Home Research More Censorship: How Russia Changed the Rules for Its National Domains

More Censorship: How Russia Changed the Rules for Its National Domains

On September 1, two government decrees took effect that rewrote how Russia registers domains in the .ru, .рф, and .su zones.

News coverage focused on identification through Gosuslugi (the state public services portal) and on name length running from two to 63 characters. We read both documents in full and found what almost no one is talking about.

Summary

  • Domain rules now belong to the state. For fifteen years, the Coordination Center (an industry non-profit) wrote them. Now a government decree sets them.
  • Anonymous registration is over. Domains have long required passport details on paper, but the loopholes are closed: a government system now verifies the information.
  • A blocked name never comes back to anyone. There’s a separate ground for refusal: a name that was used for a site with restricted access. Past tense, written right into the text.
  • People and organizations on state lists won’t get a domain. Involvement in extremism or terrorism, or “undesirable organization” status, is a direct ground for refusal.
  • Foreign organizations are locked out. They can’t complete identification, and the window to transfer a domain closed on September 1.
  • The industry is bracing for consolidation. There are more than a hundred registrars today. Market estimates suggest only a few dozen will survive.
  • But nothing actually shut off on September 1. The Coordination Center allowed registrars to keep operating under the old rules until January 18, 2027.

What happened

On August 31, the government approved Decrees No. 1119 and No. 1120. The first decree introduced the Domain Name Registration Rules. The second one described how the list of authorized registrars should be formed and what requirements they must meet. Both were published on September 1 and will remain in force until September 1, 2032.

Both decrees implement Article 14.2 of the law “On Information.” Federal Law No. 569-FZ, signed on December 29, 2025, added the identification requirement to that article.

Zones .рус, .com, and other zones aren’t affected by these requirements.

Further in the text we will often reference specific clauses. Unless stated otherwise, these refer to the Domain Name Registration Rules approved by Decree No. 1119.

Who writes the rules now

Before September 1, the Coordination Center for the National Domain of the Internet (an autonomous non-profit) set the registration rules for the .ru and .рф zones. The rules in force were approved by the Center’s decision on October 5, 2011. For the .su zone, a dedicated institute, RosNIIROS, played the same role.

This kind of industry self-regulation is standard for domain zones worldwide. The community writes the rules. The government intervened through courts and blocking, but it didn’t touch the registration procedure itself.

Now it does, and thoroughly. The government sets the rules, and the government will change them too. Under the self-regulatory model, changing the terms had required a decision by a body where market participants were represented. Under state regulation, a decree drafted by a ministry is enough.

The Coordination Center hasn’t gone anywhere. The new Rules call it the coordinator: it maintains the domain name registry, forms the lists of registrars, and keeps the stop list. The changed part was who wrote the rules.

The state has been trying to influence domain registration since the 2000s

Before 2009. Registrants had to provide passport details, but nobody asked for copies of the documents. In 2010, the newspaper Kommersant described a typical situation: an administrator disclosed passport details back in 2006, but nobody requested copies at the time. As a result, people routinely listed fictional individuals as domain owners.

October 1, 2009. A new version of the .RU rules required sending the registrar electronic copies of documents: a passport for individuals, and registration certificates plus an appointment order for the head of the organization for legal entities. A domain without a confirmed owner got the status “unverified,” but it stayed in the registry and delegation didn’t stop.

July 1, 2011. A relaxation: registrars stopped requiring a passport copy for registration; a filled-out form became enough.

October 5, 2011. The Coordination Center adopted the rules that, with amendments, stayed in force for fifteen years.

The way owner data had been displayed also changed in the early 2010s. Before that, WHOIS for Russian domains showed the full name of an individual administrator. After enforcement of Federal Law No. 152-FZ (on personal data) had tightened, public output became anonymized, and “Private Person” replaced the surname. This didn’t mean privacy from the authorities.

December 12, 2022. Registrars became obligated to stop delegation at the request of Roskomnadzor (Russia’s communications and media regulator) if a domain was registered using a third party’s personal data without their consent, or points to a site with restricted access. Previously, only bodies conducting operational investigative activity had this right. A member of the Association of Russian Lawyers explained to ComNews at the time that the agency got to act “without a court, through a direct request from Roskomnadzor to the Coordination Center”.

