These numbers are revealing - and appalling. No doubt in my mind that we need the tools to make this abuse of the system, cease. Getting the policy setting correct is clearly the first priority. I support this proposal.
On Mon, 21 Sept 2026 at 14:27, Jonathan Brewer <jon@tō.nz> wrote: > Dear SIG-Policy community, > > I'd like to offer some evidence of the acute need for prop-173. > > You might have seen my earlier post announcing an analysis platform for > APNIC directory services use. The platform is here: https://apnic.tō.nz/ > ( https://apnic.xn--t-0la.nz/ if your email client doesn't support IDN). > > This platform shows that one ASN (out of APNIC's 10,000 members) is > responsible for 37% of all use of WHOIS. It shows that the top ten ASNs > (0.001% of APNIC members) are responsible for 73% of all WHOIS use. > > Similarly one ASN is responsible for 41% of all RDAP use, and the top ten > ASNs are making 81.5% of all requests. > > This is not operational use of directory services as intended. This kind > of abuse is forbidden and protected against in other RIRs, but not in > APNIC. This is because APNIC does not have an acceptable use policy for its > directory services. > > I'd appreciate it if all of you who understand the problem express a view > on the proposal. And if you don't understand the problem, let me know how I > can make it more clear. > > Best Regards, > > Jon > > On Mon, 17 Aug 2026, at 19:32, Bikram Shrestha wrote: > > Dear SIG members, > > A new proposal "prop-173: Copyright and Acceptable Use Terms for APNIC > Directory Services" > has been sent to the Policy SIG for review. > > It has been published to the mailing list for community discussion. > > We encourage you to express your views on the proposal: > > Do you support or oppose this proposal? > > Does this proposal solve a problem you are experiencing? If so, > tell the community about your situation. > > Do you see any disadvantages in this proposal? > > Is there anything in the proposal that is not clear? > > What changes could be made to this proposal to make it more effective? > > Information about this proposal is appended below as well as > https://www.apnic.net/community/policy/proposals/prop-173/: > > Regards > Bikram, Shaila, and Ching-Heng > > ------------------------------------------------------- > prop-173-v001: Copyright and Acceptable Use Terms for APNIC Directory > Services > ------------------------------------------------------- > > Proposer: Jonathan Brewer > [email protected] > > > 1. Problem statement > ------------------------------------------------------- > APNIC provides access to its whois database through WHOIS, RDAP, and > web-based services. Although APNIC publishes an Acceptable Use Agreement > for bulk Whois data, it does not publish a separate, clearly scoped policy > governing ordinary ad-hoc queries. > > Users of WHOIS and RDAP therefore cannot readily determine: > > - what uses of query results are permitted; > - whether results may be stored, compiled, republished, or incorporated > into other services; > - what constitutes excessive or abusive querying; > - what enforcement action APNIC may take; or > - whether APNIC asserts copyright or other intellectual-property rights in > its directory database and services. > > Current WHOIS and RDAP responses refer users to terms associated with the > bulk-access agreement, but that agreement is designed for applicants > seeking bulk downloads or mirrors. It does not clearly establish terms for > users making ordinary queries. APNIC has also previously indicated that > specific terms of use for WHOIS and RDAP would be implemented, but no > distinct policy appears to have been published. > > This is inconsistent with APNIC’s historical practice. During its first > decade, APNIC published copyright and restricted-rights statements applying > broadly to data retrieved from APNIC databases. These statements restricted > reproduction, storage, and transmission outside agreed Internet-operational > purposes, prohibited targeted advertising, and allowed APNIC to limit or > deny access for excessive querying. > > APNIC should restore a clear policy position on its WHOIS database by > asserting the rights available to it under Australian law and publishing > specific acceptable-use terms for ordinary WHOIS, RDAP, and web-query > access, separate from the existing bulk-access agreement. > > > 2. Objective of policy change > ------------------------------------------------------- > APNIC will publish a clear, public, versioned APNIC Directory Services > Acceptable Use Policy governing ordinary access to WHOIS, RDAP, and > web-based directory searches. > > The policy will: > > - be separate from the existing agreement governing bulk downloads and > mirroring; > - assert APNIC’s copyright and other applicable intellectual-property > rights in the directory database; > - clearly define permitted and prohibited uses; > - be presented to users through every directory-service interface and > interaction; > - provide protections at least as strong as those contained in APNIC’s > early database copyright and restricted-rights statements. > > > 3. Situation in other regions > ------------------------------------------------------- > RIPE NCC publishes both comprehensive RIPE Database Terms and Conditions > and a separate Acceptable Use Policy. Accessing the database constitutes > agreement to the terms. Permitted purposes are enumerated, advertising and > direct marketing are prohibited, and users may not repackage, download, > compile, redistribute, or reuse a significant part of the database without > permission. The terms also assert RIPE NCC ownership of all copyright, > trademarks, database rights, and other intellectual-property rights > subsisting in the database, its