On 18 August 2026, ICANN published for public comment the Initial Report of its DNS Abuse Mitigation Policy Development Process (PDP 1). At the heart of the discussion are Associated Domain Checks (ADCs): when a registrar receives sufficiently specific information indicating that a domain name is involved in abusive activity, it could be required to look beyond that individual domain and investigate whether other domain names associated with the same customer are being used for similar abuse.
WIPO Calls for a Broader Scope
In its comments submitted on 25 September 2026, the WIPO Arbitration and Mediation Center supports this approach but points to one of its key limitations: the proposed checks would remain largely confined to the portfolio held with a single registrar.
Yet these administrative boundaries can themselves be exploited by malicious actors. In cybersquatting cases, certain patterns of conduct appear designed to make it more difficult to identify coherent portfolios of domain names and, where appropriate, to consolidate them into a single UDRP proceeding. Spreading registrations across multiple registrars, accounts or apparent identities can therefore turn the fragmentation of the system into a procedural obstacle.
WIPO consequently suggests exploring mechanisms that would ultimately allow checks to be conducted across registrars, for example by comparing certain data elements they collect in anonymised form. However, WIPO does not specify which data could serve as a common denominator or what technical mechanism should be used to match them. At this stage, the proposal is therefore more a direction of travel than a ready-made architecture.
This logic is not entirely new to online brand protection professionals. At IP Twins, our Detective monitoring tool already enables us to cross-reference information collected on domain names and uncover potential connections between them. These correlations can help assemble the evidence needed to consolidate multiple domain names into a single UDRP proceeding, including where registrations have been deliberately dispersed. Experience shows that a domain name viewed in isolation often tells only part of the story. Analysing the connections between multiple registrations can reveal a strategy that would remain invisible if each domain were examined separately.
From the Domain Name to the Network
Behind these technical discussions lies a more profound evolution.
For many years, the fight against online abuse has largely followed an individual approach: one domain name, one report, one investigation, one measure. That approach reaches its limits when the same actors can register dozens of domain names, rapidly change infrastructure and move from one registrar to another.
The question remains, however, of what could serve as a common denominator across different registrars. WIPO does not resolve this issue. One possible avenue would be to associate certain payment methods with a common pseudonymised identifier, making it possible to detect that several domain names were registered using the same payment method without publicly revealing the underlying payment data.
This possibility echoes a broader development that we recently discussed in relation to the fight against sports piracy in Belgium. The Belgian decisions examined in that article require intermediaries to disclose not only identification data, but also certain information relating to payment methods, crypto-assets and connection logs. The same underlying idea is emerging: effectively identifying the actor behind an illicit infrastructure may sometimes require looking beyond domain name registration data alone.
An identifier linked to a payment method would, of course, have its limitations. Prepaid cards, the use of different payment methods, or the fraudulent use of cards belonging to third parties would prevent it from constituting proof of identity. Such an identifier would therefore be an indicator of a possible connection, rather than sufficient evidence on its own. Combined with other elements, however, it could help reveal what a domain-by-domain analysis leaves hidden.
Associated Domain Checks therefore offer another way of approaching the problem: treating a reported domain name not merely as the subject of an investigation, but as its starting point.
The question now is how far that investigation should be allowed to reach.
About IP Twins
IP Twins assists trademark owners in monitoring, identifying and addressing online infringements. Our monitoring tools, including Detective, help identify domain names that may infringe our clients’ rights while also enabling available information to be cross-referenced in order to uncover connections between multiple registrations. This analysis can support a coherent enforcement strategy, including the consolidation of multiple domain names into a single alternative dispute resolution proceeding where the circumstances permit.