COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARY

Transcription

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYOn 7 February 2014, ICANN published a Request for Information to identify any commercially-available services and software thatmight be capable of validating or verifying domain name registration contact data (such as WHOIS).This RFI was intended to inform two distinct ICANN projects that require address validation and verification. The first project relatesto a near-term need for postal address cross-field validation services arising out of requirements applicable to those registrars whohave signed the new 2013 Registrar Accreditation Agreement (RAA Project). In addition, ICANN sought similar information for aseparate longer term project in connection with Expert Working Group on Next Generation gTLD Directory Services ("EWG")recommendations to identify a replacement to the current WHOIS system.RFI submissions were received from eight (8) organizations: CNNICDigiCertExperianInformaticaMelissa DataSDFStrikeIronUPUThese submissions are summarized in two tables that follow. The first table focuses on each respondent’s background, services,costs, and other related information. The second table summarizes validation and verification approaches for each data element, asdescribed by all respondents. Individual RFI responses provided additional discussion about available services and software and howeach Respondent might help meet ICANN’s current and future address validation and verification needs.14 March 20141 Page

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYSUMMARY OF RFI RESPONDENTS, SERVICES, AND COSTSNameBackgroundServicesOther InfoCostAddressDoctorMaxdorf,GermanyAddressDoctor is anenterprise class postaladdress validation &correction engine, which hasbeen engineered from theground up to effectivelymanage the myriadidiosyncrasies present inglobal postal address formatstandards & to correct theinherent problem of humanerror within all datacollection points.Syntactical and operationalpostal Address ValidationResponse Time:A single core of our engine iscapable of processing in excess of3 million records per hour. Inother integrations we canperform real time global addressvalidation in 100ms, which variesbased on latency issues.There are two main components toconsider from a licensing perspective:AddressDoctor is the mostmature address validator on theplanet, with over 20 years ofindependent research &development; it was selected foracquisition in 2009 by parentcompany Informatica due to thefact that it significantlyoutperformed all othercommercially available offeringsin speed, reliability & qualityresults.AddressDoctor boastspremium postal referencedata for over 251 countries& territoriesCNNICChina InternetNetworkInformationCenterBeijing, ChinaChina Internet NetworkInformation Center (CNNIC),founded as a non-profitorganization on Jun. 3rd1997, is the state networkinformation center of China,which has taken theresponsibility of operatingand administrating “.CN”country code top leveldomain (ccTLD) for 15 years.CNNIC locates at South 4th14 March 2014CNNIC is capable of performingall the above verification in typesof syntactical, operational andidentity. As to operationalverification, CNNIC conductsvalidation with email address,phone number, matchingaccuracy with postal address andzip code.a.The “engine” which arelicensed per core for a one-time fee of 25,000/coreb.The “data subscription” whichis licensed annually & varies dependingon the countries selected. We offerregional discounts & an “All world” packwhich includes every country we offer.For guidance, our “251 Country WorldData Subscription” is 143,900 peryear/copyc.In certain integrations aseparate annual maintenance cost willapply which pays for bug fixes, support,updates to the data subscriptions &feature releases. This is 22% of the netlicense cost, charged annually.CNNIC currently supports addressvalidation in China with realname verification ration achieves99.3% upon more than 10 million“.CN” domains.CNNIC is capable of registrationdata verified upon syntacticalvalidation within 50 milliseconds;operational validation within 400milliseconds; identity validationwithin 5 minutes.2 Page