data, software, and accompanying documents. > > ARIN publishes Whois Terms of Use that apply to any use of its Whois > service, including compilation, repackaging, and dissemination. Use of the > service constitutes acceptance of the terms. The document enumerates > operational and technical-research uses and prohibits advertising, direct > marketing, marketing research, republication, resale, and use as part of an > unauthorised commercial data product or service. > > LACNIC includes a copyright and lawful-use statement directly in its WHOIS > responses. Users are told that the data is provided for information > concerning IP address and AS number registrations and that submitting a > query constitutes agreement to use the data only for lawful purposes. > > AFRINIC publishes terms applying to access, querying, compilation, > repackaging, dissemination, and other uses of its Whois Database. Its terms > enumerate permitted operational and research purposes, prohibit commercial > data products, advertising, direct marketing, market research, and illicit > uses, reserve the right to rate-limit or terminate access, and treat bulk > access under a separate agreement. > > AFRINIC also asserts that copyright, trademarks, database rights, and > other intellectual-property rights subsisting in the database, its > contents, software, documents, and agreements remain AFRINIC property. > > > 4. Proposed policy solution > ------------------------------------------------------- > 1. Scope > > APNIC will publish an APNIC Directory Services Acceptable Use Policy > applying to any person or system that accesses, queries, receives, or uses > APNIC-authoritative directory data through: > > WHOIS; > RDAP; > APNIC web-based directory searches; > APIs providing equivalent registration data > > The policy will apply to APNIC-authoritative data and objects identified > as having APNIC as their source. Data mirrored or referred from another > registry will remain subject to the terms of the authoritative source > registry. > > The policy will define “user” broadly enough to include a person who > directly accesses the service and a person or organisation that causes > automated access to be made on its behalf. > > 2. Separation from bulk access > > The ordinary-query policy will be a separate document from the existing > bulk-access agreement. > > The policy will state that it does not grant bulk-download or mirroring > rights. Users requiring high-volume access, a significant extract, a > mirror, or a substitute database will apply through APNIC’s separately > governed bulk-access process. > > 3. Copyright and intellectual-property statement > > The policy will state that APNIC must assert all copyright and other > rights available to it under Australian law. > > 4. Permitted uses > > The policy will expressly permit ordinary low-volume queries for defined > Internet-operational and technical-research purposes, including: > > evaluating routing policies and routing-policy compliance; > network troubleshooting and operational coordination; > identifying the holder or operator of Internet number resources; > maintaining the uniqueness and accurate registration of Internet number > resources; > providing and troubleshooting reverse DNS; > reporting, investigating, and mitigating network abuse or security > incidents; > identifying resources suspected of unlawful or harmful use; > conducting scientific or technical research into Internet operations, > routing, security, resilience, or topology; > supporting lawful resource-registration disputes; and > responding to legally valid requests from competent authorities. > > 5. Prohibited uses > > The policy will prohibit: > > advertising, targeted advertising, direct marketing, lead generation, > marketing research, or similar activity; > compiling contact or marketing lists; > harassment, intimidation, surveillance, or unlawful activity; > using directory data to build demographic profiles; > using directory data to infer or represent the geographic location of an > address, network, organisation, or individual; > selling, licensing, or republishing directory data as a data product; > making directory data available as part of a commercial enrichment, > profiling, or lookup service without written permission; > systematic harvesting through ordinary query interfaces; > using distributed hosts, addresses, accounts, or intermediaries to evade > rate limits; > interference with the availability, integrity, or security of the > directory services; and > any use inconsistent with the stated purposes of the APNIC Directory > Database. > > Ordinary operational use by a commercial network operator or security > provider will not be prohibited merely because the organisation operates > commercially, provided the directory data is not itself resold, > republished, or made into a separate commercial data product. > > 6. Reproduction, storage, and redistribution > > Except as necessary for a permitted Internet-operational or > technical-research purpose, users will not reproduce, persistently store, > compile, transmit, repackage, redistribute, or make available a substantial > part of the database without APNIC’s prior written permission. > > The policy may permit limited and temporary caching of individual query > results where necessary for a permitted use. APNIC will publish any > applicable retention, refresh, security, and deletion requirements. > > Caching will not be used to assemble a substitute directory database or > circumvent the bulk-access process. > > Any permitted onward disclosure will remain subject to restrictions at > least as protective as the APNIC policy. > > 7. Query conduct and rate limits > > APNIC may establish and enforce reasonable query-volume, rate, > concurrency, and result-size