These numbers are revealing - and appalling.  No doubt in my mind that we
need the tools to make this abuse of the system, cease.
Getting the policy setting correct is clearly the first priority.
I support this proposal.

On Mon, 21 Sept 2026 at 14:27, Jonathan Brewer <jon@tō.nz> wrote:

> Dear SIG-Policy community,
>
> I'd like to offer some evidence of the acute need for prop-173.
>
> You might have seen my earlier post announcing an analysis platform for
> APNIC directory services use. The platform is here:  https://apnic.tō.nz/
> ( https://apnic.xn--t-0la.nz/ if your email client doesn't support IDN).
>
> This platform shows that one ASN (out of APNIC's 10,000 members) is
> responsible for 37% of all use of WHOIS. It shows that the top ten ASNs
> (0.001% of APNIC members) are responsible for 73% of all WHOIS use.
>
> Similarly one ASN is responsible for 41% of all RDAP use, and the top ten
> ASNs are making 81.5% of all requests.
>
> This is not operational use of directory services as intended. This kind
> of abuse is forbidden and protected against in other RIRs, but not in
> APNIC. This is because APNIC does not have an acceptable use policy for its
> directory services.
>
> I'd appreciate it if all of you who understand the problem express a view
> on the proposal. And if you don't understand the problem, let me know how I
> can make it more clear.
>
> Best Regards,
>
> Jon
>
> On Mon, 17 Aug 2026, at 19:32, Bikram Shrestha wrote:
>
> Dear SIG members,
>
> A new proposal "prop-173: Copyright and Acceptable Use Terms for APNIC
> Directory Services"
> has been sent to the Policy SIG for review.
>
> It has been published to the mailing list for community discussion.
>
> We encourage you to express your views on the proposal:
>
> Do you support or oppose this proposal?
>
> Does this proposal solve a problem you are experiencing? If so,
> tell the community about your situation.
>
> Do you see any disadvantages in this proposal?
>
> Is there anything in the proposal that is not clear?
>
> What changes could be made to this proposal to make it more effective?
>
> Information about this proposal is appended below as well as
> https://www.apnic.net/community/policy/proposals/prop-173/:
>
> Regards
> Bikram, Shaila, and Ching-Heng
>
> -------------------------------------------------------
> prop-173-v001: Copyright and Acceptable Use Terms for APNIC Directory
> Services
> -------------------------------------------------------
>
> Proposer: Jonathan Brewer
> [email protected]
>
>
> 1. Problem statement
> -------------------------------------------------------
> APNIC provides access to its whois database through WHOIS, RDAP, and
> web-based services. Although APNIC publishes an Acceptable Use Agreement
> for bulk Whois data, it does not publish a separate, clearly scoped policy
> governing ordinary ad-hoc queries.
>
> Users of WHOIS and RDAP therefore cannot readily determine:
>
> - what uses of query results are permitted;
> - whether results may be stored, compiled, republished, or incorporated
> into other services;
> - what constitutes excessive or abusive querying;
> - what enforcement action APNIC may take; or
> - whether APNIC asserts copyright or other intellectual-property rights in
> its directory database and services.
>
> Current WHOIS and RDAP responses refer users to terms associated with the
> bulk-access agreement, but that agreement is designed for applicants
> seeking bulk downloads or mirrors. It does not clearly establish terms for
> users making ordinary queries. APNIC has also previously indicated that
> specific terms of use for WHOIS and RDAP would be implemented, but no
> distinct policy appears to have been published.
>
> This is inconsistent with APNIC’s historical practice. During its first
> decade, APNIC published copyright and restricted-rights statements applying
> broadly to data retrieved from APNIC databases. These statements restricted
> reproduction, storage, and transmission outside agreed Internet-operational
> purposes, prohibited targeted advertising, and allowed APNIC to limit or
> deny access for excessive querying.
>
> APNIC should restore a clear policy position on its WHOIS database by
> asserting the rights available to it under Australian law and publishing
> specific acceptable-use terms for ordinary WHOIS, RDAP, and web-query
> access, separate from the existing bulk-access agreement.
>
>
> 2. Objective of policy change
> -------------------------------------------------------
> APNIC will publish a clear, public, versioned APNIC Directory Services
> Acceptable Use Policy governing ordinary access to WHOIS, RDAP, and
> web-based directory searches.
>
> The policy will:
>
> - be separate from the existing agreement governing bulk downloads and
> mirroring;
> - assert APNIC’s copyright and other applicable intellectual-property
> rights in the directory database;
> - clearly define permitted and prohibited uses;
> - be presented to users through every directory-service interface and
> interaction;
> - provide protections at least as strong as those contained in APNIC’s
> early database copyright and restricted-rights statements.
>
>
> 3. Situation in other regions
> -------------------------------------------------------
> RIPE NCC publishes both comprehensive RIPE Database Terms and Conditions
> and a separate Acceptable Use Policy. Accessing the database constitutes
> agreement to the terms. Permitted purposes are enumerated, advertising and
> direct marketing are prohibited, and users may not repackage, download,
> compile, redistribute, or reuse a significant part of the database without
> permission. The terms also assert RIPE NCC ownership of all copyright,
> trademarks, database rights, and other intellectual-property rights
> subsisting in the database, its data, software, and accompanying documents.
