ICANN terminated the accreditation of Trustname.com, an Estonia-based domain registrar that marketed itself as “bulletproof,” effective September 11, 2026 — one day after the fourth formal breach notice it had received in 78 days, according to CircleID and Domain Incite. The domains it held, reportedly numbering in the low thousands, did not disappear; they were reassigned to a new custodian chosen entirely by the Internet Corporation for Assigned Names and Numbers (ICANN), with no registrant given a vote, a say in timing, or an extension of their registration term.
What did ICANN actually decide on August 27?
ICANN Compliance issued the termination notice against Fewmoretaps OU, the registrar operating as Trustname.com, on August 27, 2026, citing repeated failures to act on phishing reports involving impersonation of banks and a government tax agency, according to CircleID. The notice alleged violations of Sections 3.18.1 and 3.18.2 of the Registrar Accreditation Agreement (RAA) — the clauses that require a registrar to take prompt action against domains used for DNS abuse and to investigate abuse reports it receives.
Trustname had built its brand around resisting exactly this kind of pressure. Its own marketing, reported by Domain Incite, described it as a registrar “built for businesses in competitive niches that often face false or bad-faith abuse reports” and claimed it would disregard DMCA takedown notices, requiring a court order from each of the three jurisdictions it operated in — the United States, Estonia, and Saint Kitts and Nevis — before it would remove a domain. ICANN Compliance had been pressing the registrar privately since February 2026, and remediation promises made in June and July did not hold, according to the termination notice.
Where does a domain actually go when its registrar disappears?
Under ICANN’s De-Accredited Registrar Transition Procedure, a terminated registrar’s entire portfolio moves in a single bulk transfer to a “gaining registrar” that ICANN certifies as accredited, operational, and in the community’s interest to receive the names. Registrants pay nothing for the move. But the procedure also specifies that, unlike an ordinary inter-registrar transfer a customer initiates, a bulk transfer does not add a year to the registration term — the receiving registrar simply inherits the expiration date that was already on the file.
Registrants of a de-accredited registrar therefore experience something that looks, from the outside, like nothing happened: the domain still resolves, still points where it always pointed. What actually happened is that a third party neither the registrant nor their in-house counsel chose now controls the account that can transfer, lock, or lapse that domain — and the registrant found out only if they were paying attention to registrar-industry trade press, not to their own inbox.
Why does a de-accreditation aimed at “bulletproof” abuse reach ordinary brand portfolios?
It is tempting to read the Trustname case as a story about a niche operator serving customers who wanted an accomplice, not a registrar. That misses the exposure. Trustname reportedly held on the order of 4,000 .com domains at the time of termination, according to registrar statistics tracked by ntldstats.com — a figure large enough that it was not exclusively phishing infrastructure. Domain portfolios accumulate through acquisitions, agency handoffs, and defensive registrations that nobody revisits for years; a brand’s trademark team can end up with names sitting at a registrar chosen by a marketing vendor in 2019 for reasons no longer documented.
None of that requires the registrant to have done anything wrong. The RAA obligation Trustname violated is the registrar’s, not the registrant’s. But the consequence — an involuntary, ICANN-directed change of custodian, on ICANN’s timeline, to a registrar of ICANN’s choosing — lands on the registrant regardless of which side of the abuse caused it. A second registrar, IPIP, was terminated in the same window for unrelated failures involving registration data escrow and RDAP compliance, according to CircleID, underscoring that this is a recurring enforcement pattern, not a one-off.
What should an IP or brand portfolio manager check this quarter?
The practical response is not to distrust every small registrar; ICANN accreditation itself is the baseline check that keeps a registrar in the pool. It is to know, name by name, which registrar holds each domain in a defensive or active portfolio, and to treat “which registrar” as a governance fact worth auditing alongside renewal dates and DNS records — the same way a licensing team already tracks jurisdiction and term on a patent portfolio. A registrar’s public compliance history with ICANN, including breach notices, is published and searchable; a portfolio manager who has never checked it has an unmonitored point of failure sitting inside the domain layer of their brand’s IP.
Key takeaways
- ICANN terminated Trustname.com’s registrar accreditation effective September 11, 2026, after four breach notices in 78 days over unresolved phishing-related DNS abuse, according to CircleID.
- Domains held at a terminated registrar move in a single bulk transfer to a registrar ICANN chooses, with no registrant vote and no year added to the existing registration term.
- Trustname reportedly held roughly 4,000 .com domains, a portfolio large enough that ordinary brand and defensive registrations, not just abusive ones, were caught in the reassignment.
- A second registrar, IPIP, was terminated in the same window for unrelated compliance failures, indicating a broader enforcement push rather than an isolated case.
- Brand and IP portfolio managers should audit which registrar holds each domain in their portfolio and check that registrar’s ICANN compliance history, treating it as a governance risk distinct from the registrar-market concentration this blog has covered separately.