At last month’s Australian Internet Governance Forum (auIGF), .au Domain Administration (auDA) and its peers discussed resilience, trust, and multistakeholder cooperation. Weeks earlier, auDA’s Board had backed in principle a .com.au and .net.au eligibility change that registrars, investors and small businesses say fails all three tests. Domainer.com.au asks whether auDA’s words and its policy settings still line up.
What does Internet resilience in Australia actually mean in practice? Policymakers, engineers, security agencies, and Pacific neighbors were asked that question in Session 1: Internet Resilience in Australia and Beyond at the Australian Internet Governance Forum (auIGF), held in Canberra on 22 and 23 September 2026.
The answers were thoughtful and, for the most part, consistent. Resilience isn’t one rule, one organisation, or one technical fix. It comes from redundancy, diversity, tested relationships, shared purpose and a willingness to plan for risks nobody can yet fully predict.
The forum also coincided with one of the most contentious periods in the recent history of the .au namespace. In August 2026, the auDA Board approved in principle a set of licensing rule recommendations. One of them would remove a long-standing basis for 2.7 million of .com.au and .net.au names. The backlash from registrars, domain investors and small business owners has been loud.
This article puts both discourses side by side, and asks a simple question: does auDA’s proposed eligibility change sit comfortably with the resilience and trust principles the industry endorsed in Canberra, and with auDA’s own published strategy? Or is there a gap between what the Australian domain regulator says and what it proposes to do?
Day one: resilience is technology, people and relationships
In his keynote, David Mackay, Deputy Secretary, Communications, Media and Sport, said, “The government recognises the .au domain space as part of Australia’s critical infrastructure regime. If the domain is not secure and trusted, Australians lose confidence in part of the digital environment they rely on every day.”
Mackay’s broader point was that no single party can secure the Internet. He argued that resilience depends on shared responsibility across standards, investment, operations, transparency, and the ability to respond when things go wrong.
Key takeaways from Session 1:
- Chris Horlyck, First Assistant Director-General of Cyber Security Resilience at the Australian Signals Directorate (ASD), said the Security of Critical Infrastructure Act is about keeping systems running through adversity, not sealing Australia off. ASD asks operators to plan for running critical assets while disconnected for three months or longer.
- Dr Ellen Strickland, Director at the BrainBox Institute in New Zealand, described a two-year climate resilience project that found relationships were most important for building resilience, with work anchored in a shared, community-centred purpose.
- Ram Mohan, Chief Strategy Officer at Identity Digital, warned that national measures which break interoperability can create a fragmented Internet “one policy at a time”.
- Andrew Mollivurae, Senior Internet Governance Advisor for the Telecommunications, Radiocommunications and Broadcasting Regulator (TRBR) of Vanuatu, reminded the room that regulation without compliance and capacity can fail with real-world consequences.
- Bruce Tonkin, CEO of auDA, described critical infrastructure as both a technology problem and a people problem. On the technology side, he discussed duplicating systems so one failure doesn’t stop the service and avoiding a situation where everything depends on the same software or cloud provider. On the people side, he stressed the importance of building industry relationships in advance through crisis exercises and learning lessons even from minor incidents.
Tonkin’s closing remarks are worth dwelling on. He said some telcos automatically block every domain that appears on a threat-intelligence feed. auDA, he said, deliberately does not do that. It checks suspect domains manually, even though that is expensive, and he urged the industry to distinguish between “this might be a problem” and “this is definitely bad” when sharing information.
Moderator Narelle Clark, Chief Executive Officer (CEO) of the Internet Association of Australia Ltd, summed it up by saying, “Today, true resilience goes beyond meeting the compliance metrics, about building an infrastructure flexible enough to handle physical and cyber threats, collaborative enough to assist and support our Pacific neighbours and principled enough to preserve open [internet] standards”.
Day two: preparing for Q-Day and the long tail
Day two turned to a more distant threat: “Q-Day”, the point at which quantum computers become powerful enough to break the public-key cryptography that much of the Internet, including DNSSEC, depends on.
The session’s conclusions echoed day one closely:
- DNS resilience is an infrastructure problem, not just a cryptography problem. Swapping algorithms is the easy part. Making sure every layer can adopt them is the hard part.
- Future-proofing matters. Systems should be crypto-agile and adapt as standards evolve, rather than relying on one permanent fix.
- Resilience has to include the long tail. Hardening registry infrastructure isn’t enough if millions of smaller registrants, businesses, and legacy systems remain exposed.
- Planning has to start early. Panellists kept returning to education, testing and preparation rather than waiting for certainty about timing.
The session closed on a simple formula: educate, plan and prepare.
