What Is Domain Suspension?
Domain suspension is a registrar or registry operator stopping a registered domain name from resolving in the DNS by applying the clientHold or serverHold EPP status code (opens in new tab). The registration stays in the registry database and the registrant keeps the name, but the domain drops out of the TLD zone file, so its website, email, and other DNS-dependent services stop working.
Suspension differs from domain deletion (opens in new tab), which removes the registration entirely, and from domain seizure (opens in new tab), which hands control of the name to a court-authorized party.
How domain suspension works
Registered domains carry EPP status codes (opens in new tab) that tell the registry what to do with them. In the EPP model the registrar is the "client" and the registry is the "server," so the registrar sets clientHold, the registry sets serverHold, and server codes take precedence over client codes. Either hold pulls the domain's nameserver records out of the zone file, so the name stops resolving.
The registry retains the registration record; WHOIS and RDAP still show it, with a status line reading clientHold or serverHold — under RFC 8056 (opens in new tab), RDAP represents these as "client hold" and "server hold." Removing the hold restores the nameserver records and resolution resumes, though cached DNS can sustain the site briefly.
Lifting a serverHold takes longer than lifting a clientHold, since the registrar must forward the request (opens in new tab) to the registry and wait.
In ICANN's compliance advisory (opens in new tab), a credit union reports a newly registered domain collecting login credentials, with a screenshot as evidence. That is actionable evidence of phishing: the information available lets the registrar make a "reasonable determination" that the domain is being used for DNS Abuse.
The registrar applies clientHold, can add a transfer lock so the registrant can't move the domain to evade the mitigation, and the page goes dark as resolver caches expire.
Why domain suspension matters
Since 5 April 2024, suspension has been how registrars meet a contractual duty. Under Section 3.18.2 (opens in new tab) of the amended Registrar Accreditation Agreement, a registrar holding actionable evidence that a domain it sponsors is used for DNS Abuse must promptly take the mitigation action needed to stop it. DNS Abuse (opens in new tab) covers malware, botnets, phishing, pharming, and spam that delivers one of those.
A lookalike domain serving a credential-harvesting page is phishing under that definition. Enforcement has followed: ICANN compliance issued its first breach notices (opens in new tab) under the amendment to a TLD and a registrar in 2024, and now runs routine audits (opens in new tab) targeting registrars with the highest concentration of reported abuse.
The duty doesn't extend to trademark or content complaints. Parties must resolve most trademark disputes by agreement, court action, or arbitration before a registrar will cancel or suspend (opens in new tab) a domain for that reason.
A domain that only carries a brand's name, or sells counterfeit goods, is a content dispute; the moment it serves a working phishing page, it becomes DNS Abuse, and registrars refer trademark-only reports to the UDRP instead.
Suspension only reaches the registered domain itself. When phishing runs on a subdomain of a legitimate hosting or document-sharing platform, the registrar has no hold to place on the platform's own domain without taking every legitimate tenant on it offline too, so that case routes to the host instead.
Bulk domain registration (opens in new tab) is also common enough among attackers that suspending one domain rarely stops the operation, so suspension is one action inside a broader takedown that also hits hosting, certificates, and the channels feeding traffic to the domain.
Types of domain suspension
Suspensions differ by who applies the hold and what triggers it.
- Registrar-initiated (clientHold). The common form for abuse cases, legal disputes, non-payment, or pending deletion; for DNS Abuse, it's the mitigation action described in ICANN's 2024 advisory. Only the sponsoring registrar can remove it.
- Registry-initiated (serverHold). The registry operator applies this to keep a domain from activating in the DNS. Whether a reporting team can escalate to the registry when the registrar refuses to act depends on that TLD's own procedures.
- Suspension for inaccurate registration data. Under RAA Section 3.7.7.2 (opens in new tab), a registrar must suspend or cancel a domain when the registrant knowingly gives inaccurate information, doesn't correct it, or ignores an accuracy inquiry — a WHOIS inaccuracy complaint (opens in new tab) can run alongside an abuse report.