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYNameDigiCertLehi, Utah USABackgroundStreet, Zhongguancun,Haidian district, Beijing.CNNIC provides variousinternet basis services suchas New gTLD relatedregistration services, TMCH,Data Escrow, EBERO, DNSsoftware and hardware.Being the most professionalregistrant identityauthentication institution,CNNIC also provides NewgTLD registries real nameverification services.DigiCert is a certificateauthority that providestrusted authenticationservices to large and notableorganizations such as theUnited Nations, the UnitedStates House ofRepresentatives, theCanadian InteriorDepartment of Health, andNASAServicesOther InfoCostIdentity, operational andsyntactical validation services;worldwide address validationservices;Automated services respondwithin seconds; 1 for automated services;Higher value validation 10- 300depending on level of assurancerequiredsyntactical validation checks areautomated and produceimmediate error codes;Operational validation systems –emails use a ping-back system;Operational address verificationutilizes a database verification ofthe address or a letter sent tothe address that contains anactivation code. The entityconfirms their address byinputting the activation code in apublicly available link.Identity verification uses third14 March 2014Manual processes depend onresponsiveness of the registrant,typically within minutes;Very high assurance servicestypically within an hour24/7 support and an appealsprocess is available within anhourFalse positives – better than 1 in100,000, with appeals processesavailable to remedyHandles more than 100,000verifications annuallyCan flag a name as potentially3 Page

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYNameExperian an Data Qualityprovides contact datavalidation services for13,000 customers globally,many of which utilize oursoftware within theireCommerce platform. Someexamples of directcustomers who haveintegrated our data qualitytools within their websiteinclude: Overstock.com, 1800-Flowers.com,drugstore.com, NevadaDMV and McMillion14 March 2014ServicesOther Infoparty databases and othersources to confirm the physicalexistence or legal registration ofthe entity. Individuals aretypically verified through a photoID document. Legal entities areverified by confirming theirregistration with the appropriategovernment authority. For legalentities, the authority of therequester is verified bycontacting the entity usinga reliable method ofcommunication and confirmingthe requester’s agency. IfICANN wants a completelyautomated system, verificationof identity is possible byrequiring a credit card associatedwith the registrant.fraudulent, triggering additionalvalidation checks.Provide syntactical andoperational validation servicesfor address, email and telephonenumbers.Experian Data Quality will supplyan address validation solutionthat allows the capture ofvalidated and standardized postaladdress information in real-time.Experian Data Quality addressverification engine uses fuzzymatching and proprietaryalgorithms that have beenoptimized over 20 years.Algorithms use rules based onmisspellings, phonetic matching,address element recognition, andmore.CostDepending on the number of productsand services selected there is thepotential of a one-time service feeassessed to ICANN. This fee would likelyrange from 2-15% of the overall price ofthe solution provided.For all of our products and services ourpricing model is an annual license feebased on annual transaction volume.4 Page

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYNameBackgroundServicesResearch. We are alsopartners with organizationswith similar challenges, suchas The Common Application,which hosts collegeapplications for over 500schools within the UnitedStates.Melissa DataCorporationRancho SantaMargarita, CAUSAExperian Data Quality hasoffices in Boston, London,Paris and Sydney.Melissa Data is an OEMsoftware manufacturer thatdevelops software and toolsfor data quality, dataenrichment, and dataverification and providesover 6000 clients with acomprehensive suite of datacentric solutions as a trustedpartner.Every year Melissa Datainitiates hundreds ofcommercial deployments ofon premise tools, cloudsoftware, and professionalservices in the domain ofdata quality and dataenrichment, as well as entitymatching and dataconsolidation. Our clientsare found in many verticalsfrom government, tobanking, insurance,14 March 2014Melissa Data’s services includeglobal address, telephone, emailverification as well as global IPaddress and name parsing andrecognition solutions.The Melissa Data services arecapable of full syntactical andoperational validation andIdentity with many of therequest elements.Other InfoFor our hosted addressverification, and phoneverification products there aretypically sub-second responsetimes.Our email verification productwill interact with mail servers, sothe actual response times vary.However, for popular domainssuch as Yahoo.com, the responsetime is sub second as well.The services are designed toreturn responses of 100 recordsin less than a second. Dependingon variables such as internetcongestion sometimes theresponses may be up to 3seconds.CostBased on the information on the RFI andthe custom application that would needto be built we are estimating 500,000and up.Melissa Data’s Personator cloudproduct merges more than 20different datasets and over 3billion records of constantlyupdating consumer data pointscovering the entire United States.Nicknames and Abbreviations:Melissa Data’s matchingleverages databases and logicbuilt over decades to findmatches for nicknames andabbreviations.- Different Formatting:Formatting concerns are5 Page

