Board Activities and Meetings
Approved Resolutions | Special Meeting of the ICANN Board | 25 November 2024
1. Main Agenda
a. Renewal of .COM Registry Agreement 2024
Whereas, the current .COM Registry Agreement (.COM RA) between ICANN and Verisign commenced on 1 December 2012, has been amended three times during its term, and is scheduled to expire on 30 November 2024.
Whereas, Verisign satisfied the criteria in the .COM RA to qualify for renewal.
Whereas, ICANN org consulted with the Board on key objectives prior to beginning negotiations with Verisign for the proposed renewal of the .COM RA (.COM Renewal RA).
Whereas, ICANN and Verisign negotiated in good faith to develop the proposed .COM Renewal RA for the operation of the .COM generic top-level domain (gTLD), and a second amendment to the Letter of Intent (LOI) between ICANN and Verisign.
Whereas, the Board recognizes that together the proposed .COM Renewal RA and the second amendment to the LOI represent meaningful progress on each of the agreed upon key objectives for the negotiations of a renewal of the .COM RA.
Whereas, the proposed .COM Renewal RA includes new or modified provisions to enhance obligations related to the Domain Name System (DNS) Abuse consistent with the 2024 Global Amendment to the Base gTLD Registry Agreement (Base RA) and new or modified provisions to provide Registration Data Directory Services (RDDS) via the Registration Data Access Protocol (RDAP) consistent with the 2023 Global Amendment to the Base RA.
Whereas, the proposed .COM Renewal RA includes new and modified provisions consistent with all gTLDs on the Base RA, including the addition of new provisions that enable ICANN to include .COM in any potential fee increases applied to gTLDs operating under the Base RA.
Whereas, the proposed .COM Renewal RA includes new provisions designed to further enhance and/or preserve the security, stability or resilience of .COM. These new provisions include: a provision requiring ICANN and Verisign to work together on a plan to preserve and enhance the security, stability, and resiliency of .COM operations should the need arise; and a new obligation for Verisign to report certain security incidents to ICANN, based on advice from the Security and Stability Advisory Committee (SSAC) in SAC0741 that was accepted2 by the Board in February 2018.
Whereas, ICANN and Verisign agreed on a second amendment to the LOI to work with the ICANN community and within ICANN processes to develop Internationalized Domain Name (IDN) solutions to improve the accessibility of the DNS in local languages and/or scripts, while continuing to maintain the security, stability and resiliency of the DNS.
Whereas, ICANN org briefed the Board on 29 August 2024 on the preliminary outcome of the negotiations for the proposed .COM Renewal RA and second amendment to the LOI.
Whereas, ICANN held a public comment period from 26 September 2024 through 5 November 2024 on the proposed .COM Renewal RA and the second amendment to the LOI. ICANN received comments from twenty-eight (28) organizations or individuals. A summary and analysis report of the public comments, which was provided to the Board and will be published shortly, make clear that all of the received public comments were considered.
Whereas, ICANN org recommends the Board to approve the proposed .COM Renewal RA and second amendment to the LOI.
Whereas, after considering all received public comments and upon the recommendation of ICANN org, the Board has determined that no revisions to the proposed .COM Renewal RA or second amendment to the LOI are necessary.
Resolved (2024.11.25.01), the Board approves the proposed .COM Renewal RA as the "November 2024 .COM Registry Agreement," approves the second amendment to the LOI between ICANN and Verisign, and authorizes the Interim President and CEO, or her designee(s), to take all actions as appropriate to finalize and execute the November 2024 .COM Registry Agreement and second amendment to the LOI between ICANN and Verisign.
Rationale for Resolution 2024.11.25.01
Why is the Board addressing the issue now?
The current .COM RA between ICANN and Verisign is scheduled to expire 30 November 2024. ICANN and Verisign initiated renewal discussions in March 2024 and reached agreement on a proposed .COM Renewal RA in September 2024.
What is the proposal being considered?
The proposed .COM Renewal RA is based on the current .COM RA with modifications agreed upon by ICANN and Verisign. In January 2024, ICANN org and the ICANN Board aligned on the following key objectives for ICANN in the .COM RA renewal discussions with Verisign:
- Incorporate key concepts and provisions from the 2023 Global Amendment to the Base RA related to RDDS over the RDAP.
