Past week, I attended the NDDCamp for its Paris edition.

It was really excellent!

NDDCamps are conferences gathering together domain name professionals.

If you read my very recent posts, you should know that one of my “hat” is to be Domain Names Portfolio Manager for my company. The term “Managing private portfolio of domains” can be maybe even more meaningful, at least it’s often how people in NDDCamp designated my role when I described it.

I felt very lucky to be accepted, because if I consider myself somehow a domain name professionnal, I’m not working in the field of domain name industry.

I represented here Deriv so in addition to get more expertise on domain name matters (valuable for my position here), I was able to connect with current (B2B registrars) and possible future partners (consulting firms, online tools creators and registrars).

Before going further, I warmly thank my company for supporting me.

The event was really great and I’m impressed about the organization of it, and I tip my hat at you Marc-Olivier Bernard, David Chelly and Philippe Franck.

What I expected from NDDCamp

The complexity of managing domain names is understated and the role itself is very niche. It’s also highly critical and rarely a full time role.

For me, it results into a sort of loneliness feeling, even if I have people assisting me, when having to decide a matter, with sometimes difficults decisions to take (risks).

I also have the strong feeling to have reached a level of expertise (from portfolio reshuffle, TMCH enrollment, registry lock, brand protection, ConsoliDate, Web3 domains…) where I can talk with experts of the matter, and in particular ask (or share) on topics that involves deep understanding and (more important) real experience of this field.

When looking for forums a few weeks ago, I was delighted to also get aware that gatherings on the topic of domain names actually existed, and multiple times a year!

So I decided to join the event, a bit “last minute”, but I’m so glad I dared.

Few public pictures

The event was running for one day, with breaks where participants could connect around a coffee and 2 tracks of presentations with multiple speakers.

It was split into 2 rooms but I only sat into the big one. Please find below few public pictures (source) like if you were there :)

A full amphiteatre, with a good chunk of Internet Governance:

Representatives of registrars and registries:

Some SEO well-known personalities:

Brand protection experts (lawyers, WIPO…):

My notes

My notes, we are going very deep into domain name professional topics. It’s possible that they correspond more to my own concerns and that you have little use of them, but still, sharing :)

New extensions coming:

  • 1600 new extensions applications for “round 2” (“round 1” was 2012).
  • “Reveal day” in October followed by (even more important) “String Confirmation & Objections” in November.
  • New TLDs should have a sunrise period.
  • Excitement around .web, managed by Verisign (.com) expensively acquired years ago, was it more defensive for their .com business? Or will become major alternative to .com?.

Brand protection:

  • TMCH sees 40,000 marks registered.
  • Block list: multiple people can have same block.
  • When relevant, one can partially finance (sourcing money) a block list by releasing owned domain to the block list.
  • We can “consolidate” an UDRP (dispute) if disputing multiple domains with same owner. It makes procedure more cost effective (multiple domains but pay once).
  • UDRP can be a “last chance whois”.
  • Bad opinion of URS “cure the symptoms” when UDRP “cure the sickness”.
  • WIPO introduced “Expedited UDRP” with effect to reduce suspension/transfer of domain from ~60days to ~25days.
  • Disputing a newly created TLD: “wait for String Confirmation & Objections first” (because purified list) then the right procedure would be Legal Rights Objection (recommended over String Confusion Objections)

Security:

  • Phishing speed (from ~6h down to 40min to produce a “phishkit”) and effectiveness (jumping success rate for phishing emails) improve dramatically with AI.
  • Homoglyphs and homophones mentionned but risk moderated and mitigated: most registry/registrar forbidding mixed script or deciding a subset preventing mixing with look-alike characters, browsers helping (punycode fallback, script mixing detection, TLD whitelisting) .
  • Only 10% of domains use DNSSEC.
  • Not all registries are compatible with DNSSEC.
  • Registrars reported an exploding number of dispute and complaints (generated by AI but not discarded by receivers because of that) that are pre-filtered by IA on their side: AI becoming the problem AND the solution.

Domain SEO and reputation:

  • The past life of a domain (bad reputation or even parking for too long ~2years) are irreparable (from their experience) and one SEO agency goes further by only considering using never used domain name .
  • SEO experts are waiting less than a month to decide if a domain will actually rank correctly or abandon and trash.
  • Creator of dom-verify.fr (analysis of domain reputation) was there and pitched me his product (french only).
  • Domain re-purposing (e.g. changing thematic of a domain from town hall to shop) works without problem.
  • Domain juice backlinks is one if not the best SEO trick.
  • You can manipulate gemini (actual POC from one speaker) by manipulating corpus (revealed to be easy).

Other:

  • Some registrars are deliberately delaying auth code (for transfers) to customers having not set the OTP.
  • NIS 2 article 28 will enforce very strictly collection and verifications of the whois data (weighting on registrars and end owners).
  • Some domainers have more than 200,000 domains and buying 1,000 per week.
  • Everybody hates GoDaddy

Key takeways for me:

Strategy

Experts 100% validated my strategy (see here for details)

Reseller accounts?

A “reseller account” (specifically designed for management of large portfolio) could be valid for mid-sized portfolio of domains (but does not help for price nor risk)

NIS2 article 28

NIS2 directive article 28 imposes a legal obligation on whois data collection and verification (new responsibilities for registrars mainly), it’s gradually coming into effect and this could strongly impact end owner with a possible avalanche of whois updates (effort, risk)

Strategy for new extensions:

New >1000 (?) extensions should be available in sunrise period (I asked confirmation to experts about that). With a TMCH enrollment in hands, if it requires to monitor carefully, one have priority to grab interesting extensions one by one as they enter the priority sunrise period!

Conclusion

I’m immensely grateful of having been accepted and have the opportunity to attend this NDDCamp.

Quality of speakers, sponsors and attendees was impressive and I felt privileged.

I got exactly what I was looking after and beyond. Plus, I was not only a “consumer” but gave back in return my experience to others.

Thank you again Marc-Olivier Bernard, David Chelly and Philippe Franck.

See you again maybe for another NDDCamp? :)