Registrar Scorecard has a positive impact on all fronts

Incentive programme worked well in 2020

4 ascending stacks of coins on wooden blocks with year 2020

We use the Registrar Scorecard (RSC) to encourage registrars to maximise the security of the .nl domain names they host. It's an approach that's been getting results: adoption of e-mail security standards, DNSSEC and IPv6 continues to climb. Progress hasn't been as quick as we'd ideally like, but experience shows that getting internet standards into general use takes time. Last year, the RSC was again a significant driver of progress in the ongoing effort to keep making the .nl zone more secure.

What is the Registrar Scorecard?

Launched in 2015, the Registrar Scorecard is an incentive programme for .nl registrars. It serves as a vehicle for SIDN and the registrars to invest together in the quality and security of the .nl zone. Registrars who participate in the programme receive financial incentives for deploying secure, modern internet standards. We're currently incentivising the security extension to the DNS (DNSSEC) and the e-mail security standards DMARC (in combination with DKIM and SPF) and STARTTLS (with DANE). Incentives are also available for adopting IPv6, a new version of the internet protocol, needed because there are no more 'old-style' IPv4 addresses left. Throughout the year, we scan the .nl zone for use of the standards and report the results to participating registrars, giving them a clear picture of their portfolios' status. Incentive payments are made twice a year. Via the RSC, we invested more than a million euros in the security of the .nl zone over the last twelve months.

Adoption of internet security standards

Since its introduction, the RSC has had a positive effect on the use of internet security standards. Nevertheless, the adoption of IPv6 and the e-mail security standards wasn't proceeding as quickly as we had hoped. So, in the middle of last year, we temporarily increased the incentives for using the relevant standards. And, because we see financial incentives as one element of a broader strategy, we have also been investing in knowledge-sharing, through vehicles such as the SIDN Academy. The Academy is an online learning platform where registrars can brush up their knowledge of modern internet standards.

Progress on all fronts

Our data shows that the various initiatives have been having the desired effect. Clear progress has been made on all fronts, and we've had positive feedback from registrars getting to grips with implementation of the standards. The results achieved last year are summarised below.

Incentive

January 2020

% of .nl zone

January 2021

% of .nl zone

IPv6

1,765,614

29.91

2,098,148

34.33

StartTLS plus DANE

453,133

7.54

726,501

11.94

DMARC plus DKIM & SPF

953,541

16.15

1,357,785

22.32

DNSSEC

3,236,568

54.82

3,418,586

55.93

Collaboration with the Secure E-mail Coalition

With a view to continuing to encourage adoption, last summer we linked up with the Secure E-mail Coalition, an initiative by the Platform for Internet Standards, to support the E-mail Security campaign. The partnership will yield various initiatives next year, with the focus on promoting awareness and supporting implementation of DMARC and STARTTLS, because they aren't easy standards to roll out. More information about the campaign is available on the ECP website.

Downscaling the DNSSEC incentive

As an incentive takes effect and adoption of a standard rises, a time comes for tightening the qualification criteria and scaling back the incentive. That's what we've been doing with our oldest incentive, the DNSSEC incentive, over the last couple of years. Tightening the qualification criteria for the DNSSEC incentive has not so far had any discernible adverse effect on growth. But what would happen if such an important incentive were withdrawn altogether? What impact would that have on adoption? Would the use of DNSSEC begin to decline? DNSSEC is too important to warrant no support at all. On the other hand, the DNSSEC incentive has achieved its goal, and there are other standards that we'd like to incentivise within our budget. Any course of action we might take depends on support from the registrar community. All decisions to scale back incentives or introduce new ones are therefore taken in close consultation with the Registrars' Association.

New incentive

Because we want to go on promoting DNSSEC use, we're planning to introduce a new incentive in the second half of 2023, which will take in all facets of the DNS. The new incentive will focus on the technical status of the .nl domain names in a registrar's portfolio. New reports and meters will be developed to show registrars how well they're performing in relation to the technical requirements we make for domain names, regarding things such as name servers, reachability, ports and DNS records. Qualification for the new incentive will depend on DNSSEC support, so that DNSSEC retains its central position in our vision of a secure internet.

Joint effort

Enhancing and maintaining the security and reliability of the .nl zone depends on a concerted effort by the registry, the registrars and other actors. In the year ahead, we will continue investing in that joint enterprise by launching new incentives, increasing the range of e-learning resources available through the SIDN Academy and offering services such as the Hosting Infrascan.