Quick answer
How do I report abuse on a BuyDomainsCrypto domain?
Email [email protected] with the domain, the full URLs, your evidence and timestamps. BuyDomainsCrypto, a no-KYC domain registration service paid in crypto, suspends phishing, malware, botnet and fraud domains within 24 hours of a well-documented report, and child sexual abuse material immediately, with a report to the competent hotline or authority. Any other complaint needs a Panamanian court decision. Registrant data only goes out on a Panamanian court order, except urgent ICANN cases.
Abuse desk at a glance
| Address | [email protected] |
|---|---|
| Phishing, malware, botnets | Suspension, within 24 hours of a well-documented report |
| Child sexual abuse material | Suspension, immediately, with a report to the competent hotline or authority |
| Fraud that takes money from victims | Suspension, within 24 hours of a well-documented report: fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand |
| Copyright, defamation, political or competitor complaints | No suspension on a complaint alone: a decision from a Panamanian court (foreign judgments must first be recognised in Panama) is needed |
| Trademark disputes | UDRP: domain locked within 2 business days of a request from a UDRP provider; panel decisions applied |
| Associated domains | Other domains in the same account are reviewed after a confirmed strict-exception case (phishing, malware, botnet, CSAM or fraud) |
| Registrant data | Released only on a Panamanian court order, except urgent requests that ICANN rules require registrars to answer (imminent threat to life, serious bodily injury, critical infrastructure, child exploitation); in a UDRP case, the registrant details are confirmed to the dispute provider, as ICANN requires |
| Rules we follow | ICANN 2013 Registrar Accreditation Agreement §3.18, with the DNS abuse amendments in force since 5 April 2024 |
| Language | English |
What is BuyDomainsCrypto's official takedown and data policy?
Four rules, in force since 8 October 2026, apply to every domain:
- No takedown on a complaint alone. A complaint about copyright, defamation, politics, or one sent by a competitor does not get a domain suspended. We need a decision from a Panamanian court; foreign judgments must first be recognised in Panama.
- Your data only goes out on a Panamanian court order. We do not hand registrant data to a foreign lawyer, a private company or a foreign government without Panamanian legal process. The only exception: urgent requests that ICANN rules require registrars to answer, for an imminent threat to life, serious bodily injury, critical infrastructure, or child exploitation.
- No ID, no KYC. Only a verified email, kept private. Payment in crypto, WHOIS privacy included where the registry allows it.
- Strict exceptions, stated openly. Phishing, malware, botnets, child sexual abuse material, and fraud that takes money from victims (fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand) lead to suspension, without waiting for a court.
Trademark disputes follow the UDRP, because ICANN requires every registrar to apply it. The domain is locked, the registrant details are confirmed to the dispute provider, and the panel's decision is applied. We follow the UDRP as written.
What counts as domain abuse?
Domain abuse, for us, means phishing, malware, botnets, child sexual abuse material, and fraud that takes money from victims (fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand). These are the only cases where we suspend a domain on a well-documented report, without a Panamanian court decision.
ICANN's 2024 amendments define DNS abuse as five things, all covered by our exceptions:
- Malware: software that infects devices, served from or controlled through the domain, including crypto wallet drainers.
- Botnets: command-and-control servers for networks of infected machines.
- Phishing: pages that imitate a bank, an exchange, a wallet or a brand to steal credentials or funds.
- Pharming: redirecting users to fake sites, for example through DNS hijacking. We treat it as phishing.
- Spam, when it serves as a delivery mechanism for the four above.
We also suspend child sexual abuse material (CSAM), with zero tolerance, immediately, with a report to the competent hotline or authority.
We also suspend fraud that takes money from victims within 24 hours of a well-documented report: fake shops, fake investment and crypto platforms, wallet drainers, sites that impersonate a bank or a brand to deceive, and the sale of stolen data.
Everything else needs a decision from a Panamanian court. Foreign judgments must first be recognised in Panama. We register domains; we do not host websites. Complaints about a site's content, such as copyright, defamation, political speech or a competitor's claims, go to the hosting provider or to the courts. We act on the domain when a Panamanian court decision or a UDRP decision requires it.
What should an abuse report include?
A report we can act on at once contains five things:
- The domain name, or a list of domains, one per line.
- The full URLs where the abuse is visible, for example the phishing page or the malware download.
- The type of abuse: phishing, malware, botnet, pharming, spam, CSAM or fraud.
- Evidence: screenshots, full email headers for a phishing email, malware hashes or a sandbox report, blocklist entries.