That third point, about the long tail, matters for what follows. The forum consistently argued that the .au ecosystem is only as resilient as its smallest, least-resourced participants. In the .au namespace, those participants are overwhelmingly small businesses, sole traders, clubs and community groups.
The bigger takeaway from both days was that resilience comes from planning across the whole ecosystem, building in redundancy and adaptability, and cooperating before a crisis rather than after.
This raises an editorial question worth putting to auDA directly: is .au policy being designed for today’s risks, or to build an ecosystem resilient enough for the risks we cannot yet predict?
The current proposal: deleting subparagraph (f)
The current auDA dispute centres on Australian policy changes, in particular, Recommendation 2 of auDA’s external Policy Advisory Panel, which reviewed the .au Licensing Rules between September 2025 and July 2026.
To hold a .com.au or .net.au licence today, a registrant must be an Australian commercial entity and meet one of several allocation tests in rule 2.4.4(2). Most of those tests require the domain to match a registered company name, business name or trade mark. Subparagraph (f) is the exception. It allows a domain that matches, or is a synonym of, a service the registrant provides, goods it sells, an event it runs or sponsors, an activity it teaches, or premises it operates.
That clause is a descendant of the old “close and substantial connection” test that has existed since the early days of .com.au. According to the Panel’s final report, deleting it would effectively limit registrants to domain names that match their own name, business name, or trade mark.
Key facts:
- Status: The auDA Board approved the Panel’s recommendations in principle at its August 2026 meeting, announced on 6 September. No rule has changed yet.
- Next steps: Management must prepare an implementation plan, then draft rule changes, then publish those drafts with an explanatory guide for public consultation.
- The next Board meeting is 13 October 2026, which will publish a plan and mark-up of the licensing rules for public comment.
- It will then go to the Board for final approval in mid-December 2026.
- For an implementation date, Registrars will be given 90 days’ notice of the change, and the registry also needs to make changes, so it could potentially go live in March or April 2027.
- The vote: The Panel could not agree on Recommendation 2. Four members supported deletion, two opposed it, and one abstained before later supporting the minority.
- Monetisation stays: In the same package, Recommendation 1 keeps parking, reselling and pay-per-click arrangements permitted in com.au, net.au and .au direct.
- Scale of the namespace: auDA’s July 2026 registry report counted about 3.3 million com.au names and around 179,000 net.au names.
Estimates of how many existing domains rely on subparagraph (f) vary enormously. The Panel did not conduct its own costings. The minority suggested the change could reach around one million registrants and cited a submission estimating an extra A$30 million a year in costs to Australians.
In response, social media has seen backlash from concerned industry members and business owners, prompting a petition launched on 21st September to Stop auDA’s Licensing Rules Changes, which currently has over 1,500 verified signatures.
The Internet Commerce Association (ICA) initially cited up to one million affected names, but has since corrected that figure to 2.7 million domains.
Domain Industry expert David Warmuz, whose companies include Trillion.com, Drop.com.au, Above.com and Help.com.au, has confirmed the figure is as high as 2.7 million of roughly 3.47 million .com.au and .net .au names, based on Registrar audits of the domains they manage.
David said he has spoken with most of the Registrars, and each has provided internal audit results that align with the 80% of all domains that will be affected. On that upper estimate, roughly four out of five names in the two namespaces would be affected.
Those figures are from the Registrars directly, and a sample has been verified from the eligibility tool created solely for this purpose: https://www.help.com.au/au-eligibility
During the monthly auDA and Registrars call, auDA CEO Bruce Tonkin said the number of affected domains “is substantial”. Opinions are not facts. The exact number has not been worked out, but Domainer welcomes auDA to provide the public and the auDA board with actual numbers for review.
The following data is required and should be made public for accuracy and transparency:
- What % of domain names will not require any action, as they will remain eligible and comply with the policy change? (estimated 20%).
- What % of domain names will remain eligible, but will require a correction or Change of Registrant at the Registrar to be compliant? (estimated to be 40%)
- What % of domain owners will need to pay for a new Business Name or Trade Mark to be eligible and then make an additional Correction/Change of Registrant at the Registrar? (estimated to be 40%)
Clarity is required on the impact this proposed change would have on Australian business owners and Australian domain owners who will need to register new domain names.
Existing business owners will be forced to pay $47 more to register every new domain, and so far auDA has neither justified nor explained why it would enforce this payment. How, then, does this protect, safeguard, and instil trust in the Australian namespace?
Is there a conflict with auDA’s own strategy?
On close reading, at least five points sit uneasily with auDA’s stated strategy, compliance posture, and the principles it endorsed at auIGF. None of them proves the change is wrong. Together, they suggest auDA has a case to answer.
auDA’s 2026–30 Strategy rests on four pillars: Trust, Innovation, Impact and Capability. Its vision is for .au to be “the primary online identity for Australian individuals and organisations, supported by a nimble and resilient auDA”. The Trust pillar aims to strengthen Australians’ trust in both .au and auDA itself, with objectives including reducing DNS abuse and improving the integrity of the .au domain.
