Nicholas Nugent[1]*

It is increasingly becoming the practice of domain name system (DNS) intermediaries to seize domain names used by lawful websites for violating acceptable use policies related to offensive content or hate speech. Website hosting companies and social media platforms, entities that use but do not operate core Internet infrastructure, have long reserved and exercised their rights to gate their offerings, leaving booted speakers free to migrate to other providers. But registrants deprived of their domain names lack similar options to maintain their presence in cyberspace. The loss of a domain name inexorably results in the takedown of any website that uses the domain name, even if hosted elsewhere, and leaves a potentially invaluable asset essentially free for the taking by another. Proponents of Internet freedom have therefore argued that companies that operate foundational Internet infrastructure, such as the DNS, should play no role in policing content, no matter how deplorable, and that DNS censorship, once normalized, could easily spread to other minority groups and viewpoints.

Acknowledging that DNS intermediaries—the companies that offer domain names and make them operational on the Internet—are private actors whose actions are not subject to First Amendment constraints, critics of DNS censorship seem to tacitly concede that DNS intermediaries may take whatever actions are permitted under their terms of service, appealing instead to policy arguments or calls to enact new protective legislation. But I argue that registrants already possess the legal means to protect themselves from domain name seizure through the property rights they acquire in their domain names.

Although the property status of domain names is by now fairly well established in the case law, scant attention has been paid to the precise nature of registrants’ interests in that property. Making the case that registrants take title to their domain names upon registration, I argue that registrants may state valid claims under conversion and trespass to chattels when DNS intermediaries attempt to seize lawfully registered and operated domain names in the absence of court orders, despite the contractual rights such intermediaries purport to reserve to themselves. I further explore how federal law could supplement these existing common law protections by enshrining domain names as a new class of intellectual property.


In August 2017, GoDaddy, the world’s largest domain name registrar and website hosting provider, served notice to DAILYSTORMER.COM that the website had twenty-four hours to move its domain name to another registrar before the domain would be canceled.[2] Daily Stormer, GoDaddy alleged, had violated the latter’s terms of service by hosting website content mocking the death of Heather Heyer, a woman killed in the course of protesting a white nationalist rally.[3] Within hours of moving to Google’s domain management service, Google followed suit by first suspending[4] and then canceling Daily Stormer’s domain name.[5]

In October 2018, GoDaddy issued a similar eviction notice to GAB.COM, the so-called “free speech Twitter,”[6] for hate speech posted by users on the website.[7] When Gab proved unable to transfer its domain name to another registrar within twenty-four hours, GoDaddy suspended the domain, effectively taking the website down until another registrar was found.[8] One month later, DoMEn d.o.o., the company responsible for managing the .ME top-level domain, suspended INCELS.ME, a domain name used by a forum for “involuntary celibates,” after the website failed to remove user content that promoted violence.[9] The domain name remained offline for more than a year thereafter.[10]

These actions were consistent with a broader trend in which domain name system (DNS) intermediaries, such as registrars and registry operators, have begun to take a more active role in policing website content through their control over Internet domain names.[11] This trend began with efforts by DNS intermediaries to combat online piracy and quickly expanded to other categories of illegal conduct, such as child pornography and “rogue” online pharmacies.[12] However, the new form of content regulation that brought down DAILYSTORMER.COM, GAB.COM, and INCELS.ME differed from previous campaigns by DNS intermediaries in one important respect: it concerned legal content. In all three cases, the basis for suspension was community speech found on the registrants’ websites that, although certainly offensive, was fully protected under the First Amendment.

While some groups have cheered these developments and urged DNS intermediaries to play a stronger role in combating hate speech,[13] advocates of online freedom have argued that, unlike Internet service providers or social media networks, DNS intermediaries do not host or transmit any content and therefore should play no role in policing speech that is external to their systems.[14] The latter fear that allowing private domain name companies to effectively boot entities from the Internet based on the expressive content of websites risks creating tools of censorship that could be leveraged in the future to suppress other viewpoints or causes.[15] Commentators have also noted with alarm the lack of due process protections that often accompany domain name takedowns, whether for legal or illegal conduct.[16]

But even assuming we want domain name companies to operate the DNS in a content-neutral manner—a goal I assume in this article—it might seem that little can be done to ensure that outcome. DNS intermediaries are private actors, and the Supreme Court has long held that the First Amendment does not protect speech from censorship by private actors, with limited exceptions that have not been extended to cyberspace.[17] And although the United States used to exercise oversight over the Internet Corporation for Assigned Names and Numbers (ICANN)—the non-profit corporation that sets policy for the DNS—that power was relinquished in 2016 when the United States permitted ICANN to transition to a global multi-stakeholder governance model.[18] DNS intermediaries thus have wide latitude, it would seem, to impose content-based restrictions on domain name registrants through their terms of service and to enforce those terms through the self-help remedies of domain name suspension, cancellation, and transfer.

In this article, I argue that one potential bulwark against content regulation by DNS intermediaries—one that has been largely overlooked—is registrants’ property rights in their domain names. Although once the subject of debate between different lines of cases, both federal and state courts in the United States have largely settled on the proposition that domain names are a form of personal property and that a registrant may state a claim for conversion against an entity that unlawfully interferes with that property.[19] Thus far, such conversion claims have been brought almost exclusively in situations where one registrant manages to appropriate another registrant’s valuable domain name in order to commercialize the name for its own purposes.[20] In other words, the goals of both plaintiff and defendant have been the same: to use the domain name for a website. However, if we take the property nature of domain names seriously, we see that similar conversion claims could be made by domain name owners against DNS intermediaries who suspend, cancel, or transfer domain names in the absence of court orders or similar legal processes. Consulting the closest available analogs in disparate areas of law such as repossession, bailment, and liquidated damages, I argue that such property rights may even suffice to override explicit contractual terms granting DNS intermediaries the right to seize domain names for breach of contract.

This article proceeds as follows. Part I presents a technical overview of the DNS with a particular view to separating core DNS services from non-core and value-added services that intermediaries might provide. Part II analyzes various provisions in DNS intermediary service contracts that purport to empower DNS intermediaries to regulate content. It also describes ways, both systematic and ad hoc, in which DNS intermediaries have exercised that power. Part III traces the historical debate as to whether domain names should be classified as property versus mere contractual rights. It explains how the property view of domain names has become the consensus position and shows why this view is correct. It further analyzes the previously ignored issue of which party holds title to a registered domain name and concludes that only the registrant could legitimately be regarded as the owner. Finally, Part IV argues that a robust doctrine of domain names as property can be used to cabin intermediaries’ private regulatory power. It explains how common law claims of conversion or trespass to chattels could be brought against DNS intermediaries who interfere with domain names in response to legal, or perhaps even illegal, web activity. But it notes the legal and practical limitations of such common law remedies and, therefore, explores additional potential options for strengthening property rights, such as through federal legislation that would recognize domain names as a new and distinct class of intellectual property.

Technical Overview of the DNS

Although many primers already exist that describe the structure and operation of the DNS, the arguments presented in this article turn on specific technical and historical nuances that are either absent from introductory descriptions or otherwise buried within advanced texts on the subject. Hence, in this Part, I aim to survey the DNS in a way that covers some of the more specialized details omitted by other summaries while remaining accessible to a generalist audience. Section A explains how users and computers use domain names in real time to locate content on the Internet. Section B describes the roles played by various intermediaries in that process.

IP Addresses and Domain Names

At the heart of nearly all modern Internet communication lies the mighty Internet Protocol (IP) address, a unique, 32-bit identifier represented as a string of up to twelve digits—for example,—that indicates the logical location of a device on the public Internet.[21] For a first computer (a client) to communicate with a second computer (a host), the client must append the host’s IP address to any message it sends, and the host, in turn, must append the IP address of the client in any response. But twelve-digit strings are difficult for users to remember, and so the domain name system (DNS) was devised to make it easier for users to access resources on the Internet without having to remember IP addresses.[22]

Fundamentally, the concept behind the DNS is quite simple: create a list (a registry) that maps alphanumeric hostnames to IP addresses—e.g., “UCLA_server:”—then, when a user wishes to access an Internet resource, such as a website, she need only enter the hostname into her browser. The registry is consulted to find the IP address of the host (here, a web server), and then the user’s computer uses the IP address to request the resource (here, a web page) from the host. As a result, the user no longer needs to know the IP address of any website to access it. She need only know the hostname, and the DNS and her computer will take care of the rest.

Building upon this basic concept, the architects of the early Internet designed the DNS with several important enhancements including top-level domains, authoritative registries, and caching. Starting with top-level domains, as the number of servers connected to a network increased, so did the risk of naming collisions, wherein two different entities seek to use the same hostname.[23] One solution to this problem was to create separate zones, also known as “domains,” for hostnames based on the type or purpose of the host. Accordingly, in 1984, the Internet Engineering Task Force (IETF) published RFC 920, which proposed the creation of six “top-level domains” (TLDs), including COM (commercial), EDU (education), GOV (government), and ORG (a catch-all for other organizations).[24] The result was the modern “domain name” syntax that remains in use today, in which a top-level domain (e.g., COM) follows a second-level domain (e.g., MICROSOFT) with the two strings separated by a dot—hence, MICROSOFT.COM. This design permits two different entities to use the same hostname in different domains—e.g., FMC.COM (Ford Motor Company) vs. FMC.EDU (Fine Mortuary College)—without any conflict.

Next, for a name-to-address mapping to be effective, it must be globally consistent. It will not do for some clients to map FACEBOOK.COM to one set of IP addresses while other clients map it to a different set. Moreover, if Facebook elected to change an IP address, some mechanism must exist to inform any clients using the old IP address to switch over to the new address. Hence, at the core of the modern DNS is the concept of authoritative registries. For each top-level domain, a single entity known as a “registry operator” maintains an authoritative zone file that contains information for all domain names registered within the top-level domain.[25] For example, Verisign, Inc., which operates the .COM top-level domain, maintains the authoritative zone file for all .COM domain names.[26] Any computer may therefore determine the IP address for any .COM domain name by sending a DNS query to Verisign’s nameservers.

But because it would strain a registry operator’s servers to respond to a DNS query every time a computer uses a domain name, the DNS makes extensive use of caching. When a nameserver responds to a DNS query with authoritative IP address information about a domain name, its response also includes a “time-to-live” (TTL) value, which can range from seconds to days, indicating how long the information should be regarded as valid. Any computers receiving the response are expected to store (cache) the information in memory and use it for all future communications involving the domain name, rather than querying the registry operator each time, until the TTL expires, at which time the DNS information is deleted from cache.”

The following diagram illustrates these concepts in the context of an actual DNS query.[27] Although all steps depicted in Fig. 1 are relevant to how domain names are used to access web content, the reader is directed to pay close attention to the description of Steps 4–5 and 9–10 which will prove central to certain arguments against DNS censorship.

Figure 1

The process begins when a client needs to communicate with a host but has only the host’s domain name. Although the client and host may be any two computers on the Internet and the communication may occur in the context of any type of Internet activity, whether or not involving a human participant, for purposes of this illustration, I use the familiar scenario in which an end user attempts to visit a website by typing a domain name—here, EXAMPLE.COM—into his browser. The end user’s computer first consults its local cache. Has the user visited EXAMPLE.COM recently such that its IP address is already stored locally on the computer? If not, the computer sends a DNS query to a DNS Resolver (Step 1), which is typically provided by the user’s Internet service provider but may be operated by any service provider or by the user himself.

The DNS resolver then consults its own cache. Has the DNS resolver received a DNS query for EXAMPLE.COM from another user or computer recently such that its IP address is already cached in memory? To illustrate the entire end-to-end flow, we will assume that the cache in the DNS Resolver is empty[28] and that the full DNS resolution process must play out. Without any information about the requested name, the DNS Resolver looks first to the most basic component of the domain name: its top-level domain (here, .COM). To find a server that can provide authoritative information about .COM names, the DNS Resolver sends its own query to a root nameserver which is operated by an entity called a root server operator (Step 2). The root server operator maintains an authoritative “root zone file” that contains the name and IP address of the registry operator for each top-level domain.[29] The root nameserver responds to the query by sending back the IP address for the .COM nameserver (Step 3).

Using the IP address returned by the root nameserver, the DNS resolver sends a DNS query for EXAMPLE.COM to the .COM nameserver (Step 4), which is operated by the .COM registry operator. Just as a root server operator maintains an authoritative root zone file containing information about all top-level domains in the root (i.e., the Internet), the registry operator for a given top-level domain maintains an authoritative zone file containing information about all second-level domains (i.e., the “EXAMPLE” in EXAMPLE.COM) in the top-level domain. Accordingly, in response to the query from the DNS resolver, the .COM nameserver checks the .COM zone file to see if a record exists for EXAMPLE.COM. If so, it responds with the information in that domain name record.

In theory, the DNS could have been designed so that the zone file for a top-level domain stores the actual IP address for each domain name in the top-level domain. For example, if the website associated with EXAMPLE.COM is hosted at, the .COM nameserver could just respond to DNS queries for EXAMPLE.COM by returning that IP address. In practice, however, rather than storing the actual IP address of the domain name host, the zone file stores the IP address of a separate computer called an authoritative nameserver. An authoritative nameserver is a server that is ultimately responsible for providing the IP address associated with a domain name. The domain name owner can choose any available service provider to operate an authoritative nameserver for his domain name or could even operate the nameserver himself.[30]

Thus, in this example, the .COM registry operator responds to the query by returning the IP address of the authoritative nameserver for EXAMPLE.COM (Step 5). Next, using the IP address returned by the .COM registry operator, the DNS resolver sends a DNS query to the authoritative nameserver for EXAMPLE.COM (Step 6). At long last, the authoritative nameserver responds with the actual IP address at which the domain name is hosted (Step 7). At this point, the website address is known. The DNS query, and the domain name associated with it, can be said to have “resolved.” The DNS resolver updates its cache and returns the IP address to the user’s computer (Step 8).[31] Finally, the user’s computer sends a request[32] for a web page to the web server hosted at the IP address associated with the domain name (Step 9), and the web server responds by sending the content contained in the requested web page (Step 10). The user has, thus, successfully accessed a website despite knowing only its domain name mnemonic.

Two important observations can be gleaned from this architecture. First, the process is inherently authoritative and centralized.[33] A single, authoritative zone file exists for each top-level domain, and a single entity—the registry operator—maintains that zone file and responds to queries for information about any domain names within the top-level domain (Steps 4 and 5). If the registry operator fails to resolve queries for a given domain name for any reason, Internet traffic that relies on the domain name will function only for as long as the IP address of the domain name host remains in cache somewhere in the DNS query chain (typically, less than 24 hours).[34] Thereafter, any network communications that rely on the domain name will fail. If the domain name is associated with a website, the website will be effectively inaccessible. Although the website will continue to be reachable through its IP address, users who do not know that IP address (the vast majority of users) will not be able to access the website.[35] As explained infra,[36] it is this central control over the DNS resolution process that provides registry operators with unique control over the accessibility of website content and thus makes DNS censorship possible.

Second, no content ever flows through the DNS itself, whether website, email, video, chat, or other content.[37] The DNS exists only to answer a simple question—what IP address is associated with a given domain name? Once the requesting computer receives the answer to that question, it communicates directly with the host (using the IP address) through an Internet service provider and not through any DNS servers. The servers involved in resolving a DNS query (Steps 1-8) have no visibility into what the requesting computer does with the returned IP address (Steps 9 and 10)—much less the content provided by the host located at the address. In this manner, the DNS has been analogized to a phonebook.[38] It is used to look up numbers associated with the names of persons or organizations but plays no role in the activities performed by those listed persons or organizations. As further described infra,[39] the fact that web content is wholly external to the DNS provides one of the strongest policy arguments against DNS censorship.

DNS Intermediaries

Entities that necessarily participate in the operation or management of the DNS (for purposes of this article, “DNS intermediaries”) generally fall into one or more of the following categories: Internet Assigned Numbers Authority (IANA), root server operators, registry operators, and registrars. The following diagram depicts the relationship between the various DNS intermediaries.

