No KYC — no ID, no selfie · Pay in BTC, USDT, USDC, ETH, SOL, LTC · .com $11.49/year, same price to renew
Search a domain

Legal · effective 8 October 2026

Acceptable Use Policy

No KYC does not mean no rules. This policy lists what you may and may not do with a domain registered through BuyDomainsCrypto, and how we enforce it. It forms part of our Terms of Service.

Last updated: · 6 min read

Quick answer

What is not allowed on a BuyDomainsCrypto domain?

BuyDomainsCrypto, a no-KYC domain registration service paid in crypto, allows any lawful use of a domain. Twelve uses are banned, from phishing and malware to fraud, spam and bad-faith trademark registrations. Phishing, malware, botnets, child sexual abuse material and fraud that takes money from victims lead to suspension, with no refund. For every other breach, a complaint alone is not enough: we act on a decision from a Panamanian court, or on a UDRP decision for trademarks.

Policy summary

Applies toEvery account and every domain registered through BuyDomainsCrypto, and anyone you let use them
AllowedAny lawful use: business, personal, projects, blogs, shops, parking, resale, privacy
Banned12 categories, listed in section 3: phishing, malware, botnets, CSAM, fraud, scams, impersonation, sale of stolen data, spam, bad-faith trademark use, sanctions evasion, illegal goods
Registrant dutiesOne working email per domain, verified as ICANN requires
EnforcementStrict exceptions (phishing, malware, botnets, fraud that takes money from victims): suspension within 24 hours of a well-documented report, no refund. CSAM: immediately, with a report to the competent hotline or authority. Other breaches: action on a decision from a Panamanian court (foreign judgments must first be recognised in Panama) or a UDRP decision, never on a complaint alone
Child sexual abuse materialSuspension immediately, with a report to the competent hotline or authority
Reports[email protected], see report abuse
Effective8 October 2026

1. Who does this policy apply to?

This policy applies to every BuyDomainsCrypto account and to every domain registered through BuyDomainsCrypto. It also covers anyone you allow to use your domains, such as a developer, a hosting provider or a client. You are responsible for what is published or sent with your domains.

This policy forms part of our Terms of Service. If the two documents differ on a point, the stricter rule applies. "We" and "us" mean BuyDomainsCrypto and DomaineGoat LLC, the company that operates it.

2. What can I use a BuyDomainsCrypto domain for?

You may use a domain for any lawful purpose, including:

  • Business: a company website, an online shop, a SaaS product or a landing page.
  • Personal use: a blog, a portfolio, a family site or your own email server.
  • Projects: open-source projects, developer tools, Web3 and crypto project websites that follow the law.
  • Domain investing: holding, parking and reselling domains, as long as the name does not target a trademark in bad faith.
  • Privacy: keeping your email out of public WHOIS and RDAP, with free WHOIS privacy where the registry allows it.

A use that is not listed is allowed if it is lawful and not banned in section 3. Paying in crypto and registering without ID are lawful choices, not signs of abuse.

3. What is banned?

You may not use a domain registered through BuyDomainsCrypto, or let anyone else use it, for the twelve uses below. They fall into two groups.

Strict exceptions: suspended on a well-documented report, without waiting for a court.

  1. Phishing: pages or emails that imitate a bank, an exchange, a wallet, a brand or a public body to collect credentials, card data or funds.
  2. Malware: distributing malicious software, hosting exploit kits, or running crypto wallet drainers.
  3. Botnets: command-and-control servers, and pharming or DNS hijacking that redirects users.
  4. Child sexual abuse material (CSAM): zero tolerance, with a report to the competent hotline or authority.
  5. Fraud that takes money from victims: fake shops, advance-fee schemes, fake invoices, fake support lines.
  6. Scam investment and crypto sites: fake trading or investment platforms, "doubling" and giveaway scams, wallet drainers, fake exchanges and fake token sales.
  7. Impersonation to deceive: passing yourself off as a bank, a brand, a government body or a person, to take money or data.
  8. Sale of stolen data: card data, login credentials or personal data taken without consent.

Items 1 to 3, and spam that delivers them, are DNS abuse as ICANN defines it. We act on items 1 to 3 and 5 to 8 within 24 hours of a well-documented report. CSAM is handled immediately, with a report to the competent hotline or authority.

Also banned, but a complaint alone does not suspend a domain. We act on a decision from a Panamanian court (foreign judgments must first be recognised in Panama), or on a UDRP decision for trademarks:

  1. Spam: unsolicited bulk messages sent from or advertising the domain, other than spam that delivers phishing or malware.
  2. Bad-faith trademark registrations: registering a name that copies a trademark to sell it to the owner, to divert its customers or to harm it. These cases go through the UDRP.
  3. Sanctions evasion: using the service to evade economic sanctions that apply to you or to us.
  4. Illegal goods and content: selling illegal drugs or weapons, or content that a Panamanian court has ordered removed.

Complaints about copyright, defamation, politics or from a competitor also need a decision from a Panamanian court.

4. What are my obligations as a registrant?

Every registrant must follow ICANN's Registrants' Benefits and Responsibilities and the rules of the registry. In practice:

  • A working, verified email. It is the only data we ask for. ICANN rules require it: the registrant email is verified after registration, as ICANN rules require (within 15 days). A domain whose email is never confirmed can be suspended.
  • Keep it up to date. Change the email of a domain in the client area if you stop using the old one.
  • Extension rules. Some registries add technical conditions: .app, .dev and .page require HTTPS, and .ai is sold 2 years at a time. We do not sell extensions that require more than an email, such as .us, .eu or .uk. Each extension page lists its rules.

No ID document is ever required by us. The only check is the email.

5. How does BuyDomainsCrypto enforce this policy?

We act on evidence, in two ways.

Strict exceptions: phishing, malware, botnets, child sexual abuse material, and fraud that takes money from victims (fake shops, investment and crypto scams, wallet drainers, impersonation of a bank or brand), and the sale of stolen data. A well-documented report is enough. We act within 24 hours of a well-documented report, and on CSAM immediately, with a report to the competent hotline or authority.

Everything else: no takedown on a complaint alone. Copyright, defamation, political or competitor complaints need a decision from a Panamanian court (foreign judgments must first be recognised in Panama), and so do spam outside DNS abuse, sanctions evasion and court-ordered content removal. Trademark disputes follow the UDRP: the domain is locked within 2 business days of a request from a UDRP provider and the panel's decision is applied.

Possible actions:

  • Suspension of the domain, which takes it out of service: website and email stop working.
  • Lock of the domain, so that it cannot be transferred while a case is open.
  • Review of the other domains in the same account after a confirmed exception case, because abuse campaigns often use several names.
  • Closure of the account for serious or repeated abuse.

Registrant data only goes out on a Panamanian court order, except urgent requests that ICANN rules require registrars to answer, as described on our abuse page.

6. What happens to my payment if my domain is suspended?

A domain suspended for abuse is not refunded. The registry fee is paid when the domain is registered, renewed or transferred, so the registration fee is not returned.

Opening a new account to carry on after a suspension is a breach of this policy. Prices themselves are the same for every customer, on the pricing page. Refund rules for other cases are on the refunds page.

7. How do I report a breach of this policy?

Email [email protected] with the domain, the full URLs, your evidence and timestamps. The abuse page explains what to include and what happens next. Do not send CSAM files: send the URL and the time only.

8. Can this policy change?

Yes. When we change this policy, the new version shows its update date at the top of this page. The change is also listed in the changelog. The new version applies from that date. If you do not accept it, you can transfer your domains to another registrar with their transfer code.