edit/solution:
Several people claim PIR, the US organisation that manages the .org TLD, for being ultimately responsible.
They have a contact form on their website: https://pir.org/contact/
We should pepper them with complaints.*
Also there’s a pretty informative write-up here.
So yeah, antifascism is now terrorism according to the US gov.
Their website and mailing server has been taken down in Europe, too now.
Are they still willing to kiss his ass, or does the USA have the power to do that globally?
Only yesterday most DNS services allowed it (OpenNIC, NextDNS, and the big ones).
Now they all return this:
whois autistici.org (edited)
Registrar URL: http://www.gandi.net/
Registrar: Gandi SAS
Registrar Abuse Contact Email: abuse@support.gandi.net
Registrar Abuse Contact Phone: +33.170377661
Domain Status: serverHold https://icann.org/epp#serverHold
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
Domain Status: serverUpdateProhibited https://icann.org/epp#serverUpdateProhibited
URL of the ICANN Whois Inaccuracy Complaint Form: https://icann.org/wicf/
Check out these links, it’s bad:
serverHold https://icann.org/epp#serverHold
clientTransferProhibited https://icann.org/epp#clientTransferProhibited
serverTransferProhibited https://icann.org/epp#serverTransferProhibited
serverUpdateProhibited https://icann.org/epp#serverUpdateProhibited
One can log a complaint here but all the form links resolve to my.site.com. Which is invalid.
Question
Where (in Europe or globally) can I log a complaint resp. protest?
What is autistici.org
It’s the Italian volunteer technology collective Autistici/Inventati. Has been around for decades.
There’s been some reports on the fediverse during the past days, and personally I’ve been using them for years. Among other things they provide free email accounts for people who ask.
https://piefed.zip/c/[email protected]/p/1770717/trump-admininistration-has-designated-the-italian-pro-privacy-and-anticapitalist-collectiv
https://piefed.zip/c/[email protected]/p/1767731/united-states-sanctions-autistici-inventati-for-supporting-far-left-terrorism
https://piefed.zip/c/[email protected]/p/1773823/autistici-inventati-s-main-org-domain-goes-dark-after-us-terrorism-designation
And of course their own blog post about it:
https://cavallette.noblogs.org/2026/08/10076
edit1:
Since their registrar is Gandi, I think it makes sense to log a complaint with them even if they aren’t ultimately responsible:
[email protected]
https://helpdesk.gandi.net/hc/en-us/requests/new
* and not ICANN. I have no idea how these things work internally; maybe ICANN defers power over such things to these TLD-orgas and avoiding US-controled TLDs is enough for the time being.
I would hate to think that the US can control ALL domains by bullying ICANN into submission.


https://opennic.org/
https://en.wikipedia.org/wiki/Alternative_DNS_root
OpenNIC also blocks autistici.org.
Yeah, it’s bad.
I was told these services get lists from ICANN without checking them. Although the wikipedia article suggests OpenNIC has its own, different root?
I do hope manual intervention is possble, otherwise Trump has the whole WWW by the balls.
Can confirm it’s blocked. I use OpenNIC’s root. It is independent from ICANN, but it doesn’t resolve any ICANN related domains. It only resolves its alternative TLDs, which fall within its jurisdiction. Everything else gets bounced to ICANN’s part of the DNS.
Yeah because they refer to the same ICANN root servers for the ICANN root domains. The point of an alternative DNS root is that they can provide their own specific top-level domains, so sites that are targeted by this kind of censorship can register a domain in an OpenNIC managed TLD and then they are only subject to moderation by OpenNIC instead of ICANN.
Hmmm then they are not as independent as one would think of them. Do we know who is funding opennic?
I was lurking in their IRC yesterday, their stance seems to be that they will never override an existing record, but there was some discussion about possibly overriding an NXDOMAIN. The main issue is DNSSEC - with it, negative answers are authoritative and signed, so they’d need to stop supporting DNSSEC altogether to restore the record. In general, they mirror “standard” TLD zones 1:1 from the root servers, their “libre” and “censor-free” mostly seems to apply to their own TLDs that are only available on OpenNIC.