- Timestamps with timezone, ideally in UTC, of when you saw the abuse.
Plain-text email is fine, and no special format is needed. Reports from automated systems are welcome when each one carries this evidence.
Do not send CSAM files or images. Send the URL and the time only. We report CSAM to the competent hotline or authority.
What happens after you report abuse?
Every report follows the same five steps.
Acknowledge
We acknowledge the report by email and ask for any missing detail, such as a URL or a timestamp.
Check
We check the evidence and the live content. Third-party blocklist entries count as evidence, not as proof on their own.
Act
We act within 24 hours of a well-documented report: the domain is suspended. Child sexual abuse material is handled immediately, with a report to the competent hotline or authority.
Review associated domains
We review the other domains in the same account. Abuse campaigns often use several names at once.
Close
We tell the reporter whether we acted. Registrant data is never part of this reply.
Why does BuyDomainsCrypto review other domains in the same account?
Because phishing is often registered in batches. Interisle's Phishing Landscape 2025 found that 77% of phishing domains were registered for that purpose, and 37% through bulk registrations.
When one domain is confirmed abusive, we review every other domain in the same account. We do this without any ID: the account itself links the domains.
ICANN's policy body, the GNSO, started a policy process in January 2026 on such "associated domain checks", per Spamhaus. We already apply them.
How does BuyDomainsCrypto handle UDRP complaints?
We lock the domain within 2 business days of a request from a UDRP provider and apply the panel's decision. The Uniform Domain-Name Dispute-Resolution Policy (UDRP) lets a trademark owner act against a domain registered and used in bad faith.
- Notice: an approved provider, such as WIPO, notifies the registrar of the complaint.
- Lock: the registrar confirms the registrant details to the provider and locks the domain. It cannot move to another registrar or registrant while the case runs.
- Decision: the panel orders a transfer, a cancellation, or rejects the complaint. We apply the decision as the UDRP requires.
An email to us cannot transfer a domain to a trademark owner. File a complaint with an approved UDRP provider. Registrants should read our Acceptable Use Policy: registering a trademark in bad faith is banned.
When does BuyDomainsCrypto disclose registrant data?
Only on a Panamanian court order. We do not hand registrant data to a foreign lawyer, a private company or a foreign government without Panamanian legal process.
Three things follow from ICANN rules, and we state them plainly:
- Urgent requests: the only exception to the court-order rule. ICANN rules require registrars to answer urgent requests about an imminent threat to life, serious bodily injury, critical infrastructure, or child exploitation, and we do.
- UDRP cases: when a trademark complaint is filed, the registrar confirms the registrant details to the dispute provider handling the case, such as WIPO. This is part of the UDRP, which every ICANN-accredited registrar must apply.
- Disclosure requests: ICANN's Registration Data Policy, in force since 21 August 2025, requires registrars to answer requests for registration data. We answer every request; outside urgent cases, the answer is no unless a Panamanian court order is attached.
We can only release what we hold, and we never collect ID documents. We do not sell extensions whose registry publishes registrant data, such as .us. The full list of what we hold is in our privacy policy.
Foreign authorities should use Panamanian legal process. Write to [email protected] from an official address with the legal basis, the issuing authority, the domain names and any deadline. Reports of phishing, malware, botnets, CSAM or fraud against victims never need a court order: send them directly.
What does ICANN require of registrars on abuse?
ICANN requires a published abuse contact, a response to every report and prompt action against well-documented DNS abuse. The rules sit in section 3.18 of the 2013 Registrar Accreditation Agreement (RAA).
Since 5 April 2024, amendments to the RAA require registrars to "promptly" take reasonable action to stop or disrupt well-documented DNS abuse. In the first six months, ICANN Compliance ran 192 investigations, and more than 2,700 abusive domains were suspended.
Every BuyDomainsCrypto domain is registered through an ICANN-accredited registrar, so these rules apply to every domain we sell.
Why does a no-KYC domain service enforce abuse rules?
Because abuse at one registrar harms every customer of that registrar. No KYC means no ID documents. It does not mean no rules.
The Trustname case. Trustname marketed itself as a safe place for "sensitive niches" and was slow to act on phishing. ICANN sent it four breach notices in 78 days, starting in June 2026. A notice terminating its accreditation followed on 27 August 2026. ICANN noted two failures: Trustname asked for proof that credentials had been stolen before acting on phishing, and acted weeks after reports.