Figure 2

As depicted, each top-level domain is managed by a single registry operator, be it a for-profit or non-profit corporation, a state-controlled entity, or a government agency.[40] Although only five top-level domains are depicted in Fig. 2, and only seven top-level domains existed when the DNS was first implemented in 1985, website operators may now choose from among 1,587 top-level domains when registering a domain name.[41] The vast majority of top-level domains (1,242 as of this article) are classified as generic top-level domains (gTLDs)[42] meaning that any person or entity may theoretically register a domain name within the TLD for any purpose. Examples of gTLDs include the .COM, .ORG, and .NET legacy TLDs as well as newer strings, such as .BOOK, .FUN, and .XYZ. Set against these permissive gTLDs are generic-restricted and certain sponsored top-level domains which limit registration to certain classes of organizations or individuals.[43] Examples include .BIZ (reserved for business entities), .EDU (accredited post-secondary institutions), .JOBS (human resources managers), and .XXX (adult entertainment). In some cases, a registry operator may limit registration within a branded top-level domain (e.g., .BMW) to itself and its affiliates—a “closed TLD.”[44]

The remaining top-level domains[45] (315 as of this article) are classified as country code top-level domains (ccTLDs), predominantly two-character strings that map to a distinct country, sovereign state, or dependent territory.[46] Examples include .US (United States), .CN (China), and .NP (Nepal).[47] Country code top-level domains are typically delegated to the government of the country or territory to which they refer or to a private entity within the country or territory,[48] although technical operations may be outsourced to another entity, whether domestic or foreign.[49]

Country code top-level domain managers may set their own policies concerning who may register domain names within their top-level domains.[50] In some cases, a country will impose strict registration criteria (e.g., .JP domain names are limited to individuals and corporations located in Japan).[51] In other cases, a country will allow any organization or individual to register within its ccTLD, resulting in an additional class of de facto generic top-level domains that may be popular because of their similarity to English words or acronyms—e.g., .ME (Montenegro), .TV (Tuvalu)—or because they can be used as “domain hacks” to spell other words—e.g., INSTAGR.AM (Armenia), YOUTU.BE (Belgium).[52]

Although an entity may manage more than one top-level domain, each top-level domain is delegated to only a single registry operator.[53] As described supra, by vesting a single entity with the responsibility of maintaining the authoritative zone file for a top-level domain, the risk of naming collisions is effectively eliminated.[54] The registry operator not only maintains the zone file for its top-level domain but also operates the nameserver for the top-level domain, responding to DNS queries for domain names registered therein (Steps 4 and 5 in Fig. 1).

In addition to the zone file, the registry operator maintains an authoritative registry database for the top-level domain. The registry database lists authoritative information about each domain name that has been registered within the top-level domain including, typically, the name and contact information of the person or business who registered the domain name, the registration creation and expiration date, and the domain status.[55] Whereas the zone file maintained by the registry operator functions like a phonebook, listing addresses associated with names. The registry database can best be analogized to a land registry maintained by a county title office or similar administrator. Because only one entity can be listed as the holder of a domain name, the registry database, which is publicly accessible through a WHOIS service, operated by registrars and registry operators, serves to put the world on notice of which parties claim exclusive rights to which domain names.[56] Registering a domain name, therefore, is fundamentally a matter of recording a person’s or organization’s interest in the domain name within the authoritative registry database for the associated top-level domain. As we’ll see,[57] the distinction between recordation in the authoritative registry database and the answering of DNS queries from the zone file will prove important when it comes to separating the property status of domain names from certain domain-related services provided by DNS intermediaries.

Although registry operators maintain the authoritative registry databases for the top-level domains they manage, they typically do not offer domain name registration services directly to the public, at least for generic top-level domains.[58] Instead, when a person wishes to register a domain name, he engages the services of a domain name registrar, in most cases, through the registrar’s self-service online registration system. For example, and as depicted in Fig. 2, a customer who wishes to register the domain name EXAMPLE.INFO might visit the website of a registrar, such as Network Solutions, Inc. The registrar then queries the authoritative registry database maintained by the registry operator responsible for the .INFO top-level domain (currently, Afilias Ltd.) to determine whether the domain name is available. If so, the customer pays the registrar-prescribed fee (the “registration fee”),[59] the registrar transmits the customer’s information to the registry operator, and the registry operator creates a record in the registry database associating the domain name with the customer information so provided. At this point, the customer becomes the sole holder of the domain name and is deemed the “registrant.” In addition, if the registrant wishes to make the domain name operational, he provides the registrar with the name and address of authoritative nameservers for his domain name, which the registrar forwards to the registry operator and the registry operator records in the zone file.

Registrars typically contract with multiple registry operators in order to be able to offer domain names across multiple top-level domains. Registry operators are likewise required to allow any accredited registrar to sell domain names within their top-level domains.[60] As a result, a customer who desires to register a domain name may choose from among thousands of different registrars.[61] Moreover, after registering a domain name through one registrar, a registrant may later transfer his registration to another registrar.[62]

Domain names may be registered in one-year increments, up to a maximum registration term of ten years.[63] At any time during the registration term, a registrant may renew his registration by paying the prescribed renewal fee for a renewal term of one to ten years, provided that the total remaining registration term does not exceed ten years. In this manner, a registrant can maintain exclusive rights to his domain name indefinitely as long as he continues to renew the domain and pay the required renewal fees before his current registration term expires. If a registrant fails to renew his domain name before the registration term expires, a series of grace periods apply during which he may still renew the name subject to additional fees.[64] Once all grace periods have been exhausted, the registration is deleted, the domain name reverts to unregistered status, and any customer may register the name on a first-come basis.[65]

Importantly, upon expiration, control of the domain name reverts back to the registry operator and not to the registrar whom the registrant used to register the name.[66] Accordingly, just as when the domain name was originally registered, a new registrant may register it through any accredited registrar.[67] The original registrar can lay no greater claim to the domain name than any other registrar. If the registrar wishes to possess the now-expired domain name for its own purposes, it must register the domain name just like any other customer. And, despite knowing when an un-renewed domain name will expire, even the original registrar may not be the favorite to win the registration race. “Drop-catchers,” a special class of professional domain name investors (“domainers”), employ sophisticated, automated systems to monitor high-value domain names that are scheduled for expiration and attempt to register them before any other entity.[68] As a result, valuable domain names are often snatched up by drop-catchers within seconds of their expiration.[69] As will be shown,[70] limited registration periods and control over expired domain names will prove relevant to the issue of which party may claim title to registered domain names.

Atop this organizational scheme sits the IANA. By itself, IANA is not an entity but a function (or set of functions), and the entity who performs the IANA function is responsible for coordinating the delegation of top-level domains and the allocation of IP addresses.[71] Since 2000, ICANN, a non-profit corporation headquartered in California, has performed the IANA function.[72] But prior to 2000, the function was performed by universities and, in its earliest incarnation, by a single individual, John Postel.[73] In performing the IANA function, ICANN is responsible for delegating each top-level domain to a registry operator, which it does pursuant to registry agreements typically lasting ten years.[74] Absent breach, a registry agreement may automatically renew for an additional ten-year period.[75] However, such a presumptive right to renewal was not always guaranteed to registry operators. Early registry agreements, such as ICANN’s delegation of .COM to VeriSign and .ORG to Network Solutions, provided no presumptive right to renewal. And ICANN was free to re-delegate such top-level domains to other parties upon expiration of the registry agreements.[76]

In addition to setting policy for the DNS through a global stakeholder process, the IANA function vests ICANN with responsibility for allocating IP address blocks to network operators around the world.[77] ICANN also oversees the Root Server System, a set of thirteen different root zone servers (lettered ‘a’ through ‘m’), each of which hosts a copy of the root zone file and responds to DNS queries for the IP addresses of top-level domain nameservers (Steps 2 and 3 of Fig. 1).[78]

Notably, among these four categories of DNS intermediaries, only registry operators and root server operators necessarily participate in the resolution of domain names. As depicted in Fig. 1, when a query is made to resolve a domain name, in the absence of any temporarily cached information, the query is ultimately routed to a root server operator, then to the registry operator, and then to an authoritative nameserver for the domain name. Because it is impossible, under the current configuration of the DNS, for an un-cached DNS query to resolve if these functions are not performed, I refer to them as “core DNS services.”

By contrast, at no point is it necessary for the registrar or ICANN to participate in the resolution of any domain name. Instead, the registrar’s role is largely limited to registering and renewing domain names on the registrant’s behalf, sending reminders when the domain name is approaching expiration (if applicable), and allowing the registrant to update aspects of the registration, such as contact information, nameserver delegation, and security parameters.[79] Registrars perform most or all of these functions through the registry operator’s automated system.[80] In any event, none of these functions must be performed on a continual, real-time basis for a domain name to remain operational. Because registrars play no part in resolving DNS queries for domain names, I refer to the administrative services they provide as “non-core DNS services.”

To be sure, registrars frequently offer value-added services when customers register domain names, such as website hosting, email, or WHOIS privacy.[81] Indeed, such value-added services may provide the bulk of a registrar’s net income, given the low profit margins involved in simply marking up domain name registration and renewal fees. And frequently, one such value-added service that a registrar offers when a customer registers a domain name is to allow the registrant to use the registrar’s authoritative nameservers to resolve DNS queries for the domain name (Steps 6 and 7 in Fig. 1).[82] While authoritative name resolution is a core DNS service, a registrant is free to choose any available provider to operate authoritative nameservers for his domain and may even perform the function himself. Thus, after registering a domain name, the services of the sponsoring registrar are not strictly necessary for the name to remain operational.

Likewise, as the performer of the IANA function, ICANN’s role is to set technical policy for the DNS, not to operate it.[83] Although ICANN delegates responsibility for managing top-level domains to registry operators, ICANN itself neither manages any top-level domain nor operates any top-level domain nameserver. And although ICANN operates one of the thirteen root zone servers, it does so only as one of thirteen mirrors and, thus, is not essential to the resolution of any DNS query. This distinction between core and non-core DNS services will become important when it comes to analyzing whether a given DNS intermediary should be able to suspend, cancel, or transfer a domain name in the course of terminating its relationship with a registrant.

DNS Intermediary Power over Content

DNS intermediaries lack direct control over Internet content. At any time, a user may visit a website by simply typing the IP address of a provider’s web server into her browser and downloading the content provided by that server (Steps 9 and 10 of Fig. 1). These steps are wholly external to the DNS, and so registrars, registry operators, and even ICANN are powerless to interfere. But because IP addresses are not only difficult to remember but also constantly changing, DNS intermediaries can exert de facto control over website content through their control over the registration and resolution of domain names. In this part, I trace the history of that control, as intermediaries first tailored their agreements to prevent the DNS from becoming a tool of trademark infringement, then to disrupt criminality, and finally to police offensive, but legal, content.

  1. Cybersquatting and Restrictions Against Illegal Content

In the early days of the DNS, domain names came with few, if any, strings attached. Even as late as 1994, one could register a domain name by simply emailing a request to Network Solutions, a private corporation under contract with the National Science Foundation (NSF) to manage several legacy top-level domains, including .COM and .ORG.[84] No registration fee was required and no contract governed the registration.[85] By the end of 1995, however, Network Solutions was receiving more than 20,000 registration requests per month—taxing its limited, NSF-funded resources and resulting in a five-week delay to register any name.[86] As a result, on September 14, 1995, the NSF authorized Network Solutions to begin charging a $50 fee to register new domain names and to retain such registration fees to offset operational costs.[87] Formal terms and conditions soon followed in the form of registration agreements that customers were required to accept in order to register domain names.

Early registration agreements were relatively simple, requiring the registrant to do little more than pay the required registration fee, provide accurate contact information, and submit to the registrar’s dispute resolution policy.[88] Dispute policies empowered registrars to resolve disputes between registrants and trademark holders over registered domain names[89] and reflected the fact that trademark infringement was the predominant legal concern in the DNS at the time. That concern stemmed from the fact that initially, nothing stopped an individual from registering almost any available string as a domain name, even if the string consisted of a trademarked word or phrase in which the registrant possessed no rights. Coupled with the absence of registration fees before 1995, this lax registration environment gave rise to the practice of deliberately registering a company’s name or trademark in hopes of selling the domain name at a high price once the less tech-savvy company belatedly realized the importance of establishing a presence in cyberspace. Famous early examples include disputes over, MTV.COM, and[90]

This problem, colloquially termed “cybersquatting,” was originally left to registrars to resolve under the terms of their registration agreements. But by 1999, after significant pressure from trademark owners, Congress enacted the Anticybersquatting Consumer Protection Act (ACPA) to provide a uniform federal framework for resolving cybersquatting disputes.[91] Under the ACPA, a person may be liable in a federal civil action by a trademark owner if that person registers, traffics in, or uses a domain name that is identical or confusingly similar to the trademark with bad faith intent to profit from the trademark.[92] If a court finds for the trademark owner in an ACPA action, the court may order the forfeiture or cancellation of the domain name or transfer the domain name to the trademark owner.[93] Moreover, to deal with the problem of cybersquatters located abroad, the ACPA provides for in rem jurisdiction over the disputed domain name by deeming its situs to be in the judicial district in which the domain name registrar, registry operator, or other relevant DNS intermediary is located.[94]

Likewise, shortly after ICANN assumed the mantle of the IANA, ICANN followed suit with its own procedure for dealing with trademark disputes—the Uniform Domain Name Dispute Resolution Policy (UDRP).[95] Like the ACPA, the UDRP provides a mechanism for trademark holders to challenge the bad faith registration and use of domain names that implicate registered trademarks.[96] Unlike the ACPA, however, which requires the trademark holder to file suit in federal court, the UDRP establishes a lightweight, alternative dispute resolution framework that provides for fast and inexpensive adjudication of cybersquatting claims. Complainants may select from ICANN-accredited arbitrators, such as the World Intellectual Property Organization (WIPO), the National Arbitration Forum (NAF), or, previously, certain for-profit companies.[97] If a complainant prevails, the only available remedies are cancelation or transfer of the subject domain name.[98] However, a losing registrant may stay either remedy by challenging the decision in a court of competent jurisdiction within ten days of the ruling.[99]

Although both the ACPA and the UDRP provide a forum for IP infringement claims to be made against domain name registrants, such infringement claims are limited to trademark disputes. Moreover, a trademark claim against a domain name registrant can be stated under the ACPA or UDRP only to the extent it alleges that the domain name itself infringes the complainant’s trademark.[100] Neither framework provides a cause of action against a registrant based on the content of any website associated with the domain. Thus, actions may not be brought under the ACPA or the UDRP against the operator of a website selling counterfeit merchandise, such as fake Gucci bags or Rolex watches, if the trademark owners’ claims go to the content or operation of the website rather than the domain name used to host the website. Likewise, movie and music rights holders could not look to the ACPA or UDRP to take down a domain name associated with a website hosting pirated movies and music if the dispute concerns only copyright infringement.

Over time, registrars added restrictions to their agreements concerning how registrants may use domain names in the form of “acceptable use policies” that went beyond cybersquatting. Registrars introduced prohibitions on malicious cyber activity (spamming, phishing, and distributing malware),[101] IP piracy (copyrighted movie, music, and software sharing),[102] and other types of illegal activity (child pornography, online gambling, and money laundering).[103] While registrars might be commended for seeking to curb illegal activity, such restrictions marked a fundamental expansion of registrar authority into new territory: content regulation. In most, if not all, cases where a registrant might run afoul of an acceptable use policy, the source of the violation is content or activity occurring on a website, rather than within the domain name pointing to the website. And unless the registrant is using the registrar as a web host, such content will not be hosted or transmitted by the registrar since, as explained supra, no website content ever flows through the DNS.[104]

The separate nature of DNS services and website hosting have led some commentators and public interest groups to question whether registration agreements should include acceptable use policies.[105] They argue that such policies, while well-intentioned, go beyond the legitimate scope of concern or authority of DNS intermediaries.[106] Moreover, as private actors, registrars are not well-positioned to determine the legality of registrants’ behavior.[107] And to the extent they solicit help from industry players, such as the RIAA or MPAA, as “trusted notifiers” to advise on legality, such industry players may have strong incentives to take positions that benefit their financial interests.[108]

Consequences for breaching an acceptable use policy are often steep. Registrars reserve broad rights to take down domain names associated with illegal activity by suspending, canceling, or transferring the domain.[109] Suspending a domain name involves instructing the registry operator to temporarily cease resolving DNS queries for the domain name (Step 7 in Fig. 1), effectively taking down the site.[110] Canceling a registration entails instructing the registry operator to remove the registrant’s information from the authoritative registry database, which would allow any other entity to register the domain name on a first-come basis.[111] Alternatively, a registrar may transfer the domain name directly to another registrant, as is often done in the case of a successful ACPA or UDRP action.[112]

In fact, registrars often reserve the right to terminate a registration agreement, and any domain name registrations along with it, for any breach of the agreement, no matter how minor.[113] Thus, registrars can cancel, and previously have canceled, domain name registrations for breaches as immaterial as failing to keep one’s contact information up to date.[114] To be sure, market forces prevent registrars from operating with too heavy a hand in the case of otherwise harmless websites. Registrars who earn a reputation for canceling registrations of legitimate websites may soon find themselves with few remaining customers, given the ease of transferring domain names to other registrars. But other market forces may compel registrars to opportunistically seize upon any contractual basis to cancel or suspend a domain name if public pressure mounts against an unpopular group or viewpoint with which the domain name is associated.

In addition to registrars, other DNS intermediaries have seen fit to place restrictions on how registrants may use their domain names. While registry operators and ICANN typically do not have contractual privity with registrants, the contractual framework that ties together the different levels of DNS intermediaries provides a mechanism to impose flow-down terms that ultimately bind registrants.

