Security and abuse

Opaque Research LLC · last updated 16 September 2026

This document is not final. The technical statements below — what we store, for how long, and who it is shared with — are accurate and describe what the service actually does. The surrounding legal language has not yet been reviewed by a lawyer. We would rather publish what we can stand behind now than wait and tell you nothing.

This page is for two people. If you are a customer, it is what could happen to your hostname, why, and how you get it back. If you are reporting misuse, it is what your message sets in motion. Both of you should be able to check what we say here against what we actually do.

The principle: we act on the name, not the person

When a report holds up, our first action is to stop the name resolving — it is withheld from DNS and stops working. The hostname and anything beneath it go together, so a name and its subdomains do not end up in different states.

We act on the name rather than the person, deliberately. A mistake on our part then costs a customer one hostname for as long as it takes to tell us, rather than their account, their other names and their data. It also lets us move quickly, because being wrong is recoverable. Enforcement that cannot be undone has to be slow; enforcement that can be undone does not.

Your hostname shares a domain with other customers, and blocklists judge the domain rather than the account. That is the reason this page exists at all: one abused name is a cost the other people on that domain pay.

Compromise is not abuse

Most of the harm we see will not come from people who set out to cause it. It will come from a customer's own machine being taken over. Those two cases look similar from outside and deserve opposite responses, so we separate them.

If your box is compromised, you are the victim of the thing we are responding to. You need your other services reachable and your monitoring working while you clean up. Suspending everything at that moment takes down your NAS, your reverse proxy and your alerting exactly when you most need them — adding a second incident to your first. So the ordinary response to one compromised host is that one name stops resolving and the rest of your account keeps working.

The account goes down when the evidence says the account is the problem: several names implicated rather than one host, or a recently created account that already looks purpose-built, or no response from anyone after we have tried to make contact. Silence is the hard one, and it resolves toward containment — a customer we cannot reach cannot clean up, and we cannot tell victim from operator.

We surveyed eight providers' published terms and found none that draws this distinction. It is the difference we would most want a customer to know about.

Reporting something

Email abuse@closetserver.com. It reaches a person, not a queue that nobody reads. You do not need an account with us to report something.

Tell us the hostname, what you observed, and roughly when. Evidence helps — a URL, a message header, a log line, a sample. What we most need is something that ties the behaviour to the name, because the name is what we can act on.

What we act on: phishing and credential harvesting, malware distribution, botnet command and control, pharming, a hostname impersonating another organisation, bulk registration of names nobody intends to use, and anything unlawful where you are or where we operate. The list in the terms is the one we enforce.

What we are not the right venue for: a dispute about content you disagree with, a trademark complaint, or a copyright claim about material on someone's server. We run the name, not the machine, and pulling a hostname is a blunt answer to those. Tell us anyway if you think we are wrong about that — but expect us to say the machine's host or the courts are the better route.

If you are reporting on behalf of a network, a bank, a CERT or a security vendor, say so and say what you need. A takedown, a customer contact and a preserved record are different requests and we would rather answer the one you actually have.

What happens after you report it

In order:

We read it and check it. We assemble what we already hold about that name — its update history, the addresses it has published, signals we have recorded, whether anyone has reported it before.

We may come back to you. Usually to pin down timing or ask for one more piece of evidence. It is also how a malicious report gets caught, which is a real category — people do try to get a competitor's hostname pulled.

If it holds up, the name stops resolving and the customer is emailed the reason and the route to contest it.

A review opens on the account. Nothing the customer experiences changes — their other names resolve and they can still make changes. What it does is stop the clock that would otherwise release their hostnames, so an unresolved case cannot quietly cost them their names.

For clear or repeated misuse a person — never an automated rule — may suspend the account, and we may report what we observed to the network operator responsible for the address involved. Suspension stops the records resolving and leaves login open, so the customer can still see their account and answer us.

Closing the account is the end of the ladder and also a person's decision, reached only after the appeal window below has passed or an appeal has been heard and rejected. The account is locked rather than deleted, and the hostnames are held for 90 days rather than handed to anyone else.

If it does not hold up, we tell you that too, rather than letting the report go quiet.

We do not publish a response-time commitment, because we do not yet measure one honestly enough to promise it. When the figures below exist they will be the real ones, including the slow cases.

We look, rather than wait

Abuse that nobody reports is still abuse on a domain our customers share. We check for it ourselves — addresses appearing on blocklists, hostnames pointed somewhere that does not look like someone running a home server, signups that trip our anti-abuse rules — rather than relying on complaints arriving. Findings are recorded as evidence with their source and the date we first saw them, so a decision later can be traced back to what was actually known at the time.

What we do not do

We do not probe. We know the addresses our customers publish, so scanning them would be easy and we decline it. We are not a scanner. Deciding whether a name is being misused is done from what we already hold and what a reporter shows us.

