Reporting abuse on a .my domain
We do not publish a registry operator for .my because we have not verified one, and naming the wrong company on an abuse page is not a small error. The registration record below is the checkable starting point.
The facts
- TLD
.my- Registry
- not verified by us
- RDAP
- No RDAP service is listed in IANA’s bootstrap file. Fall back to
whois. - Country
- Malaysia
- Why it is here
- A Southeast Asian country-code TLD — the jurisdiction this practice works in.
Who can switch it off
Nobody owns a website. A live site is a stack of separate commercial relationships, each with its own abuse desk and its own appetite. The practical move is to file with all of them at once and let the most responsive party act.
serverHold — removes the domain from the zone. The registrar cannot lift it.
Routinely skipped by people filing abuse reports, and often the one that moves.
clientHold, suspend, or terminate the registration.
The default recipient, and frequently the least responsive one.
Stop answering.
Fast when it is a real provider rather than the operator’s own nameservers.
Pull the server. A CDN will usually forward the report to the hidden origin.
Use the CDN to find the host, not to kill the site.
Unpublish.
Very responsive — but the domain stays live and re-arms for free.
Once something happens, the registration record tells you who acted. serverHold means the registry acted and is effectively final; clientHold means the registrar did and can be lifted by the same registrar.
Registry and RDAP data from IANA’s RDAP bootstrap. Last built 2026-09-20.