Registrars who wish to offer domain names within a particular top-level domain name are required to execute the registry operator’s “registry-registrar” agreement, which prescribes the fees charged to registrars for registering and renewing domain names on behalf of registrants and the process for using the registry operator’s automated registration system.[115] In addition, many registry-registrar agreements include flow-down terms that registrars must include in their registration agreements, such as local presence requirements (in the case of certain country code top-level domains), industry membership or accreditation (in the case of certain restricted or sponsored top-level domains), and, increasingly, restrictions against illegal conduct and IP infringement.[116] Like registrars, registry operators reserve the right to cancel, suspend, or transfer the domain name of a registrant who violates such restrictions.[117]

At the IANA level, ICANN has two separate mechanisms to impose flow-down terms on registrants. For generic top-level domains, ICANN typically requires each registry operator to execute a “registry agreement,” which delegates management of the top-level domain to the registry operator for a limited, ten-year period in exchange for certain reciprocal commitments.[118] ICANN also includes flow-down terms in its registry agreements that registry operators must incorporate into their registry-registrar agreements and, by extension, flow down to registrars to include in their agreements with registrants.[119] For example, ICANN’s Base Registry Agreement for new generic top-level domains states:

Registry Operator will include a provision in its Registry-Registrar Agreement that requires Registrars to include in their Registration Agreements a provision prohibiting Registered Name Holders from distributing malware, abusively operating botnets, phishing, piracy, trademark or copyright infringement, fraudulent or deceptive practices, counterfeiting or otherwise engaging in activity contrary to applicable law, and providing (consistent with applicable law and any related procedures) consequences for such activities including suspension of the domain name.[120]

ICANN also imposes similar policies directly on registrars through its Registrar Accreditation Agreement, which registrars must sign to become accredited to offer domain name registration services.[121] In that agreement, ICANN requires registrars to bind registrants not only to the UDRP for trademark disputes but also to representations that registrants will not use their domain names “directly or indirectly” to “infringe[] the legal rights of any third party.”[122]

Figure 3 depicts the above-described multi-tier contractual framework through which registrars, registry operators, and ICANN each impose content-based restrictions on registrants.

Figure 3

Restrictions against Legal Content

Whatever the merits of permitting DNS intermediaries, who play no role in hosting or delivering website content, to seize domain names associated with malware, counterfeit goods, or pirated media, their advancement into content regulation is at least understandable given the illegal nature of such activities.[123] Where DNS governance becomes harder to justify is where DNS intermediaries seek to regulate legal content or conduct based solely on moral grounds. For example, GoDaddy prohibits registrants not only from engaging in illegal activity but also from “promot[ing] or encourag[ing]” illegal activity,[124] a category of content that encompasses constitutionally protected speech.[125] In addition, many registrars now include so-called “morality clauses” in their acceptable use policies that prohibit registrants from engaging in “offensive,”[126] “morally objectionable,”[127] or even “inappropriate” conduct.[128] Such conduct might include publishing “profane,”[129] “vulgar[],”[130] “embarrass[ing],”[131] “derogatory,”[132] “racist,”[133] “homophobic,”[134] or “blasphemous”[135] content. In other cases, restrictions against “morally objectionable activities” are not further defined, leaving the registrar to determine in its sole discretion whether any registrant’s activities violate these amorphous standards.[136]

Some registrars abdicate even this responsibility, outsourcing it instead to the community. For example, GoDaddy reserves the right to cancel a domain name if it receives an “excessive amount of complaints” from the public about the domain name or content on the registrant’s website.[137] Thus, even if GoDaddy itself does not object to a particular website, a vocal interest group could succeed in revoking a lawful domain name solely through a coordinated email or Twitter campaign, an alarming power to grant the public against minority opinions or controversial ideas. Still other registrars dispense with the need to find any cause for termination and reserve the unilateral right to cancel a domain name for any reason or no reason.[138]

Not limited to termination rights, registrars may also decline to register or renew any domain name.[139] Thus, if a registrar cannot point to a morality clause or other provision in its agreement that a disfavored registrant has violated, the registrar can simply refuse to renew the domain name when the current registration term ends. If the registrant fails to transfer the domain name to another registrar before that time (or is not permitted to do so[140]), the registration will automatically expire. And because automatically filtering out controversial registrants during registration may be difficult, some registration agreements allow registrars to rescind an existing registration within thirty days of creation for any reason.[141] Still, registrars need not rely on non-renewal, an eventuality that may occur years later and a fate that most registrants may avoid by transferring to another registrar. Many registrars reserve the right to modify their registration agreement at any time.[142] These registrars may, therefore, introduce new acceptable use policies targeted specifically at registrants whose domain names they wish to cancel more expeditiously.

Restrictions against legal content are by no means confined to a select group of niche, activist-minded registrars. In 2017, the Internet Governance Project out of the Georgia Institute of Technology (IGP) undertook to determine the number of domain name registrations subject to morality clauses.[143] In doing so, the IGP analyzed registration agreements used by 70 different ICANN-accredited registrars, which together accounted for 90% of all gTLD domain registrations worldwide.[144] The IGP found that 59% of these registrars, which together managed more than 62% of all domain registrations, included a morality clause (or functional equivalent) in their terms of service.[145] Thus, more than half of all domain names registered on the Internet are subject to suspension, cancelation, or transfer if a registrar—or, in some cases, the community—objects to the registrant’s legal activity based on subjective moral standards.

Like registrars, registry operators have sought to regulate legal content through their own morality clauses. Working through the instrumentality of flow-down provisions, some registry operators prohibit registrants from engaging in behavior that is “abusive,”[146] “obscene,”[147] “contrary to public order or morality,”[148] or “otherwise objectionable.”[149] DotMarkets Registry Limited, a UK company that operates the .MARKETS top-level domain, prohibits registrants from engaging in “hate propaganda” or even directing “scorn” or “ridicule” at the registry operator.[150] As with registrars, registry operators may cancel, suspend, or transfer registrants’ domain names if they violate such policies.[151] And some registry operators even require registrars to report any objectionable registrant activity to them.[152]

While individual registrars and registry operators remain free to construct their own terms of service, subject only to any mandatory flow-down provisions, the effort to regulate content through the DNS is becoming increasingly organized and coordinated across the industry. In 2017, the Domain Names Association (DNA), an industry group comprised of registrars and registry operators, launched a “Healthy Domains Initiative” (HDI) aimed at curbing “unhealthy” domain practices.[153] The HDI’s initial policy document called for registries and registrars to implement policies and procedures to combat illegal or tortious online conduct, such as security abuse (malware, phishing, pharming), child abuse (child pornography), “rogue” online pharmacies, and copyright infringement.[154] The HDI recommended that DNS intermediaries work to combat these activities by incorporating sample clauses in their acceptable use policies, implementing trusted notifier programs, and suspending or deleting affected domain names.[155]

The HDI is both an attempt to influence industry practice and a reflection of an already advancing trend toward greater content regulation by DNS intermediaries. According to the HDI, 78% of DNA members already employ contractual provisions and procedures similar to those recommended by the HDI, and 89% of DNA members plan to expand the list of online practices they intend to regulate.[156]

While ICANN has so far resisted pressure to directly police legal content through its exercise of the IANA function,[157] it has nonetheless encouraged efforts by other DNS intermediaries to do so[158] and has even instituted policies and procedures that may contractually require registrars and registry operators to censor. Under ICANN’s New gTLDs Program, which governs how registry operators may apply to create and manage new top-level domains, third parties can object to any applied-for string, or the manner in which the applicant intends to operate the new top-level domain, as “contrary to general principles of international law for morality and public order,” or “detriment[al] to a broadly defined community.”[159] Objections are reviewed by a panel of independent experts, which may approve or deny the application based on whether the applicant has demonstrated that it will police content under the top-level domain, either by restricting registration or by prohibiting certain forms of content.[160] If the applicant is ultimately awarded the new string but fails to substantially enforce any “Public Interest Commitments” it made in its application—which may include commitments to enforce content-based restrictions—third parties can again challenge the delegation and cause ICANN to revoke the registry operator’s management of the top-level domain.[161] Thus, an expectation of content regulation and mechanisms to enforce it have effectively been built into the structure of the New gTLDs Program, and it may not be long before such policies and procedures are extended to legacy top-level domains, such as the all-important .COM.[162]

In the same manner, ICANN has foisted potential content regulation responsibilities onto registrars through its new Registrar Accreditation Agreement, which requires registrars to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.”[163] Unfortunately, the RAA neither defines “abuse” nor prescribes the “reasonable and prompt steps” that registrars must take.[164] But simply by forcing registrars to maintain such contacts, ICANN increases the likelihood that registrars will feel compelled to take action against a domain name if members of the public contact the registrar to allege that a given website is “abusive.”[165] In that event, a registrar could very well conclude that ICANN’s term is capacious enough to include the same kinds of objectionable, but legal, behavior catalogued in registrar or registry operator morality clauses.

Examining DNS Censorship

Commentators have criticized the practice of taking down domain names based on legal website content as a form of “private censorship.”[166] Clearly, by itself, private censorship does not implicate constitutional concerns, since the Supreme Court has long held that the First Amendment applies only to actions by the state.[167] While the public function doctrine operates as a limited, narrow exception to the state action requirement, that doctrine has never been applied to cyberspace, and at least one recent case suggests that the Supreme Court is not likely to do so.[168]

Moreover, as scholars have noted, in some cases, private censorship may represent simply the exercise of traditional intermediary functions, such as protecting users from dangerous content or providing curated experiences to match consumer interests, both of which may be beneficial.[169] And the exercise of editorial discretion—also technically a form of private censorship—can itself further important free speech interests.[170] It therefore warrants examining whether DNS censorship furthers the same benefits as other forms of private censorship, such as might be exercised by search engines and social media networks, or whether DNS censorship is different in nature. In the subsections that follow, I present three arguments for why DNS censorship presents unique threats to free expression on the Internet.

“Dumb Pipes”

One concern with DNS censorship is that it seeks to regulate content that is wholly external to the DNS. To borrow from another debate within Internet governance, proponents of “network neutrality” argue that the Internet was designed as a “dumb” network in which its foundational protocols (the TCP and IP protocols) functioned only to transmit packets of data without asking questions about the sender of the packet, the recipient, or its content.[171] This “end-to-end” principle, proponents argue, was instrumental to the growth and success of the Internet and remains foundational to the principle of a fair and open Internet.[172] Internet service providers should therefore provide only dumb pipes and should not be permitted to advantage some content over other content in terms of access, transmission speed, or prioritization.[173]

Without wading into the merits of network neutrality itself, I note that to the extent the “dumb pipes” argument counsels in favor of prohibiting content discrimination by Internet Service Providers (ISPs), it provides an even more compelling argument against DNS censorship. Like ISPs, DNS intermediaries provide core network services that make Internet communications possible. From an openness and fairness perspective, we should expect DNS intermediaries to register, renew, and resolve domain names without regard to the identity of the person who hosts an associated website or the content on that website. But unlike ISPs, DNS intermediaries provide no pipes, whether smart or dumb, for website content. As noted supra, no website content ever flows through the DNS or through registrars, registry operators, or ICANN in their role as DNS intermediaries.[174] The sole function of DNS infrastructure is to provide a name-to-address mapping system that can be used to locate content.[175] Once located, that content flows through other parties’ pipes.[176] It therefore makes even less sense to allow DNS intermediaries to disadvantage website owners based on content that does not even flow through DNS pipes.[177]

If the DNS truly is the “phonebook of the Internet,”[178] then canceling a domain name is not unlike removing a company’s name and address from a traditional phonebook. While we might support the de-listing of proven criminal enterprises, we would object to removing the contact information of a law-abiding entity, such as a strip club or unpopular political organization, simply because some might find that entity’s activities or viewpoints to be morally objectionable. The latter should not be within the purview of a phonebook company that holds itself out to the public as an authoritative, comprehensive, and reliable omnibus of all registered entities within a geographical area. Likewise, the DNS has historically held itself out as, and the Internet community has viewed it as, an authoritative, comprehensive, and reliable omnibus of all hosts on the Internet that are intended to be publicly accessible.[179] The DNS should no more attempt to regulate website content by making websites unreachable than a phonebook company should attempt to improve public morality by making strip clubs difficult to locate.

Censorship Creep and Collateral Censorship

To be sure, some might be inclined to support DNS censorship depending on the nature of the websites so targeted. After all, the three registrants referenced in the Introduction all faced suspension or cancellation of their domain names due to bigoted or hateful speech found on their websites. If the primary effect of DNS censorship is to make it harder to locate “vulgar,” “derogatory,” or “blasphemous” websites, then far from being problematic, proponents might argue, DNS censorship may represent an important tool in the fight for a healthy and tolerant Internet. Viewed from this perspective, DNS intermediaries may even have a moral duty to practice DNS censorship as a matter of corporate social responsibility.

Some groups certainly take this position. A group of civil rights, human rights, technology policy, and consumer protection organizations called the “Change the Terms” coalition has created recommended corporate policies and terms of service with the goal of helping technology companies combat hate online.[180] One of the coalition’s model terms states, “[u]sers may not use [the provider’s] services to engage in hateful activities or use [the] services to facilitate hateful activities engaged in elsewhere, whether online or offline.”[181] Because online service providers who include such restrictions would presumably have the right to terminate services for a breaching customer, and because “domain name service providers” are intended adopters of these terms, the coalition is effectively calling for DNS intermediaries to use the threat of domain name cancelation to police online (and even offline) content.[182]

But if history teaches anything, censorship that is initially limited to one category of content rarely remains so confined. The phenomenon of “censorship creep,” by which is meant “the expansion of speech policies beyond their original goals,”[183] is well documented in the literature. As one commentator noted, “when you build a censorship system for one purpose, you can be pretty certain that it will be used for other purposes.”[184] Nor is private censorship, including speech restrictions imposed by U.S. technology companies, immune from this phenomenon. As Danielle Keats Citron chronicled, U.S. technology companies, including Twitter and Google’s YouTube, initially resisted pressure to remove terrorist propaganda from their platforms, adhering instead to free speech policies that were largely consistent with First Amendment doctrine.[185] After U.S. technology companies changed course and agreed to voluntarily cooperate with European regulators in 2016 to remove terrorist propaganda, it was not long before the scope of prohibited material expanded to other categories, such as “fake news” and generalized “hate speech.”[186] The problems of definitional ambiguity and imperfect automation have even led to the banning of users engaged in political dissent or legitimate debate on hot-button issues such as minority users who repost racist messages directed at them on online platforms.[187] As Citron notes, well-intentioned censorship may inadvertently work against its own goals by suppressing “legitimate debate and counter speech that might convince people to reject bigotry and terrorist ideology.”[188]

DNS censorship is no less likely to experience scope creep and produce unintended consequences with the passage of time. The joint problems of definitional ambiguity, imperfect automation, and public pressure could very well combine to eventually expand DNS censorship to other unpopular viewpoints, or to chill legitimate dissent or debate. In this, proponents of DNS censorship might consider that one of the main techniques used by authoritarian regimes to block dissident or disfavored online content is to block websites through the DNS.[189] And thus, proposals to encrypt DNS queries are gaining in popularity, with the goal of helping persons under authoritarian regimes circumvent Internet censorship.[190]

Even the U.S. government, which is bound by the First Amendment, has engaged in a form of “collateral censorship”[191] by pressuring DNS intermediaries to take action against domain names associated with suspected illegal activities as an end-run around official judicial processes. In 2012, the Secret Service secured GoDaddy’s agreement to suspend JOTFORM.COM after one of JotForm, Inc.’s customers was suspected of using the service to facilitate a phishing scheme, an extreme move that took down the online business and left 700,000 other customers without service.[192] In 2014, the FDA successfully pressured easyDNS, a Canadian registrar, to take down a domain name associated with an allegedly illegal online pharmacy, despite the FDA’s lack of jurisdiction over easyDNS or the online pharmacy.[193]

These practices stand to reason. A government that lacks jurisdiction over a website hosted abroad will see DNS resolution blocking as the most efficient way to prevent its citizens from accessing the website.[194] And if the domain name was registered with a registrar or registry operator having a local presence, compelling or simply pressuring the DNS intermediary to suspend or cancel the domain name may succeed in taking the target website offline globally. That a single government or DNS intermediary may easily remove global access to a website simply by targeting the website operator’s domain name certainly resonates with Sir Tim Berners-Lee’s description of DNS as the “Achilles heel of the Web.”[195]

Disproportionate Effects

Finally, depending on the actions taken by the DNS intermediary and the role of the intermediary in the DNS hierarchy, DNS censorship can have severe consequences for website operators, including the loss of valuable assets, business disruption, appropriation of goodwill and traffic, and potentially the systematic purging of certain minority viewpoints from the Internet.

As to the first consequence, a domain name may be extremely valuable[196] depending on the nature of the second-level string, the top-level domain, and how much goodwill has been accumulated in the domain name. The value of the second-level string will depend, in part, on lexical features, such as length and the absence of numbers or dashes; semantic distinction, such as inclusion of meaningful words; and mnemonic value, such as memorability or guessability.[197] A registrant who managed to obtain a domain name that rates highly along these dimensions may have little hope of finding a comparably valuable replacement if her original domain is seized.