- If .au is meant to be the default identity for Australian organisations, a rule that may push a large share of existing com.au and net.au holders into new paperwork, or out of the namespace altogether, works against that goal. Many expert registrars and domain investment communities have already advised auDA that this friction will push some businesses toward .com or other gTLDs with few eligibility requirements, and if that happens, both .au’s market share and auDA’s vision lose.
- auDA’s annual compliance plans describe its posture as “proportional and considered”. At the auIGF, Bruce Tonkin explained that auDA checks suspicious domains individually rather than blocking everything on a list. Yet Recommendation 2 in their proposed changes targets a behaviour concentrated among roughly 3,386 high-volume registrants by removing an allocation route for every one of the 1.7 million registrants in those namespaces. Critics argue that is the blanket-block approach Tonkin warned against, applied to policy.
- The auDA Board accepted Recommendation 1 in its proposal, keeping parking and pay-per-click arrangements permitted. The Panel minority called that the “correct position”, but said it was inconsistent with deleting subparagraph (f). As this activity is a legitimate business, critics therefore ask: why remove the existing, most commonly used route to qualify for it?
- The issue is not about DNS abuse. auDA’s own reporting says DNS abuse in .au is exceptionally low, at around 0.0002% of names, and well below global averages. Its fact sheet attributes almost all .au DNS abuse to compromised websites rather than to who registered the name or on what basis. The majority’s case for deleting subparagraph (f) is about fairness between applicants, not security. That matters, because the change is often discussed in the language of trust and integrity that auDA otherwise reserves for its security work.
- Day one of auIGF was about identifying hidden dependencies. Without subparagraph (f), a domain that does not match a registered business name depends entirely on that registration staying current. The minority noted that a business which forgot to renew its business name could breach the rules and risk losing its domain. For a small business, losing its domain means losing its website and professional email addresses, not to mention years of marketing and branding. That is exactly the kind of long-tail fragility the Q-Day panel warned about.
auDA could reasonably argue the change serves its Trust pillar directly. The strategy commits to raising the integrity of .au domain names, and the majority’s view is that subparagraph (f) lets registrants self-certify a connection that isn’t checked against any database. The question is whether the benefit outweighs the disruption, and so far no published impact assessment has answered it.
Registrars, red tape and the consultation question
If the change goes ahead, accredited registrars will carry much of the practical administrative workload. They will need to field calls from confused customers, check eligibility at renewal and transfer, and process cancellations at their own cost, or pass that cost on to registrants.
Registrars are already absorbing a recent change in May 2026, requiring them to confirm that the ABN or ACN behind a com.au or net.au domain is active before a renewal goes through. Removing subparagraph (f) would add a second, more complex test: whether the domain itself matches a registered name or trade mark. Unlike the ABN check, a simple WHOIS lookup does not always answer that question, and for generic terms the honest answer may be that no matching business name is available at all.
auDA’s Panel flagged the gap, noting that Recommendation 2 does not say what happens to existing registrants who currently rely on subparagraph (f), or whether any transition or grandfathering would apply. Until that is settled, registrars cannot tell customers whether a domain they have held for 20 years is safe.
Critics are dubbing this uncertainty ‘administrative chaos ‘. David Warmuz put the complaint bluntly to Domainer.com.au:
“Australian domain Registrars and non-affiliated industry professionals were not consulted on this proposed policy change. Even after its public announcement, when we collectively provided logical, proactive feedback, it was ignored.”
auDA could dispute the claim that it did not consult. The Panel ran town halls and in-person sessions in four capital cities, plus an information session at auIGF 2025 in Adelaide and two rounds of written submissions between September 2025 and July 2026, drawing 78 written submissions. However, the ICA’s more precise concern is that the people most affected, such as individual registrants, were never directly told their licences could be at risk. The ICA has asked auDA to require registrars to notify every registrant before adopting any change to existing licences.
In its recent blog, ICA Objects to auDA Plan to Scrap 25-year Old .au Registration Pathway (Aubrey 2026), the ICA also notes that auDA management rejected similar restrictions in 2019 after finding no evidence that domain investment was harming the .au namespace or creating scarcity. What has changed since then, critics ask, other than the panel’s composition?
auIGF’s recent message about multistakeholder governance was validated after multiple panellists in Canberra agreed that good Internet governance means involving the people who build, operate and rely on the system early enough for their input to matter.
Dr Ellen Strickland highlighted that the people affected by policy changes “won’t be in every room, so a process has to find ways to reach them”. On a policy of this scale, a split panel, no published cost estimate and no direct notice to registrants sit awkwardly against that standard.
auDA’s Case for the Potential Change
Fairness requires setting out the majority’s reasoning, which is more considered than some of the online commentary suggests.