Edit:
logs
20:17 ohnonot: Some of you may be aware that some domains are being blocked because USA pressure. The reasoning is, of course, "AntiFa terrorism". 20:18 One of these domains is autistici.org. 20:18 But shouldn't I be able to reach it with OpenNIC? I am currently using one of your nameservers. 20:23 ohnonot: Because I cannot. 20:31 phschafft: there has been some dicussion about it so far. 20:31 I would assume, if it's gone from the parent zone (here the TLD), it's gone. end of story. 20:47 ohnonot: Thanks. I just read that OpenNIC is an "alternative DNS root" but apparently it still gets the list from somewhere - ICANN or whoever takes care of the TLD, and once the IP/name connection is lost, it's lost? 20:48 Could not such sites request to be included in OpenNICs lists, and f*** the USA-based "parents"? 20:49 BYW where can I follow OpenNIC's discussion? 21:04 phschafft: there is a mailing list. 21:05 ohnonot: it's not that simple. starting with the fact that once a zone is signed it's not possible to just edit it however you like. 21:06 this is a very much more complicated topic than most people realise. 21:08 Shdwdrgn: Just waking up here, but I wanted to point out that Openinic's root zone pretty much just points all the ICANN tld's directly to the official providers. So if an .org domain gets blocked, I cannot edit the direct response. 21:09 There IS a possible way around it... Any dns server can add their own manual entry for a domain to point back to the original dns servers of that domain 21:10 There was some heated discussion here years ago when the US similarly censored some other domains. I brought up this idea at the time and a lot of people were strongly against it because then opennic no longer faithfully resolved the ICANN domains exactly as the rest of the internet saw them 21:34 EMREOYUN: Following up after Shdwdrgn, this is why there are proxy websites, for example, the website that lists torrents. You can't simply change everyone's DNS'es but you can always register a new domain 21:35 Also supporting whytek, DNS is decentralized by design but it is extremely centralized in terms of politics & power 21:37 But I didn't expect Italy to do something like this. I know it is nowhere close to our country in terms of magnitute of cencorship but still [snip] 22:16 whytek: And the debate over faithfully reproducing ICANN domains is of course valid. I certainly would not want to see a difference in results from one DNS provider to another. But actually servicing a domain that does not exist in the _other_ provider is not the same thing. 22:18 The way I'd see that is that ICANN server won't resolv .libre OK fine. but i will. we do this at TLD without problem, why not do it are secondary level? ICANN doesn't resolve whatver.org, ok we will.. Of course, maybe then you want to ensured monitoring to make sure that once ICANN is servicing the domain, you replicate it correctly. We DON'T want diverse results. 22:19 the once a domain is signed... argument then is not applicable.. the "upstream" domain cannot be signed, as it does not exist. 22:21 whytek: But.. in the end, you know.. I think DNS is just a problem, punkt,punto,fullstop. Over on fediverse some poeple are throwing out ideas into the mix.. the debate is always bubbling under there somewhere. 22:22 Shdwdrgn: whytek, that was actually my argument in the matter... if any government has forcefully removed a domain from the registry then that domain technically no longer exists, so by adding our own entries back into the record we're not breaking anything, we're just adding functionality that shouldnt have been removed in the first place. 22:32 whytek: Shdwdrgn, ack. 22:33 of course.. good luck getting a LE SSL cert for the domain then.. and then we are going down the road to the alternate Cert Authority..... 22:33 (again) 22:33 phschafft: whytek: maybe it can. but so far all ways I have seen people suggest had one or more of those three main flaws: 0) they did not remove the complexit but made it less visible, 1) they removed security, 2) they removed features. 