While the registrant could potentially find the same, or a comparable, second-level string in another top-level domain, it is well established that different top-level domains carry different economic and reputational value.[198] Just as SEX-18273.COM is no substitute for SEX.COM, the registrant deprived of HERITAGE.ORG could take little comfort in the availability of HERITAGE.NINJA. Even if a substitute string of comparable lexical value is available in the same top-level domain, the primary value of a lost domain name may instead lie in the goodwill accrued in the name. By itself, “google,” an intentional misspelling of the word “googol,” may carry only marginal intrinsic value. Still, GOOGLE.COM retains the title of most visited website[199]—and, therefore, likely also the most valuable domain name in the world—almost entirely on account of the goodwill accrued in the string through popular usage.

For companies with a significant online presence, losing a domain name can significantly disrupt business. For companies that operate primarily or exclusively online—so-called “born in the cloud” companies—domain name seizure represents an existential threat. Losing a domain name effectively causes a registrant’s website to go offline. Even if an online business manages to establish a replacement domain name—a proposition that may take days or weeks depending on the complexity of the website—the intervening downtime will inflict injuries from which some websites may never recover. If the website provides services to business customers, downtime could subject the owner to claims for breach of contract, or customers may elect to take their business elsewhere in response to the perceived unreliability of the service.[200]

Even if a website owner manages to immediately failover to an alternate domain name, there may be downstream dependencies on the original name. If the website receives significant traffic from links on third-party websites pointing to the original domain name, that traffic will be lost, and it may take years to replace it through the organic growth of links pointing to the new name.[201] Such links further play a role in a website’s search engine rankings, which may be damaged or lost as well.[202] Moreover, no matter how quickly a website is migrated to a replacement domain name, if the website owner lacks the means to contact users directly, users may have no way of even learning about the new domain name, since the website owner will not be able to publish any kind of notice reachable through the original domain known to users. Instead, users who attempt to navigate to the original domain name will either see an error message, and potentially conclude that the website has shut down, or a website belonging to a new owner, and potentially take their business to the new owner going forward.[203]

The last consequence of DNS censorship—the systematic purging of certain minority viewpoints from the Internet—has been limited thus far.[204] However, it threatens to become a greater problem the more aggressively DNS intermediaries seek to regulate content based on vague notions of morality and the higher the level of enforcement from within the DNS hierarchy.[205]

Threatened with DNS censorship by a registrar, a registrant’s ability to protect her domain name depends only on her ability to transfer the name before the current registrar takes action and her ability to find a new registrar with more lenient acceptable-use policies. With over two thousand ICANN-accredited registrars in the market,[206] including some who market themselves as free speech-friendly,[207] our registrant should have little trouble with the latter. As a last resort, a marginalized registrant could even complete the process of becoming accredited as her own registrar, thus defusing the threat of DNS censorship by third-party registrars altogether.[208]

If, however, a registrant faces DNS censorship courtesy of a registry operator, her options dwindle. Because each top-level domain is managed by a single registry operator, a registrant cannot evade registry-imposed content policies by switching to a different registry operator unless she is also willing to move to a different top-level domain. But changing the top-level domain associated with a domain name is equivalent to losing the original domain name altogether and replacing it with a new domain name, one that may be considerably less valuable or even unavailable. The result is that a registrant who faces suspension, cancellation, or transfer by her registry operator has no option to preserve her domain absent legal recourse. Thus, while the owners of DAILYSTORMER.COM and GAB.COM managed to keep their domain names by transferring to new registrars, the owner of INCELS.ME was powerless to maintain the domain name after the .ME registry operator decided to suspend it.

Likewise, if ICANN eventually reaches a point where it begins imposing robust, top-down morality restrictions, a censored registrant will not be able to save her domain name, even by attempting to migrate to a different top-level domain. Because ICANN sits atop the DNS governance hierarchy, no other domain name could be registered as a substitute for the website if the offending content remains in place. That content would effectively be banned from the Web. Without question, the content could remain accessible through the Internet outside of the DNS. The website could be accessed, and linked to, using its IP address, or the content could be distributed via other application-layer means, such as peer-to-peer applications, email, or FTP. But these alternatives would be poor substitutes for a conventional, DNS-accessible website, the predominant medium through which news and ideas are made globally accessible. Moreover, the notion that a single, private entity could set content policy for the entire DNS-accessible Web, a policy that might restrict constitutionally protected speech by all Internet users in the U.S., is an alarming possibility and one that deserves careful attention now that ICANN is no longer subject to U.S. oversight.

Property Rights in Domain Names

Given this background, one wonders if a registrant has any option to protect herself from DNS censorship if a DNS intermediary is determined to stamp out her viewpoint. After all, since DNS intermediaries reserve broad rights to suspend, cancel, or transfer domain names in their contracts, a registrant can protect herself from DNS censorship only by demonstrating a superior right to the disposition of her domain name. In this article, I argue that registrants’ property interests provide that superior right. However, to make that case, it is first necessary to analyze whether domain names qualify as property and, if so, what interests registrants acquire in that property. In this Part, I show that domain names are best characterized as intangible, personal property, as most courts that have considered the issue have held. To do so, I trace the history of the case law, as courts first appeared to reject and then later clearly embraced the property status of domain names. I then summarize the best arguments for such a classification and answer some of the lingering objections that courts have failed to address adequately. Next, having established the property nature of domain names, I turn to a question that, curiously, has received no attention in the literature to date: which party has title to that property? Using property theory as a guide and weighing competing claims to ownership that might be made by other parties, I conclude that title to a registered domain name lies with its registrant and not with any DNS intermediary.

  1. Domain Names as Contractual Rights

The best argument against characterizing domain names as property is that domain names do not, and cannot, exist outside of the services provided by DNS intermediaries. Standing on this rationale, the earliest cases to consider the issue suggested, but did not squarely hold, that domain names are mere contractual rights and not property. For example, in the 1999 case of Dorer v. Arel, faced with the issue of whether a judgment creditor could levy a domain name registered to a judgment debtor to satisfy a judgment, the U.S. District Court for the Eastern District of Virginia held that it could not.[209] The court noted that under Virginia law, a writ of fieri facias could be used only to levy a debtor’s “personal property.”[210] But a domain name registration, the court found, represented only the “product of a contract for services” between the registrar and the registrant.[211]

Likewise, in Network Solutions, Inc. v. Umbro Int’l, Inc., the Virginia Supreme Court denied a plaintiff’s request to garnish various domain names registered to a defendant to satisfy a default judgment.[212] Citing Dorer, the court held that “[a] contract for services is not ‘a liability’ as that term is used in [the Virginia garnishment statute] and hence is not subject to garnishment.”[213] As additional support, the court noted that a registrant’s right to use a domain name is “inextricably bound to the domain name services” that a registrar provides, and that “[w]hatever contractual rights the [registrant] has in the domain names . . ., those rights do not exist separate and apart from [the registrar’s] services that make domain names operational Internet addresses.”[214] The court also feared that allowing domain names to be garnished would allow any contractual right under a service contract—for example, prepaid satellite television services—to be garnishable.[215]

Although Dorer and Umbro have both been cited for the proposition that domain names are contractual rights rather than property, their holdings are not so clear. In Dorer, after suggesting that a domain name represented only the “product of a contract for services,” the court ultimately declined to rule on the property status of domain names, finding instead that the plaintiff already had an adequate remedy under trademark law through the registrar’s dispute resolution procedure.[216] Similarly, during oral argument in Umbro, the registrar had already conceded that the right to use a domain name is a form of intangible personal property.[217] And the court found that it was not essential to outcome of the case to determine whether domain names are a form of intellectual property but instead limited its holding to the fact that domain names were not “liabilities” under the Virginia garnishment statute.[218] Thus, while the Dorer and Umbro courts suggested that domain names are contractual rights rather than property, neither court explicitly held so.

Domain Names as Property

It wasn’t until the 2003 case of Kremen v. Cohen that a court squarely addressed the property status of domain names.[219] In Kremen, the owner of SEX.COM sued Network Solutions after the registrar was defrauded into transferring the domain name to another party.[220] Because the domain had originally been registered in 1994, when Network Solutions was under contract with the National Science Foundation to provide domain names for free, no contract governed the plaintiff’s registration.[221] Without a basis to assert a claim for breach of contract, the plaintiff argued that in transferring the domain name to another party without his consent, Network Solutions had tortiously converted his personal property.[222]

In evaluating this novel argument, the Ninth Circuit first applied a three-part test to determine whether a property right existed.[223] Was there “an interest capable of precise definition”? Yes, the court said. “Like a share of corporate stock or a plot of land, a domain name is a well-defined interest.”[224] Was the interest “capable of exclusive possession or control”? A domain name was. “Someone who registers a domain name decides where on the Internet those who invoke that particular name—whether by typing it into their web browsers, by following a hyperlink, or by other means—are sent.”[225] Finally, did the putative owner “establish[] a legitimate claim to exclusivity”? The court found that domain name ownership was “exclusive in that the registrant alone makes [the] decision” as to where requests for the domain name are sent.[226]

As additional evidence, the Ninth Circuit noted that a robust secondary market exists in which “domain names are valued, bought and sold, often for millions of dollars.”[227] Moreover, the court observed, the ACPA provides for in rem jurisdiction over domain names where process cannot be served on an alleged cybersquatter, indicating that Congress intended to treat domain names as property.[228] The court therefore concluded that domain names were best characterized as a form of intangible personal property.[229]

But classifying domain names as property did not end the matter. Under the “merger requirement” prescribed by the Restatement (Second) of Torts, a conversion claim for intangible property can be stated only if the intangible property rights converted are “of the kind customarily merged in a document.”[230] In reversing the trial court, the Ninth Circuit nonetheless found that California “does not follow the Restatement’s strict requirement that some document must actually represent the owner’s intangible property.”[231] Alternatively, the court reasoned that even if California retained some vestigial merger requirement, it could be satisfied by looking to the DNS itself as the relevant—albeit, electronic—document in which a domain name registrant’s rights are merged.[232] The court therefore held that the plaintiff had “an intangible property right in his domain name and that a jury could find that Network Solutions ‘wrongfully disposed of’ that right to his detriment by handing the domain name over” to another party.[233]

Shakeout and the Merger Requirement

  1. Other Courts

Since Kremen, U.S. courts have generally sided with the view that domain names are personal property rather than mere contractual rights.[234] Other jurisdictions to follow the Kremen approach include Texas,[235] Utah,[236] Minnesota,[237] Louisiana,[238] Pennsylvania,[239] Florida,[240] and the District of Columbia.[241] U.S. courts have found domain names to be assets in bankruptcy,[242] and, contra the result in Umbro, some courts have permitted creditors to seize domain names under garnishment, attachment, or other forms of execution.[243]

Courts outside of the U.S. have followed suit. Canada[244] and Sweden[245] have explicitly recognized domain names as property. Judges in at least two UK cases implicitly recognized domain names as property but did not decide squarely on the issue.[246] However, just after those decisions were handed down, the EU Court of Human Rights expressly held that domain names are “property rights” under Protocol No. 1 to the Convention for the Protection of Human Rights and Fundamental Freedoms, thus arguably setting policy for all of Europe.[247] Courts in India[248] and Australia[249] have also implicitly recognized domain names as property.[250]

Merger Requirement

But recognizing domain names as property does not, by itself, protect registrants from interference by other parties. As described above in connection with Kremen, because conversion is a common law cause of action, whether a registrant may prevail on a claim for conversion of a domain name also depends on whether the forum state adheres to the merger requirement and, if so, whether a domain name can satisfy that requirement. While the Kremen court found that California does not follow the merger requirement or, if it does, that the DNS itself qualifies as the requisite document, other jurisdictions have not had such lax attitudes toward the rule.

In Xereas v. Heiss, the U.S. District Court for the District of Columbia, after finding domain names to be a form of intangible property, nonetheless dismissed a plaintiff-registrant’s claim for conversion of his domain name by his former business partners after strictly applying the merger rule.[251] In Hoath v. Connect Internet Services Property, Ltd., the Supreme Court of New South Wales denied a plaintiff’s conversion claim for theft of his domain name because Australia not only follows the merger rule but further requires the plaintiff to own or control the very document or object in which the intangible right is merged.[252] In the court’s judgment, that object was an actual server operated by the .AU registry operator, an even stricter form of the rule.[253] A strictly applied merger rule, therefore, may present a registrant with the bewildering situation in which her domain name is recognized as property and yet she is powerless to protect that property from theft or interference.

It should be noted that rejecting a conversion claim, whether on account of the merger rule or for other reasons, will not always leave a plaintiff-registrant without a remedy for the theft of her domain name. Where a cause of action for conversion has been unavailable, some courts have entertained claims for fraud.[254] Moreover, the ACPA and UDRP remain avenues for relief where a colorable claim of trademark infringement accompanies the actions of an alleged domain name thief.[255] In many cases, these causes of action may suffice to make the aggrieved plaintiff-registrant whole. But facts to support these other claims may not be present in all situations. And, importantly for cases involving DNS censorship, none of the aforementioned causes of action would likely be available where a DNS intermediary seizes a registrant’s domain name pursuant to a contractual right.

Resolving the Debate

Although the status of domain names as property has become the consensus view, both in the United States and abroad,[256] it bears taking a fresh look at the issue for at least two reasons. First, a number of DNS intermediaries—both registrars and registry operators—still include terms in their agreements requiring registrants to disclaim any property rights in domain names they register.[257] Second, and closely related, courts and scholars who have previously analyzed the property status of domain names have not done so in the context of domain takedowns by DNS intermediaries. Previous analysis, therefore, concerns only the rights of a registrant over and against third parties who were not parties to any registration agreement.[258] By contrast, a DNS intermediary that seizes a registrant’s domain name will, in most cases, act pursuant to a purported contractual right to do so. If a registrant would use property rights to protect herself against such actions, the status of her domain name as property must be sufficiently compelling to overcome any terms in her registration agreement that state otherwise.

In the following sections, I recap some of the stronger arguments for recognizing property rights in domain names. Then, leveraging the technical concepts explained in Part I, I elucidate the precise dividing line between the property nature of domain names and the domain-related services provided by DNS intermediaries, an issue that has at times confused courts and commentators alike.

  1. Property Theory

Although no single, canonical definition of property exists, a common formulation holds that property comprises three fundamental rights: the right to use, the right to exclude, and the right to transfer.[259] Within this trio, it is commonly accepted that the right to exclude is the most important and distinctive characteristic of property.[260] It is this element of exclusion that Lord Blackstone referred to in his oft-quoted description of property as “that sole and despotic dominion which one man claims and exercises over the external things of the world, in total exclusion of the right of any other individual in the universe.”[261]

Domain names meet all three criteria. Registering a domain name permits the registrant to use the domain by directing all DNS requests for it to her website. That right is, by definition, exclusive. As the registrant, Microsoft alone determines, for example, that all requests to MICROSOFT.COM should be directed to Microsoft’s website and never to another site. Finally, domain names are freely transferable. As the Kremen court noted, a robust secondary market exists in which domain names are frequently bought and sold for millions of dollars. By contrast, secondary markets typically do not exist for rights under consumer service contracts, such as the satellite television service contract hypothesized by the Umbro court.

Another important distinction between property rights and contract rights, as pointed out by Anupam Chander, lies in the identity of the individual against whom a right can be asserted:

If the right can be asserted solely against the contractual counterparty, then the right should properly be declared to be contractual. If the right can be asserted against third parties not in privity with the holder of that right, then it seems appropriate to consider characterizing the right as a property right, even if contract rights may also be involved. Unlike contracts, property gives one rights against third parties.[262]

Under this framework, domain names clearly align with property rights rather than contractual rights. If domain names constituted only contractual rights, registering a domain name would restrict only the contracting registrar from using the name or offering it to another customer. But the promise inherent in registering any domain name is that the same name may not be registered or used in a DNS setting by any other party in the world, irrespective of whether that person is a contractual counterparty. In fact, as discussed further infra,[263] the rights conferred in a domain name registration transcend the registrant-registrar contractual relationship in other ways, since a registrant may easily transfer a registered domain name from one registrar to another registrar. And even other registry operators may not offer the same domain to other registrants. ICANN’s delegation of each top-level domain to a single registry operator ensures that each domain name remains globally unique across the entire DNS. These characteristics of domain names provide exclusive rights beyond the registrant-registrar relationship and even the registrant-registry relationship.