The Panel majority’s central argument is about two unequal pathways. A registrant relying on a company name, business name or trade mark must produce documentary evidence. In contrast, a registrant relying on subparagraph (f) can, in practice, establish a connection with minimal administrative effort by setting up a referral or information service. The majority saw that as unfair to small businesses, sole traders and start-ups competing for the same names against investors registering for resale.
The majority also made two points that tie directly to themes raised at auIGF:
- AI has lowered the barrier. Generative AI makes it trivial to produce a plausible pay-per-click or “information” site purely to satisfy the allocation test. That echoes the forum’s broader concern that AI is changing the economics of online abuse and low-value content.
- Compliance rests on self-declaration. Eligibility under subparagraph (f) depends on a registrant’s warranty, not a check against an authoritative register. In a forum preoccupied with verifiable identity and trust, a regulator’s concern is reasonable.
The majority considered narrower alternatives, such as tighter definitions or disclosure requirements targeting pay-per-click sites. It concluded those would require substantial resources for content vetting and compliance. That is the same cost trade-off Bruce Tonkin described at auIGF when explaining why manual review is expensive.
auDA also notes that the change would not lock anyone out of .au altogether. .au direct names, which have no second-level label, remain available to any registrant with an Australian presence. Businesses that already hold a matching business name, company name or trade mark would not be affected.
The Board approved the proposal in principle, and management has been directed to prepare an implementation plan that accounts for the recommendation’s impact before anything changes. In other words, auDA has signalled that the details, including any transition arrangements, are still open, but reversing this decision is not.
auIGF 2026 made a persuasive case that resilience comes from redundancy, diversity, tested relationships and planning for the long tail. The test for auDA is whether its licensing policy meets the same standard as its DNS operations. That means proportionate rules, a clear view of who is affected, and a process people can trust.
The question raised in Canberra is the right one to leave with auDA: is .au policy being written for today’s concerns, or to build a namespace resilient enough to keep Australian businesses’ trust for the next 40 years?
What happens next, and how to be heard
auDA has yet to publish draft rules and an explanatory guide for public consultation, including potential transition arrangements, an important opportunity to influence the outcome of the proposed changes.
auDA’s yearly Registrar Summit is on 28-30 October 2026 in Cape Shank, which the Above.com team, along with other Registrars, will attend. For registrars, investors and small businesses, the strongest questions are likely to focus on five unresolved questions:
- Grandfathering. Will existing licences relying on subparagraph (f) be protected? The ICA argues any change should apply only to new registrations, and that protection allowing renewal, but not transfer, would be meaningless.
- Impact data. Will auDA publish a quantified estimate of how many registrants and businesses are affected, and at what cost, before finalising the rules?
- Narrower alternatives. Could a targeted fix aimed at pay-per-click qualification address the fairness concern without catching bakeries, brokers, schools and football clubs?
- Notice. Will every affected registrant be told directly, through their registrar, before any rule change takes effect?
- Reversal. Can this decision be reversed and placed on hold pending further discussion? This is by far the most important of the five questions and the most logical action.
The lack of accurate data shows that a government-endorsed not-for-profit organisation cannot provide certainty to millions of affected Australians. The proposed changes, opinion-based decision-making, and potential enforcement of a change of this magnitude are progressing without an agreed estimate of who it will negatively impact and why.
Domainer.com.au has invited auDA to respond to the points raised in this article.
Disclaimer: As stated on the auIGF website, “Transcripts were captured through live captioning during auIGF 2026. They have not been edited and may contain minor inaccuracies.” Domainer used AI-assisted analysis to help identify and summarise key takeaways from the session transcripts. The content has been reviewed and, where possible, details have been fact-checked against available sources. For full context, readers should refer to the original auIGF sessions and materials.
Sources
- auIGF 2026 program and transcripts
- auDA statement: .au Licensing Rules Review completed by external Policy Advisory Panel
- .au Licensing Rules Review 2025 Final Report
- webhosting. today: auDA backs removing a .com.au allocation route
- IT Brief: auDA faces backlash over .com.au eligibility shake-up
- Dynamic Business: auDA just made a move that could shake up .com.au domains
- CircleID: auDA moves to tighten domain name eligibility
- auDA 2026–30 Strategy
- auDA CEO blog: Stepping into our new Strategy
- auDA Compliance Plan 2026–27
- auDA: Combatting DNS abuse in .au fact sheet
- auDA: A secure .au report
- Change.org petition: Stop auDA’s policy changes
Further discussion and comments here:
https://www.linkedin.com/feed/update/urn:li:activity:7514189128650014720/