December 29, 2025. Federal Law No. 569-FZ on identification through ESIA (the Unified Identification and Authentication System, the backbone of Gosuslugi) was signed.

September 1, 2026. The law and both decrees took effect.

Identification: what actually changed

You already had to identify yourself before. What has changed is how reliable the check is.

The old scheme relied on manual verification. The registrar asked for the data, looked at a scan if it felt like it, and everything after that depended on good faith. Getting around this was easy, and in practice, people did so.

Now a state system confirms identity. Andrey Kuzmichev, CEO of RU-CENTER, sums up the shift in one line: “We’re moving from manual document checks to automatic ones”. The company openly admitted that the previous mechanisms didn’t rule out knowingly false information.

The procedure does not run on the Gosuslugi portal itself, but within the registrar’s personal account interface. You start the check, get redirected to Gosuslugi, log in with a verified account, and consent to sharing your data. The registrar receives the data and checks it against the domain administrator’s form.

The registrar never gets your Gosuslugi password and never logs into your account.

The data collected goes further than people assume. Clause 11 of the Rules lists, for an individual: last name, first name and patronymic, date of birth, registered residential address, email address, phone number. Plus the full details of the identity document: type, series and number, date of issue, issuing department code, name of the issuing authority, and expiration date. And the ESIA account identifier too.

For a legal entity: full name, location and address, INN (taxpayer identification number), email, phone, account identifier, OGRN (primary state registration number), KPP (tax registration reason code), and the legal form code.

The data goes into the domain name registry, which the coordinator maintains. What’s publicly disclosed is less: for an individual, only an anonymized note that the domain belongs to a private person. But the registry itself contains everything, and clause 21 explicitly names identifying the person a domain is registered to as one purpose the data can be used for.

The data is kept for three years after the registration is cancelled (clause 22).

What you can’t get around, and what you can

You can’t preserve anonymity inside the Russian domain zones. You can move your project outside them, or split responsibility for it, and both paths are legal.

  • Register the name in a different zone. The requirement doesn’t apply to .com, .org, .net.
  • Register the domain to a trusted individual with a verified account. This works, but that person becomes the administrator (legally, the domain belongs to them).
  • Register it to a Russian legal entity, if you have one.
  • Renew in advance and get a delay.

What not to do: register using someone else’s verified account. This isn’t a loophole anymore, it’s a violation on both sides, and the domain owner becomes whoever’s account got used.

Foreigners: an important distinction

Foreign citizens can complete identification. Non-residents must follow the same rules and set up a personal account on Gosuslugi.

Foreign organizations can’t complete identification, since no mechanism has been established for them. There were two ways out: transfer the domain to an individual with a verified account, or to a Russian branch. This window closed on September 1. After that date, any operation requires completed identification.

One foreign registrar has already suspended registration of domains in these zones, citing identification difficulties.

What’s actually on the stop list

The claim that a blocked name never comes back holds up. It’s among the grounds on which a domain can’t be registered at all:

The following cannot be registered: […] (d) domain names whose own designation is used (was used) to address a site on the internet, access to which is restricted under the Federal Law “On Information, Information Technologies, and the Protection of Information.”

Clause 8, Domain Name Registration Rules

Notice the parenthetical. “Was used” is past tense, written directly into the legal text. Nobody will ever be able to register the name of a once-blocked site again. Not the former owner, not a stranger, not even in ten years.

This is fundamentally different from blocking. A blocked site still exists and is accessible through circumvention tools. A name caught by this clause stops existing.

When a domain gets shut off

Clause 54 gathers all the grounds for terminating delegation in one place, and the second one is worth quoting word for word:

Delegation of a domain name is terminated by the registrar: […] (b) based on a reasoned demand from the Federal Service for Supervision of Communications, Information Technology, and Mass Media (Roskomnadzor), in the case of registering a domain name using third parties’ personal data without their consent, or if the domain name is intended to address a site on the internet whose access is restricted.