Federal Support

Federal laws also support classifying domain names as property. As courts and commentators alike have noted, in cybersquatting cases, the ACPA provides for in rem jurisdiction over domain names where the defendant domain name owner cannot be served with process in the United States.[264] Because in rem jurisdiction permits a court to exercise jurisdiction over an item of real or personal property based on the fact that the property is located within the jurisdiction, the ACPA evidences Congress’s intent to treat domain names as property.[265] Also, Chander notes, the remedy against a cybersquatter under both the ACPA and the UDRP is to transfer the domain name to its “rightful owner”—a property rule.[266]

The PRO-IP Act, another piece of federal legislation, lends additional credence to this notion.[267] Under the PRO-IP Act, as interpreted and executed by the Department of Homeland Security, domain names may be, and have been, seized by federal agents and subject to forfeiture when used in conjunction with websites that host infringing content.[268] The PRO-IP Act, thus, acts as a civil asset forfeiture statute for cybercrimes and, in doing so, treats domain names as property.[269]

Service Separability

Some have argued that domain names should not be characterized as property because they are not separable or independent from the services provided by DNS intermediaries.[270] As first articulated in Dorer, a domain name registration is the “product of a contract for services” between the registrar and the registrant.[271] By itself, this statement does little to advance a contract rights theory of domain names. Service contracts often give rise to property rights. Examples include freelance developers hired under contract to build software products or a patron who commissions a work of art. Instead, what the Dorer court likely meant was better articulated by the Virginia Supreme Court in Umbro, which stated, “whatever contractual rights the judgment debtor has in the domain names at issue in this appeal, those rights do not exist separate and apart from [Network Solutions’] services that make the domain names operational Internet addresses.”[272] Or, even more to the point, “[the registrant’s] contractual right is inextricably bound to the domain name services that [Network Solutions] provides.”[273]

However, both statements misconstrue the role of registrars, such as Network Solutions, in the operation of a domain name. As explained supra, registrars perform no core DNS services necessary to make domain names operational.[274] A registrar’s role is largely limited to taking payment for a domain name registration or renewal, instructing the relevant registry operator to register the domain name and authoritative nameservers in the registry database and zone file, and notifying the registrant of upcoming renewal deadlines. These functions, all of which may be classified as merely administrative or clerical, are not necessary for a domain name to function in connection with a website. If a customer registers a domain name for the maximum ten-year registration period and pays all necessary fees upfront, the domain can continue to operate uninterrupted for the full ten-year period, even if the registrar stops providing services or goes out of business altogether.[275]

Without doubt, operability of a domain does require that a registry operator—an entity that was not a party in Dorer or Umbro—provide ongoing service by responding to DNS queries (Steps 4 and 5 in Fig. 1). If the registry operator fails to provide name resolution services, even for a day, the domain name will cease to function. And given the hierarchical nature of the DNS, no other entity may perform this function. Yet, this fact does not disqualify the domain name from property status. To hold that it does is to ignore the bundle-of-sticks nature of property, to conflate the plural attributes of property into a unitary definition. A registry operator’s refusal to provide resolution services for a particular domain name would operate to remove only one stick from the registrant’s bundle: the right to use—or, perhaps more accurately, the ability to use—the domain name. But a domain name is no less property because a registrant depends on a third party to use the domain name, any more than other assets lose their property status when the use right is abridged.

In addition to providing resolution services, a registry operator must also maintain accurate records in its registry database to prevent multiple parties from registering the same domain name. A registrant can remain secure in her right to a domain name only if the registry operator continues to perform these registry services. But the same could be said of other classes of property. A corporation’s failure to perform the basic clerical service of maintaining an accurate shareholder registry could endanger the security of shareholders’ property rights. But that fact does not take away from the property status of corporate shares, just as a parcel of land does not depend on the continued services of a title office in order to remain property. Record-keeping merely operates to clarify which party can lay superior claim to the subject property.

Nature of the Property Interest

Having established domain names as a form of personal property, a question naturally arises: what specific rights do registrants have in that property? In particular, the existing literature has been strangely silent on what is perhaps the most important question: does a registrant own her domain name, or does she merely acquire a right to possess it?

As analyzed further infra, whether registrants own or merely lease their domain names significantly affects the balance of power between registrants and DNS intermediaries.[276] If a registrant merely leases her domain name, then, presumably, her registrar can prescribe enforceable rules for how she may use it in a registration agreement, such as by imposing morality-based content policies or other acceptable use restrictions. By contrast, if a registrant takes title to her domain name when she registers it, courts may be less willing to uphold a registrar’s right to seize her property as a self-help remedy for breach.

Not surprisingly, DNS intermediaries have largely remained silent on this issue.[277] To speak of ownership, even to require registrants to disclaim it, could lend credence to the foundational premise that domain names are property—something DNS intermediaries may be reluctant to do. But even if DNS intermediaries took a strong stance on this issue in their contracts, multiple factors support the notion that registrants take title to their domain names upon registration. Those factors include the case law, property theory, and the role of DNS intermediaries, including ICANN, in the global Internet community.

  1. Case Law

In addition to recognizing domain names as property, several courts have either explicitly referred to registrants as owners of their domain names or else used language strongly suggestive of ownership. For example, in Kremen, the Ninth Circuit referred to the original registrant as “the proud owner of SEX.COM.”[278] In Gill v. American Mortgage Educators, Inc., the United States District Court for the Western District of Washington stated, “Domain names are considered to be owned by the person who registered the name with the registrar.”[279] In Inc. v. Inc., the Ontario Superior Court of Justice had occasion to consider a case in which one partner used another partner’s money to register various company domain names in his (the first partner’s) own name.[280] Dismissing the defendant’s argument that the contact information used during registration should control, the Court held, “Title to the domain names belongs to the corporate plaintiffs.”[281] Other courts have used similar language.[282]

Some DNS intermediaries might object to drawing conclusions based on this language alone. In these cases, they might argue, the courts were not called upon to decide whether registrants own their domain names or merely had possessory interests. The courts were instead adjudicating other issues and simply reached for familiar and accessible terminology when describing how certain domain names in dispute were acquired or held. Or, because one can “own” a right in a property (e.g., an exclusive possessory right) without owning the property itself, courts’ use of ownership language in dicta does not, by itself, mean that registrants own their domain names.

While it is true that some of the cases that used ownership language did not hinge on whether registrants actually held title to their domain names, in other cases, courts relied on property concepts that make little sense outside of an ownership context. For example, in Express Media Group v. Express Corp., a cybercriminal managed to alter the WHOIS information associated with a domain name by replacing the plaintiff-registrant’s email address with its own.[283] The defendant, believing it was communicating with the plaintiff, later purchased the domain name from the cybercriminal at a price far below market value.[284] When the plaintiff, which the court described as the “rightful owner” of the domain, sued the defendant for conversion of its domain name, the defendant argued that it was immune to liability under the good-faith purchaser defense.[285] The U.S. District Court for the Northern District of California disagreed, explaining that “[t]he law distinguishes between the person who purchased from someone who obtained title to the property by fraud”—in which case the defense applies—“and the person who purchased from a thief who had no title to sell”—in which case it does not.[286] Because the cybercriminal had merely altered the WHOIS information associated with the domain name, rather than transferring the domain to itself, title never passed to the cybercriminal.[287] The cybercriminal, therefore, could not pass title to the defendant, and the good-faith purchaser defense did not apply.[288]

In Miles dba Jazz Alley v. Tokaido Shosha, an employee registered to himself a domain name comprising his employer’s trademark, which he later sold to a third party.[289] To gain control of the domain name, his employer filed a cybersquatting claim against the purchaser under the UDRP.[290] Although the respondent-purchaser had not registered the domain name in bad faith when he purchased it from the erstwhile employee, a necessary element to prevail in a UDRP action, the UDRP panel held that “[o]ne cannot pass good title to a domain name where it does not have good title.”[291] Thus was born the rule that if a party registers a domain name in bad faith, that bad faith will run with title to the domain name for any future purchaser of the domain, a rule that has been reaffirmed in multiple UDRP proceedings, including proceedings adjudicated by the World Intellectual Property Organization.[292]

These cases turned on chain-of-title and defect-of-title issues, concepts having meaning typically only in transfers of title-held or owned property. In the same manner, the remedies of garnishment and attachment typically require that the debtor own the garnished or attached property.[293] Therefore, it could be said that courts that have allowed creditors to garnish or attach domain names have, by necessary implication, also held that the registrants owned their domain names. It thus becomes more difficult in these decisions and others like them to dismiss the court or panel’s language of ownership as mere dicta.

Property Theory

Property theory also supports the notion that registrants own their domain names. In his famous 1961 essay, “Ownership,” Oxford Regius Professor, A. M. Honoré listed and described what he regarded as the eleven incidents of ownership—namely,

[T]he right to possess, the right to use, the right to manage, the right to the income of the thing, the right to the capital, the right to security, the rights or incidents of transmissibility and absence of term, the prohibition of harmful use, liability to execution, and the incident of residuarity. . . .[294]

Setting aside the prohibition of harmful use, which operates as more of a limitation on use than a positive indicium of ownership, we see that the manner in which registrants hold domain names accords with most or all of these incidents. Upon registering a domain name, a registrant has exclusive possession of the name, having sole authority to determine which IP addresses it maps to.[295] Furthermore, in jurisdictions that recognize claims for the conversion of domain names, courts will order misappropriated domain names to be returned to the exclusive possession of the registrant.[296] Registrants have the right to use their domain names to direct Internet traffic to whichever websites they choose. Registrants have the right to manage their domain names by deciding which employees, contractors, or other parties may use or configure the registration and zone file records for DNS resolution.

Registrants have the right to income from their domain names, either indirectly through revenue from their websites or directly by leasing their domain names to third parties.[297] Registrants have the right to capital, which Honoré describes as “the power to alienate [or] consume” the thing, including the power to transfer title upon death.[298] Registrants may sell their domain names to whom they like, and domain names constitute heritable assets in that an owner’s death does not terminate the domain registration. The incident of transmissibility, which Honoré describes as the ability of the interest to be “transmitted to the holder’s successors and so on ad infinitum,”[299] reflects how domain names are held, in that they can be bought and sold through a chain of title that continues indefinitely. At no point, does a domain name reach its maximum number of owners such that it cannot be acquired by the next successor in interest, reverting instead to unregistered status. As for liability to execution, a number of jurisdictions have permitted domain names to be seized from debtors through bankruptcy, garnishment, or attachment.[300] Finally, registrants are the ultimate residuaries when any interests they grant to others short of ownership cease.

With respect to the right to security, which Honoré describes as the right “to remain owner indefinitely,”[301] and the absence of term, satisfying these incidents of ownership is admittedly more complicated. Registrants may register or renew their domains for no more than ten years at a time. Registrants must also pay renewal fees; failure to do so will cause the registration to expire, at which point another party may register the domain name. Still, if we analogize renewal fees to property taxes, we find that their existence is not inconsistent with domain name ownership.

Derived from the feudal concept of socage, in which the king would divide land among his lieutenants and collect a share of their profits in exchange for his protection over the land,[302] property taxes are still used today to fund services that protect private property in the United States, such as police and fire protection.[303] Revenue from property taxes is also used to subsidize infrastructure such as roads, bridges, and drainage.[304] Together, these public functions operate to protect and connect real property. Moreover, even in fee simple absolute, a property owner’s failure to pay property taxes may result in a tax lien and foreclosure, depriving her of title and making the property available to others.[305]

These facts and rationales align nicely with the DNS, wherein DNS intermediaries must perform ongoing services to protect and connect domain name properties. Like county title offices, registry operators maintain authoritative registry databases indicating which registrants own which domain names, thus protecting registrants from competing claims by third parties. Registry and root server operators connect domain names to the global Internet by mapping IP address associations in zone files and responding to DNS queries.

Originally funded by universities and government agencies—with the result that domain names were free until 1995—these services are now funded almost exclusively through registration fees.[306] Like a foreclosure to enforce a tax lien, the specter of domain name expiration serves as an enforcement mechanism to ensure that registration fees are paid so that the broader DNS can continue to operate. Were these functions to be subsidized through other means, domain names could theoretically be held perpetually without the need for renewals or renewal fees.

The notion that limited registration terms derive from the need to collect registration fees to offset DNS operational costs finds support in the administration of IP addresses. Although the legal status of IP addresses is beyond the scope of this article, as with domain names, there is support both for the proposition that IP addresses are a form of property[307] and that entities may own their address blocks.[308] Unlike domain names, however, IP addresses, once procured, can be held perpetually.[309] Address block holders need not renew their IP addresses or pay ongoing fees in order to maintain their blocks.[310]

This distinction between perpetually held IP addresses and merely renewable domain names is no doubt explainable by the fact that IP addresses operate in a decentralized manner. Unlike, a domain name, which depends on one of thirteen root server operators and a single registry operator to resolve, an IP address does not depend on any central authority to ensure that Internet traffic bound for the address reaches the appropriate host. Instead, through a complex web of peering agreements and the border gateway protocol (BGP), ISPs and Internet backbone operators together ensure that IP addresses remain under the exclusive control and use of their owners. The costs of protecting and connecting IP addresses are, thus, subsumed within the broader network connectivity and peering market. Were the DNS to operate in a similar decentralized manner in which the costs of operation were borne by network operators, as some scholars have proposed,[311] recurring registration fees could be done away with and the enforcement mechanism of domain name expiration along with it.[312]

Still another rationale for renewal fees might be to promote the efficient use of domain names by ensuring that valuable names do not lie fallow on account of registrants who register and then neglect them. This too accords with one of the classic rationales for property taxes.[313] It may provide a further reason why IP addresses, which, unlike domain names, are essentially fungible, have not been subject to renewal fees.

Accordingly, when viewed through the lens of property taxes, the requirement that registrants continue to pay renewal fees, or else risk losing their domain names, is not antithetical to the right-to-security and absence-of-term incidents of ownership. Property taxes present similar burdens and title risks to holders of fee simple estates, and yet few would argue that such estate holders do not own their properties as a result.[314]

In any event, even if these particular incidents are not met, their absence alone does not vitiate registrants’ claim to title.[315] Indeed, other forms of intellectual property in the United States have limited terms and/or require the owner to pay maintenance or renewal fees. Patent terms are limited to twenty years[316] and may be cut short by an assignee’s failure to pay maintenance fees after issuance.[317] Copyrights have limited terms, and under the 1909 Copyright Act, prior to its replacement in 1976, copyright holders were required to pay a renewal fee to extend their registrations for a second twenty-eight-year term.[318] Similar to the maximum ten-year registration period for domain names, holders of registered trademarks must submit a Declaration of Use and Renewal and pay the accompanying renewal fee every ten years to maintain their trademarks.[319] Despite the limited terms or renewal fees associated with these categories of intellectual property, few would argue that holders of patents, copyrights, or trademarks do not own their intellectual property.

No Better Claimant to Title

If DNS intermediaries would argue that registrants do not hold title to their domain names, then they must establish which party does hold title.[320] It will not do simply to characterize registrants as lessees of their domain names; one must identify the lessor. If title does not lie with registrants, then four other candidates emerge: registrars, registry operators, ICANN, and the global Internet community. I now analyze whether any of these entities may have a better claim to title.

If a registrant merely leases her domain name, then her registrar becomes an obvious candidate for lessor. After all, registrants pay and contract with registrars directly for their domain names. Registrants appear to receive their domain names from registrars, and registrars claim the right to revoke registrations under the terms of their registration agreements. However, a registrar’s similarity to a lessor ends there, and at least three facts weigh strongly against characterizing registrars as the owners of registered domain names.

First, prior to registration, no registrar has a superior claim to a domain name over any other registrar. The registrant who chooses to register EXAMPLE.COM may select from any registrar authorized to offer .COM domain names. If the registrant merely leases her domain name from her registrar, then the registrar must somehow acquire the domain name from another party (e.g., the registry operator) at the time of registration in order to simultaneously lease it to the registrant. No evidence suggests this happens. ICANN refers to registrars as mere “sponsors” of domain names registered through them,[321] and some registry operators expressly state that registrars acquire no proprietary interests in registered domain names.[322] Nor do any registrars appear to lay claim to title for registered domain names anywhere in their registration agreements. While some registrars disclaim any proprietary right to domain names on behalf of the registrant, they do not go further by claiming that they own such proprietary rights.

Second, registrants are free to transfer their domain names between registrars pursuant to ICANN’s Inter-Registrar Transfer Policy.[323] If registrars hold title to registered domain names, then transferring a domain name from one registrar to another would necessarily entail a transfer of title between the two registrars, complete with consideration and a deed of conveyance of some sort. Again, no evidence suggests this happens. No money flows from the losing registrar to the receiving registrar during a domain name transfer, and registrars do not enter into any contracts or deeds of conveyance with each other. Moreover, it would indeed be a strange phenomenon in property law if a lessee had the unilateral power to swap out her lessor and force a conveyance of her leased property between third parties at any time.

Finally, when a domain name registration expires, the domain name reverts not to the sponsoring registrar but to the registry operator for the top-level domain. And, once reverted, anyone can register the domain name through any accredited registrar. If registrars own all registered domain names, one would expect all rights to a domain name to revert to the sponsoring registrar when the registration expires. This does not happen. Instead, if the sponsoring registrar wishes to use an expired domain name for its own purposes, it must register the domain name like any other registrant; it must even compete with professional drop-catchers in the race to snatch the domain name once it becomes available.[324] Together, these facts show that whatever property role registrars assume in the registration of a domain name, it is not the role of a lessor, and thus registrars cannot be said to own the domain names registered by their customers.[325]

Given that a domain name reverts to the relevant registry operator when a registration expires, registry operators represent the next logical candidate for title-holder. Yet, registry operators, like registrars, do not claim to own domain names within the top-level domains they manage, and some registry operators expressly disclaim any proprietary interest in second-level domains.[326] Nor do registry operators claim registered or unregistered assets in their financial statements.[327] Moreover, as with registrars, if a registry operator wishes to use a domain name for its own purposes, it must register the domain name through an ICANN-accredited registrar just like any other registrant.[328] It is not permitted to use an unregistered domain name in any manner it chooses, as would be expected of a typical property owner whose property is not under lease.

