacto en el email.

Por favor, es muy importante que tengas en cuenta que nosotros somos el registrador del dominio pero no somos los responsables del contenido del dominio ya que ni ofrecemos hosting ni email. Esto quiere decir que nosotros no estamos en posición de juzgar el contenido ni obligados a suspender, eliminar o transferir un dominio.

Por esta razón, nuestro procedimiento normal es informar al revendedor del dominio y reenviarles la queja. Ellos, en comunicación con el titular del dominio, serán los que decidirán investigar, suspender, solucionar el abuse o eliminar el dominio.

Si después de contactar con nosotros ves que el problema sigue allí, lo que deberás hacer solicitar una queja formal a ICANN ([https://www.icann.org/es/compliance/complaint](https://www.icann.org/es/compliance/complaint)) o WIPO ([http://www.wipo.int/portal/en/index.html](http://www.wipo.int/portal/en/index.html)). Solamente con una resolución formal nosotros podremos eliminar o transferir un dominio.

 **<span>Información para el reseller (revendedor)</span>**

Cuando recibimos una queja, la reenviamos al reseller y marcamos el dominio como "abusivo". Este correo electrónico contiene una fecha límite.

Normalmente, el reseller tiene 5 días para resolver el problema y proporcionar una respuesta utilizando el panel de control. Este marco de tiempo puede ser diferente en casos específicos. La respuesta debe indicar claramente cómo se solucionó el problema y cómo se evitará el abuso en el futuro. O bien, si la queja no es válida, debe explicar claramente por qué la queja es incorrecta.

Asegúrese de enviar una respuesta antes de la fecha límite. La falta de respuesta puede provocar la suspensión del dominio: el dominio permanece inactivo. Si se suspende un dominio, el revendedor será informado por otro correo electrónico. En cualquier momento, el revendedor puede eliminar la suspensión del dominio del panel de control.

Openprovider tiene las siguientes opciones:

- Solo notificar: no se programarán acciones de seguimiento. Por ejemplo, una solicitud para eliminar información específica de un sitio web más grande o malware distribuido a través de un subdominio.
- Suspender dominio: cuando la fecha límite pase y no haya respuesta, el dominio se desactivará. El sitio web, el correo electrónico y otros servicios dejarán de funcionar. El reseller puede reactivar fácilmente un dominio proporcionando una respuesta válida a través del panel de control.
- Eliminar dominio: en circunstancias excepcionales, es posible que se nos solicite eliminar un nombre de dominio del registro.

![1531921686760.jpg](https://openprovider.help/uploads/images/gallery/2026-08/embedded-image-zydsftaj.jpeg)

# Reporting abuse

*This article explains how to submit a complaint about a domain name to our team. As the registrar, we will notify the relevant reseller; however, we cannot make judgments about website content, nor can we transfer a domain to another owner or registrar. For such matters, please refer to our formal [Abuse and Complaints Policy](https://dev-docs.op-staging.net/books/domains/page/abuse-and-complaints-policy-in-openprovider).*

*As a large registrar, some domains under our management may be misused for fraudulent web-shops, phishing, copyright infringements, or other forms of abuse. If you encounter such domains, please report them to our abuse department via this website: [https://abuse.registrar.eu](https://abuse.registrar.eu)*

### <span>Common misunderstanding while reporting abuse:</span>

Before submitting an abuse report, please be aware of a very common misunderstanding: Domain registrars like Openprovider manage domain name registrations (for example, yourexample.com or yourownbusiness.nl). We maintain the technical link between a domain name and the services it connects to but we do not host or control the website content displayed under that domain. If you have concerns about a website’s content, please contact the website owner or the hosting provider directly, as they are the ones able to review and remove the material in question.

<span>  
**Contacting the Domain Owner**</span>

<span>  
</span>The domain owner (registrant) can usually be reached in one of the following ways: Through the website itself: You can look for a “Contact,” “About,” or “Legal” page. This is usually the fastest and most direct way to reach the website owner.

*By performing a Whois lookup* : Check for a “Registrant Email” address or a privacy contact form. If privacy protection is active use the contact form included in the Whois results to send a message through the privacy service.

  
Openprovider cannot forward messages or mediate between you and the registrant regarding website content.