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYNameBackgroundServicesmanufacturing, and thehealthcare industry.Other InfoCostautomatically handled by theengine. Melissa Data will take thedata and parse it out correctly tofind the best match.Fuzzy Algorithms: MelissaDatahas a toolbox of over 12 generalstring matching algorithms. Theseinclude industry- acceptedalgorithms like Levenstein andJaro-Winkler, as well asproprietary Melissa Data oneslike MD Keyboard.SecureDomainFoundationOntario,CanadaThe SDF has developed aSubstantial database ofdomain names classifiedBy their type of maliciousbehavior, IP addressreputationdata, email addressreputationdata, and geo locationvalidation.The SDF provides aReputation system;Essentially a verificationSystem with the addedbenefit of providing anindication of reputationassociated with the dataelement or elements.StrikeIron Inc.Cary, NorthCarolina, USAIndustry Leader in APIs andAPI Management offeringemail validation andtelephone validationservices in North AmericaEmail validation- Syntactical,operationalGlobal address verificationPhone Number Validation onlyfor North America14 March 2014There is currently noFee for membership inThe SDF and no fee foraccess to the API. TheSDF is a not- for- profitand the operational costsare covered bysponsors.Performs Syntax checks, checksdomain and whether can itaccept mail, conducts inline smtpconversations and proprietaryreal time verification that detectsrecipient level validity fordomains that do not providestandard responses and have anexternal return path for recipientresponse.6 Page

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYNameBackgroundServicesOther InfoCostApplies a scoring methodologywith specific classificationmessagesValidates phone numbers in realtime. Can validate that is amobile number and can SMScustomersResponse rates for phonenumbers and addresses inseconds; Email validation insecondsUniformPostal ed in 1874, theUPU is the second oldestinternational organizationworldwide. As a specializedagency of the UnitedNations, with its 192member countries, the UPUis the primary forum forcooperation between postalsector players. It helps toensure a truly universalnetwork of up-to-dateproducts and services.It is the authoritative sourceof postal addressinformation for its membercountries,Postal Address syntacticvalidation, operational validationTelephone number syntacticvalidationSome identity validation possibleThe PTC which is an operationalunit within the UPU has beenproviding for more than 15 yearsmission-critical 24*7 softwaresuites to Designated PostalOperators in the areas of: International mailmanagement (IPS suite) International and domesticpostal Money Orders andClearing (IFS suite) Postal Customs Declarationsmanagement (CDS) Together with a full-blownEDI network with 10 MillionEDI messages per month andthe quality & monitoringapplications to ensure realtime management of crossborder postal deliveryquality.S42 License fee:- UPU Standards can issue a globallicense for ICANN and ICANN canredistribute the information needed tothe Registrars.- License for "above 30 workstations" at:11,480.00 CHF (US 12,575.00).Verification of address dataFREE - Postal Addressing Systemsinformation(included in the POST*CODE DataBaselicense)Information, on a country-by-countrybasis, is also available to any public rence data/comparison data :14 March 20147 Page

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYNameBackgroundServicesOther InfoCostFor the IPS suite there is a realtime check of all parameter datarelated to international postaltraffic against which each EDImessage on the network ismonitored.In the IFS suite – dealing withmoney orders – there arefunctions (must be) that allowthe identification of persons(know-your-customer) as well aspossibilities to check personsagainst existing international andnational Black Lists (e.g. OFAC,CTF )Universal POST*CODE DataBase datalicensing (examples)POST*CODE DataBase DEVeloperLicense (example for a software serviceprovider)Initial License fee : CHF11,968.00 annually (can be renewed)Amortization possible at anytime by switching to a standard license(in-house or commercial purposes)UPU’s Postal Technology Centreis the global repository with 190postal operators sending EDImessages for each barcodedpostal item, with 10 Million ofmessages per month andTerabytes of data in our DataWarehouse for monitoring andreporting.Billions of international addressesare corrected against theUniversal POST*CODE DataBase.Against a database at UPU,response rates should be nearreal-time (milliseconds toseconds).14 March 2014POST*CODE DataBase standard License(example for ICANN)Annual license fee, Standardpackage, World option: 10,880.00 CHFComplementary annual usagelicense fee (users, address volume):Licensing flexibility: Regarding thePOST*CODE licensing, the data licensingabove will be tailored to ICANN’s preciseusage. It can be evolving starting withlower complementary usage fee andcoming to a fee close to the exact usageonce in production. Anyway, 3 months,in case of a standard license, will not bebilled for ICANN’s development andtesting period.Specific countries additional licenses(not mandatory but maybe addeddepending the data check level down tostreet and house number in a street).Ask for our “Specific countries”document to get an overview on suchadditional licenses.8 Page