While there may be some merit to the argument that registry operators have a residuary interest in expired domain names, they too could be dispossessed of any such interest if ICANN were to re-delegate management of the top-level domain to another entity. It is perhaps for this reason that ICANN has vigorously asserted in litigation that country code top-level domain managers do not own the top-level domains they manage.[329] If ICANN were to re-delegate management of the .BIZ top-level domain, for example, from NeuStar, Inc. to another entity,[330] NeuStar would necessarily lose control of all .BIZ second-level domain names. By contrast, if NeuStar owns all .BIZ domain names, it could not be so easily dispossessed of such property by another entity without compensation.

If registry operators do not own domain names under their management, then perhaps it follows that title ultimately rests with ICANN. After all, ICANN has the power to deprive a registry operator of a top-level domain through re-delegation and therefore has a stronger residuary interest than registry operators, registrars, or registrants. Still, this theory suffers from some of the same problems that arise when analyzing other DNS intermediaries’ claims to ownership.

First, under this reasoning, ICANN would hold title not only to all domain names within a particular top-level domain but to all domain names in all top-level domains—effectively, all domain names in the world. If true, such an extensive asset base would make ICANN one of the most valuable private corporations in the world. One method for appraising already-registered domain names involves measuring the daily unique visitors, unique pageviews, and revenue from advertisements of the website associated with the domain name. Using these and other factors, one appraisal tool estimates the value of GOOGLE.COM at $2.25 billion;[331] BAIDU.COM, the most popular search engine in China, at $560 million;[332] and FACEBOOK.COM at $740 million.[333] The market value of these three domains alone dwarfs the $514 million in assets listed in ICANN’s latest financial report.[334]

Not surprisingly, ICANN has never asserted ownership of third-party domain names, which explains the absence of any domain name assets from its financial statements. In part, ICANN’s failure to claim ownership of domain names may stem from a policy position that would classify domain names as contract rights rather than property.[335] The more likely reason is that ICANN would risk a public backlash if it ever claimed to own all domain names. ICANN’s role as the IANA, the global coordinator of the DNS, depends entirely on the trust and consent of the global Internet community, a role that could be revoked if the global Internet community were to become dissatisfied.[336] If ICANN were to claim ownership of all domain names, such a move could provoke the Internet community—in particular, foreign nations already leery of management by a U.S. corporation, holders of valuable domain names, and professional domainers—and reignite discussions about replacing ICANN. But just as the prospect of redelegation cuts against ownership of domain names by registry operators, the possibility that ICANN could be removed from its position as global coordinator of the DNS strongly suggests that title to registered domain names does not lie with ICANN.

Second, and related to the first point, ICANN did not officially assume the IANA role until 2000, approximately fifteen years after the DNS became operational.[337] For ICANN to own all domain names, it would need to have acquired those assets from their previous owners, whether registrants or a preceding administrator. However, none of the documents governing ICANN’s assumption of the IANA role memorialize any such conveyance.[338] In short, the idea that ICANN ultimately holds title to all registered domain names finds no support in either DNS governance documents or the manner in which ICANN operates.[339]

If registrants do not own their domain names and no DNS intermediary can lay claim to title, then the only remaining possibility is to argue that the global Internet community (GIC) collectively owns all domain names. On its face, this argument seems plausible. Because the GIC could band together to strip ICANN of the IANA function, it could be said that the GIC is the ultimate residuary interest holder. Moreover, the GIC could theoretically establish new policies, whether through its stakeholder position in ICANN or through a successor organization,[340] that cause all domain name registrations to permanently revert back to the GIC upon expiration of their current terms or reallocate domain names in other ways, which individual registrants would be powerless to prevent.

But this proves too much. It is true only in the sense that the citizens of a democratic country, as a collective, “own” all the land in the country. Legal property ownership is a creation of the state,[341] the state itself being a creation of the people in a given territory. The people are thus free, through the apparatus of government, to rewrite the laws of the state to reclaim or reallocate private property. But just because the people of a state could rewrite existing property laws, we would not therefore say that ownership of every estate lies with the general population instead of the individual. Although a sovereign nation may own all land within its borders, it does not follow that the general population of that nation owns each and every lot and house within the land. It likewise does not make sense to place title to individual domain names with billions of undifferentiated people just because the GIC has the power to set DNS policy either through ICANN or by replacing ICANN.

A Thought Experiment

Still, the strongest argument that registrants own their domain names may boil down to a simple thought experiment. Suppose that Verisign, the .COM registry operator, declined to renew the registration for the domain name GOOGLE.COM at the end of its current registration period. Suppose further that Verisign’s refusal to renew the name did not stem from Google LLC’s breach of any registration agreement or other restrictions imposed by Verisign. Instead, exercising its right under the .COM registry agreement with ICANN to reserve any strings in the top-level domain,[342] Verisign simply elected to discontinue registration of the GOOGLE string by any party going forward.

Nothing in Verisign’s terms for .COM domain names guarantees any registrant the right to renew.[343] And if Google merely leases, but does not own, its domain name, then Verisign, as a lessor, may decline to renew any lease agreement upon its expiration.[344] Google would therefore appear to be without a remedy for the loss of its domain name, other than to pressure ICANN to enact new policies, such as a right-to-renew rule. Yet it seems exceedingly unlikely that Verisign would be able to prevail in court under this fact pattern. Verisign’s actions would deprive Google of a billion-dollar asset—likely the most valuable domain name in the world—and it seems far more likely that a court would order the asset returned (effectively mandating renewal) and potentially assess damages for conversion of the asset. Although Verisign’s financial and reputational interests discourage the registry operator from acting in this manner, our intuition that a court would not countenance such actions—despite the clear freedom of lessors under property law to cease leasing property at their discretion—strongly suggests that registrants are owners, rather than lessees, of their domain names and that courts would be compelled to draw the same conclusion were the right case presented.

Having established that domain names constitute personal property and that registrants hold title to that property, the next section explores how property rights may be used to protect registrants from DNS censorship.

Propertization as a Bulwark Against DNS Censorship

In the arena of cloud computing, it’s been said that data has mass.[345] By which it is meant that data exerts a gravitational pull on other data and possesses inertia.[346] Unused virtual servers, which represent mere potential processing power, can be scaled down or terminated altogether to reduce or eliminate computing costs. But just as stationary matter still carries weight, data incurs storage costs, even while at rest. Lightweight applications and services can be copied or migrated easily across similarly configured hardware or even across service providers. But just as greater force is needed to displace increased mass, it may require weeks and thousands of dollars to move a single petabyte of data.[347]

In the same manner, property—whether real or personal, tangible or intangible—has mass, in a sense. By themselves, contract rights can easily be created, modified, or destroyed by the stroke of a pen, the occurrence of a condition, or the breach of a covenant. But when contract terms concern property, they cannot operate with the same freedom of motion. Centuries of property law suddenly attach to the object of agreement, imbuing it with the inertial mass of rights and protections that prevents it from being taken from an unwilling party without commensurate force.[348]

This phenomenon is no less true in the arena of DNS censorship. If domain names are mere service rights, then the battle may be fought almost entirely within the four corners of DNS service agreements, which, being contracts of adhesion, can be crafted to provide every advantage to DNS intermediaries. If, however, domain names are property, then registrants enter into registration agreements with independent protections conferred by property law that can act as counterweights to unlimited contractual power. Whether a DNS intermediary can seize a registrant’s domain name becomes no longer an exercise merely to identify a contractual basis to do so, but a careful balancing of interests—the intermediary’s contractual right to distance itself from objectionable content weighed against the nature and extent of the registrant’s property interest.

Having analyzed the property status of domain names and examined the hitherto neglected issue of title to domain name property in Part III, this Part explores how a robust theory of propertization can be used as a bulwark against DNS censorship. I explain, first, how property rights in domain names can be used to stop domain name seizures by DNS intermediaries. I then analyze where property law, by itself, may fall short, and I consider other potential options to shore up these deficiencies.

  1. How Property Law Protects Registrants

As explained supra, the locus of title to domain name property significantly affects the balance of power between a registrant and any DNS intermediaries.[349] If a registrant does not own a domain name that she registers but merely leases it from her registrar, then the registrar should have the traditional powers of a lessor. Like a lessor of other forms of property, a registrar may include restrictions in the registration agreement (the lease) concerning how the registrant-tenant may use the domain name property. And the registrar may revoke the registrant’s right to possess the property (the leasehold) for violating those restrictions. If, however, a registrant owns her domain name, as I have shown, then the registrar occupies a very different position. A registrar who seizes a validly registered domain name is no longer in the position of a lessor protecting its own property from improper use by a registrant-lessee. Instead, the registrar becomes only a party to a contract for registration-related services, and domain name seizure becomes a general self-help remedy for breach of the registration agreement. When viewed in this manner, contract terms permitting registrars to seize domain names become suspect, and the registrar must point to accepted practices in other areas of law to show that such terms should be enforceable.

In particular, the registrar must identify some analog in which A may permanently seize property owned by B as a self-help remedy for B’s breach of contract. Where A has no interest in the property, the breach is unrelated to B’s payment obligations,[350] and A has no duty to sell the property or otherwise account to B for the value of the property seized. For ease of reference in the discussion that follows, I will refer to these criteria as (1) Right to Seizure, (2) Self-Help Remedy, (3) Non-Monetary Breach, (4) Absence of Interest, and (5) No Duty to Account. As potential analogs, I examine the rights afforded to parties under repossession, execution, bailment, and liquidated damages.

  1. Repossession

Under the law of repossession, a lender may seize property owned by a debtor when the debtor fails to make timely payments on a loan that was used to purchase the property.[351] Importantly, in certain cases such as vehicle repossession, the lender is permitted to seize the debtor’s property immediately once the debtor becomes delinquent without the need to first obtain a court order.[352] Repossession therefore shares two criteria with domain name seizure: Right to Seizure and Self-Help Remedy.

However, under repossession, the creditor may seize the debtor’s property only in the event of a monetary breach—namely, the debtor’s delinquency in repaying the loan. The resulting lien permits the lender to seize only the property that secures the loan and no other property owned by the debtor.[353] Finally, after repossessing the secured property, the lender must sell it and remit any proceeds in excess of the outstanding balance back to the debtor (minus expenses).[354] A lender who repossesses and sells an automobile for $20,000 may not retain the entirety of the proceeds to satisfy a loan balance of only $5,000. Repossession thus requires proportionality between the value of the property seized and the amount of outstanding principal. Accordingly, repossession fails to meet the remaining three criteria listed above—Non-Monetary Breach, Absence of Interest, and No Duty to Account—and thus fails to provide a suitable precedent for the enforceability of domain name seizure.


I use “execution” as an umbrella term to refer to the forced sale of assets under bankruptcy, garnishment, attachment, or similar proceedings in order to satisfy an outstanding debt.[355] Unlike repossession, in these proceedings, the creditor need not have a pre-existing interest in the particular property seized. Thus, execution meets two of the above criteria: Right to Seizure and Absence of Interest.

However, execution proceedings require a court order—issuance of the appropriate writ—before the debtor’s property may be seized.[356] Moreover, like repossession, the creditor is not permitted to retain the seized property but must sell it and account to the debtor for any excess proceeds from the sale.[357] Finally, the remedy is applicable only where the debtor is unable or unwilling to pay some amount due; it does not apply to merely alleged damages. Execution therefore fails on three of the above criteria—Self-Help Remedy, Non-Monetary Breach, and No Duty to Account—and likewise does not provide a suitable analog for domain name seizure.


Under the law of bailment, a storage contract may entitle a warehouseman to sell a customer’s property held in a rented storage unit if the customer has fallen into arrears in order to satisfy any outstanding balance.[358] As with repossession, storage providers who sell a customer’s property to satisfy amounts owed need not obtain a court order to act; the remedy is self-help in that regard.[359] Moreover, the remedy may be used to compensate bailees for certain non-monetary breaches, such as to repair damage to the bailee’s facilities.[360] Therefore, bailment could be said to satisfy three of the above criteria: Seizure, Self-Help Remedy, and Non-Monetary Breach.

But the bailee’s right to sell the bailor’s property still differs from domain name seizure in at least two respects. First, bailees automatically acquire a lien on any bailed goods.[361] It is to execute on that lien that the storage provider may sell the bailor’s goods.[362] Second, the bailee must account to the bailor for the sale and remit any excess proceeds.[363] Bailment, thus, fails to satisfy two of the criteria of domain name seizure: Absence of Interest and No Duty to Account.

Bailment fails to provide a suitable analog for another, important reason. Inherent in bailment is the fact that the bailor’s goods are in the physical possession of the bailee. The bailee’s right to sell the goods, therefore, functions not only to compensate the bailee for non-payment but also to relieve the bailee of the goods and to reclaim his space for other purposes. By contrast, a registrar does not possess a registrant’s domain name. Instead, possession lies either with the registry operator, who maintains the registry database and the zone file,[364] or, it could be argued, with the registrant herself. This fact makes bailment an even weaker analogy, since the law does not permit a bailee to seize property outside of his facilities to satisfy outstanding debts.

Liquidated Damages

A liquidated damages clause is used to specify predetermined damages for breach of a contract where the injury to the non-breaching party may be difficult to quantify.[365] To be enforceable, liquidated damages must be reasonable and non-punitive.[366] Liquidated damages do meet some of the above criteria in that they are awarded for breach of contract that may be unrelated to payment obligations, and the party enforcing a liquidated damages clause need not have a pre-existing interest in property belonging to the breaching party—the Non-Monetary Breach and Absence of Interest criteria.

However, liquidated damages diverge from domain name seizure in that they do not entitle the non-breaching party to seize property belonging to the breaching party. The non-breaching party must first bring suit and obtain a judgment and verdict for damages—monetary damages. Thus, liquidated damages do not satisfy the Right to Seizure and Self-Help Remedy elements of domain name seizure.

Not all forms of liquidated damages require the non-breaching party to bring suit, however. Under Section 2-718 of the Uniform Commercial Code, a seller may withhold delivery of goods for which a buyer has already paid to offset an unrelated breach of contract by the buyer.[367] It could also be argued that although the buyer has not yet received the goods, withholding delivery to a party who has equitable title constitutes a form of seizure. UCC § 2-718, therefore, arguably brings in the Right to Seizure and Self-Help Remedy elements. But it does so at the expense of the Non-Monetary Breach element, since it applies only to payment-related breaches. In any event, liquidated damages, whether in the form of UCC § 2-718 or the common law, fail as a suitable analog to domain name seizure because they must reasonably approximate the injury suffered by the non-breaching party.[368] This proportionality requirement stands in contrast to the No Duty to Account element.

Domain Name Seizure as Tortious Conversion

The above comparisons having failed, one struggles to find a good analog to justify using domain name seizure as a catch-all remedy for breach of a registration agreement.[369] This makes sense. As a matter of public policy, private parties should not have unilateral power to seize property belonging to other parties for general breaches of contract where damages are unknown, minor, or non-existent. A domain name may appraise for millions of dollars and represent the single most important asset for an online company. And yet, if certain registration terms are to be taken at face value, a registrar may seize that domain name if the registrant so much as fails to update her contact information within seven days[370] or publicly disparages the registrar.[371] A mature legal system should not countenance the forfeiture of so valuable an asset for such speculative harms.

Without precedent for domain name seizure, and with strong arguments against it, it seems plain that contact terms allowing registrars to seize domain names should not be enforceable as a matter of public policy. To the extent a registrar reserves the right to seize a registrant’s domain name as a self-help remedy for breach, that contractual right should be negated under the doctrine of unconscionability.[372] To the extent a registrar reserves the right to cancel a domain name for any reason or no reason, the entire registration agreement might be unenforceable as an illusory contract.[373]

It follows, then, that a registrar that takes a registrant’s domain name against her will without a legally enforceable right to do so would be subject to common law claims for conversion or trespass to chattels. The tort of conversion, which occurs when a person wrongfully deprives another of possession of or title to an object,[374] would certainly describe a registrar’s act of canceling a domain name or transferring it to a new registrant without the previous registrant’s permission. Such was the cause of action permitted by the court against Network Solutions in Kremen, when the registrar transferred the highly valuable SEX.COM to another party in the absence of a valid right to do so.[375] Conversion further extends to interference with an owner’s right to control how her property is used, as does trespass to chattels, even if the owner is not dispossessed of the property itself.[376] Given that suspending a domain name renders it unusable by the registrant, such action could also be tortious, even if the registrar allows the registrant to technically retain ownership by leaving the registration record itself undisturbed.

Limiting registrars’ power to seize domain names would not leave registrars without a remedy for breach of their registration agreements. Registrars could still pursue damages and could even terminate all registration-related and value-added services, such as webhosting, DNS privacy, or email services.[377] But, importantly, a registrar should not be permitted to act against the domain name itself. This stands to reason. The domain name is not in the registrar’s possession; it lies instead with either the registrant or the registry operator. The registrar need not provide any ongoing services for the domain name to remain operational, authoritative DNS resolution being performed by the registry operator. Accordingly, there can be no justification for permitting a registrar to proactively interfere with an already registered and operational domain name in course of terminating a registration agreement.

