Reporting abuse on a .net domain
The .net registry is Verisign. That matters because the registry sits above the registrar: it can remove a domain from the zone with serverHold, and the registrar cannot undo it.
The facts
- TLD
.net- Registry
- Verisign
- Why it is here
- One of the TLDs clones are most often registered under. We have observed 10 live impersonating domains on this TLD.
Who can switch it off
Nobody owns a website. A live site is a stack of separate commercial relationships, each with its own abuse desk and its own appetite. The practical move is to file with all of them at once and let the most responsive party act.
serverHold — removes the domain from the zone. The registrar cannot lift it.
Routinely skipped by people filing abuse reports, and often the one that moves.
clientHold, suspend, or terminate the registration.
The default recipient, and frequently the least responsive one.
Stop answering.
Fast when it is a real provider rather than the operator’s own nameservers.
Pull the server. A CDN will usually forward the report to the hidden origin.
Use the CDN to find the host, not to kill the site.
Unpublish.
Very responsive — but the domain stays live and re-arms for free.
What we have seen on this TLD
Across 30 brand sweeps we recorded 10 live domains on .net that resembled a brand we were checking, out of 103 across all TLDs. That is a count of what resolved and served a page — not a count of confirmed impersonation, which is a judgement a person makes one domain at a time.
We do not publish a takedown rate for this TLD. We have nowhere near the number of filings needed to state one honestly, and a rate quoted from a handful of cases is a guess wearing a percentage sign.
Once something happens, the registration record tells you who acted. serverHold means the registry acted and is effectively final; clientHold means the registrar did and can be lifted by the same registrar.
Registry and RDAP data from IANA’s RDAP bootstrap. Last built 2026-09-20.