DNS Abuse Policy
Last updated: [TBD] · This is a working draft pending legal review.
1. About this policy
Coded B.V. ("Coded", "we", "us", "our") provides hosting and technical infrastructure that lets merchants run their own branded online shops and other projects ("projects") under an Organization. As part of that infrastructure, Coded provides or forwards domain-registration and domain-management services so that merchants can connect a domain name to a project. Coded acts in these matters in its capacity as a domain and hosting provider. Where domains are sponsored, registered or resold through an upstream registry or registrar partner ([to be confirmed]), Coded acts as an intermediary between the merchant and that partner.
This policy explains how Coded prevents, detects, investigates and mitigates DNS abuse affecting domains and hosting it provides or manages. It describes what DNS abuse is, how to report it, what evidence we need, how we investigate, what mitigation actions we may take, and how we treat the affected registrant or merchant. Coded is a hosting and intermediary service. Coded is not an online marketplace, and Coded is not the seller, merchant or trader of record for any product or service offered through a merchant's shop or hosted on a merchant's domain. The merchant is responsible for the content it hosts and for the lawful use of any domain connected to its projects.
This policy is written to be consistent with, among other applicable laws and industry standards:
- the DNS-abuse obligations in the ICANN Registrar Accreditation Agreement and Registry Agreement as amended (the targeted DNS-abuse amendments effective 5 April 2024), to the extent Coded acts as, or through, a contracted party; and
- the EU NIS2 Directive (Directive (EU) 2022/2555), including the obligations it places on TLD name registries and entities providing domain-name registration services, such as maintaining accurate registration data and responding to lawful requests.
Coded is an international company; references to these instruments are included for transparency, and we apply this policy consistently to domains and hosting we provide wherever the reporter, the registrant or the harm is located, in addition to any mandatory local-law obligations and any stricter requirements imposed by an upstream registry, registrar or registry operator.
Capitalized terms not defined here have the meaning given in our Terms of Service, Acceptable Use Policy and Merchant Agreement, of which this policy forms part.
2. What DNS abuse means
For the purposes of this policy, "DNS abuse" means any of the following five categories of harmful activity carried out using a domain name that Coded provides, registers, manages or forwards, consistent with the definition adopted under the ICANN DNS-abuse framework:
- Malware — malicious code, software or content installed onto, or distributed through, a device or system without the user's informed consent, designed to harm a device, system, network or data, or to gain unauthorized access (including viruses, worms, trojans, spyware, ransomware and similar code).
- Botnets — collections of compromised, internet-connected devices controlled remotely, and the use of a domain to operate command-and-control infrastructure for such a network.
- Phishing — the use of a domain to deceive users into divulging sensitive personal, financial, authentication or account data, including by impersonating a legitimate entity, brand, service or person.
- Pharming — the redirection of users to fraudulent or malicious destinations through unauthorized manipulation of the DNS, such as DNS hijacking, cache poisoning or unauthorized resolution changes.
- Spam, but only where spam is used as a delivery mechanism for any of the four categories above — for example bulk unsolicited messages that distribute malware or carry out phishing. Spam that does not serve as a delivery mechanism for malware, botnets, phishing or pharming is addressed, where relevant, under our Acceptable Use Policy and Anti-Spam rules rather than as DNS abuse under this policy.
DNS abuse is distinct from, and additional to, illegal content hosted on a project (counterfeit goods, IP infringement, unlawful listings, and similar), which is handled under our Reporting Illegal Content process at /legal/dsa-notice, and from copyright infringement, which is handled under our Copyright & DMCA Policy. A single matter may involve more than one process; we route each part to the correct procedure.
3. Reporting DNS abuse
Anyone — including individuals, security researchers, brand owners, ISPs, CERTs/CSIRTs, registries, registrars, and law-enforcement or regulatory authorities — may report suspected DNS abuse. You do not need to be directly affected to submit a report.
3.1 How to report
Send your report by email to report@coded.co, which is our abuse and DNS-abuse intake address. To allow us to act quickly, please send one report per distinct abuse event where practical, and use a clear subject line (for example, "DNS abuse — phishing — example.coded.shop").
3.2 Required evidence
So we can assess your report diligently and act on actionable evidence, please include as much of the following as you can:
- The affected domain name(s) or URL(s), stated precisely and in full, and, where relevant, the specific path, subdomain or resource involved.
- The category of DNS abuse you are reporting (malware, botnet, phishing, pharming, or spam used as a delivery mechanism), and a short explanation of why.
- Supporting evidence appropriate to the category — for example: the phishing or malware URL and what it impersonates or delivers; screenshots; message headers and full email source for spam-delivered abuse; malware sample hashes or sandbox/scanner reports; blocklist or threat-intelligence references; packet captures or logs for botnet command-and-control; and timestamps with time zone.