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYSUMMARY OF VALIDATION APPROACHESData ElementValidation StepsPostal .7.1.2.3.4.5.6.7.8.9.Government documentation such as local mailing authority or UPU databasesA database verified as providing reliable informationUtility or financial information associated with the address (such as payment with a credit card corresponding to theregistrant address)An activation letter mailed to the addressLocal mailing authority where one existsWhen a local mailing authority does not exist, referencing proprietary datasets which provide additional address databeyond government sourcesValidation of postal addresses Using Google’s Maps APIValidation through geocoding servicesIt is possible to have a fully verified address, partially verified address, or un-verified address. It is also possible to verify tothe sub-premise level, premise level, locality level, postal code level, or administrative area level. The combination of thesecodes can be used to generate a score based on the client requirements.E mail is validated using a ping back system that confirms the registrant’s control over the email addressValidate the syntax of the domainValidate the domain name exists of an email addressFor email verification products, a known limitation is validating email addresses that belong to an accept-all domain. If a mailserver is accept-all, it will not be possible to validate whether the mailbox is deliverableValidate the Email address via mailserver interrogation to validate its existenceSyntax, mx, domain, and fuzzy, and spelling correctionsEmail addresses must conform to RFC 5322Calling the specified number and obtaining an affirmative response deemed sufficient to conclude that the registrant isaccessible at the telephone numberConfirming that the number is listed in a database verified as providing reliable contact information and verifying that thenumber is associated with the registrantAccepting a call from the specified telephone numberAn automated call back system that confirms the number is able to receive communicationThe service will verify the number as current OR update the landline phone number given OR append a landline phonenumber where none is given and one is available.An additional service can be provided that returns attributes about the address and phone, such as phone type (mobile /landline), listing type (business /residential) and whether the phone appears to be activeChecks against US switch data, global reference dataChecks against Do Not Call Registry to see if number is valid (but not who owns it).Telephone numbers must follow the ITU-T E.164 notation for international telephone numbers14 March 20149 Page

COMMERCIAL VALIDATION SERVICE RFI - RESPONSE SUMMARYData ElementValidation StepsIdentityIndividuals1.Legal EntitiesRequester’s Authority toAct on behalf of legal EntityUnique IdentifierAuthority of Contact:Through a face to face verification with a trusted agent or an entity typically responsible for conducting identity verification(such as a notary, attorney, accountant, or similar professional)2. Via a remote vetting process that confirms the identity of the individual, such as a record check on an identifying number3. Using a photo ID document provided by the registrant1. Confirming the entity’s status directly with a government body responsible for the formation or creation of the entity2. Payment using a mechanism linked to the registrant’s name or address3. By confirming the entity’s existence using reliable data sources4. By confirming the entity’s existence using account information tied to the entity’s name, although this method is notrecommended5. In the Universal POST*CODE DataBase, the Organization table records some businesses for some countries (businesses withdedicated PO boxes or not)ICANN should consider requiring the validator to verify the requester’s authority to act for a legal entity when registering adomain. This can be done by:1. Requiring that the contact email as verified through the ping back be associated with a domain name held by theorganization2. Requiring that the contact’s phone be associated with the phone numbers controlled by the organization3. Contacting the organization and confirming the contact’s authority4. Requiring that that the registrant contact information match the contact information1. Digicert: DigiCert creates a unique identifier for each r

StrikeIron Inc. Cary, North Carolina, USA Industry Leader in APIs and API Management offering email validation and telephone validation services in North America Email validation- Syntactical, operational Global address verification Phone Number Validation only for North America