- Incorporate key concepts and provisions from the 2024 Global Amendment to the Base RA related to mitigating DNS Abuse.
- Align certain obligations for the .COM gTLD with those in the Base RA, including those related to fees paid to ICANN.
- Add commitments to further enhance the security, stability, resilience and accessibility of the .COM gTLD.
Following the preliminary completion of negotiations, ICANN org updated the Board in late August 2024 prior to opening the public comment proceeding on the proposed .COM Renewal RA and the second amendment to the LOI. At that time, ICANN org and the ICANN Board agreed that meaningful progress had been made on each of these objectives.
-
Incorporate key concepts and provisions from the 2023 Global Amendment to the Base RA related to providing RDDS over RDAP.
As part of ICANN's commitment to improving RDDS, ICANN worked with the contracted parties to make RDAP the primary protocol for delivery of RDDS, as RDAP is a significantly more technically capable protocol than the WHOIS protocol. The 2023 Global Amendment to the Base RA established the critical performance requirements for registry operators to provide RDDS over RDAP, obligations to provide RDAP in accordance with a standard output profile for the benefit of Internet users, and requirements to report the number of queries to the registry RDAP service to ICANN. ICANN and Verisign agreed to provisions for all of these concepts for the proposed .COM Renewal RA.
The Base RA includes the option for the registry operator to discontinue (or sunset) the WHOIS service in January 2025. Verisign requested to have no such option to discontinue the WHOIS service for the .COM gTLD. Instead. Verisign, committed to continue to operate the WHOIS service in parallel with the RDAP for RDDS, which is reflected in the proposed .COM Renewal RA.
-
Incorporate key concepts and provisions from the 2024 Global Amendment to the Base RA related to mitigating DNS Abuse.
Verisign agreed to include the same DNS Abuse obligations as set forth in the approved 2024 Global Amendment to the Base RA. These include: the definition of DNS Abuse as domain names used to perpetrate phishing, malware, botnets, pharming, and spam (when spam is used to deliver other forms of DNS Abuse); the requirement to publish an abuse contact for the receipt of abuse reports; and the obligation to take the appropriate mitigation actions to stop, or otherwise disrupt, a registered domain name in .COM from being used for DNS Abuse. Bringing these obligations to the world's largest gTLD is a significant achievement in ICANN's efforts to combat DNS Abuse and are in line with the Interim President and CEO's goals for FY2024 and 2025 set by the ICANN Board.
-
Align certain obligations for the .COM gTLD with those in the Base RA.
The proposed .COM Renewal RA includes new provisions related to fees paid to ICANN that align more closely with the Base RA. While .COM's per-transaction fee of US$0.25 is already consistent with the Base RA, the proposed .COM Renewal RA adds the quarterly fixed fee of US$6,250 from the Base RA.
The proposed .COM Renewal RA also includes the same right for ICANN as under the Base RA to impose an adjustment to the fees based on a percentage change in the U.S. Consumer Price Index (CPI). This ability to invoke an adjustment reflects a key ICANN initiative relative to funding, as it paves the way for ICANN to utilize this adjustment provision with .COM, as well as all gTLDs operating under the Base RA as well as .COM.
On 24 October 2024, ICANN communicated3 its plan to adjust the registry fees in line with inflation effective 01 January 2025 to gTLD registry operators4. This adjustment will be the first time ICANN has exercised its right to raise the fees. If the proposed .COM Renewal RA is executed as proposed for public comment, these increases will also apply to the .COM gTLD and will also be effective 1 January 2025.
-
Add commitments to further enhance the security, stability, resilience and accessibility of the .COM gTLD.
In 2023, as part of the .NET RA renewal, ICANN and Verisign agreed to Amendment 1 to the LOI for ICANN and Verisign to work together for the development and adoption of appropriate reporting of security incidents based on recommendations by the Security and Stability Advisory Committee (SSAC) in SAC0745 that were adopted6 by the ICANN Board of Directors. In the proposed .COM Renewal RA, ICANN and Verisign agreed to security incident reporting obligations to address this advice. The new obligations require Verisign to provide notice to ICANN within seventy-two (72) hours following the discovery of any cyber or physical security incident that significantly jeopardizes, or is reasonably likely to significantly jeopardize, the registry system. The notice must provide details regarding the incident including statistics about the number of registrars, domains, and registrants impacted, and the actions taken by Verisign in response to the incident. This provision can be used by ICANN as a model for the current Base RA and the Next Round Base Registry Agreement.
