Acceptable Use and Abuse Response

July 16, 2026 ยท View on GitHub

The registrant is responsible for understanding the current policies that apply to the account, namespace, domain, and hosted content.

Before Publishing

Review the current:

  • Terms of Service
  • Acceptable Use Policy
  • Privacy Policy
  • Namespace-specific rules
  • Hosting and DNS service terms
  • Laws applicable to the project and its users

This guide does not replace those documents or legal advice.

Common High-Risk Uses

Do not use a domain for phishing, malware, credential theft, spam, impersonation, unauthorized proxying, deceptive redirects, illegal content, or activity that violates current policy.

Protect forms, file uploads, redirects, user-generated content, and abandoned subdomains. A legitimate project can still be abused through an unpatched application or forgotten DNS record.

Monitor for Abuse

  • Review web and authentication logs.
  • Patch public applications and dependencies.
  • Remove unused DNS records and services.
  • Scan for exposed secrets.
  • Monitor certificates and DNS changes.
  • Provide a working security or abuse contact.
  • Rate-limit sensitive endpoints where appropriate.

Respond to a Report

  1. Preserve the report and relevant timestamps.
  2. Confirm the affected hostname and content.
  3. Contain active harm without destroying evidence.
  4. Rotate compromised credentials.
  5. Remove malicious content or configuration.
  6. Patch the root cause.
  7. Reply through the official reporting channel with concise facts.
  8. Document the incident and preventive action.

Do not publish complainant data, access tokens, full logs, or unrelated user information.

If a Domain Is Suspended

Read the current status and official notice first. Gather evidence of ownership, remediation, and current configuration. Use the official appeal or support channel and avoid creating duplicate requests that obscure the timeline.

Responsible Shutdown

When ending a project, remove user data, disable vulnerable applications, revoke credentials, archive necessary records securely, update public documentation, and follow the domain offboarding checklist before allowing registration to expire.

Continue to Backups and Restoration.