- URS suspension. The Uniform Rapid Suspension System lets a trademark holder get suspension for the balance (opens in new tab) of the registration term on clear and convincing evidence of cybersquatting, through an expedited process, on new gTLDs.
The complainant can extend it for a further period at commercial rates; after that, the name becomes available for re-registration.
How to request a domain suspension
Start with the registrar's abuse contact. Every ICANN-accredited registrar must publish an abuse email or web form, confirm receipt, and take reasonable, prompt steps (opens in new tab) to investigate. Report to the host at the same time, not after — a host can pull the page (opens in new tab) while the domain stays registered, and for a compromised legitimate site the host is the right target, since a hold there would take an innocent business offline.
Build the report to the actionable-evidence standard: a "reasonable determination" based on independently accessible information. Include:
- Defanged URLs and the bare domain name
- Timestamped screenshots showing the phishing content, the full address-bar URL, and the impersonated brand
- WHOIS or RDAP output, DNS records, IP address, and hosting ASN
- HTTP headers, redirect chains, and form-post or exfiltration endpoints
- Email headers or SMS content when the lure arrived by message
- The abuse type (phishing), plus ticket numbers from any prior reports
If the registrar stalls, NetBeacon Reporter (opens in new tab) routes a standardized report to the sponsoring registrar or, for ccTLDs, the registry directly. Failing that, file with ICANN Contractual Compliance using its step-by-step guide (opens in new tab), and report criminal phishing to CISA (opens in new tab) or the FBI's IC3.
In parallel, submit the URL to Google Safe Browsing (opens in new tab) and Microsoft SmartScreen (opens in new tab), and ask the certificate authority to revoke, as the CA/Browser Forum baseline (opens in new tab) requires on evidence of misuse.
That sequence breaks down by hand once attackers register in batches.
How Doppel helps
Doppel is the Frontier AI Social Engineering Defense (SED) platform unifying Digital Risk Protection (DRP) and Human Risk Management (HRM). A suspended domain rarely runs alone: the same campaign usually has a spoofed social profile, a paid ad, or an SMS lure that sent victims to it in the first place, and none of those close when the domain does.
Brand Protection maps every asset into the Doppel Threat Graph and dismantles the connected campaign in one action across registrars, hosting, social platforms, ad networks, and telco infrastructure. Its agentic AI detects and correlates signals and executes takedowns at scale; Doppel reports a median takedown of under 10 hours (opens in new tab).
Analysts handle unresponsive registrars, compromised legitimate domains, and cases that call for a URS filing or court action.
Request a demo to see campaign-level mapping in the Threat Graph and the enforcement actions it triggers.
Frequently asked questions about domain suspension
What is domain suspension?
Domain suspension is a registrar or registry operator stopping a domain from resolving in the DNS by applying an EPP hold — clientHold or serverHold. The registry keeps the registration, and WHOIS or RDAP still show it, but the registrar or registry withholds its nameserver records from the zone file, so the site and email attached to it stop working. Lifting the hold restores resolution without re-registering the name.
What is domain suspension in cybersecurity?
In cybersecurity, domain suspension is the standard registrar response to a domain used for DNS Abuse — phishing, malware, botnets, pharming, or spam that delivers one of those. Brand-protection teams rely on it to disable lookalike domains hosting credential-harvesting pages, usually by reporting the abuse rather than waiting for a registrar to find it first.
What is the difference between domain suspension and a UDRP transfer?
Suspension leaves the domain registered to the attacker and pulls it out of the DNS; a UDRP decision transfers or cancels the registration outright. Suspension can happen quickly on evidence of abuse; a UDRP case is an arbitration that takes weeks to months (opens in new tab) and requires proving the domain is confusingly similar to a mark the complainant holds, that the registrant has no legitimate interest in it, and that they registered and used it in bad faith. Suspension stops the harm while a UDRP proceeds in parallel toward cancellation or transfer (opens in new tab).
What is an example of domain suspension?
The credit union scenario above is ICANN's own worked example: a newly registered domain harvesting login credentials, reported with a screenshot, clears the actionable-evidence bar, and the registrar applies clientHold, often with a transfer lock, the same way it would for any brand a criminal impersonates the same way.