Public metrics. ICANN's Domain Metrica, open to all since 18 February 2025, shows abuse concentration per registrar from reputation lists. Spamhaus ranks registrars by the share of their domains that are abusive, not by volume. A registrar with a high share sees its domains blocked and its customers' email filtered.
So we suspend phishing, malware, botnets, CSAM and fraud against victims quickly, and nothing else without a Panamanian court decision. Honest customers keep the benefits: no ID, crypto payments, free WHOIS privacy where allowed, and the same public prices for everyone.
Abuse reports: FAQ
Does BuyDomainsCrypto take down websites?
BuyDomainsCrypto acts on domains, not on hosting. We register domains and do not host websites. When a domain is suspended for abuse, it is taken out of service, so the website and email on that domain stop working. For content hosted elsewhere, also contact the hosting provider, which can remove the files themselves.
Will BuyDomainsCrypto suspend a domain over a copyright or defamation complaint?
Not on the complaint alone. Copyright, defamation, political and competitor complaints need a decision from a Panamanian court before we suspend a domain; foreign judgments must first be recognised in Panama. Send the complaint to the hosting provider, or obtain a decision from a Panamanian court. The only cases we suspend on a well-documented report are phishing, malware, botnets, child sexual abuse material, and fraud that takes money from victims (fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand). Trademark disputes go through the UDRP.
Can you tell me who registered a domain?
Not without a Panamanian court order, except urgent requests that ICANN rules require registrars to answer (threat to life, serious injury, critical infrastructure, child exploitation). We do not release registrant data to lawyers, companies or foreign governments on request. In a UDRP case, the registrant details are confirmed to the dispute provider, as ICANN requires. Public registration data is available through RDAP, for example at lookup.icann.org, but personal data there is usually redacted.
How fast does BuyDomainsCrypto act on phishing?
We act within 24 hours of a well-documented report. A report with the full URL, a screenshot and a timestamp is acted on fastest. We do not ask you to prove that credentials were stolen before we act. Child sexual abuse material is handled immediately, with a report to the competent hotline or authority.
I received a phishing email that uses one of your domains. What should I send?
Forward the email with its full headers to [email protected], as an attachment if you can. Add the link the email points to, and the time you received it with your timezone. The headers show the sending servers and the domains involved. Do not click the link again to collect more evidence.
Does no KYC mean abusers cannot be stopped?
No. BuyDomainsCrypto stops domains and accounts, not identities. Abusive domains are suspended, the other domains in the same account are reviewed, and suspended domains get no refund. Every registrant also has a verified email, as ICANN requires. No KYC removes paperwork for honest customers. It does not remove our rules.
My domain was suspended. What can I do?
Write to [email protected] from the registrant email, with the domain name. Explain what happened, for example a hacked website that has since been cleaned, and add evidence. We review the reply and answer by email. Suspensions for abuse carry no refund, as our Acceptable Use Policy states.
Is a UDRP complaint the only way to recover a domain that infringes my trademark?
It is the standard way for a domain registered and used in bad faith. File the complaint with an approved provider such as WIPO. We lock the domain within 2 business days of a request from a UDRP provider and apply the panel's decision. A decision from a Panamanian court is the other route. An email or a letter to us alone cannot transfer or suspend a domain.
Sources (12)
- 2013 Registrar Accreditation Agreement and specifications — ICANN (checked 2026-10-08)
- Global amendments to the RAA and base registry agreement (DNS abuse) — ICANN (in force 2024-04-05)
- Advisory: compliance with DNS abuse obligations — ICANN (2024-02-05)
- ICANN's DNS abuse mitigation program: key updates — ICANN Blog (2024-12-10)
- ICANN sends breach notice to Trustname — Domain Name Wire (2026-06-10)
- Notice of termination of registrar accreditation agreement (Trustname) — ICANN Contractual Compliance (2026-08-27)
- ICANN Domain Metrica: access now open to all users — ICANN Blog (2025-02-18)
- The 10 most abused registrars — Spamhaus (checked 2026-10-08)
- Domain Reputation Update, October 2025 to March 2026 — Spamhaus (April 2026)
- Phishing Landscape 2025 — Interisle Consulting Group (2025)
- Rules for Uniform Domain Name Dispute Resolution Policy — WIPO (checked 2026-10-08)
- Registration Data Policy now in effect for contracted parties — ICANN (2025-08-21)
Report abuse to [email protected]
Send the domain, the URLs, your evidence and timestamps. Read the rules every customer accepts, and what we hold.