Property rights also protect registrants from domain name seizure by other DNS intermediaries. Except in the case of certain country code top-level domains, where the registrar and registry operator may be the same entity, registry operators lack contractual privity with registrants.[378] Thus, unless a registry operator is named as a third-party beneficiary in a registration agreement,[379] the registry operator would have no contractual basis to seize a registrant’s domain name for violation of its flow-down terms. Under these circumstances, a registry operator that interfered with a registrant-owned domain name would just as surely be subject to claims for conversion or trespass to chattels. However, if the registry operator is named as a third-party beneficiary, the analysis is admittedly more complicated, as explained infra.[380]

ICANN does not appear to have engaged in domain name seizure yet in its role as IANA. And it would be difficult for ICANN to do so, given that it has no direct control of registry databases or zone files.[381] That said, if ICANN ever tried to interfere with registered domain names—e.g., by ordering registry operators to take action through ICANN’s registry agreements—the same analysis would apply. Whatever contractual rights ICANN might reserve for itself through its flow-down terms, property law should restrict ICANN from seizing assets belonging to registrants as a self-help remedy, especially where ICANN does not perform any core DNS services required to keep domain names operational.

Where Property Law Falls Short

As should be clear from the above discussion, the property status of domain names, when properly understood, adds significant protection to registrants in the face of DNS censorship. However, just as trademark law, with its nuanced limitations on geography and field of use, maps awkwardly to the concept of globally exclusive domain names,[382] the equally vintaged principles of property law, forged in an age of horse and socage, are an imperfect substitute for a modern DNS governance framework. While the common law claims of conversion and trespass to chattels do much to protect registrants from heavy-handed contractual terms by DNS intermediaries, they also leave gaps. Those gaps include heterogeneous treatment under state law and a registrant’s inability to procure a different provider for registry services if a registry operator remains unwilling to service a domain name.

  1. Heterogeneous Treatment under State Law

As a threshold matter, for a registrant to successfully repel DNS censorship using these common law claims, he must first establish that domain names are property; that, as intangible property, they can be the subject of a conversion claim; and that he holds title to that property. If any of these propositions fails, his defense against contractual terms granting DNS intermediaries broad rights to seize domain names based on website content may also fail. And because “property interests are created and defined by state law,”[383] different states may reach different conclusions on these prerequisites.

Although the status of domain names as property is fairly well established,[384] not all states have had occasion to consider the issue. And at least two jurisdictions have sent mixed messages as to where they stand on this foundational question.[385] Even if a state recognizes a registrant’s domain name as property, the registrant may nonetheless be barred from bringing a conversion claim if the state adheres to a strict version of the merger rule.[386] While some courts have found creative ways to skirt the merger requirement—such as finding reason to apply another state’s law or characterizing domain names as physical property—other courts have not hesitated to use the merger rule to stop domain conversion claims in their tracks.[387] Finally, even if a domain name is classified as property and the state allows conversion claims concerning intangible property, a registrant would likely need to establish that he holds title to the seized domain name in order to override contractual terms permitting DNS intermediaries to seize the domain name. Although several cases have suggested or implicitly found that registrants own or hold title to their domain names, and although property theory strongly suggests that registrants should be regarded as owners of their domain names, no U.S. court has had occasion to rule squarely on this topic. The issue is therefore unsettled in American law, and it is possible that different courts might arrive at different conclusions in the future.

Given the common law nature of these issues, DNS censorship may be subjected to heterogenous treatment under state law. The result is that two different registrants might publish identical content on their websites. And yet, if DNS intermediaries attempt to take down both domain names, one registrant might successfully repel the attempt in court while the other is permanently deprived of his domain, depending on the locus of the registrant, the intermediary, or the forum.


With respect to registrars, common law claims of conversion and trespass to chattels should generally prevent registrars from canceling, suspending, or transferring registrants’ domain names as self-help remedies for contract breach. But registrars remain free to refuse new registrations or to decline to renew existing registrations for any reason or no reason. A marginalized registrant in such situations must rely on his ability to find another registrar who will sponsor his domain name or otherwise become a registrar himself.

Registry Operators

With respect to registry operators, as noted previously, if a registry operator that is named as a third-party beneficiary in a registration agreement decides to seize a registered domain name, property law, by itself, might not suffice to protect the registrant from DNS censorship. Unlike registrars, which can terminate their relationships with registrants, and cut off all services in the process, without affecting the operation of already-registered domain names, the same cannot be said of registry operators. A registrant’s ability to continue to own and use a domain name depends on two core DNS services that must continually be performed by a registry operator. First, to preserve ownership, the registry operator must maintain the registrant’s registration record in the registry database for the top-level domain. Second, to use the domain name, the registry operator must continue to resolve DNS requests for the domain name (Steps 4 and 5 in Fig. 1). Failure to perform the former would allow another party to register the domain name, an outcome tantamount to cancelation or transfer. Failure to perform the latter would make the domain name non-operational, functionally equivalent to suspension. Thus, a registry operator cannot exercise its right to terminate services for violation of its flow-down terms without depriving the registrant of his domain name in the process.

Could a registry operator be compelled to continue to maintain a domain name registration record despite having the contractual right to terminate services for violation of its flow-down terms? Perhaps. Under corporate law, a corporation may be required to maintain various shareholder records such as a stock ledger listing every current shareholder or a list of all voting shareholders.[388] Failure to do so could dilute an existing owner’s stake in the corporation or deprive him of his shares altogether. And, given the long-recognized status of corporate stock as intangible property,[389] such inaction on the part of a corporation would easily give rise to a claim for conversion of the shareholder’s personal property. In a sense, requiring a corporation to maintain an accurate shareholder registry is more akin to a prohibition against acting—i.e., improperly assigning an owner’s shares to another party—than to a requirement to perform ongoing service.

In the same manner, preventing registry operators from deleting existing registration records should be viewed as an extension of the prohibition against conversion rather than the forced provision of services. Thus, a registry operator should have no more right to seize a domain name owned by a registrant as a self-help remedy for contract breach than a registrar would have. That the registry operator must continue to maintain the registration record of the breaching registrant to avoid running afoul of this prohibition should not change the analysis.

But the same cannot be said for the second core DNS service—resolving DNS requests for the domain name. Unlike the duty to maintain an accurate registry database, which could just as easily be viewed as a prohibition against recording competing ownership records, resolving DNS requests is unambiguously a proactive service. A registrant’s property interest in his domain name notwithstanding, it’s not clear whether courts would prevent a registry operator from exercising its right to terminate DNS resolution services for breach of its contract terms—at least under existing law. Although a registrant would still retain title to his domain name if a registry operator ceased to provide DNS resolution services,[390] the domain would effectively be useless.[391] Many professional domainers are happy to maintain domain names only as investment assets without using them to resolve to any meaningful websites, but those assets carry value only because they could be used to generate web traffic (through DNS resolution) at any time. To perpetually refuse to resolve a domain name is to destroy its value entirely.

Even if registry operators could somehow be prevented from terminating for breach and be compelled to provide DNS resolution services for registered domain names,[392] they, like registrars, nonetheless reserve the right to refuse to register a domain name in the first place or to decline to renew an existing registration for any reason or no reason. And, whereas a registrant might easily replace a registrar that refuses to renew an existing registration, an uncooperative registry operator cannot be replaced. A domain name cannot be transferred to a different registry operator any more than a .COM domain name can be transferred to the .NET top-level domain while remaining the same domain name. If a registry operator refuses to renew an existing domain name, the registrant will inevitably lose her domain name once her current registration term expires.

Could a registry operator be compelled, under current law, to service any and all registration requests? Most likely not. Although the law of common carriage, a subset of the law of bailment, requires certain classes of service providers to transport goods or persons without discrimination,[393] U.S. courts historically have been unwilling to classify telecommunication service providers as common carriers under the common law.[394] Registry operators, therefore, are not likely to be subjected to common carriage requirements absent a statutory basis.[395]

In sum, although existing property law should generally protect registrants from DNS censorship at the hands of registrars or ICANN, it provides imperfect coverage against a registry operator determined to stamp out an offending domain name. While some registry operators may lack the contractual basis to enforce their flow-down terms, others have established the right to terminate DNS resolution services through third-party beneficiary status and, thus, render controversial domain names useless. And whatever claims a registrant might successfully mount against registrars or registry operators under existing property law for interference during a registration term, both DNS intermediaries can decline to renew an existing domain name for breach of a morality clause, with the refusal of a registry operator ultimately proving fatal.

Filling the Gaps

This section presents three potential options for filling the gaps left by traditional property law. Those options include enacting new federal law to protect domain names in the United States, leveraging ICANN’s top-down power to prohibit DNS censorship, and creating a new DNS altogether.

  1. Federal Law

“Property and law are born together, and die together. Before laws were made, there was no property; take away laws, and property ceases.”[396] This statement, penned by Jeremy Bentham more than 200 years ago, finds meaningful application in the modern DNS. While traditional, common law doctrines of property and conversion protect domain name owners in important ways, their gaps, if aggressively exploited, could effectively kill domain name property altogether, paving the way for DNS intermediaries to become the new arbiters of speech on the public Internet. One obvious solution to prevent this outcome is to enact new federal legislation to protect registrants from DNS censorship.

On the modest side, such legislation could be relatively simple, doing little more than making explicit Congress’s already implicit recognition of domain names as property in the ACPA and the PRO-IP Act.[397] By further establishing registrants’ title-rights to their domain name property and providing a federal cause of action for conversion thereof, Congress could solve the problem of heterogeneous treatment of domain name theft and interference under state common law.

On the more ambitious side, Congress could enshrine a new class of intellectual property in domain names, on par with federally protected patents, trademarks, and copyrights. Going beyond merely establishing property rights in domain names, such legislation could further ensure that the DNS remains available to all by subjecting DNS intermediaries to common carriage requirements.[398] Preventing registry operators from silencing disfavored viewpoints by declining to renew domain names associated with controversial websites would do much to advance the goal of a content-neutral DNS.

While DNS intermediaries might understandably object to any legislation that shifts power over domain names to registrants, such a federal regulatory scheme could also include important protections for DNS intermediaries. Consider that if property rights prevent DNS intermediaries from seizing registrants’ title-held domain names for breach of contract, that prohibition would likely extend to domain names associated with infringing or illegal content. As argued supra, a lessor who retains title to his property may retake possession from a breaching lessee under the terms of his lease agreement. But if the non-breaching party sold, rather than leased, the subject property, the law should not afford him the right to re-appropriate the property, where he has no security interest in it, as a general, self-help remedy for breach. Whether the breach stemmed from legal, infringing, or illegal conduct should make no difference in terms of property rights. The seller’s rights against a party engaging in illegal conduct are limited to terminating services, not seizing property believed to be used to facilitate the crime.

Federal law could give back to DNS intermediaries what pure property law takes away by enumerating circumstances in which intermediaries could suspend, or potentially even cancel, domain names associated with clearly illegal or infringing content.[399] Or, if it would still be inappropriate to entrust private parties with enforcement of matters better left to courts, Congress could chart a middle course by providing immunity to DNS intermediaries for taking no action against domain names associated with illegal or infringing content until presented with a court order.[400]

Others might object to federal protection of domain names on the grounds that doing so would require the U.S. to effectively regulate ICANN, a role the U.S. relinquished to the international community in 2016. However, targeted laws affecting certain domain name practices in the United States are not inconsistent with allowing ICANN to remain an independent body or with ICANN’s exercise of the broader IANA function. Protecting domain name property at the federal level would no more reassert U.S. control over ICANN than the Ninth Circuit’s existing recognition of domain name conversion claims allows California to regulate ICANN. In the first place, Congress could explicitly limit the ambit of the law to domain names registered through registrars or registry operators having a presence in the United States. Moreover, protection could be limited to unrestricted generic top-level domains, leaving other countries free to set their own policies for country code top-level domains (even where a registry operator may be located within the U.S.) and leaving industries free to regulate their own restricted and sponsored top-level domains.

Existing federal laws related to domain names—namely, the ACPA and PRO-IP Act—have successfully coexisted with an independent ICANN.[401] And given the special status of the .COM top-level domain on the Internet, the NTIA currently requires Verisign to operate the .COM registry in a content-neutral manner through the Cooperative Agreement pursuant to which Verisign manages the authoritative root zone file.[402] Thus, the U.S. could prevent DNS censorship solely within its borders without disrupting ICANN’s right to self-governance through its international multi-stakeholder process.

Top-Down ICANN Policy

Absent federal protection of domain names, ICANN could enforce content neutrality though flow-down terms in its registrar accreditation agreement or registry agreements.[403] However, given ICANN’s uniquely powerful position over global DNS policy, inviting ICANN to engage in direct policymaking over Internet content could prove a dangerous proposition. Even if ICANN initially exercised such new powers to ensure DNS content neutrality, one can easily imagine a progression of events through which those powers could eventually be turned to the opposite purpose. Succumbing to public pressure, ICANN might see fit to make narrow exceptions, granting registry operators and registrars latitude to formulate their own policies for the most extreme forms of illegal, violent, or hateful speech. Consistent with historical examples of censorship creep, those exceptions would likely expand over time. In the fullness of time, what began as areas of permissive content regulation might evolve into areas of required content regulation, with ICANN’s transformation into a global content regulator complete. Thus, enlisting ICANN to protect content neutrality could very well prove fatal to the cause.

A more measured approach might be for ICANN to simply enumerate the criteria under which a registration may be suspended, canceled, or transferred—for example, limiting such actions to fraud, non-payment,[404] and valid court orders. But this approach could theoretically evolve in a similar manner, again leading to the unintended consequence of greater censorship in the DNS ecosystem. Thus, the goal of a content-neutral DNS might best be served by encouraging ICANN to take a hands-off approach to censorship rather than try to proactively prevent it.

Alternative DNS

If protection does not come at the hands of either Congress or ICANN, and if DNS censorship continues to expand, then the only remaining option to ensure an open Internet for all viewpoints may be to create an alternative DNS. Nothing inherent in the world-wide web requires clients to use the existing ICANN-administered DNS to translate human-readable strings into IP addresses. Browsers and DNS resolvers could be configured to point to different nameservers and zone files that stand apart from the current DNS hierarchy.

Although alternative DNS systems have been proposed and even attempted in the past,[405] the broader Internet community has not found a sufficiently compelling reason to adopt a competing service. DNS censorship could change that.[406] Moreover, the advent of blockchain-based technology has now made the once-impractical idea of a decentralized DNS a real possibility, as some experts have proposed.[407] Apart from protecting domain names from interference by governments or private parties, shifting the burden of maintaining authoritative zone files and resolving DNS requests to a distributed ledger could obviate the need for registration and renewal fees and yield other interesting benefits.[408]

To be sure, many details would need to be worked out to implement an alternative DNS. And creating a parallel authority could introduce new problems related to naming collisions and trademark rights. But if nothing else, given ICANN’s strong desire to avoid a split-root world,[409] the possibility of a competing DNS could alert ICANN and DNS intermediaries to the risk that DNS censorship imposes to their hegemony and spur them to take action. It should therefore be explored in earnest.


In the heady, innocent days of the early Internet—when collaborating universities sought only to create an easier way to keep track of each other’s host servers—the notion of domain names as property seemed both unnecessary and inappropriate. But with the rampant commercialization of cyberspace in the 1990s and early 2000s, it became clear that domain names not only possessed immense economic value but also shared enough core similarities with other commercial assets that their status as property could not be denied. Until recently, merely classifying domain names as property sufficed to protect registrants from would-be domain thieves through the classic, property-based torts of conversion and trespass to chattels. But with the rise in private censorship by DNS intermediaries, elucidating the precise nature of that property interest has become essential to determining whether intermediaries may seize domain names based on registrants’ controversial, but clearly legal, speech.

Careful analysis of the property nature of domain names and the roles that intermediaries play in the DNS shows that locating title to domain names with registrants is the most defensible conclusion. Once that premise is established, it becomes clear that the law should not permit DNS intermediaries to seize registrants’ domain name property as a self-help remedy for contract breach. And, without an enforceable contractual right for intermediaries to do so, registrants could successfully bring claims against interfering intermediaries for conversion or trespass to chattels. Thus, a robust theory of the property nature of domain names goes a long way toward protecting registrants from DNS censorship.

But centuries-old doctrines of property law do not map cleanly to the modern, global DNS, leaving registrants vulnerable to registry operators who refuse to register or renew domain names that violate their self-constructed moral standards. Congress or ICANN could shore up these deficiencies by passing laws (in the case of Congress) or establishing contractual policies (in the case of ICANN) that protect domain names associated with legal websites from seizure and potentially even establish a public right to register and renew domain names without discrimination based on viewpoint. If either body fails to act and content regulation continues to grow unabated, minority resistance to DNS censorship could eventually rise to the level of creating competing, decentralized systems for name-to-address translation.