Clause 54, Domain Name Registration Rules

The key word here is “demand,” not “court ruling.” What appeared in the industry rules in 2022 is now enshrined by the government.

The other two grounds: a decision by a body conducting operational investigative activity, and a reasoned request from the National Coordination Center for Computer Incidents, if a site is involved in cyberattacks. Separately, clause 55 covers government domains. Delegation stops at the request of the FSB (Federal Security Service) and is restored by the FSB as well.

Clause 58 requires notifying the owner and stating the reasons. Clause 59 adds that on cancellation, the registrar sets up temporary servers that redirect to a service page explaining the reason, unless the owner opted out of this.

What happens to a lost domain

Here, the new Rules change the familiar mechanics, and one line explains everything:

A domain name is registered with no limit on the term of its use.

Clause 18, Domain Name Registration Rules

The familiar “paid-up term” no longer exists in the rules. Instead, the cycle now hinges on identification.

A year runs from the moment of registration or the previous identification. 50 to 60 days before it expires, the registrar must send a notice. Then comes a 30-day priority renewal period, during which the right to administer the domain stays only with the current owner, and the registrar sends two more reminders. If you haven’t completed identification by the end of this period, the registration is cancelled under subclause (b) of clause 74. A final warning arrives 10 days before that.

There’s no redemption period here, unlike in international zones. In .com, after the grace period there’s another thirty days or so when you can buy the domain back. In the Russian zones, this stage doesn’t exist. After cancellation, the name goes straight into general availability.

Will someone snap it up? Clause 36 effectively describes the mechanics of domain sniping. The coordinator ensures equal registration opportunities for all registrars once a domain frees up, and publishes when registration can start. The exact moment is known in advance to everyone, including people who do this professionally.

Why this is dangerous beyond losing the site? Along with the domain, the new owner can receive mail at any address on it. If your address was the contact one at a bank, a hosting provider, a cloud service, or social media, whoever grabbed the domain can request a password reset. Losing a domain turns into losing accounts across the whole organization.

Certificates: yours stays valid until it expires, but the new owner can issue their own without any obstacle.

What to save in advance:

  • a DNS zone export,
  • whois data as proof of ownership,
  • a site archive and snapshots in the Wayback Machine,
  • (most important) a list of every service where the domain is listed as the contact one.

The only thing that actually saves you: moving contact addresses in critical services to another domain or an independent mailbox in advance.

The reform arrives at a historic peak

It’s worth looking at what point the zone is at as it meets the new rules.

The .RU domain launched on April 7, 1994. The first million names took thirteen years to reach, arriving only by 2007. After that, growth accelerated – 1.5 million by June 2008, 2 million by March 2009, 4 million by September 2012, 5 million in November 2015.

Then growth stopped. The zone passed its peak of 5.5 million in February 2017, and then declined for five years straight. It bottomed out in 2022 with 4.93 million, down 88,000 over the year, with more than 250,000 individuals and entrepreneurs no longer administrators. Non-residents and investors who’d bought up names for resale were leaving, and Andrey Vorobyov, director of the Coordination Center, noted a decline in the number of administrators among small and medium businesses. What actually happened?

Then a turnaround. A record 5,819,288 in 2024. The six-millionth name was registered on October 20, 2025. The zone now holds around 6.1 million.

The Cyrillic zone (.рф) went through a similar but sharper story. Open registration started on November 11, 2010. More than 240,000 names were taken in the first 24 hours, and almost 700,000 in the first month. It peaked in December 2011 at just over 923,000, then declined for ten straight years. It bottomed out in August 2022 at 671,700. In April 2026, .рф crossed the 800,000 mark for the second time in its history.

But the pace is already fading. The number of administrators is growing faster than the number of domains. In the first half of 2026, the number of administrators in the .RU zone grew by 188,600, or 9.15%. Vorobyov attributes the slowdown to the zone’s sheer size and to how hard it’s become to find a short available name. Meanwhile, the share of national zones inside Russia has been shrinking for the third year running: .RU from 70.8% in 2023 to 64.2% in 2025, .рф from 8.6% to 5.6%.