<span>  
**Finding the Website’s Hosting Provider**</span>

<span>  
</span>If the issue relates to where the website is hosted, you can often identify the hosting company by checking the domain’s Name Server (NS) records via a Whois lookup.  
Example:  
Name Server: ns1.hostexample.net   
Name Server: ns2.hostexample.net  
The part after “ns1.” or “ns2.” (in this case, hostexample.net) often points to the hosting or DNS provider. In some cases, the domain may use a security or performance network (such as a content delivery network), which does not host the website itself. If so, visit that network’s website to find their abuse reporting page or guidance for identifying the underlying host.

  
At Openprovider, we understand it’s not always easy to determine who is responsible for a website’s content. However, reaching out to the correct party (the registrant or hosting provider) ensures your concern is addressed efficiently and by the people who can act on it.

### <span>Information for the complainant</span>

If you wish to report an abuse case, please contact us by completing the [contact form](https://www.openprovider.com/company/contact-us/report-abuse). To help us act more efficiently, include the fraudulent domain name and a clear explanation of why you believe the domain is being misused.

As the registrar, we may take immediate action in certain cases, such as DNS abuse. In other situations, however, we are required to follow defined processes before taking further steps.

## <span>Examples of abuse that we can address immediately:</span>

### Phishing &amp; Pharming

**Examples:**

- Fake websites imitating legitimate services (e.g., banks) to steal personal information.
- Deceptive emails that appear to come from trusted sources in order to capture login credentials.
- Redirections from legitimate websites to fraudulent ones.

**Required Evidence:**

- Full URLs of the suspected phishing sites or screenshots clearly showing the fraudulent content.
- Copies of phishing emails, including complete email headers (with IP addresses and sender details).

**What Happens Next:**

- If phishing is confirmed, we will take immediate action to suspend the domain.
- If the provided evidence is insufficient, we will escalate the case to the reseller or hosting provider for further investigation.

### Malware &amp; Botnets

**Examples:**

- Websites distributing malicious software (e.g., ransomware, spyware, trojans).
- Domains used to control botnets engaged in illegal activities.

**Required Evidence:**

- Malware scan results, antivirus or security logs, or screenshots showing the malicious behavior.
- URLs associated with malware distribution or botnet command-and-control.

**What Happens Next:**

- If confirmed that the domain is spreading malware, we will take immediate action to suspend it.
- If the evidence points to a compromised subpage or hosting account, we will refer the case to the reseller or hosting provider for remediation.

## <span>Examples of abuse that conditions need to be met for us to act:</span>

### Pharmacy &amp; Drug Complaints

**Examples of Abuse:**

- Websites selling illegal or unlicensed drugs without valid prescriptions.
- Online pharmacies offering controlled substances (e.g., opioids) without proper authorization.

**Required Evidence:**

- Official reports from law enforcement or government agencies.
- Proof that the pharmacy is operating without a valid license.

**Jurisdiction:**

- Action can only be taken if the jurisdiction of the reporter aligns with both the domain holder’s jurisdiction and our company’s jurisdiction.
- If jurisdictions do not align, the case must be referred to the appropriate local authorities or to the reseller/hosting provider for further handling.
- Openprovider has jurisdiction on these locations - Netherlands, Spain, Russia, India, Canada.

**What Happens Next:**

- If all conditions are met and sufficient evidence is provided, the domain will be suspended.
- If the evidence is insufficient or falls outside our jurisdiction, we recommend contacting your local law enforcement or reaching out directly to the hosting provider, who can take the appropriate action on their servers.

### Child Abuse Material (CSAM)

**Examples of Abuse:**

- Websites hosting, distributing, or sharing illegal content involving minors.

**Required Evidence:**

- Verified reports from trusted child protection organizations or law enforcement authorities.

**What Happens Next:**

- Upon receipt of a verified request from law enforcement or a recognized child protection authority, the domain will be suspended immediately.
- If the report does not come from a trusted authority, we will escalate the matter by notifying the appropriate agencies for further investigation.

At Openprovider, we treat all CSAM allegations with the utmost seriousness and are committed to supporting the enforcement of laws designed to protect children online. However, as a registrar, we are neither permitted nor equipped to validate such allegations ourselves, and we cannot require employees to review suspected CSAM material.

We strongly encourage you to act swiftly and report suspected CSAM directly to law enforcement in your country. You can find the appropriate reporting channel via the [official INHOPE website](https://www.inhope.org/EN#hotlineReferral).

### Intellectual Property (Trademark)

**Examples of Abuse:**

- Unauthorized use of trademarks, copyrights, or patents.

