Russia Russia Roskomnadzor internet sovereignty law

Russia's Gosuslugi Domain Rule Turns .RU Names Into Revocable State Permissions, and Registrars Say It Is Unworkable

Since 1 September 2026, .RU, .РФ and .SU domains require state ID verification, ending anonymous ownership and leaving foreign registrants with few options.

Russia's ESIA Domain Rule in Numbers People of Internet Research · Russia 6.1M Domains in .RU registry The 11th-largest country-code zone… ~4B ₽ Registrar one-time compliance cost Industry estimate of one-time cost… up to 60% Registrars that could exit Registrars warn small and mid-size… peopleofinternet.com
Russia's ESIA Domain Rule in Numbers People of Internet Research · Russia 6.1M Domains in .RU registry ~4B ₽ Registrar one-time complia… up to 60% Registrars that could exit peopleofinternet.com

Key Takeaways

What changed on 1 September

Since 1 September 2026, registering, renewing, transferring or managing a domain in the .RU, .РФ and .SU zones requires the registrant to pass identification through ESIA, the state's Gosuslugi identity system. The legal basis is Federal Law No. 569-FZ of 29 December 2025, published in Rossiyskaya Gazeta on 12 January 2026. It amends the 2006 information law (149-FZ) so that, in the text's words, domain names are registered only after the registrant has completed identification through the unified identification and authentication system. The domain provisions took effect 1 September 2026, while other parts of the same omnibus law took effect earlier.

The law also restricts who may sell domains. Registration runs through Russian legal entities on lists maintained by non-commercial organisations that the Government designates, with the Government setting the registration rules. The statute text does not name Roskomnadzor in this role. That matters for accuracy: the domain regime is a Government-and-registry construct, even though it sits beside Roskomnadzor's separate and expanding powers.

The strongest case for the rule

The regulators' argument deserves a fair hearing. Disposable domains are the cheap infrastructure of phishing, fake shops and fraud, and a registry that cannot say who stands behind a name cannot help victims. Russian officials have framed the change as anti-fraud: the registry's director, Andrey Vorobyov, has said the restrictions aim to prevent fraud and abuse in Russia-focused domains, and the Coordination Center's own site has headlined the change as the end of anonymity in the Runet. Many jurisdictions require some registrant validation. Know-your-customer checks are not exotic.

Why this goes further than fraud control

The difference lies in who holds the credential and what follows when it is withdrawn. Ordinary registrant validation checks that an email or phone number works. Here, every domain is tied to a state-issued digital identity, the registrar layer is limited to government-listed Russian entities, and the Government writes the rules. A domain stops being a contractual asset held against a registrar and becomes an asset held at the state's pleasure. Russian legal commentators quoted by the outlet Kod.ru warned of exactly this: that the domain becomes a revocable permission rather than a property right. That is one source's characterisation of the bill-stage reform, not a court finding, but the structural point stands. Anyone who has to hold a Gosuslugi account to keep a site online has an identity, and a lever, attached to their speech.

The design also has a predictable cost for journalists, researchers, dissidents and diaspora publishers. A site that criticises the state is now hosted under a name that the state can link to a verified person. Pseudonymous publication is a long-standing safeguard for speech, and the rule removes it from the national zones without any showing of individual wrongdoing.

The wider sovereignty stack

The domain rule is one layer of a broader control architecture. Government Decree No. 1667 of 27 October 2025, in force since 1 March 2026 and valid until 1 March 2032, replaced the 2020 rules for centralised management of the public communications network. It gives Roskomnadzor authority to define threats to the stability and integrity of the Russian internet segment, to issue mandatory instructions to operators, and to set conditions for routing traffic through technical countermeasure systems. Read together, the two measures give the state a view of who owns names, and the means to act on networks.

DFRLab has separately reported on a data leak suggesting Roskomnadzor monitors and acts against anti-war posts on social media. The domain rule does not cause that surveillance, but it closes another anonymity gap in the same environment.

Industry says the model is unworkable

The commercial pushback is revealing. According to reporting by SecurityLab, registrars estimated one-time industry costs of about 4 billion rubles, with annual costs of 1 to 1.5 billion, and warned that up to 60% of active registrars could exit. They asked for a delay to December 2027 or 1 January 2028 and an 18 to 24 month transition for existing registrars. These are industry claims, not audited figures, but they point to consolidation: compliance costs fall hardest on small registrars, which concentrates the market in a few large ones that are easier to supervise.

The .RU registry held 6,137,523 domains, according to DomainIncite, making it the 11th-largest country-code zone. Foreign owners are the most exposed. Verification requires Russian credentials, a process for foreigners was still being built in mid-2026 according to trade reporting, and unverified domains can no longer be renewed. After expiry they return to the public pool, which invites cybersquatting.

A proportionate alternative

A proportionate anti-fraud regime would target the harm. Risk-based verification for commercial and payment-taking sites, registrar-held records disclosed only on a court order or documented legal request, and an abuse-takedown process with appeal would address scam domains without a universal state-ID gate. It would also avoid a mandatory link between every personal website and the state's identity infrastructure.

The policy lesson reaches beyond Russia. When countries copy the fraud rationale, the design questions are the same: who holds the identity data, who can revoke, and what remedy exists. Russia's answer is the most centralised version available, and its early cost is already visible in registrar warnings and stranded foreign owners.

Sources & Citations

  1. Rossiyskaya Gazeta: Federal Law No. 569-FZ (29 Dec 2025) full text
  2. Coordination Center for .RU/.РФ domains (official registry site)
  3. PPT.ru: Government Decree No. 1667 of 27 Oct 2025 on centralised network management
  4. DomainIncite: .RU ready to crash as draconian new rules come in
  5. SecurityLab: registrars ask Ministry of Digital Development to delay ESIA rollout
  6. Kod.ru: domain verification via Gosuslugi (legal commentary)