Wholesale registrar good practices: combating online child sexual exploitation and abuse

Online child exploitation and abuse is illegal but remains a pervasive threat. Wholesale registrars play a critical role in preventing, mitigating, and responding to these harms across the domain ecosystem.

domain registrar

This resource provides guidance on operational practices for wholesale registrars and can be used to learn more about how to combat online child sexual abuse and exploitation (OCSEA), including but not limited to child sexual abuse material (CSAM), grooming and trafficking.

domain registrar

Understanding wholesale registrars in the ecosystem

Wholesale registrars operate as intermediaries between domain registries and resellers, who in turn provide services to end users.

Unlike registrars that directly interact with customers, wholesale registrars primarily manage reseller relationships, offer infrastructure services, and enforce policy compliance.

RoleResponsibility
RegistryMaintains database of domain names; sets top-level policy.
Wholesale registrarProvides infrastructure, manages reseller accounts, enforces policy with resellers.
ResellerOffers domain registration to end users; interacts directly with customers.
Hosting provider / website providerProvides website hosting, storage, and / or content delivery.
RegistrantEnd user that owns the domain/website; publishes content.

Because wholesale registrars rarely interact directly with end users and typically have less visibility into the underlying content and customer activity, they may operate with fewer data points when assessing potential abuse.

Nevertheless, wholesale registrars can investigate, identify, and take action on DNS Abuse within their sphere of control. They work alongside registrars and resellers to address abuse, with registrars ensuring that Acceptable Use Policies (AUPs) are appropriately enforced.

What is online child sexual exploitation and abuse (OCSEA)?

For the purposes of this document, OCSEA refers to a range of harms including CSAM, grooming, trafficking, and other forms of sexual exploitation of children.

OCSEA refers to the usage of the internet or communication technologies to facilitate the sexual abuse of children and adolescents. This includes – for example – the distribution, hosting, or linking to Child Sexual Abuse Material (CSAM), the live streaming or recording of abusive acts, coercion or enticement of children, and child sex trafficking.

It is a misconception that in order for an OCSEA incident to occur on a website, children must be users of the website. This is not true and many OCSEA harms occur between adults – for example, trading CSAM amongst themselves or hosting chat forums that sexualize children.

Why is it important that domain infrastructure providers respond quickly to OCSEA incidents?

Children depicted in CSAM are victims of ongoing abuse: every viewing, sharing, downloading, or hosting of the content perpetuates the abuse.

OCSEA is a priority for global law enforcement, and domain-infrastructure providers frequently receive urgent legal requests related to these cases.

Quick action is essential as every hour of exposure can mean further revictimization.

Establish operations in order to identify OCSEA

An important practice for fighting OCSEA is to incorporate public-facing language into a company’s external standards, for example their Terms of Service (TOS) and Acceptable Use Policies (AUP).  Consider including: 

  • Explicitly prohibit OCSEA or clearly reference it within broader prohibitions on illegal or harmful content.
  • Define expected response timelines and escalation approaches, taking into account the severity of the harm and applicable legal or contractual requirements.
  • Outline actions if resellers or customers fail to comply, recognizing that specific measures may vary depending on contractual agreements and available tools.
  • Include transparency commitments (e.g., publishing aggregate data on abuse reports and actions taken), where appropriate and in line with applicable regulatory requirements.

Clear TOS/AUP language ensures resellers understand their obligations and helps protect the wholesale registrar legally and operationally.

To facilitate fighting OCSEA, companies may establish internal principles to define key terms and document enforcement guidelines. This helps ensure alignment and consistency. 

Internal policies

Align abuse policies with recognized frameworks such as the DNS Abuse Framework, where applicable, while taking into account jurisdictional differences in how such content is defined and regulated.

Internal policies may include:

  • Roles and responsibilities: for example, a designated point of contact responsible for handling  time-sensitive reports involving OCSEA, with clear criteria for what constitutes an urgent escalation.
  • A review process, specifying:
    • Definitions of potential OCSEA harms and examples 
    • Note: organizations should provide examples that support reviewer understanding while minimizing exposure to harmful content and reducing the risk of re-victimization of victims and survivors. Examples should be representative, non-graphic, and limited to what is necessary to explain the policy.
    • Any evidence required to take action (e.g., URLs, screenshots, trusted notifier reports, law enforcement notifications)
    • Any emergency escalation procedures
  • Enforcement protocols that outline what actions are required depending on the scenario, for example:
    • Hosted vs. user-generated content
    • Sites primarily dedicated to abusive content vs. platforms that prohibit such content but are poorly moderated vs. sites that are compromised or taken over by bad actors
    • CSAM vs. non-CSAM abusive content
    • Scenarios requiring host, registrar, or other stakeholder contact, with the goal of directing reports to the party best equipped to take action
Feedback and communication loops

Documenting workflows ensures timely and coordinated responses, maintains accountability and preserves any evidence. A feedback loop includes:

  • Report receipt: registrar receives a report (from registry, trusted notifier (e.g., child-protection NGOs such as IWF), law enforcement, or public).
  • Verification and assignment: confirm domain ownership and gather evidence; assign the case to an internal reviewer.
  • Reseller notification: notify the reseller immediately; require acknowledgment and action per legal or stakeholder timelines and align with IIF processes.
  • Monitoring and escalation: if reseller fails to act, escalate per internal enforcement protocols; this may include DNS suspension, law enforcement notification, or registry involvement.
  • Documentation and recordkeeping: record all steps, actions taken, and communications.
  • Customer communication ownership: ensure clear assignment: resellers typically manage end-user communication, but registrars document interactions and monitor resolution.
Align processes with agreements

Your company’s TOS and reseller agreements outline key operational requirements, such as:

  • Expected response times for OCSEA reports
  • Escalation and enforcement protocols
  • Feedback and communications expectations 

In practice, these processes often operate across chains of providers (e.g., registrar → reseller → downstream provider), which can introduce delays and complexity. Establishing clear expectations at each level and accounting for these dependencies can help improve coordination and response effectiveness.