The SSAC also advised ICANN to produce public reporting that aggregates and anonymizes the data it receives from registries about security incidents. Given that the .COM gTLD would be the first and only gTLD registry at this time to have the obligation to disclose incidents to ICANN, there would be no way to produce anonymized reporting yet. As such, ICANN and Verisign agreed as part of the proposed second amendment to LOI to work together to develop appropriate processes for ICANN to report data publicly in line with the Board-adopted SSAC advice.
Additionally, ICANN and Verisign agreed to an obligation to work together on a plan to preserve and enhance the security, stability, and resiliency of .COM operations should the need arise. This includes details of how the parties may address the business continuity of .COM under various scenarios, including criteria for triggering any business continuity mechanisms, and how to mitigate risks to .COM and the Internet. The parties agree to have subject matter experts from Verisign and ICANN representing critical registry functions, operations, and security meet and develop this plan. Following the completion of this plan, the parties will use commercially reasonable efforts to determine the implementation of the business continuity practices that are appropriate for .COM. Execution on this provision will help enhance ICANN's security, stability and resiliency posture, and work to mitigate risks for ICANN and the Internet user community.
Additionally, Verisign has agreed as part of a second amendment to the LOI to work within the ICANN community and ICANN processes to develop IDN solutions to improve the accessibility of the DNS in local languages and/or scripts, while continuing to maintain the security, stability, and resiliency of the DNS. This work may include (i) new or improved data in the form of Label Generation Rules or harmonized IDN tables, (ii) the development of open-source code for processing IDN tables, and (iii) the creation of standards within technical communities such as the Internet Engineering Task Force. These are important aspects to continuing the efforts at the infrastructure level to support a multilingual Internet. Multilingual Internet is of strategic importance to ICANN as reflected in the Board-approved FY24 Interim President and CEO's goals.7
Which stakeholders or others were consulted?
The proposed .COM Renewal RA and the proposed second amendment to the LOI were posted for public comment from 26 September 2024 to 5 November 2024, ICANN and received 27 timely comments and, one additional comment three days late, that was also accepted, for a total of 28 comments. The Board has been briefed on the public comments received, received the Public Comment Summary and access to all the public comments, and considered ICANN org's recommendation and rationale for not pursuing any changes to the proposed agreement. The Public Comment Summary provides more detail on each of the issues and is expected to be published for the community the week of 25 November 2024.
What concerns or issues were raised by the community?
A common theme from commenters focused on Verisign's right to increase the maximum wholesale price of .COM domain names. Under the proposed .COM Renewal RA, Verisign will continue to have the right to increase wholesale prices for .COM by up to seven percent every four out of six years of the agreement. As of 01 September 2024,8 Verisign exercised the fourth and final price increase to the .COM wholesale domain name registration price available as per the current .COM RA. The current .COM wholesale price is $10.26 per registration.
The commenters suggest that ICANN has a responsibility to set or restrain the wholesale pricing for .COM. Some commenters even point to passages in the ICANN's Bylaws related to promoting competition and acting in the public interest as to why ICANN should be compelled to impose lower wholesale domain name registration prices for .COM. However, the mission of ICANN, as enshrined in ICANN's Bylaws that were developed through the bottom-up, multistakeholder process, is to ensure the security and stability of the Internet's unique identifier systems. ICANN is not a competition authority or price regulator and does not have the remit to serve as one. Nevertheless, unlike nearly all of the gTLDs managed pursuant to a registry agreement with ICANN that have no price control provisions, the .COM RA does contain a restriction on the maximum allowable annual wholesale price increase of domain name registrations. That price control provision in the .COM RA and in the proposed .COM Renewal RA, however, tracks the rules established by the DOC, as documented in Amendment 359 to the Cooperative Agreement10 between Verisign and the NTIA, not rules established by ICANN. This provision restricts increases to the wholesale price to a maximum of seven percent per year, and a frequency of increases occurring no more than four out of every six years. This is the same provision that has been in place since Amendment 3 which was approved in March 2020.
