How do you measure the fight against DNS abuse?
.nl scores consistently well in NetBeacon Institute reports
.nl scores consistently well in NetBeacon Institute reports
The Domain Name System (DNS) is vital for trust in the internet’s technical performance. Most people are unaware of the DNS. But, every day, the system processes hundreds of billions of queries, translating domain names that we humans can read and understand into number strings that machines can interpret, known as Internet Protocol (IP) addresses. In the background, the DNS functions like an address book for online applications. And, because it always seems to work, we tend to assume that it always will. However, as online applications become more embedded in everyday life and our reliance on the availability of digital services grows, the DNS is increasingly seen by criminals as a vehicle for malicious activities. Internationally, the system’s use for such activities is known as ‘DNS abuse’. In this blog post, I take a look at how we fight DNS abuse in the .nl zone, and how we measure the effects of our efforts.
For SIDN, the security and reliability of the .nl zone has always been the priority. Fighting the abuse of .nl domain names for malicious purposes is part of that. That’s why, for example, we perform continuous automated scans of the entire .nl zone to seek out malware and phishing. We also verify existing registrant data whenever necessary, and we have both a Notice-and-Take-Down Code and a Dispute Resolution System.
Whenever we detect unlawful use of a .nl domain name, or discover that a registrant isn’t complying with our General Terms and Conditions, we can intervene. For instance, we can disable the .nl domain name involved, so that it no longer points to an IP address. Then, any associated website can’t be accessed using the domain name. However, we intervene only if we’re convinced of abuse – in other words, that someone is using a .nl domain name to do something unlawful. And, if we intervene, the registrant of the .nl domain name in question can always appeal to the independent Complaints and Appeals Board against our decision. The Board‘s ruling on the case is then binding on SIDN.
The DNS contains only domain names and information about them. Computers and other devices use that information to find internet content such as websites. So, when we deactivate a domain name, the content it points to remains online and can still be accessed by other means. Taking down the content itself, so that no one can reach it even without the domain name, requires the cooperation of either the hosting service provider or the content owner. Before we intervene in response to a report – which, it’s worth stressing, we can only do with .nl domain names – we have to be satisfied that the hosting service provider, the website owner, the .nl registrar and potentially the reseller have all been approached about the problem, but haven’t acted. That can happen if, for example, the relevant parties have moved to another jurisdiction and either aren’t responding to the Dutch authorities’ take-down requests concerning unlawful content or aren’t cooperating. That approach, featuring a chain of actors who have to be approached in turn, starting with the content provider and ending with a registry such as SIDN, is widely used throughout the industry, having been developed by means of public-private dialogue.
As well as formulating our own policies and implementing associated procedures, SIDN is involved in various collaborative initiatives. We’re members of the public-private Anti-Abuse Network and the Anti-DDoS Coalition, for example. We also work closely with the Registrars’ Association, the body that represents the registrars that provide .nl domain name registration services. Another important part of our strategy is engaging in dialogue with the regulators and public authorities about the anti-abuse responsibilities of the various parties in the chain, and about what SIDN can do to keep the .nl domain as clean and abuse-free as possible. On the international stage, especially through CENTR, SIDN works closely with other ccTLD registries, sharing information and discussing ways of tackling abuse.
Constructive discussions with other stakeholders about cooperation on the prevention of domain name abuse depend on having a shared vocabulary – in this case, a shared understanding of what constitutes DNS abuse. Within ICANN – the international non-profit organisation that uses a universally accessible, open and transparent multistakeholder approach to set global policy on matters such management of the DNS – the following consensus-based definition has been adopted:
DNS Abuse refers to:
Such activities are considered to threaten the security and stability of, and trust in, the global DNS. It’s worth noting that ICANN doesn’t regard content-related problems as DNS abuse. So, for example, misinformation and disinformation are not DNS abuse, nor are potentially offensive content or content that might be illegal in specific jurisdictions. In contrast to SIDN’s powers for dealing with a .nl domain name that’s associated with unlawful content – under the Notice-and-Take-Down Code referred to above, for example – ICANN has no global jurisdiction over online content.