22:34 more then happy to be shown a solution that does none of that. 22:34 Shdwdrgn: right, no ssl available, but the site might still be somewhat functional without it 22:37 phschafft: whytek: 'make sure that once ICANN is servicing the domain, you replicate it correctly' <- this is a HUGE complexity added. like in at least two magnitudes larger than people think. 22:38 whytek: also, the signed parent domain (here: the TLD) might provide information that specifically states that the given domain DOES NOT exist. so if it exists the signature would missmatch. 22:38 please don't ignore the negative cases. this is actially part of my 1) 22:39 and the 'we should replicate if it is there' is somewhere around my 0) 22:40 Shdwdrgn: phschafft, I don't see that as much of a barrier? Just make a query directly to the ICANN record and if that domain reappears again, stop including the local record? 22:41 phschafft: Shdwdrgn: 'someone somewhere somehow runs an undocumented cronjob that does magic to the zones'? 22:41 ;) 22:41 whytek: phschafft, (I'm not sure I'm understanding the language structure of those last two lines re 1/0) - TTL aside, I'm not seeing the complexity in answering queries for a domain as long as so other server is not doing so. I'm not saying it has to be done EVERY time there's a query.. just have some process that checks I dunno.. once a day or whatever. 22:41 phschafft: it sounds easy. but doing it so it actually works, and keeps working is hard. 22:42 Shdwdrgn: There is certainly no easy solution to modifying the signed ICANN record to slip the domain back in place, but I do know of one method 22:42 whytek: also, in terms of signature mismatch.. what's to mismatch? If I'm using openNIS servers? where am I going to see a mismatch? 22:42 *openNIC 22:43 Shdwdrgn: you can actually get access to download local copies of .com, .org, and others. If you have a full working copy, you can self-sign the root of that tld and then you're free to make any changes you want. 22:43 phschafft: if you don't see a mismatch, that may mean that you have verification disabled ;) 22:43 Shdwdrgn: but those tld files are HUGE!!! 22:43 phschafft: the large .de outage recenty kind of demonstrated that problem in the real world. 22:44 maybe reading up on it is a generally good idea for DNS related tech people. independent on today's topic. 22:45 and the enduser needs to trust another key. 22:45 for any definition of enduser. 22:45 anyway, it's movie night! 22:46 whytek: again, I'm not against things. just consider my warnings and make sure they are *actually* void. :) 22:50 whytek: phschafft, (I missed your 1st post with points 0-2) - I'll admit I have not kept up to speed with developments in areas such as DNSSEC, although I'm well aware that a huge amount of work has gone into it in recent years. not least from NGI. 22:50 I suppose I see it as adding even more dependency onto DNS, something which I have since a long long time ago felt like needs to go away. 22:51 I do agree with those who say we are better off with encryption/identification built into the protocol. 22:51 phschafft: I'm also not arguing what is right or wrong and how things should or should not be. just, if you touch it, make it better, not worse. 22:52 whytek: I'm not sure I see the absolute need for a "human" addressable internet, certainly not if this is at the cost of sovereignity and descentraliation.Makes sense to me. Technologies and laws have to be graded in terms of who they hit negatively. if DNSSEC can be used to censor and erase people on a toddler’s whim, then it’s perhaps best that it’s removed, or that it’s at least temporarily dropped for cases like this.
Indeed, cryptography is generally good but we must remain aware of who holds the keys
Thanks. I only saw the first half of that 😁
Their and other people’s stances make it seem like ICANN itself could not pull something like this off, so all we need is a TLD governed by a non-US entity? I’m totally not sure about these things, I have to take the implied meaning from this convo and also the mastodon thread.
Just found their own write-up, it has an informative section about “ICANN, PIR, registrar and servers: who does what”.
BTW the last sentence in that log,
“But I didn’t expect Italy to do something like this. I know it is nowhere close to our country in terms of magnitute of cencorship but still”
does not seem to refer to this technical DNS stuff, as one can read above.