Whatever Happened to "Due Process" ?

This morning I received the following email:


Dear Sir or Madam,

Re: Website domain name suspension request #2

On the 24th September 2013, EasyDNS Technologies was emailed a domain suspension request for the following domain(s) that to date we have not received a reply nor seen action taken:

[redacted].com [IP redacted]

The domain(s) continues to be accessible by members of the public and is still making illicit financial gains for the criminals operating it.

It would be appreciated if you would respond either positively or negatively to this request confirming if you will assist Police in preventing this ongoing crime.

Kind regards,


The request came from The City of London (UK) Police Intellectual Property Crime Unit, and it had me thinking about this issue all morning, whether I should write anything about it, etc. It’s a strongly worded email “The domain(s) continues to be accessible by members of the public and is still making illicit financial gains for the criminals operating it.”  Ok, what exactly makes the website operators criminals (the website in question is a bittorrent search engine, I don’t even think they’re hosting the torrent files locally).

It wasn’t until I got to the office that I realized that there was a PDF attached to the email request, in it were further details/instructions:

  • It referenced the section of the ICANN RAA which states “accreditation as a Registrar can be terminated if the Registrar is found to have ‘permitted illegal activity in the registration or use of domain names’.” (Although I cannot find this text in the current RAA)
  • It requests that we freeze the whois record and permit no further changes to it.
  • It directs us to redirect the DNS for the domain to
  • It “reserves the right” to refer the matter to ICANN

After I read the attached order I realized I had to post because this opens all kinds of thorny philosophical issues which we’ve been talking about for years.

The lack of any semblance of due process when it comes to domain name takedowns.


Who decides what is illegal? What makes somebody a criminal?  Given that the subtext of the request contains a threat to refer the matter to ICANN if we don’t play along, this is a non-trivial question. Correct me if I’m wrong, but I always thought it was something that gets decided in a court of law, as opposed to “some guy on the internet” sending emails. While that’s plenty reason enough for some registrars to take down domain names, it doesn’t fly here.

We have an obligation to our customers and we are bound by our Registrar Accreditation Agreements not to make arbitrary changes to our customers settings without a valid FOA (Form of Authorization). To supersede that we need a legal basis. To get a legal basis something has to happen in court.

The request also suggests we look at the whois contact information for the domain (which looks perfectly valid) and go ahead and suspend the domain based on invalid whois data. Again, there’s a process for that, you have to go through the ICANN Whois Inaccuracy Complaint process and most of the time that doesn’t result in a takedown anyway.

What gets me about all of this is that the largest, most egregious perpetrators of online criminal activity right now are our own governments, spying on their own citizens, illegally wiretapping our own private communications and nobody cares, nobody will answer for it, it’s just an out-of-scope conversation that is expected to blend into the overall background malaise of our ever increasing serfdom.

If I can’t make various governments and law enforcement agencies get warrants or court orders before they crack my private communications then I can at least  require a court order before I takedown my own customer.

Before anybody tells me “this is just some bittorrent domain, just take it down”, remember what we said back in 2010: First They Came For the File Sharing Domains.

About a week after that was posted Senator Lieberman and friends went batshit crazy trying to take down wikileaks. Why? Egregious truth telling. Again, this is the entire point of due process it’s there to keep us collectively away from the top end of the slippery slope.

Unfortunately, we’re  most of the way down that slope and into the mud of blatant mass online surveillance – the next phase will be concerted repression of inconvenient truth-tellers and facts.

Further Reading


We took a look at – the IP address they wanted us to redirect all of this domain’s traffic to.

Note that they are promoting paid, commercial alternatives to the websites they want us to takedown.

In other words, they are ordering us to take down competing websites, with no legal basis, hijacking the traffic, and redirecting it to competing commercial services, all of which are based out of (guess where?) London, UK.

And here they are complaining about “profiting from illegal activity”.


Update #2

I’ve seen a few comments around the internet that this was so over-the-top wrong that it couldn’t be real and was probably an elaborate phishing attempt.

I too suspected as much, so I looked at the headers before writing this post, it looks like the real deal:

Return-Path: <PIPCUantipiracy@city-of-london.pnn.police.uk>

X-Original-To: markjr@[redacted]

Delivered-To: markjr@[redacted]

X-Greylist: Passed host:

X-Greylist: Passed host:

Received: from mail.pnn.police.uk (mail.pnn.police.uk [])

(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))

(No client certificate requested)

by c3po.easydns.com (Postfix) with ESMTP id 8720F8B7DB;

Tue, 8 Oct 2013 07:01:14 -0400 (EDT)

From: PIPCUantipiracy <PIPCUantipiracy@city-of-london.pnn.police.uk>

To: "'erol@[redacted]" <erol@[redacted]>

CC: "'markjr@[redacted]'" <markjr@[redacted]>

Subject: Website domain name suspension request #2 (NOT PROTECTIVELY MARKED)

Thread-Topic: Website domain name suspension request #2 (NOT PROTECTIVELY


Thread-Index: Ac7EFX3SXZveCQEuR6ePpq8AuQZZkg==

Date: Tue, 8 Oct 2013 11:00:05 +0000

Message-ID: <E3C2DE70C528F04096144CDA1C81C335029F76@CP8-DAG01.city-of-london.police.uk>

Accept-Language: en-GB, en-US

Content-Language: en-US

X-MS-Has-Attach: yes


x-officeenforcer-classification-impactlevel: 0

x-officeenforcer-classification: NOT PROTECTIVELY MARKED

x-originating-ip: []

Content-Type: multipart/mixed;


MIME-Version: 1.0

X-OriginalArrivalTime: 08 Oct 2013 11:00:05.0750 (UTC) FILETIME=[8BB3D960:01CEC415]

X-ACL-Warn: X-Virus Scan: F-Secure 9

X-PNN3-Rtr: dnslookup

Looks like it really did originate from the London Police servers.

Update #3

A friend emailed me and said that after reading this post, it wasn’t crystal clear what we did about this or what our policy is. I’ve seen a couple comments (slashdot story here, etc) that seem to allude that the domain in question now points to the IP we mentioned.

So just to clarify:

1) We haven’t taken down the domain.

2) We told them to get a court order.

Also, some people have observed that our own AUP mentions copyright infringement as grounds for termination. This is true and we have referred to  it in the past in cases where the domain was actually hosting copyrighted material and refusing or ignoring legitimate takedown requests for that material.

That said, our AUP states clearly: What constitutes a violation of our AUP is at the sole discretion of easyDNS. I cannot possibly imagine who else should be the final arbiters of that. An AUP and ToS is an agreement between the customer and the service provider. It is not a mechanism for third-parties to shoehorn their whims into somebody else’s affairs. If you want to do that, get a court order.

Update #4

It also occurs to us that any registrars that did comply with these requests may now be in violation of the ICANN transfers policy if they don’t let those domains transfer away.

Update #5

We have initiated a Transfer Dispute Resolution Process against another registrar who has complied with these takedown requests and will not let 3 domains transfer-away to easyDNS.

Update #6

It was a long haul, but the NAF panel found in our favor and ordered the three domains locked down at another registrar to be transferred to easyDNS.