Another topic that garnered a significant number of comments is the suggestion that ICANN should open the management of the .COM gTLD to a public bidding process to foster more competitive pricing. The .COM RA, as do all gTLD RAs, provides that the RA "shall be renewed" upon the expiration date absent a contractual breach. In the absence of a serious breach of any agreement, the renewal provisions in the registry agreement are in place to: (1) provide continued security and stability; and (2) encourage long-term investment in robust gTLD operations. ICANN determined that there has been no serious breach per the .COM RA and, therefore, Verisign is entitled to renewal. The .COM gTLD plays a critical role in the global Internet infrastructure, serving as the backbone for hundreds of millions of websites, apps, email accounts and core Internet systems worldwide. Ensuring the continued secure, stable, and resilient operation of the .COM gTLD is a top priority for ICANN and for the Internet community. Verisign has a track record of operational excellence, having maintained 100 percent DNS availability for .COM for more than 27 years without interruption.
Some commenters also proposed that ICANN org conduct an economic study prior to renewing the .COM RA. However, as previously mentioned, ICANN is not a competition authority nor a price regulator, and ICANN has neither the remit nor expertise to serve as one. In the case of .COM,the relevant regulatory, the DOC, through Amendment 35 of the Cooperative Agreement with Verisign, has mandated price increase restrictions, which became part of the .COM RA in 2020, and remain unchanged in the proposed .COM Renewal RA. As stated in ICANN's Bylaws, Article 1, Section 1.2(b)(iv), ICANN's role with regard to competition is "introducing and promoting competition in the registration of domain names where practicable and beneficial to the public interest as identified through the bottom-up, multistakeholder policy development process". ICANN has and will continue to work toward promoting more opportunity in the marketplace pursuant to its remit by increasing choice and innovation in the registration of domain names for the Internet community.
Some commenters criticized ICANN and Verisign for not including a provision comparable to the Base RA requirement for cooperation with ICANN if ICANN were to conduct or commission an economic study on the impact or functioning of new gTLDs on the Internet, the DNS or related matters. However, unlike most other gTLDs, the .COM RA already requires that the wholesale price for .COM be disclosed to ICANN and all the registrars six months prior to any changes taking effect. Additionally, the number of domains under management ("DUMs") within all gTLDs are available publicly on icann.org. Given that the .COM registry price and number of DUMs are already available to ICANN and the community, it is unclear what data ICANN would not have access to for .COM if it were to conduct or commission an economic study.
Some commenters expressed their appreciation for the incorporation of the DNS Abuse obligations from the 2024 Global Amendment to the Base RA, the contractual provisions for RDAP from the 2023 Global Amendment to align with the Base RA, and the new provisions that enable ICANN to include .COM in any potential fee increases applied to other gTLDs operating under the Base RA.
Two commenters asserted that Verisign should do more to curb child sex abuse material (CSAM) on .COM as reported by the Internet Watch Foundation (IWF). As noted in the public comment summary, ICANN expects all gTLD registry operators to comply with laws and to combat CSAM within their registries.
Similar to the public comments received for Amendment 3 to the .COM RA in 2020 and the .NET RA renewal in 2023, commenters expressed concerns about the transparency of the .COM RA negotiations and whether they align with the multistakeholder model. In the case of the .COM RA renewal, ICANN org followed the established process to negotiate the renewal registry agreement with the registry operator. Initial contractual negotiations were between the two contracted parties, and once the parties reached an agreement on the proposed terms, ICANN invited the community to comment on the proposed .COM Renewal RA through the public comment process to collect valuable community input before proceeding. ICANN based its negotiations on its mission, strategic priorities, and incorporation of provisions from the Base RA which included significant community consultation.
What significant materials did the Board review?
The Board considered various significant materials and documents, including, but not limited to, the following:
- Proposed .COM Renewal Registry Agreement (pdf, 1019.39 KB)
- Redline of the Proposed and 2012 .COM Registry Agreement as Amended (pdf, 1.15 MB)
- Proposed Second Amendment to the Letter of Intent between ICANN and Verisign (pdf, 117.38 KB)
- The Public Comment Summary and Analysis Report for the proposed .COM Renewal Registry Agreement (pdf, 324 KB)
What factors did the Board find to be significant?