>
> ARIN publishes Whois Terms of Use that apply to any use of its Whois
> service, including compilation, repackaging, and dissemination. Use of the
> service constitutes acceptance of the terms. The document enumerates
> operational and technical-research uses and prohibits advertising, direct
> marketing, marketing research, republication, resale, and use as part of an
> unauthorised commercial data product or service.
>
> LACNIC includes a copyright and lawful-use statement directly in its WHOIS
> responses. Users are told that the data is provided for information
> concerning IP address and AS number registrations and that submitting a
> query constitutes agreement to use the data only for lawful purposes.
>
> AFRINIC publishes terms applying to access, querying, compilation,
> repackaging, dissemination, and other uses of its Whois Database. Its terms
> enumerate permitted operational and research purposes, prohibit commercial
> data products, advertising, direct marketing, market research, and illicit
> uses, reserve the right to rate-limit or terminate access, and treat bulk
> access under a separate agreement.
>
> AFRINIC also asserts that copyright, trademarks, database rights, and
> other intellectual-property rights subsisting in the database, its
> contents, software, documents, and agreements remain AFRINIC property.
>
>
> 4. Proposed policy solution
> -------------------------------------------------------
> 1. Scope
>
> APNIC will publish an APNIC Directory Services Acceptable Use Policy
> applying to any person or system that accesses, queries, receives, or uses
> APNIC-authoritative directory data through:
>
> WHOIS;
> RDAP;
> APNIC web-based directory searches;
> APIs providing equivalent registration data
>
> The policy will apply to APNIC-authoritative data and objects identified
> as having APNIC as their source. Data mirrored or referred from another
> registry will remain subject to the terms of the authoritative source
> registry.
>
> The policy will define “user” broadly enough to include a person who
> directly accesses the service and a person or organisation that causes
> automated access to be made on its behalf.
>
> 2. Separation from bulk access
>
> The ordinary-query policy will be a separate document from the existing
> bulk-access agreement.
>
> The policy will state that it does not grant bulk-download or mirroring
> rights. Users requiring high-volume access, a significant extract, a
> mirror, or a substitute database will apply through APNIC’s separately
> governed bulk-access process.
>
> 3. Copyright and intellectual-property statement
>
> The policy will state that APNIC must assert all copyright and other
> rights available to it under Australian law.
>
> 4. Permitted uses
>
> The policy will expressly permit ordinary low-volume queries for defined
> Internet-operational and technical-research purposes, including:
>
> evaluating routing policies and routing-policy compliance;
> network troubleshooting and operational coordination;
> identifying the holder or operator of Internet number resources;
> maintaining the uniqueness and accurate registration of Internet number
> resources;
> providing and troubleshooting reverse DNS;
> reporting, investigating, and mitigating network abuse or security
> incidents;
> identifying resources suspected of unlawful or harmful use;
> conducting scientific or technical research into Internet operations,
> routing, security, resilience, or topology;
> supporting lawful resource-registration disputes; and
> responding to legally valid requests from competent authorities.
>
> 5. Prohibited uses
>
> The policy will prohibit:
>
> advertising, targeted advertising, direct marketing, lead generation,
> marketing research, or similar activity;
> compiling contact or marketing lists;
> harassment, intimidation, surveillance, or unlawful activity;
> using directory data to build demographic profiles;
> using directory data to infer or represent the geographic location of an
> address, network, organisation, or individual;
> selling, licensing, or republishing directory data as a data product;
> making directory data available as part of a commercial enrichment,
> profiling, or lookup service without written permission;
> systematic harvesting through ordinary query interfaces;
> using distributed hosts, addresses, accounts, or intermediaries to evade
> rate limits;
> interference with the availability, integrity, or security of the
> directory services; and
> any use inconsistent with the stated purposes of the APNIC Directory
> Database.
>
> Ordinary operational use by a commercial network operator or security
> provider will not be prohibited merely because the organisation operates
> commercially, provided the directory data is not itself resold,
> republished, or made into a separate commercial data product.
>
> 6. Reproduction, storage, and redistribution
>
> Except as necessary for a permitted Internet-operational or
> technical-research purpose, users will not reproduce, persistently store,
> compile, transmit, repackage, redistribute, or make available a substantial
> part of the database without APNIC’s prior written permission.
>
> The policy may permit limited and temporary caching of individual query
> results where necessary for a permitted use. APNIC will publish any
> applicable retention, refresh, security, and deletion requirements.
>
> Caching will not be used to assemble a substitute directory database or
> circumvent the bulk-access process.
>
> Any permitted onward disclosure will remain subject to restrictions at
> least as protective as the APNIC policy.
>
> 7. Query conduct and rate limits
>
> APNIC may establish and enforce reasonable query-volume, rate,
> concurrency, and result-size limits for security, privacy, and operational
> purposes.
>
> The policy will prohibit attempts to evade those limits.