- Your name and contact details, so we can acknowledge the report and request clarification. Reports may be submitted in confidence; we will not disclose your identity to the registrant except where required by law or with your consent. We accept anonymous reports but may be limited in following up on them.
- A statement of good-faith belief that the information in your report is accurate to the best of your knowledge.
We may also receive reports through trusted notifiers, blocklists, threat-intelligence feeds, upstream registry or registrar abuse channels, and competent authorities, and we may act on our own detection.
4. How we investigate
When we receive a DNS-abuse report, or otherwise become aware of suspected DNS abuse, we handle it in a timely, diligent, non-arbitrary and proportionate manner:
- Acknowledgement — where you provided contact details, we acknowledge receipt without undue delay.
- Triage and classification — we classify the report by category and severity, deduplicate against existing cases, and prioritize matters that present a clear and ongoing risk of harm (for example active phishing or live malware distribution).
- Verification — we assess whether there is actionable evidence that the domain is being used for DNS abuse. This may include reviewing the reported URLs and resources, consulting reputable scanners, blocklists and threat-intelligence sources, checking DNS and hosting configuration, and examining whether the domain itself is being abused or whether the domain is legitimate but a single resource has been compromised.
- Determining responsibility and scope — we consider whether the appropriate response sits at the hosting/content layer, the DNS/domain layer, or both, and whether the registrant is the bad actor or an innocent party whose site or account has been compromised.
- Escalation — where Coded is not the responsible party for a given layer (for example where the registry or an upstream registrar must act, or where another hosting provider serves the content), we escalate to the appropriate party through the relevant abuse channel.
We use the least intrusive mitigation that is effective for the harm identified, and we document the basis for each decision (see section 8).
5. Mitigation actions
Where we confirm DNS abuse on actionable evidence, or where we are required to act by a competent authority or an upstream registry/registrar obligation, we may take one or more of the following actions, proportionate to the severity, persistence and nature of the abuse:
- Warning / notice to remediate — notifying the registrant or merchant and giving a reasonable opportunity to remove the abusive content or remediate a compromise, where the situation allows for it without prolonging clear harm.
- Content-level action — removing or disabling access to the specific abusive resource, or restricting the affected project at the hosting layer.
- Suspension of the domain or DNS — disabling resolution of the domain (for example by removing or changing DNS delegation or name-server configuration) so that the abusive site no longer resolves.
- Registry/registrar status codes — applying or requesting client hold or server hold, or comparable status codes, to suspend the domain at the registration layer, where Coded or its registrar partner has that capability.
- Takedown — removing the project, shop or account associated with the abuse.
- Registrant data verification — requiring the registrant or merchant to verify or correct registration and contact data where we have reason to believe it is inaccurate, incomplete or false, and suspending the domain pending verification where appropriate and permitted.
- Account-level action — suspending, restricting or terminating the merchant's Organization, projects, or related services, and, where relevant, related payment facilitation, in line with our Merchant Agreement and Acceptable Use Policy.
- Referral — reporting the matter to competent authorities, the relevant registry or registrar, or to platforms and providers better placed to mitigate the harm.
Mitigation may be applied immediately and without prior notice where the abuse presents an imminent or serious risk of harm (for example active malware distribution, credential-harvesting phishing, or botnet command-and-control), or where prior notice would be unlawful, would frustrate an investigation, or is impractical. In other cases we prefer to give notice and an opportunity to remediate before acting.
6. Registrant notice, good-faith handling and reinstatement
We aim to treat registrants and merchants fairly:
- Notice — except where section 5 permits immediate action, we notify the affected registrant or merchant of the action taken, the category of abuse identified, and how to remediate, using the contact details on file.
- Compromised but legitimate domains — where a legitimate domain or site has been compromised by a third party, our goal is remediation and restoration rather than punishment of the victim; we will work with the registrant to clean up the abuse and restore service.
- Remediation and reinstatement — where the registrant remediates the abuse, corrects inaccurate registration data, or demonstrates that the report was unfounded, we will, where it is within our control and permitted by any upstream registry/registrar, lift the mitigation and restore the domain or service.
- Proportionality and rights — we apply mitigation diligently, objectively and proportionately, with due regard to the legitimate interests and fundamental rights of all parties, including freedom of expression and the interests of innocent third parties.
- Redress — a registrant or merchant who disagrees with a decision under this policy may contest it through our Complaints Procedure, and retains any out-of-court and judicial redress rights available under applicable law. Some decisions taken to satisfy an upstream registry/registrar or a competent authority may be outside Coded's discretion to reverse; we will say so where that is the case.