As outlined above, SIDN does its utmost to keep the .nl zone secure and trustworthy for internet users, and to minimise levels of abuse. However, it’s helpful to know what effect our efforts are having on DSN abuse, as defined by ICANN. So, how can we measure that? And how can we compare our performance with the performance of other top-level domain registries? All in a transparent, technically validated and unbiased way?
One highly respected body that’s active in the international measurement and reporting of DNS abuse is the NetBeacon Institute, founded in 2021 by the non-profit Public Internet Registry (PIR), which runs the .org domain and others. NetBeacon was formed with the aim of contributing to a clear, standardised reporting method for DNS abuse, and to transparent, data-driven techniques for monitoring trends, measuring the impact of abuse mitigation, and using numeric data to identify and advise on possible blind spots.
NetBeacon has 2 main products. One is their NetBeacon Reporter, a centralised tool for reporting DNS abuse and subsequently sending enriched data directly to the responsible registrar or registry in a standardised form. As a NetBeacon partner, SIDN receives and processes NetBeacon abuse reports.
NetBeacon’s second important product is the NetBeacon Measurement & Analytics Platform (MAP). The MAP publishes monthly reports that include detailed tables and analyses of the performance of registrars and registries, so that anyone can see which of them are doing relatively well or badly in terms of the prevalence of phishing and malware in their domains. The scores reflect both the number of websites compromised after registration and the number of malicious registrations. It’s important to distinguish between those two phenomena, because it’s very difficult for a registrar or registry to do anything about a compromised website. Such sites require rectification by the hosting service provider and/or the domain name’s registrant. Technical details and information about the MAP methodology are available to the public.
The NetBeacon MAP also distinguishes between generic top-level domains (gTLDs) and country-code top-level domains (ccTLDs) such as .nl. Generic TLDs operate under contracts with ICANN, which include requirements regarding anti-abuse activities. They’re also bound by consensus policies agreed within ICANN. By contrast, for historical reasons, many ccTLDs don’t have contracts with ICANN and define their own domain management policies. That results in a wide variety of governance models in the ccTLD sector; and equally varied approaches to dealing with abuse.
Published in August 2026, the most recent MAP report contains data from June of this year. The reports appear with a time lag of 2 months, so that NetBeacon has time to assess the effects of abuse mitigation in a zone. SIDN’s efforts to keep malicious activities out of the .nl zone are clearly reflected in the fact that .nl consistently appears in the table listing the larger ccTLDs with the lowest observed rates of abuse. Indeed, .nl is often named as the best-performing country-code domain. That was the case in this year’s July, May, April, March and February reports.
Table 1: Larger ccTLDs: lowest observed abuse rates, June 2026 (Source: Netbeacon).
TLD | Observed Maliciously Registered Domains Per 100,000 DUM | Observed Maliciously Registered Domains | Observed DUM |
|---|---|---|---|
.au | 0.40 | 17 | 4,275,500 |
.it | 0.51 | 21 | 4,085,508 |
.eu | 0.54 | 20 | 3,683,558 |
.be | 0.68 | 11 | 1,629,308 |
.uk | 0.79 | 79 | 10,050,339 |
.ru | 0.79 | 47 | 5,976,454 |
.de | 0.98 | 173 | 17,718,800 |
.fr | 1.01 | 45 | 4,440,395 |
.pl | 1.16 | 30 | 2,585,966 |
.nl | 1.24 | 75 | 6,046,193 |
Of course, the reports and the underlying data do require a little qualification. It’s good to look at everything with a critical eye and to discuss the findings. It’s also important that a reporting body such as NetBeacon is transparent about (the potential limitations of) its definitions and methodologies, and how they might influence the (presentation of) results and the conclusions that can and cannot be drawn. NetBeacon recognises those issues and maintains a critical outlook. The reporting system remains a work in progress, as do the fight against DNS abuse itself and SIDN’s contribution to it.