Article

Imagining the Domain Trust Badge in Action

The Domain Trust Action Working Group (DTAWG) has been meeting since June 2025. After seven sessions with over thirty registries, registrars, and abuse experts worldwide, the work is becoming real — and so are the challenges. This progress report was prepared ahead of ICANN 86 in Seville.

Picture a small blue-and-teal badge on a registry’s or registrar’s website — “Domain Trust™” — signaling at a glance that this operator takes abuse seriously.

That badge is what the DTAWG, convened by the Global Cyber Alliance (GCA), is trying to build.

After nearly a year of contributions from across the industry, the group is close enough to its goal that it can now ask: what would certification actually feel like?

The Badge in a Nutshell

The Domain Trust Badge rests on three pillars: 

  1. A set of baseline actions that registries and registrars commit to implement;
  2. A measurement framework to assess conformance, and;
  3. A certification scheme to award and maintain the badge.

The group started after ICANN 83 in Prague (June 2025), agreed to a halfway report at ICANN 86 in Seville (June 2026), and is eyeing a launch at ICANN 88 in Lisbon (March 2027).

Around twenty baseline actions have been identified, grouped into three areas of commitment and bound together by a shared measurement framework.

Three Areas of Commitment…

Walk through the application as a registry or registrar and you’d face three areas of scrutiny:

Policy asks whether you have documented, public processes around abuse: a clear definition aligned with existing frameworks (ICANN’s or FIRST’s, for instance), a public commitment to transparency, proactive detection mechanisms, a process for disputed takedowns, and human-rights provisions. Evidence means public links.

Coordination asks whether your anti-abuse work happens in isolation or in concert. You’ll need to show participation in at least one registry-registrar collaboration framework — verified by a counterpart referral — plus involvement in an established anti-abuse initiative, confirmed by its administrators.

Response looks at operational plumbing: timely, effective action against evidenced domain abuse, demonstrated through active participation in at least one accepted information-sharing platform; a dedicated law-enforcement contact; and publicly available mechanisms for criminal abuse cases.

…and a Shared Measurement Framework

Across all three areas, the badge applies a consistent principle: commitment must be evidenced, not asserted.

Policy is evaluated on publicly accessible documentation. Coordination is verified through counterpart referrals and administrator confirmation. Response is assessed through participation records and public-facing mechanisms.

For Response, auditability extends to a quantitative layer. Applicants must score above a baseline on a composite 0–100 metric aggregating mitigation rates, mitigation times, and abuse rates over one year. Individual scores remain private, visible only to the applicant and benchmarked against peers. The baseline is publicly agreed and calculated as a percentage deviation from the average across all badge holders — a dynamic floor that rises as the community improves.

A Candidate Badge: Softening the Cliff

A binary pass/fail certification creates a cliff: you’re in or you’re not, and organizations that fall short have little reason to stay engaged.

A Candidate Badge — currently under discussion — would soften that.

Valid for one year and voluntary, it would give applicants time to build their infrastructure while unlocking a shared resource pool: templates, real examples from badge holders, lists of accepted platforms, and law enforcement connections.

Modest fees on Candidate Badges could also help fund the infrastructure, keeping the main badge free.

Work in Progress: the Challenges Ahead

None of this is settled… yet.

Designing a composite metric that produces comparable results across very different TLDs and operator sizes is genuinely hard, and the group is treating it as such. The framework’s dynamic floor shows the kind of design care that turns a difficult problem into a durable one.

Industry-wide acceptance will need to be earned, but the starting point is stronger than it might appear. An active working group is already in place, and the DTAWG draws confidence from the precedent of MANRS — which followed the same consensus-building process and now counts over 1,300 organizations worldwide working toward better Internet routing security, showing the power of coordinated action.

The immediate priority is broadening the base, particularly among registrars, whose buy-in will be essential at launch. Thirty-plus organizations are already aligned, and the group has the structure to sustain that momentum through to March 2027.

Long-term funding, beyond the current Domain Trust sponsorship opportunities, remains an open question, and a critical one.

Why It Matters

Domain abuse flows disproportionately through registries and registrars that lack either the tools to combat it or the incentive to prioritize it. A credible, independently administered badge creates both: a concrete roadmap and a reputational reward for following it. It also creates a commons — a shared resource pool that lowers the cost of compliance for operators who cannot build everything from scratch.

The Domain Trust Badge is still a work in progress. But after seven meetings and contributions from across the industry, it is coherent enough that the working group can now ask the most important question: what would it actually feel like to apply?

The answer, sketched here, is more compelling than many might have expected.

Reach out or find us at ICANN 86 in Seville, 8–11 June. We’d love to talk — and we might even hand you a temporary badge.

Subscribe to our newsletter to keep up with the latest.

SUBSCRIBE

IMPROVE YOUR CYBERSECURITY. USE A TOOL.