This is where the reform’s main risk lies. It arrives at a moment when the zone is at a historic peak but growing ever more slowly, while users are already migrating to international domains. At the same time, 72.7% of domains are registered to individuals, and by September, fewer than half of administrators had completed identification.

The precedent from 2022 shows that when a quarter of a million individuals stopped being administrators all at once, the zone lost 88,000 names in a year. Right now, an order of magnitude more names are at risk. Take a mental snapshot of what the charts look like today.

Readiness turned out low

According to a RU-CENTER study, as of August 27, 42.2% of its administrators and 25.7% of Reg.ru’s users had completed identification. Together, these two registrars account for 68% of the Russian internet. One day before the rule took effect, more than half of the country’s domains didn’t meet the requirement.

And one more detail from the same source: legal entities were able to complete identification at only one registrar in Russia. The rest integrated with ESIA by the end of the summer, and only for individuals.

The reason for the shortfall is historical. In the .ru zone, 72.7% of domains are registered to individuals, in .рф it’s 82.9%. Among the five thousand most-used sites in the Russian internet, 32% are registered to individuals. For decades, companies registered domains under employees, contractors, and freelancers, and now these people have quit, are unreachable, or were fictional from the start.

That’s why nothing actually shut off on September 1. The Coordination Center notified registrars that accredited companies would keep operating under the current rules until they’re added to the new list, or until January 18, 2027. Restrictions on operations for domains without completed identification aren’t being applied yet.

This isn’t a cancellation, it’s a postponement. Things will shut off gradually, as each domain’s identification deadline comes due.

How many registrars the industry will lose, and who benefits

The requirements for registrars are gathered in Decree No. 1120, and they open like this:

A Russian legal entity included in the list of entities that register domain names is a legal entity registered in the manner established by Russian law, with no affiliation to foreign citizens or foreign legal entities.

Clause 1 of the requirements for Russian legal entities, Decree No. 1120

Further requirements: net assets worth at least 1 million rubles (about $13,300), an information system connected to ESIA. Plus a multi-page questionnaire covering equipment lists, ways of ensuring stable operation during power outages, full data recovery time, methods of defense against attacks, and DNS server specifications.

And one item on the form is worth reading twice:

Personnel information, which must include contact details for the heads of the organization’s departments […] as well as the number of employees in the following departments: […] 3.7. the employee (employees) responsible for interaction with law enforcement agencies, including preparing responses to requests.

Appendix No. 2 to the Rules for Forming Lists, Decree No. 1120

Right alongside accounting, tech support, and legal. The function is built into the market-entry conditions. To get the right to register domains, a company must designate, in advance, a person for correspondence with law enforcement.

The scale of the shakeout. According to Andrey Vorobyov, director of the Coordination Center, more than 130 companies in twelve cities handled registration in the .ru and .рф zones in 2024. Market participants estimate that thirty to fifty will survive. This is an industry estimate, not an official forecast. But registrars themselves confirm the direction. The market expects a drop in the number of players, since the requirements demand investment in infrastructure and integration with state systems.

The answer “who benefits” follows from published figures and doesn’t require any conspiracy theory.

The market is already concentrated. According to the Coordination Center’s annual report, Reg.ru’s share reached 46.9%, RSIC (operating under the RU-CENTER brand) comes second, and Beget is third with 6.5%. Together, the top two hold 68% of the Russian internet.

The requirements are set up so that for a large company, this is just paperwork, while for a small regional one, it’s an insurmountable barrier. A million rubles in net assets, a dedicated person for correspondence with law enforcement, and technical integration with a state system all mean fixed costs that only pay off at high volume.

There’s a separate category the industry talks about openly: technical registrars that don’t work with clients directly and live off catching domains as they free up. They’ll be the first to go.

And a very direct effect is already visible. The one registrar in the country able to identify legal entities is picking up competitors’ clients simply because those competitors can’t offer that operation. Corporate domains will move to it out of necessity, not choice.

