Acceptable Use and Abuse Response
July 16, 2026 ยท View on GitHub
The registrant is responsible for understanding the current policies that apply to the account, namespace, domain, and hosted content.
Before Publishing
Review the current:
- Terms of Service
- Acceptable Use Policy
- Privacy Policy
- Namespace-specific rules
- Hosting and DNS service terms
- Laws applicable to the project and its users
This guide does not replace those documents or legal advice.
Common High-Risk Uses
Do not use a domain for phishing, malware, credential theft, spam, impersonation, unauthorized proxying, deceptive redirects, illegal content, or activity that violates current policy.
Protect forms, file uploads, redirects, user-generated content, and abandoned subdomains. A legitimate project can still be abused through an unpatched application or forgotten DNS record.
Monitor for Abuse
- Review web and authentication logs.
- Patch public applications and dependencies.
- Remove unused DNS records and services.
- Scan for exposed secrets.
- Monitor certificates and DNS changes.
- Provide a working security or abuse contact.
- Rate-limit sensitive endpoints where appropriate.
Respond to a Report
- Preserve the report and relevant timestamps.
- Confirm the affected hostname and content.
- Contain active harm without destroying evidence.
- Rotate compromised credentials.
- Remove malicious content or configuration.
- Patch the root cause.
- Reply through the official reporting channel with concise facts.
- Document the incident and preventive action.
Do not publish complainant data, access tokens, full logs, or unrelated user information.
If a Domain Is Suspended
Read the current status and official notice first. Gather evidence of ownership, remediation, and current configuration. Use the official appeal or support channel and avoid creating duplicate requests that obscure the timeline.
Responsible Shutdown
When ending a project, remove user data, disable vulnerable applications, revoke credentials, archive necessary records securely, update public documentation, and follow the domain offboarding checklist before allowing registration to expire.
Continue to Backups and Restoration.