Short of these supplements, however, existing property law can still do much to protect registrants from DNS censorship at the hands of registrars or even of ICANN. The crucial question, therefore, becomes whether courts will themselves practice the neutrality required to treat laudable and execrable registrants alike. It’s been said that hard cases make bad law. If a trillion-dollar, upstanding corporation could prevail on a conversion claim for the loss of GOOGLE.COM despite clear contractual terms justifying seizure or non-renewal—a case that is unlikely ever to arise—the operators of offensive and hateful sites like DAILYSTORMER.COM should prevail on similar facts—cases that will inevitably find their way to courts over the next several years.[410]

  1. * I would like to thank Christopher Yoo, Michael Froomkin, Milton Mueller, Ryan Calo, and Konstantinos Komaitis for helpful feedback and suggestions during the drafting process. Thanks also to Alexandra Bakalar for all the great research assistance. Original illustrations use icons made by Freepik and Kiranshastry from The views expressed herein are entirely my own and do not necessarily reflect any policy positions held or endorsed by any current or former clients or employers.
  2. . Daniel Van Boom & Claire Reilly, Neo-Nazi Site The Daily Stormer Down After Losing Domain, CNET (Aug. 14, 2017, 11:19 PM), []; see also Domain Name Registrar Stats, DomainState, [] (last visited Nov. 5, 2020) (for GoDaddy’s share of global domain name and hosting market).
  3. . Bill Chappell, Neo-Nazi Site Daily Stormer Is Banned By Google After Attempted Move From GoDaddy, NPR (Aug. 14, 2017, 8:30 AM), [].
  4. . Michele Neylon, DailyStormer Offline as Google Pulls Domain Registration, InternetNews (Aug. 15, 2017), [].
  5. . Jim Finkle, Neo-Nazi Group Moves to ‘Dark Web’ After Website Goes Down, Reuters (Aug. 15, 2017, 7:42 AM), [].
  6. . Kassy Dillon, Introducing ‘Gab’: Free Speech Twitter Alternative, Wash. Examiner (Aug. 21, 2016, 11:07 AM), [].
  7. . Catherine Shu, Far-right Social Network Gab Goes Offline After GoDaddy Tells it to Find Another Domain Registrar, TechCrunch (Oct. 28, 2018, 11:28 PM), [].
  8. . Id.
  9. . The Suspension of, .Me (Nov. 20, 2018), []; Matt Binder,, A Major Hub for Hate Speech and Misogyny, Suspended by .ME registry, Mashable (Nov. 20, 2018), [].
  10. 9. Id.
  11. . See Michael Kunzelman, Online Registrar Threatens to Drop Anti-Immigration Website, ABC News (June 22, 2020, 3:16 PM), [] (describing’s threats to suspend VDARE.COM for its anti-immigration views).
  12. . See infra Part II.A.
  13. . See, e.g., FAQs, Change the Terms, [] (last visited Oct. 18, 2020) (promoting the work of a coalition of civil rights groups to encourage technology companies to use their terms of service to curb “hateful activity,” including, notably, companies that provide domain name services).
  14. . See, e.g., Jeremy Malcom, Cindy Cohn & Danny O’Brien, Fighting Neo-Nazis and the Future of Free Expression, Electronic Frontier Found. (Aug. 17, 2017), [] (“Companies that manage domain names, including GoDaddy and Google, should draw a hard line: they should not suspend or impair domain names based on the expressive content of websites or services.”) [hereinafter Malcom et al., Fighting Neo-Nazis].
  15. . Id. (“[W]e must also recognize that on the Internet, any tactic used now to silence neo-Nazis will soon be used against others, including people whose opinions we agree with.”); see also Michael C. Dorf, Free Speech Issues Raised by Internet Companies Denying Service to Neo-Nazi Sites, Verdict (Aug. 23, 2017), [] (posing hypotheticals of other groups or causes that could be de-platformed by means of DNS takedown); Will Oremus, GoDaddy Joins the Resistance, Slate (Aug. 16, 2017, 2:10 PM), [] (“Cutting off domain hosting is a potent weapon against the purveyors of objectionable content—and it could be double-edged.”).
  16. . See, e.g., Jeremy Malcolm & Mitch Stoltz, How Threats Against Domain Names Are Used to Censor Content, Electronic Frontier Found. (July 27, 2017), [] (noting the lack of due process protections for registrants whose domain names are taken down for service violations) [hereinafter Malcolm & Stoltz, Threats]; Annemarie Bridy, Notice and Takedown in the Domain Name System: ICANN’s Ambivalent Drift into Online Content Regulation, 74 Wash. & Lee L. Rev. 1345, 1385 (2017) (“Lack of transparency and due process in such programs will make them inherently vulnerable to inconsistency, mistake, and abuse and could transform the DNS into a potent tool for suppressing disfavored speech.”) [hereinafter Bridy, Notice and Takedown].
  17. . See Christopher S. Yoo, Free Speech and the Myth of the Internet as an Unintermediated Experience, 78 Geo. Wash. L. Rev. 697, 699, 702 (2010) (“Under current law, the First Amendment only restricts the actions of state actors and does not restrict the actions of private actors.”) and (“[F]ree speech considerations favor preserving intermediaries’ editorial discretion unless the relevant technologies fall within a narrow range of exceptions, all of which the Court has found to be inapplicable to the Internet.”).
  18. . See ICANN’s Historical Relationship with the U.S. Government, ICANN, [] (last visited Oct. 18, 2020) (detailing the multi-year process by which the U.S. Department of Commerce turned control of ICANN over to a system of global stakeholders).
  19. . See infra Parts IV.A–C.
  20. . See Kremen v. Cohen, 337 F.3d 1024, 1035 (9th Cir. 2003).
  21. . This definition and the explanation that follows assume the use of IPv4 addresses which are still used by most Internet devices. Although a movement is under way to convert all public Internet traffic to the more flexible and capacious IPv6 standard, that development is not germane to this article and has no bearing on its arguments. See generally Andy Patrizio, IPv4 vs. IPv6: What’s the Difference? Avast (May 8, 2020), [].
  22. . Frederick M. Abbott, On the Duality of Internet Domain Names: Propertization and Its Discontents, 3 N.Y.U. J. Intell. Prop. & Ent. L. 1, 3 (2013) (“[T]he domain name is the ‘human friendly’ way of solving the memory and data entry problem.”).
  23. . Nat’l Research Council, Signposts in Cyberspace: The Domain Name System and Internet Navigation 41 (2005).
  24. . See J. Postel & J. Reynolds, Request for Comments 920: Domain Requirements, Internet Engineering Task Force 7–8 (Oct. 1984), [].
  25. . See GlobalSantaFe Corp. v., 250 F.Supp.2d 610, 618–19 (E.D. Va. 2003); Nat’l Research Council, supra note 22 at 120–21; Mark E. Jeftovic, Managing Mission-Critical Domains and DNS 32 (2018). Registry operators are sometimes referred to simply as “registries.” To avoid any confusion with the registry databases maintained by registry operators, this article uses the long form “registry operators” throughout.
  26. . See Root Zone Database, Internet Assigned Numbers Authority, [] (last visited Oct. 18, 2020).
  27. . The savvy DNS practitioner will observe that the process has been simplified and that certain intermediate steps have been omitted for ease of discussion.
  28. . While the cache may be empty, a DNS resolver should nonetheless be pre-programmed with the names and IP addresses of the thirteen root servers. Without this a priori information, authoritative DNS resolution is not possible. Daniel Karrenberg, The Internet Domain Name System Explained for Non-Experts 4–5 (2017), [].
  29. . Nat’l Research Council, supra note 22, at 96–97.
  30. . The rationale for storing the IP address of an authoritative nameserver in the zone file, rather than the IP address of the host, is that the domain name owner can change the IP address of the host at any time by simply updating the authoritative nameserver instead of requiring the registry operator to change the zone file. Otherwise, in a sea of millions of domain names within a top-level domain with hosts constantly shifting from one IP address to another, a registry operator would potentially need to update the zone file for the top-level domain many times per second.
  31. . The user’s computer may also update its own cache to avoid the need to request the IP address again until the time-to-live (specified in the DNS record returned by the authoritative nameserver) expires.
  32. . In this case, a hypertext transfer protocol (HTTP) request.
  33. . Although the DNS is often rightly described as a decentralized system, it is nonetheless centralized insofar as only one entity—the registry operator for the relevant top-level domain—maintains the zone file for a given top-level domain and responds to DNS queries for domain names within the zone file.
  34. . See Jeff Petters, What is DNS TTL + Best Practices, Varonis: Inside Out Security Blog [] (last updated July 14, 2020) (calculating the average TTL value of the top 500 sites at 6,468 seconds or just under two hours).
  35. . See GlobalSantaFe Corp. v., 250 F. Supp. 2d 610, 620 n.31 (E.D. Va. 2003) (“[S]ince use of domain names is so ubiquitous, few if any users will know the relevant IP address.”).
  36. . See infra Part II.A.
  37. . See Malcom et al., Fighting Neo-Nazis, supra note 13 (“Domain name companies also have little claim to be publishers, or speakers in their own right, with respect to the contents of websites. Like the suppliers of ink or electrical power to a pamphleteer, the companies that sponsor domain name registrations have no direct connection to Internet content. Domain name registrars have even less connection to speech than a conduit provider such as an ISP, as the contents of a website or service never touch the registrar’s systems.”).
  38. . See, e.g., Xuebiao Yuchi, Guanggang Geng, Zhiwei Yan & Xiaodong Lee, China Internet Network Information Center, Towards Tackling Privacy Disclosure Issues in Domain Name Service 813 (describing the DNS as “the global Internet’s phonebook”); Becky Hogge, The Great Phonebook in the Sky, New Statesman (Feb. 7, 2008) [] (“Think of it as a great big telephone directory in the sky.”).
  39. . See infra Part II.B.
  40. . See Nat’l Research Council, supra note 22, at 129.
  41. . See Root Zone Database, supra note 25 (listing each operational top-level domain).
  42. . Id.
  43. . See Nat’l Research Council, supra note 22, at 114 (comparing the different categories of generic top-level domains, including sponsored-restrictive, sponsored-unrestrictive, unsponsored-restrictive, and unsponsored-unrestrictive).
  44. . See Paul Sawers, Google Domains Moves to a ‘.Google’ domain, VentureBeat (Mar. 30, 2016, 4:23 AM), [].
  45. . In this explanation, I have excluded the remaining infrastructure and test categories, which consist of fifteen top-level domains used only for technical and test purposes and not in conjunction with any meaningful websites. See Nat’l Research Council, supra note 22, at 114–20.
  46. . Id. at 113; Jeftovic, supra note 24, at 33–34.
  47. . Country Domains: A Comprehensive ccTLD List, Ionos, [] (last visited Oct. 18, 2020).
  48. . Nat’l Research Council, supra note 22, at 10; Common Questions on Delegating and Transferring Country-Code Top-Level Domains (ccTLDs), Internet Assigned Numbers Authority [] (last visited Oct. 18, 2020) (“For each ccTLD, at a minimum both the manager and the administrative contact must be resident in the country to which the domain is designated. This means they are accountable to the local community and subject to local law.”).
  49. . For example, Verisign, a U.S. company, currently operates the .CC (Cocos Island) and .TV (Tuvalu) ccTLDs on behalf of the local delegated managers. See Get Creative With A .cc Domain Name, Verisign, [] (last visited Oct. 18, 2020); A .tv Domain Name Is Where the World Turns for Entertainment, Verisign,
    en_US/domain-names/tv-domain-names/index.xhtml [] (last visited Oct. 18, 2020).
  50. . See About ccTLD Compliance, ICANN, [] (last visited Oct. 18, 2020) (“The ccTLD policies regarding registration, accreditation of registrars and Whois are managed according to the relevant oversight and governance mechanisms within the country, with no role for ICANN’s Compliance department in these areas.”).
  51. . About .jp domains, GoDaddy, [] (last visited Oct. 18, 2020); see also About ccTLDs (Country-Code Domain Names), GoDaddy [] (last visited Oct. 18, 2020) (providing specific requirements and considerations for various ccTLDs).
  52. . See Nat’l Research Council, supra note 22, at 116–17 (noting that the distinction between generic top-level domains and country code top-level domains has significantly eroded).
  53. . Id. at 129 (“There is always one, and only one, registry for a given TLD, but, as noted above, an organization can be the registry operator for more than one TLD.”). For example, Binky Moon, LLC d/b/a “Donuts” manages nearly 200 different top-level domains, including .COMPANY, .GIFTS, and .TOYS. See also Root Zone Database, supra note 25.
  54. . See supra Part I.A.
  55. . Registry Agreement: Appendix C, ICANN, §§ C2.1, C5, (June 6, 2003) [] (“[T]he registry database [is] the authoritative source of domain names and their associated hosts (name servers).”); GlobalSantaFe Corp., v., 250 F. Supp. 2d 610, 619 (E.D. Va. 2003) (“The registry . . . maintain[s] and operat[es] the unified Registry Database, which contains all domain names registered by all registrants and registrars in a given top level domain . . . .”).
  56. . See About WHOIS, ICANN [] (last visited Oct. 18, 2020). Although the .COM and .NET legacy gTLDs operate in a “thin registry” model in which information about the registrar, rather than the registrant, is stored in the registry database, information about the registrant is nonetheless accessible through the WHOIS service, which queries both the registry operator’s and the registrar’s databases to identify the end registrant. See What Are Thick and Thin Entries?, ICANN, [] (last visited Oct. 18, 2020). In any event, an effort is under way to convert .COM and .NET to “thick registries.” Thick WHOIS, ICANN (May 7, 2019), [].
  57. . See infra Part III.D.3.
  58. . See Nat’l Research Council, supra note 22, at 135–37 (chronicling the development of separate registry and registrar functions and entities).
  59. . As of this article, registration fees generally range from $2 to $20. Maxym Martineau, How much does a domain name cost?, GoDaddy (July, 8, 2019), [].
  60. . See Nat’l Research Council, supra note 22, at 136 (“Under the terms of their agreements with ICANN, gTLD registries are required to permit registrars to provide Internet domain name registration services within their top-level domains.”).
  61. . See generally ICANN, Descriptions and Contact Information for ICANN-Accredited Registrars, [] (last visited Oct. 18, 2020).
  62. . See Transfer Policy, ICANN (June 1, 2016), [] (providing registrants with the general right to transfer domain names between registrars).
  63. . FAQs, ICANN [] (last visited Oct. 18, 2020) (“Each registrar has the flexibility to offer initial and renewal [registrations] in one-year increments, provided that the maximum remaining unexpired term shall not exceed ten years.”).
  64. . Jeftovic, supra note 24, at 22–26.
  65. . Id. at 25–26.
  66. . See id. (explaining that final expiration of a domain name registration will result in deletion of the registration record from the authoritative registry database, which record would include any authoritative association between the domain name and the sponsoring registrar).
  67. . See AGP Limits Policy and Draft Implementation Plan, ICANN, [] (last visited Oct. 18, 2020) (“Once a domain name is deleted by the registry at this stage, it is immediately available for registration by any registrant through any registrar.”).
  68. . See generally Najmeh Miramirkhani, Timothy Barron, Michael Ferdman & Nick Nikiforakis, Panning for Understanding the Dynamics of Domain Dropcatching, 2018 IW3C2 (International World Wide Web Conference Committee, 2018).
  69. . See Jeftovic, supra note 24, at 25 (“If the [expired] domain has any marginal value . . ., then the ‘drop-catchers’ will now converge and the domain will be reregistered within a few milliseconds.”).
  70. . See infra Part III.E.3.
  71. . See About Us, Internet Assigned Numbers Authority, [] (last visited Oct. 18, 2019) (describing the IANA functions).
  72. . Joel Snyder, Konstantinos Komaitis & Andrei Robachevsky, The History of IANA: An Extended Timeline with Citations and Commentary, Internet Society 5 (Jan. 2017), [].
  73. . Id. at 2–5.
  74. . Base Registry Agreement, ICANN, § 4.1 [] (last visited Oct. 18, 2020) [hereinafter Base Registry Agreement, ICANN].
  75. . Id. at § 4.2.
  76. . See ICANN-NSI Registry Agreement, ICANN, § 23 (Sept. 28, 1999), [] (providing no presumptive right to renewal after eight years); See also .org Registry Agreement, ICANN, § 5.1 (May 25, 2001), [].
  77. . See Number Resources, Internet Assigned Numbers Authority, [] (last visited Oct. 18, 2020).
  78. . See Root Servers, Internet Assigned Numbers Authority, [] (last visited Oct. 18, 2020).
  79. . Jeftovic, supra note 24, at 37.
  80. . GlobalSantaFe Corp. v., 250 F. Supp. 2d 610, 619–20 (E.D. Va. 2003).
  81. . Domain Name Industry, ICANN, [] (last visited Oct. 18, 2020) (“Many registrars also offer other services such as web hosting, privacy/proxy, website builder, etc.”).
  82. . See How Do I Find The DNS Provider Of My Domain?, Intermedia, [] (last visited Oct. 18, 2020) (explaining that DNS hosting for a domain name is commonly provided by the domain name registrar).
  83. . See Bridy, Notice and Takedown, supra note 15, at 1361 (describing ICANN’s “narrow technical mandate”).