International context

The objection “everyone does this” comes to mind, and it’s partly fair.

ICANN has long required registrars to keep information accurate and provides for de-delegation if it turns out false. In the EU, the NIS2 directive obligates registrars to ensure the accuracy of registration data and disclose it on a justified request. The German and French zones have requirements for the owner or their representative to have a presence in the country.

The difference isn’t about whether you have to identify yourself. The difference is in three things.

Who checks. In the EU, the registrar does the checking, and data is disclosed on a justified request under oversight. Here, a state system does the checking, and it also logs the fact of the request itself.

What the checker can do beyond checking. A European regulator doesn’t set registration rules, doesn’t maintain a list of banned names, and doesn’t refuse a domain based on organizational lists.

Whether there’s independent oversight and a way to appeal. In the EU, data protection authorities operate, and decisions can be challenged.

It’s censorship

Anton Gorelkin, first deputy chair of the State Duma’s information policy committee, put the point of the reform this way: “Nobody will be able to register a domain anonymously anymore, using someone else’s documents or forged ones.” The idea being that phishing sites will come to an end.

The decrees contain no direct content bans. But they substantially change the state’s ability to restrict.

Anonymity is gone. Formally, it ended in 2009, but the check was manual and could be beaten with made-up data, and that worked for fifteen years. Now the link between a domain and a verified identity gets established automatically. Same trick as with caller ID labeling (see our article): the channel stays open, but you can only use it after identifying yourself.

A domain becomes revocable. Before, a site got blocked and kept existing. Now, failing identification leads to cancellation, and a cancelled name doesn’t come back.

A name gets burned forever. Clause 8 closes off registration for names that were used for sites with restricted access. Block it once, and the name is dead for everyone.

A list-based ban appears. People and organizations on state lists won’t get a domain registered at all.

The intermediary gets built into enforcement. The registrar, like the hosting provider before, becomes a participant for whom refusing to comply means losing the right to operate. And now it’s also required to keep a staff member on hand to answer law enforcement.

We covered how the state interfered with domain name resolution. This is about the layer below that: who a name belongs to, and whether it can exist at all.

What this means for NGOs, media, and activists

The Russian domain zone has stopped being a place where you can run a resource without identifying yourself. For organizations that need administrator anonymity, the .ru, .рф, and .su zones no longer work for that purpose.

Separately, for anyone already on one of the lists, or worried about ending up on one: you won’t get a domain registered, and this is spelled out directly in the rules.

  • Check that the administrator’s details match the Gosuslugi account.
  • Check who your organization’s domain is registered to. If it’s a former employee’s personal account or a made-up person, you’re in the exact group that makes up most of the zone and risks losing its name.
  • If you have several domains, put all the deadlines into one calendar.
  • Plan a backup domain in another zone in advance.

Moving off .RU without losses

A move takes months, so it’s worth starting early.

Register a new name and make it an alternate address. Make sure a certificate is issued and pages actually load.

Set up a permanent redirect, with a 301 status code. Search engines read this as a move and pass the accumulated ranking to the new address. A temporary redirect won’t do that.

Make the new name your primary one. Canonical links, the sitemap, absolute addresses in templates. Internal links shouldn’t point to the old domain even through a redirect.

Provide information to the search engines. Google Search Console has a change-of-address tool; Yandex Webmaster has a site move option, if you use it. Think about whether you want to hand your site’s statistics to a Russian company.

Check external links. Social media, directories, email signatures, business cards, QR codes, presentation templates.

Don’t forget email and everything tied to the domain. Mail records, mailboxes, email authentication settings, single sign-on, reply addresses in integrations, webhooks, payment gateways, analytics, certificates. A website moves visibly, email moves quietly.

Don’t abandon the old domain. Keep renewing it as long as you can, and keep the redirect running. You need it as a bridge, not a backup home. Keep receiving mail at the old addresses, but reply only from the new ones. If the name goes, a fake site with your data on it can appear there.

Timing matters. Renew in advance, two months before the registration ends.

Don’t miss the next Riposte!

We don’t spam! Read more in our privacy policy