**Required Evidence:**

- A valid court order or a complaint from a [trusted authority (e.g., WIPO)](https://www.icann.org/en/contracted-parties/consensus-policies/uniform-domain-name-dispute-resolution-policy/list-of-approved-dispute-resolution-service-providers-25-02-2012-en).
- Proof that the complainant is the legitimate trademark holder or an authorized representative.
- Reference to the applicable law under which the alleged infringement falls.
- Clear URLs and file paths where the infringement occurs.

**Special Note for India:**

- If the domain is registered under Indian jurisdiction, you may also file a complaint under India’s [Intellectual Property Rights (IPR) policy](https://www.ipindia.gov.in/Home/policypages).
- We will act in accordance with legal rulings issued by the relevant Indian authorities.

**What Happens Next:**

- If a court order or ruling is provided, we will suspend the domain.
- If the evidence is insufficient, we will advise you on pursuing official legal channels, such as the Uniform Domain-Name Dispute Resolution Policy (UDRP).

### Other Illegal Activities

**Examples of Abuse:**

- Online activities prohibited by law, such as financial scams, illegal content distribution, cyberstalking, or the sale of contraband.

**Required Evidence:**

- Official requests from law enforcement authorities or valid court orders.

**What Happens Next:**

- As a registrar, we cannot take direct action on these cases unless they involve phishing, malware, or other forms of DNS abuse.
- We strongly recommend reporting such illegal activities directly to law enforcement or contacting the hosting provider, who can act more quickly to remove or block the content.

## <span>Examples of abuse we do not act:</span>

### Spam (Not Phishing or Malware)

**Examples of Abuse:**

- Mass-distributed unsolicited emails, such as irrelevant marketing or promotional offers.

**Required Evidence:**

- Sample spam emails, including complete email headers (with IP addresses and sender details).

**What Happens Next:**

- Domains will **not** be suspended solely for sending general spam, unless the activity is directly linked to phishing, malware, or another form of DNS abuse.
- For regular spam issues, we recommend managing filtering settings through your email provider or contacting the hosting provider for further assistance.

  
If, after contacting us, the issue remains unresolved, you may submit a formal complaint to **ICANN** ([https://www.icann.org/compliance/complaint](https://www.icann.org/compliance/complaint)) or to **WIPO** ([https://www.wipo.int/portal/en/](https://www.wipo.int/portal/en/)).   
Please note that only upon receiving a formal resolution from these authorities are we authorized to delete or transfer a domain.

### <span>Information for the reseller</span>

When we receive a complaint, we immediately forward it to the reseller and mark the domain as **“abusive.”** The reseller will receive an email notification containing details of the complaint along with a response deadline.

**Response Timeline:**

- In most cases, the reseller has **5 days** to address the issue and provide a response via the control panel.
- The abusive domain will be highlighted in the control panel, and accessing its details page will display a pop-up with the full abuse report.
- In specific cases, a different deadline may apply (this will be stated in the email).

**Response Requirements:**

- The response must clearly explain how the abuse was resolved and what measures are in place to prevent recurrence.
- If the complaint is invalid, the response should provide a clear explanation of why the complaint is incorrect.

**Failure to Respond:**

- If no response is submitted by the deadline, the domain may be suspended and rendered inactive.
- If a domain is suspended, the reseller will be notified via email.
- At any time, the reseller can remove the suspension directly through the control panel.

<div class="subtle-wrap" id="bkmrk-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-note"> ![embedded-image-lsyuaz1x.png](https://openprovider.help/uploads/images/gallery/2026-08/embedded-image-lsyuaz1x.png)

Note: From [Domains Overview](https://cp.openprovider.eu/web/action/index#/domain/overview), you can filter abusive domains by selecting the option **Show only 'abusive' domains**.

![embedded-image-h0vvwkzi.png](https://openprovider.help/uploads/images/gallery/2026-08/embedded-image-h0vvwkzi.png)

Depending on the nature and severity of the complaint, Openprovider may take one of the following actions:

- **Only Notify** – We forward the complaint to the reseller without scheduling follow-up action. This is typically applied to requests such as the removal of specific information from a larger website or cases where malware is distributed through a subdomain.
- **Suspend Domain** – If the reseller does not respond by the deadline, the domain will be suspended (inactivated). As a result, the website, email, and any related services will stop functioning. The reseller can lift the suspension at any time by submitting a valid response through the control panel.
- **Delete Domain** – In exceptional cases, we may be required to delete the domain name from the registry entirely. This measure is taken rarely and only when mandated by law, policy, or authoritative rulings.

</div>