Team structure

How a company organizes  its approach to child safety can have implications for effectiveness, collaboration, and risk management. While many wholesale registrars may not have dedicated child safety teams, it is important to ensure that relevant functions (e.g., Trust & Safety, Abuse, Fraud, Legal) collaborate effectively.

This can help to:

  • Facilitate the sharing of expertise across functions like abuse detection, investigations, enforcement, and legal compliance.
  • Support timely and coordinated response for OCSEA- related incidents.
Employee and vendor wellness

If employees or contractors may be exposed to potentially harmful material – potentially through reviewing reports, handling abuse cases, or interacting with escalated incidents – it is important to consider their wellbeing.

In some cases, wholesale registrars may not directly review content (e.g., due to legal or operational constraints) and instead rely on trusted notifiers or law enforcement. However, employees may still be exposed to descriptions, metadata, or other distressing information as part of their work.

Where applicable, companies can consider implementing wellness measures to support employees and contractors, such as:

  • Providing access to mental health resources or specialized support
  • Encouraging regular breaks or workload management practices
  • Offering guidance on handling exposure to sensitive or distressing material

Companies that partner with 3rd party vendors for abuse review can ask about and ensure wellness resources are in place for their contractors.

Take action when an OCSEA incident is reported

When a report is received, wholesale registrars may follow different processes depending on legal requirements, operational models, and the source of the report.

In some cases, registrars may not be permitted to directly investigate certain types of reports (e.g., CSAM) and instead rely on authorized or qualified entities (such as law enforcement or INHOPE-affiliated hotlines). In these cases, initial reports may be redirected, and action is taken based on validated or trusted notifications.

Where investigation is permitted, or when acting on trusted reports, processes may include:

  • Confirm domain ownership in your system.
  • Ensure that the report includes sufficient information (e.g. URLs, references etc).
  • Follow internal policies to review and investigate the incident, if applicable.
  • Notify the reseller or relevant downstream provider as appropriate.
  • Require acknowledgment and action that complies with any legal requirements and/or stakeholder policy timelines (for example, registry CSAM mitigation processes).

If no action is taken to remove the content within the outlined timelines, follow enforcement protocols.

The goal is to ensure the abusive content is addressed while minimizing impact on benign content.

The DNS Abuse Framework recognizes that DNS-level suspensions are blunt instruments, but it recommends considering their use in cases involving CSAM due to the extreme and urgent nature of the harm.

Additional steps may include:

  • Informing the registry and any other stakeholders as outlined in agreements.
  • Documenting all steps taken.
  • Preserving relevant registration records for potential law enforcement requests.
  • Monitoring for appeals. 

For US based companies
  • Register with The National Center for Missing & Exploited Children (NCMEC) in order to report CSAM cases:
    • NCMEC operates the CyberTipline, a national clearinghouse for leads and tips regarding child sexual exploitation. 
    • To create an account with the CyberTipline a company should register as an ESP (Electronic Service Provider), or contact NCMEC at [email protected] for a form requesting the necessary information. Once the form is completed and submitted, NCMEC will issue the login credentials, enabling the company to begin submitting reports.
    • In addition to mandatory reporting obligations, companies must also comply with data preservation requirements.
For companies based outside the US

INHOPE serves as the umbrella organization for a global network of hotlines working to combat OCSEA. To locate the appropriate hotline, visit their website and select your country. 

INHOPE will redirect you to the relevant national hotline, who can help find the appropriate local reporting option. Some hotlines accept direct reports from companies while some will signpost to the relevant law enforcement channels.

Establish policies and protocols to ensure an efficient response to law enforcement requests.  

Develop a law-enforcement response policy defining:

  • What required and relevant information should be preserved and accessible for authorized requests.
  • What legal processes are required.
  • Expected response timelines.

Prevention

Wholesale registrars can reduce the risk of abuse entering their ecosystem through:

  • Robust reseller vetting and oversight: assess reseller risk at onboarding and over time, and monitor for abuse patterns (e.g. elevated abuse rates or repeated incidents) that may indicate higher-risk activity within a reseller’s customer base..
  • Monitoring for high risk signals: identify suspicious registrations or content patterns
  • Educating resellers about:
    • OCSEA and abuse reporting
    • Guidance on detecting malicious customers
    • Any considerations for their own TOS/AUPs and internal policies and protocols

Participate in cross industry initiatives

  • Join IWF’s domain abuse mitigation services
    • PIR sponsors free access to two of the key IWF domain abuse mitigation services: Domain Alerts and the Top‑Level Domain (TLD) Hopping List for registries and registrars that choose to join. 
    • These services help identify and disrupt domains associated with the distribution of CSAM and proactively counter criminal domain‑hopping tactics that attempt to evade takedown efforts.
  • Adopt frameworks such as the DNS Abuse Framework
  • Sign up for the Tech Coalition’s Pathways program which includes expert advice, resources and opportunities for the tech companies to further build capacity to combat online child sexual exploitation and abuse. 

Sign up for Pathways, expert advice, resources and opportunities for the tech industry to further build capacity to combat online child sexual exploitation and abuse.

Explore Pathways