The Board considered the terms agreed upon by Verisign as part of the bilateral negotiations with ICANN org and the meaningful progress the proposed .COM Renewal RA represents on each of the key objectives for the negotiation. The Board considered ICANN org's summary and analysis of the public comments received for the proposed .COM Renewal RA and the second amendment to the LOI. While the Board acknowledges the concerns expressed by some community members regarding Verisign's ability to increase the wholesale price seven percent four out of the six years over the term of the agreement, the Board recognizes that the registry operator is allowed to determine the wholesale price for .COM domain name registrations subject to the limitations set by the Cooperative Agreement and inserted at Verisign's request into the .COM RA and proposed .COM Renewal RA. Further, the Board understands that the pricing provision was not changed from Amendment 3 to the .COM RA, that the wholesale pricing for .COM domains is governed by Amendment 35 to the Cooperative Agreement between Verisign and the DOC, and that ICANN is not a party to the Cooperative Agreement. The Board further acknowledges that ICANN is neither a competition authority nor a price regulator, and it is not within ICANN's remit or expertise to serve as one.
The Board also acknowledges the comments requesting ICANN to open the management of the .COM gTLD to a public bidding process to foster more competitive pricing. However, the Board notes that the .COM RA, as with all gTLD RAs, is clear that the RA "shall be renewed" upon the expiration date absent a contractual breach. In the absence of a serious breach of any agreement, the renewal provisions in the registry agreement are in place to: (1) provide continued security and stability; and (2) encourage long-term investment in robust gTLD operations. ICANN must honor and abide by the contractual terms, in which Verisign has qualified for renewal of the .COM RA.
The Board recognizes the comments from community members requesting that ICANN org conduct an economic study prior to the renewal of the .COM RA. However, as previously noted, the Board wants to make clear that ICANN is not a competition authority or a price regulator, and ICANN has neither the remit nor the expertise to serve as one. As such, pricing decisions for any gTLD will remain with the respective registry operator and, in the case of .COM, the relevant regulatory authority as set forth in the Cooperative Agreement.
The Board also recognizes commenters' request that ICANN seek community input prior to negotiating the .COM Renewal RA. All registry operators have the ability to negotiate the terms of their RA with ICANN, which inherently means discussions between the two contracted parties, in this case ICANN and Verisign. The process is straightforward and involves discussions between the two parties until agreement is reached. The Board is aligned with ICANN org and agrees that ICANN followed the established process to negotiate the renewal of a registry agreement with the registry operator and, once both parties reached agreement on the proposed terms, ICANN invited the community to comment on the proposed .COM Renewal RA through the public comment process. The Board reiterates the unique framework of ICANN's contracts with registries, which allow for two primary methods of incorporating new obligations for registries. The first is through direct bilateral negotiations between ICANN and the registry operator. The second is by way of the bottom-up Consensus Policy process. The policy process is the way the ICANN community can evolve or create new obligations for gTLD registries to address the changing environment and address security, stability or resilience needs. The obligations must be within what is known within the ICANN community as "the picket fence11" which is enumerated in Annex G-2 of ICANN's Bylaws12 and must be "developed through a bottom-up consensus-based multistakeholder process and designed to ensure the stable and secure operation of the Internet's unique names systems".
The Board would also like to acknowledge the significant progress made to further align the .COM RA to the Base RA by including the obligations from the 2023 Global Amendment to the Base RA to include the contractual provisions for RDAP, from the 2024 Global Amendment to the Base RA to incorporate the DNS Abuse obligations, and to incorporate similar fee provisions to the Base RA, particularly the ability for ICANN to apply adjustments to the registry fees to account for inflation.
The Board also appreciates the steps made to include within the .COM RA the recommendations from the SSAC in SAC074 to report security incidents and the commitment from Verisign to work with ICANN on how to produce public reporting that will aggregate and anonymize the data ICANN receives from registries about security incidents. The Board also notes the addition of commitments from Verisign to work with ICANN on a plan to preserve and enhance the security, stability, and resiliency of .COM operations should the need arise. This is a critical step to ensuring the security and stability of the Internet as a whole. The Board also appreciates Verisign's commitment to work within the ICANN community and ICANN processes to help advance the multilingual Internet and foster digital inclusivity as reflected in ICANN's Interim CEO goals.