7. Cooperation with authorities and trusted notifiers
- Competent authorities — we cooperate with law-enforcement, regulatory and supervisory authorities and with CERTs/CSIRTs, and we respond to lawful requests in accordance with our Legal Requests process. Under NIS2, we respond to lawful and duly justified requests from competent authorities to access domain-name registration data necessary for the prevention, investigation, detection or prosecution of crime.
- Trusted notifiers — we give priority handling to reports from recognized trusted notifiers, blocklist operators, registries, registrars and security organizations operating within their area of expertise. Such notifiers should identify themselves and their status when reporting through the channel in section 3.
- Registration-data accuracy — consistent with NIS2 and applicable ICANN requirements, we (or our registrar partner) collect and maintain accurate and complete domain-name registration data, apply reasonable verification procedures, and act on indications that registration data is inaccurate, including by requiring correction and, where appropriate, suspending the domain.
8. Recordkeeping
We keep records of DNS-abuse reports we receive and the actions we take, including the report, the evidence relied on, our classification and decision, the mitigation applied, and relevant correspondence. We retain these records for as long as necessary for the purposes of operating this policy, demonstrating compliance with applicable ICANN, NIS2 and other legal obligations, defending or bringing legal claims, and cooperating with authorities and upstream registries/registrars, after which they are deleted or anonymized in line with our Privacy Policy and Data Retention practices. Personal data within these records is processed in accordance with our Privacy Policy; we do not sell or share personal data, and our hosting is located in the EU (Frankfurt).
9. Relationship to other policies
This policy operates alongside, and does not replace:
- our Acceptable Use Policy and Prohibited Businesses rules (general prohibited conduct and content, including non-delivery spam);
- our Reporting Illegal Content process at /legal/dsa-notice (illegal content hosted on a project);
- our Copyright & DMCA Policy (copyright infringement) and trademark/brand-misuse handling at legal@coded.eu;
- our Merchant Agreement, Terms of Service, Complaints Procedure, Legal Requests and Privacy Policy.
Where a matter spans more than one of these, we apply each relevant process.
10. Changes
We may update this policy from time to time to reflect changes in our services, the requirements of our registry/registrar partners, evolving DNS-abuse standards, or applicable law. The current version is always the one published on our website, with the "Last updated" date above.
Contact
- Report DNS abuse / abuse intake: report@coded.co
- Legal and authority matters: legal@coded.eu
- Data protection / privacy: privacy@coded.eu
- Security and vulnerability reports: security@coded.co
- General support: support@coded.co
Coded B.V. is a private limited company registered in the Netherlands, a wholly owned subsidiary of Coded Holding B.V.
- Registered address: De Taling 15, 2761 SL Zevenhuizen, The Netherlands
- Dutch Chamber of Commerce (KvK) number: 42027097
- VAT number: NL869368795B01
- Registrar / registry partner: [to be confirmed]
- Effective date: 11 June 2026
This policy is governed by the laws of the Netherlands. The courts of Amsterdam, the Netherlands have jurisdiction over disputes arising from it, without prejudice to any mandatory rights you may have under the law of your own country or jurisdiction.
<!-- OPEN ITEMS FOR COUNSEL: (1) Confirm Coded's exact role in the domain chain — does Coded hold ICANN registrar accreditation itself, act as a reseller of [to be confirmed], or only forward domains? This determines which RAA/RA DNS-abuse obligations bind Coded directly vs. flow through the upstream partner, and whether client/server hold and registration-data verification are within Coded's control or must be requested. Align section 1, 5 and 7 accordingly. (2) Confirm NIS2 applicability and the Member State(s) of competence — NIS2 obligations on TLD registries and domain-registration service providers depend on whether Coded qualifies as such an entity and on national transposition; verify the registration-data accuracy and lawful-access duties as transposed in NL and any other relevant state. (3) Define concrete response/turnaround SLAs for DNS-abuse categories (e.g., expedited handling for active phishing/malware) and align with upstream-partner contractual deadlines — left general here pending the partner contract. (4) Confirm data-retention periods for abuse records and reconcile with the Privacy Policy, DPA and Subprocessors list (including [to be confirmed]). (5) Confirm whether non-delivery spam is fully out of scope of this policy and adequately covered by the Acceptable Use Policy/anti-spam rules. (6) Verify the abuse-intake address report@coded.co is the single published abuse contact required by ICANN/registry policy and that it is monitored to meet response-time obligations. (7) Confirm whether any registry/registrar requires Coded to publish a specific abuse-reporting format or to register a dedicated abuse point of contact. -->