>
> APNIC will publish:
>
> the general principles used to identify excessive querying;
> how a blocked user can identify the reason for a restriction;
> a contact or review process for legitimate operational and research users;
> and
> the process for obtaining approved high-volume or bulk access.
>
> APNIC need not publish limits where doing so would materially assist
> evasion or threaten service security.
>
> 8. Notice through each service
>
> The policy will be readily available before or at the time directory data
> is supplied.
>
> WHOIS responses will contain a concise notice substantially equivalent to:
>
> % APNIC Directory Services data is subject to the APNIC
> % Directory Services Acceptable Use Policy.
> % By querying or using this service, you agree to those terms.
> % Copyright APNIC. See:
>
> RDAP responses will include:
>
> a notices entry identifying the policy;
> a link with rel set to terms-of-service;
> a copyright or intellectual-property notice; and
> the current policy URL.
>
> Web query interfaces will display a link to the policy and state that
> submitting a query and using the results is subject to it.
>
> The notices will use a stable, maintained HTTPS URL that will not be
> subject to HTTP redirection.
>
> 9. Enforcement and review
>
> APNIC may warn, throttle, suspend, block, or terminate access where it
> reasonably believes that a user has breached the policy. This may happen
> via automated means.
>
> Repeated or deliberate circumvention may result in long-term or permanent
> denial of ordinary query access.
>
> The policy will provide a review mechanism for a user who believes that
> access has been restricted in error or who can demonstrate a legitimate
> operational or technical-research requirement.
>
> 10. Historical protection floor and future amendments
>
> The policy will not be materially less protective than APNIC’s copyright
> and restricted-rights statements published during its early operation,
> particularly in relation to:
>
> the assertion of copyright;
> reproduction and persistent storage;
> transmission and redistribution;
> targeted advertising and similar activities;
> use outside agreed Internet-operational purposes; and
> excessive automated querying.
>
> The wording may be modernised and adapted to WHOIS, RDAP, privacy law, and
> contemporary Internet operations, but the substantive level of protection
> will not be weakened.
>
> The policy will include a version number, effective date, revision
> history, and archive of previous versions.
>
> APNIC will provide reasonable advance public notice of amendments. Any
> amendment that materially expands permitted reuse or materially weakens
> protections will be subject to the APNIC Policy Development Process or an
> equivalent community-consultation process.
>
> APNIC should implement this policy within six months of adoption.
>
>
> 5. Advantages / Disadvantages
> -------------------------------------------------------
> Advantages:
> The proposal would restore the clear copyright and restricted-use position
> that APNIC maintained during its early years of operation.
>
> Disadvantages:
> APNIC would incur legal, documentation, and software-development costs to
> draft the terms, update all query interfaces, maintain stable policy links,
> and operate a review process.
>
>
> 6. Impact on resource holders
> -------------------------------------------------------
> Resource holders that operate automated WHOIS or RDAP clients may need to
> ensure that their querying, caching, and redistribution practices comply
> with the published policy.
>
>
> 7. References
> -------------------------------------------------------
> https://www.apnic.net/manage-ip/using-whois/bulk-access/
> https://www.apnic.net/manage-ip/using-whois/bulk-access/copyright/
> https://www.apnic.net/community/policy/proposals/prop-167/
> https://docs.db.ripe.net/HTML-Terms-And-Conditions
> https://docs.db.ripe.net/RIPE-Database-Acceptable-Use-Policy
> https://www.arin.net/resources/registry/whois/tou/
> https://web.archive.org/web/20260514102154/https://afrinic.net/whois/terms
>
> https://web.archive.org/web/19991128203448/http://www.apnic.net/db/dbcopyright.html
>
> https://web.archive.org/web/20050531210605/http://www.apnic.net/db/dbcopyright.html
>
> https://web.archive.org/web/20080000000000*/http://www.apnic.net/db/dbcopyright.html
>
> https://web.archive.org/web/20100125052321/http://www.apnic.net/apnic-info/whois_search/about-whois/protecting-whois/copyright
>
> https://web.archive.org/web/20110728054323/http://www.apnic.net/db/dbcopyright.html
>
> https://web.archive.org/web/20161009105427/https://www.apnic.net/db/dbcopyright.html
>
> https://web.archive.org/web/20161009105430/https://www.apnic.net/apnic-info/whois_search/using-whois/bulk-access/copyright
>
>
> _______________________________________________
> Go to the SIG-policy-chair mailing list on Orbit --
> https://orbit.apnic.net/mailing-list/[email protected]
> Explore https://orbit.apnic.net, where the APNIC community connect,
> discuss and share information related to Internet addressing and networking.
> To unsubscribe send an email to [email protected]
> _______________________________________________
> SIG-policy - https://mailman.apnic.net/[email protected]/
> To unsubscribe send an email to [email protected]
>
>
> https://jon.brewer.nz/
> _______________________________________________
> SIG-policy - https://mailman.apnic.net/[email protected]/
> To unsubscribe send an email to [email protected]
_______________________________________________
SIG-policy - https://mailman.apnic.net/[email protected]/
To unsubscribe send an email to [email protected]

Reply via email to