Article

The Domain Trust Badge Portal Is Here: Testers Are Welcome! 

Domain name abuse remains one of the Internet’s most persistent challenges, enabling phishing, fraud, scams, malware, and other harmful activity. Addressing it requires more than any one organization can do alone.

GCA’s Domain Trust initiative has been working with registries, registrars, security experts, and other stakeholders to develop the Domain Trust Badge—a measurable, community-driven framework designed to encourage stronger anti-abuse practices across the domain ecosystem. Inspired by lessons from routing security-focused MANRS, the Domain Trust initiative uses shared standards, transparency, and positive incentives to help organizations adopt and demonstrate effective practices.

Now, that work is moving into its next phase: a pilot of the Domain Trust Badge, putting the framework into practice and helping us learn what works before it is introduced more broadly.

Available for guest participants through direct invitation, the Domain Trust Badge Portal is a working pilot of the platform on which the certification scheme will run. Apart from including the agreed components and resources of the certification process, the tool incorporates a series of feedback boxes and sections aimed at turning the pilot experience into a mechanism to detect possible flaws, inconsistencies, and areas for improvement.

This feedback will help us understand the exact incentives for operators to obtain their Domain Trust Badge. From initial conversations, we know some will use it to demonstrate their existing commitment to good anti-abuse practices. Others will use it as a marketing tool to attract new clients. Some others will use it to upgrade or even incorporate their anti-abuse practices. There may also be some incentives we haven’t realized yet, and we look forward to hearing about those, too.

The Portal is open for testing until the end of 2026. After that, GCA will review the feedback and make any necessary changes. If everything goes according to schedule, the final, polished version will be released during the ICANN 88 meeting in March 2027 in Lisbon, Portugal.

What’s in the Portal?

The portal has three essential components: a Self-Assessment Tool, a Resource Pool, and DTm Analytic Tools. Let’s take a closer look.

Self-Assessment Tool

The Self-Assessment Tool is where candidate registries and registrars check their compliance. The process is entirely free and anonymous, both at this testing stage and once the full certification scheme is launched.

No rankings or scores will be public: the candidates will only know their individual result, in the form of a final indicator between 0 and 100, and whether this places them above or below the threshold for obtaining the Badge.

The assessment goes through three blocks of anti-abuse actions (as agreed by the working group that has defined the Badge requirements): one on Policy, one on Coordination, and one on Response. Different types of evidence are required for each block and candidates receive guidance and links to available resources at every stage of the process via the Resource Pool, a component that reflects the spirit behind the Badge Portal.

Resource Pool

The Resource Pool, a section in which candidates find help for almost every action in the certification, is a key component of the Self-Assessment Tool. The Domain Trust Badge was designed as a community effort, and so is the Resource Pool, a space where organizations and initiatives addressing abuse from different angles can offer targeted help to candidates, indexed action by action.

Thus, thanks to the Resource Pool, the Badge Portal goes beyond its value to individual candidates to become a full ecosystem-building tool, a place where abuse can also be dealt with collectively.

DTm: the Measurement Component

At the end of the self-assessment process, candidates will be able to check their Domain Trust measurement score, or DTm score, which combines key abuse indicators: their mitigation rate, their abuse exposure, and their mitigation time. This figure, a single value that cannot be broken down into its individual component indicators, will remain private. Candidates will only know where they stand with respect to the agreed threshold, which will be based on the collective performance of their corresponding category (registrars, gTLDs, and ccTLDs).

The DTm will be calculated externally by a group of participating trusted data sources that will run the calculation on their own data upon request from the candidates, pushing the DTm value to the Portal via an API.

With this approach, these data platforms will retain the integrity of their methodologies and their associated business models and will not reveal any detailed information on any candidate other than their DTm. For their part, candidates will be able to choose their own data sources, based on their individual approaches to abuse.

The DTm itself is part of the pilot period, and we’re looking for data platforms to get involved. The calculation algorithm will be shared with a number of organizations working with large volumes of abuse data, together with the specific parameters and controls for the experiment. After the experiment, we will know whether the DTm calculation shows divergent or homogeneous results across different datasets.

Our intuition is that since we are measuring the long-term attitude of operators toward abuse, rather than specific cases, the results should be similar. If that is not the case, then we may try different approaches. The Domain Trust Action Working Group will decide once the results of the test are available.

Help us Test the Pilot

Currently, more than 13,000 operators are eligible to test the Portal, including more than 11,000 registrars (ICANN accredited and from CENTR’s Registrar Repository), close to 1,500 gTLDs (the list will be updated on ICANN’s upcoming Reveal Day), and more than 200 ccTLDs. 

All of them can request an invitation to test the Self-Assessment Tool by simply reaching out to us. However, it is important to note that because the abuse data currently available for testing through the Domain Trust Platform is limited, not all of them will have enough sample coverage to run the DTm.

At this stage, for practical reasons, the testing period will run mostly with operators, data sources, and resource providers that have already participated in the Badge discussions. About 30–40 organizations belong to this group. They will all receive individual invitations to run the tests.

After the Testing Period

Once the testing period is over, the Portal will be adjusted and then, by the end of the first quarter of 2027, it will be formally launched.

It is still uncertain whether a small group of operators will have been certified by the time of the launch (some have already expressed their interest in being among the first Badge holders) or whether actual certification will begin after the launch.

In any case, and since this is an entirely voluntary process, we hope to have a gradual but steady uptake. 

As registrars and registries begin earning certification, we will activate the second phase of the Badge initiative, focused on the hosting service community, for which we would also like to build a similar scheme, with a set of industry-led initiatives and a measurement framework. Some efforts are already in place and some conversations have begun. However, this work won’t become systematic until the second quarter of 2027.

Sustainability

Running a free certification scheme for such a large industry will require significant resources.

GCA has begun addressing its financial needs by introducing sponsorship opportunities targeted at the Domain Trust Community and the domain industry as a whole. At this early stage, we are glad to confirm that some key industry players have already committed funds and resources to the work. This creates an exciting starting point, but we are fully aware that additional and sustained collaboration and funding will be required.

Get Started

We are convinced that addressing abuse by building industry-led spaces of trust where responsible operators can show their commitment is the way to go.

Whether you are planning to participate in the testing or certification process, have data or resources to share, or would like to support the initiative by contributing to its visibility or sustainability, we welcome your collaboration. Contact us to get started.

Subscribe to our newsletter to keep up with the latest.

SUBSCRIBE

IMPROVE YOUR CYBERSECURITY. USE A TOOL.