We do not block by country. It punishes the wrong people and does not stop anyone who does not want to be stopped. Where sanctions law obliges us, that is a legal obligation and we treat it as one, not as an abuse control.

We do not take a name away because someone asked loudly. A report is a claim until it is checked, including a report from a large company.

If we act on your name

You get an email saying which names are affected, why, and where to contest it. If you are signed in, the dashboard tells you your account's standing too — because the case where email is most likely to be broken is exactly the case where the account is compromised, and one channel is not enough.

To contest it, reply to the message we sent you or write to abuse@closetserver.com. We would far rather restore a name quickly than leave a working service dark on a bad call. A name withheld in error goes back as soon as we establish that, along with everything beneath it.

A suspension does not quietly become permanent. While a case is open, the clock that would otherwise release your hostnames back to other customers is stopped — so an unresolved abuse flag cannot turn into losing your names by inaction. Suspension is a position we are prepared to reverse.

You get 30 days to contest it, and the notice states the actual date rather than inviting you to appeal in the abstract. An account less than 30 days old gets 7 days instead — not because a new customer deserves less, but because there is no history for us to read either way, and holding a name for a month on an account created last week costs someone else the name. The channel is the same and the recourse is not removed, only shortened. See the terms for what we commit to contractually.

What we hold while a case is open

Investigating a report means keeping the data that supports it. Being specific about that is the point, so:

› Update history, including the address each update came from, is kept 7 days on a trial and 90 days on a paid plan.

› Refused signup attempts, where an anti-abuse rule fired, are kept 30 days.

› Evidence supporting an open case is held while that case is live and through its resolution — including, where the case is substantiated, after the account is closed. Evidence that disappears when someone deletes their account is not evidence.

While a case is being investigated, nothing about it is published and nothing is shared. Only data from accounts we have found to be abusive and acted on may ever leave this service. Nothing derived from a legitimate or paying customer is shared with anyone, in any form, aggregated or otherwise. If we report a case to a network operator, the report contains what we observed about that account and nothing about anyone else.

You can ask for a copy of your data or ask us to delete it, at privacy@closetserver.com. The one exception, stated plainly: deleting your account does not delete records of abuse we have already acted on. The privacy policy covers the rest, and the retention numbers on both pages are read from the code that enforces them rather than written by hand.

How this differs from the rest of the market

We read eight providers' published terms on 7 September 2026 — dynamic DNS services and the larger hosting and DNS companies — to find out whether any of this is unusual. It is, and mostly in one direction.

Six of the eight reserve the right to suspend or terminate with or without notice. One reserves it "for any reason or no reason at all".

Seven of the eight describe no appeal process of any kind. Ours is a stated number of days, on a date, in the notice.

None of the eight offers a window to retrieve your data after enforcement.

None of the eight distinguishes a compromised customer from an abusive one. Several draft it the other way, applying prohibited-use terms whether the customer's conduct was intentional or inadvertent.

Two of the eight claim the right to take over a hostname outright. We hold names for a period after an account closes rather than reassigning them.

One caution we would apply to anyone's policy page, including this one: the strongest published stance we found lives on a policy page while that company's contract still reserves unlimited discretion. A promise that is not in the terms is not a promise. What we commit to is in the terms, and there is no arbitration clause and no class-action waiver there.

The history this is written against

In 2014 a court order handed twenty-three of one dynamic DNS provider's domains to Microsoft, on the argument that the provider had not acted on repeated reports of abuse. Roughly five million hostnames stopped working, the overwhelming majority of them belonging to people who had done nothing.

The lesson usually drawn is that the seizure was heavy-handed. The more useful one is that the provider could not demonstrate otherwise. The defence against being treated as an abuse haven is not a policy document; it is a dated, specific record of individual names being acted on, and how fast, that exists before anyone demands it. We run 5 shared domains with the same structure and the same exposure, which is why the enforcement here is per-name and logged rather than broad and discretionary.

What we publish

We intend to publish, regularly: how many reports we received, how many we acted on, how quickly — split by whether we found it ourselves or were told — how many accounts were suspended, how many appeals we received, and how many we got wrong and reversed.

The last number is the point. Any provider can claim to handle abuse well. A provider publishing its own error rate is making a claim you can check — and one that gets harder to fake the longer the series runs.

Alongside the counts we intend to publish redacted summaries of substantiated cases: what was served, what indicators we had, and how long it took, with no hostname, no customer, no reporter and no named victim. Counts alone read as compliance theatre; the shape of a case is what makes the numbers mean something.

Neither the figures nor the case summaries are published yet, and no link here points at them. They will be reported from the same records the process above creates, and this page will carry the link once there is a period worth reporting on. Until then, treat this section as a statement of intent rather than something you can check — which is exactly the distinction the rest of this page asks you to hold us to.