Are there positive or negative community impacts?
The proposed .COM Renewal RA provides for positive impacts to the Internet community. Provisions aligned with the recent global amendments to the Base RA related to mitigating DNS Abuse and providing RDDS via RDAP have been considered by the ICANN Board and determined to be positive benefits to the Internet community.
Additionally, provisions focused on increasing security, stability and resilience are expected to have positive impacts on the Internet community. These include the disclosure of security incidents to ICANN as advised by the SSAC in SSAC 074 and accepted by the ICANN Board and working together on a plan to preserve and enhance the security, stability, and resiliency of .COM operations should the need arise.
Are there fiscal impacts or ramifications on ICANN (strategic plan, operating plan, budget); the community; and/or the public?
The proposed .COM Renewal RA is positive for ICANN's funding, which in turn provides ICANN with more resources to support the community and overall Internet community. The proposed .COM Renewal RA aligns the fees for the .COM gTLD with the fees in the Base RA, adding the $25,000 annual fee to the .COM RA. The alignment with the Base RA also provides ICANN the right to adjust the annual fee and per transaction fee for .COM in accordance with inflation.
Are there any security, stability or resiliency issues relating to the DNS?
The proposed .COM Renewal RA strengthens the security, stability and resilience of the .COM namespace. This is evident in certain provisions based on Base RA related to: (1) providing RDDS over RDAP; and (2) mitigating DNS Abuse. Additionally, the proposed .COM Renewal RA adds requirements to disclose security incidents to ICANN as advised by the SSAC in SAC074 and commits ICANN and Verisign to work together on a plan to preserve and enhance the security, stability, and resiliency of .COM operations should the need arise. These provisions along with Verisign's track record of performance in DNS services contribute to a more secure, stable and resilient DNS with this decision.
Is this decision in the public interest and within ICANN's mission?
The decision to enter into the proposed .COM Renewal RA with Verisign for the operation of the .COM gTLD is determined to be within ICANN's mission and supports the public interest.
Is this either a defined policy process within ICANN's Supporting Organizations or ICANN's Organizational Administrative Function decision requiring public comment or not requiring public comment?
The decision to renew is within ICANN's organizational administrative function of negotiating and entering into registry agreements for gTLDs. ICANN conducted a public comment proceeding from 26 September 2024 to 5 November 2024 and received 27 comments. One additional comment was submitted by the ALAC on 8 November and was accepted by ICANN org for a total of 28 comments. The Board was briefed on and considered the public comments and ICANN's analysis of comments.
b. AOB
Footnotes
[1] https://itp.cdn.icann.org/en/files/security-and-stability-advisory-committee-ssac-reports/sac-074-en.pdf
[2] https://www.icann.org/en/board-activities-and-meetings/materials/approved-board-resolutions-regular-meeting-of-the-icann-board-04-02-2018-en#1.f
[3] https://www.icann.org/en/system/files/files/attn-planned-registry-level-fee-adjustment-24oct24-en.pdf
[4] Following a communication to the gTLD registries about anticipated fee increases ICANN published this blog and thought paper for general awareness. https://www.icann.org/en/blogs/details/investing-in-our-mission-by-enhancing-financial-stability-at-icann-30-10-2024-en
[5] https://itp.cdn.icann.org/en/files/security-and-stability-advisory-committee-ssac-reports/sac-074-en.pdf
[6] https://www.icann.org/en/board-activities-and-meetings/materials/approved-board-resolutions-regular-meeting-of-the-icann-board-04-02-2018-en#1.f
[7] https://www.icann.org/en/blogs/details/icann-interim-president-and-ceo-shares-goals-for-fiscal-year-2024-27-09-2023-en
[8] https://itp.cdn.icann.org/en/files/registry-agreements/com/com-fees-01-09-2024-en.pdf
[9] https://www.ntia.doc.gov/files/ntia/publications/amendment_35.pdf
[10] https://www.ntia.gov/program/verisign-cooperative-agreement
[11] https://gnso.icann.org/sites/default/files/file/field-file-attach/picket-fence-overview-23jan19-en.pdf
[12] Annex G-2 of ICANN's Bylaws, https://www.icann.org/resources/pages/governance/bylaws-en/#annexG2

