A Multi-Billion Dollar Problem
India's digital transformation has been incredibly rapid, with internet penetration soaring from just 15% in 2015 to an estimated 70% in 2025. While this boom has connected the nation and powered the economy, it has also created a fertile ground for cybercriminals.
In a single recent year, the government recorded 2.4 million cyber fraud complaints, amounting to losses of around $2.4 billion. A new victim falls prey to scams every 37 seconds, a situation that risks becoming a national crisis. At the core of this issue are fraudulent websites, often impersonating trusted brands like Amazon, Microsoft, and major banks to deceive unsuspecting users with fake jobs, bogus franchises, and phishing schemes.
Shifting from Reaction to Prevention
For years, the battle against these sites has been a frustrating game of whack-a-mole. Authorities would block one site, only for another to pop up. Now, India is shifting its strategy from simply taking down fraudulent sites after the fact to disrupting the infrastructure that enables them in the first place. This proactive approach involves a fundamental change in how the digital ecosystem is regulated. The focus is now on the intermediaries—the platforms and service providers that form the backbone of the internet. This includes social media platforms, messaging apps, and most recently, domain name registrars.
The New Mandates for Registrars
The most significant development comes from a series of court rulings, primarily from the Delhi High Court, in cases brought by major corporations tired of battling brand impersonation. These rulings have imposed stringent new obligations on domain registrars like GoDaddy and others offering services in India. Key directives include mandating Know Your Customer (KYC) verification for anyone registering a domain, effectively ending the anonymity that scammers have long exploited. Registrars must now verify identities using official documents and cannot offer privacy-masking services as a default, free feature; it must be a paid, opt-in service. This makes the details of who owns a website more transparent and accessible to law enforcement.
Faster Takedowns and Greater Accountability
Another crucial change is the requirement for registrars to disclose a domain owner's contact and payment information within 72 hours of receiving a request from a court, law enforcement agency, or any party with a “legitimate interest”. This is a dramatic acceleration of the process, designed to help authorities trace perpetrators before they can disappear with victims' money. Furthermore, registrars can no longer hide behind “safe harbour” immunity if they fail to prevent abuse. For .IN domains specifically, the National Internet Exchange of India (NIXI) has rolled out mandatory e-KYC and has even warned it could de-accredit registrars who facilitate the trading of domains for speculative purposes.
The Privacy Debate
This crackdown has not been without controversy. Major registrars like GoDaddy have challenged the new rules, arguing that removing default privacy protections exposes legitimate website owners—from small businesses to journalists and activists—to risks like stalking and harassment. They contend that making personal names, addresses, and phone numbers public by default could have a chilling effect on free expression and clashes with global data privacy standards like the EU's GDPR. GoDaddy has also argued that as a global company, an Indian court order could force it to regulate domains worldwide, creating a messy international precedent. The case highlights the difficult balance between fighting rampant fraud and protecting individual privacy in the digital age.