limits for security, privacy, and operational > purposes. > > The policy will prohibit attempts to evade those limits. > > APNIC will publish: > > the general principles used to identify excessive querying; > how a blocked user can identify the reason for a restriction; > a contact or review process for legitimate operational and research users; > and > the process for obtaining approved high-volume or bulk access. > > APNIC need not publish limits where doing so would materially assist > evasion or threaten service security. > > 8. Notice through each service > > The policy will be readily available before or at the time directory data > is supplied. > > WHOIS responses will contain a concise notice substantially equivalent to: > > % APNIC Directory Services data is subject to the APNIC > % Directory Services Acceptable Use Policy. > % By querying or using this service, you agree to those terms. > % Copyright APNIC. See: > > RDAP responses will include: > > a notices entry identifying the policy; > a link with rel set to terms-of-service; > a copyright or intellectual-property notice; and > the current policy URL. > > Web query interfaces will display a link to the policy and state that > submitting a query and using the results is subject to it. > > The notices will use a stable, maintained HTTPS URL that will not be > subject to HTTP redirection. > > 9. Enforcement and review > > APNIC may warn, throttle, suspend, block, or terminate access where it > reasonably believes that a user has breached the policy. This may happen > via automated means. > > Repeated or deliberate circumvention may result in long-term or permanent > denial of ordinary query access. > > The policy will provide a review mechanism for a user who believes that > access has been restricted in error or who can demonstrate a legitimate > operational or technical-research requirement. > > 10. Historical protection floor and future amendments > > The policy will not be materially less protective than APNIC’s copyright > and restricted-rights statements published during its early operation, > particularly in relation to: > > the assertion of copyright; > reproduction and persistent storage; > transmission and redistribution; > targeted advertising and similar activities; > use outside agreed Internet-operational purposes; and > excessive automated querying. > > The wording may be modernised and adapted to WHOIS, RDAP, privacy law, and > contemporary Internet operations, but the substantive level of protection > will not be weakened. > > The policy will include a version number, effective date, revision > history, and archive of previous versions. > > APNIC will provide reasonable advance public notice of amendments. Any > amendment that materially expands permitted reuse or materially weakens > protections will be subject to the APNIC Policy Development Process or an > equivalent community-consultation process. > > APNIC should implement this policy within six months of adoption. > > > 5. Advantages / Disadvantages > ------------------------------------------------------- > Advantages: > The proposal would restore the clear copyright and restricted-use position > that APNIC maintained during its early years of operation. > > Disadvantages: > APNIC would incur legal, documentation, and software-development costs to > draft the terms, update all query interfaces, maintain stable policy links, > and operate a review process. > > > 6. Impact on resource holders > ------------------------------------------------------- > Resource holders that operate automated WHOIS or RDAP clients may need to > ensure that their querying, caching, and redistribution practices comply > with the published policy. > > > 7. References > ------------------------------------------------------- > https://www.apnic.net/manage-ip/using-whois/bulk-access/ > https://www.apnic.net/manage-ip/using-whois/bulk-access/copyright/ > https://www.apnic.net/community/policy/proposals/prop-167/ > https://docs.db.ripe.net/HTML-Terms-And-Conditions > https://docs.db.ripe.net/RIPE-Database-Acceptable-Use-Policy > https://www.arin.net/resources/registry/whois/tou/ > https://web.archive.org/web/20260514102154/https://afrinic.net/whois/terms > > https://web.archive.org/web/19991128203448/http://www.apnic.net/db/dbcopyright.html > > https://web.archive.org/web/20050531210605/http://www.apnic.net/db/dbcopyright.html > > https://web.archive.org/web/20080000000000*/http://www.apnic.net/db/dbcopyright.html > > https://web.archive.org/web/20100125052321/http://www.apnic.net/apnic-info/whois_search/about-whois/protecting-whois/copyright > > https://web.archive.org/web/20110728054323/http://www.apnic.net/db/dbcopyright.html > > https://web.archive.org/web/20161009105427/https://www.apnic.net/db/dbcopyright.html > > https://web.archive.org/web/20161009105430/https://www.apnic.net/apnic-info/whois_search/using-whois/bulk-access/copyright > > > _______________________________________________ > Go to the SIG-policy-chair mailing list on Orbit -- > https://orbit.apnic.net/mailing-list/[email protected] > Explore https://orbit.apnic.net, where the APNIC community connect, > discuss and share information related to Internet addressing and networking. > To unsubscribe send an email to [email protected] > _______________________________________________ > SIG-policy - https://mailman.apnic.net/[email protected]/ > To unsubscribe send an email to [email protected] > > > https://jon.brewer.nz/ > _______________________________________________ > SIG-policy - https://mailman.apnic.net/[email protected]/ > To unsubscribe send an email to [email protected]
_______________________________________________ SIG-policy - https://mailman.apnic.net/[email protected]/ To unsubscribe send an email to [email protected]
