Tackling scams together: insights from the Australian Internet Infrastructure Forum

Online scams do not sit neatly within one part of the internet. A scam can involve a domain name, website hosting, a digital platform, telecommunications services and payments – often moving quickly between them.

That creates a challenge: each organisation involved can see and act on only part of the scam lifecycle. Effective prevention and disruption therefore depends on the actions of individual organisations and how well they work together.

To explore how that coordination could be strengthened, auDA convened the inaugural Australian Internet Infrastructure Forum (IIF) in Sydney on 17 August 2026. The event brought together 29 participants from:

  • Government and law enforcement
  • The domain name, hosting and telecommunications sectors
  • Industry and consumer organisations
  • Civil society and academia
  • Along with auDA and .au registry operator Identity Digital.

Attendees exchanged perspectives and knowledge from their respective areas to together, helping build a shared picture of the problem and to identify practical opportunities for cooperation.

Looking across the scam lifecycle

The discussion reinforced that there is no single technical measure or organisation that can solve online scams.

As administrator of the .au domain, auDA has strong visibility of the domain name layer of the internet. But scams can cross many different infrastructure and service layers, each with different capabilities, information and limits.

Instead, a multifaceted response is needed, with action directed to the organisation best placed to intervene.

For example, a domain name registered specifically for malicious purposes may warrant action at the domain level. However, a legitimate website that has been compromised to host a phishing page may require a more targeted response elsewhere.

The aim is to address abuse at the most appropriate point rather than simply shifting responsibility between organisations.

Making the existing system work better

One of the clearest takeaways from the forum is that there are opportunities to improve existing systems and capabilities.

Participants discussed difficulties ensuring scam reports reach the right organisation with the information needed to act. Evidence and checks can also be lost as an issue moves between consumers, service providers, regulators and law enforcement.

A useful analogy raised during the forum was a hospital handover: when responsibility passes from one team to another, the relevant information should travel with it. Applying that thinking to scams could mean better ways to communicate what has already been checked, what remains uncertain and what action is being requested.

The forum also identified opportunities to improve understanding and adoption of tools and information sources that already exist. These included:

  • Domain Name System Security Extensions (DNSSEC) which helps ensure the integrity and authenticity of information transmitted over the internet
  • Domain-based Message Authentication, Reporting and Conformance (DMARC) for more secure and scam resistant emails
  • Registration data from domain name registries
  • Authoritative business information
  • Blocklists
  • Lookup tools (such as the .au WHOIS)
  • Providers’ own detection capabilities.

No single tool addresses every scam, but using the available set of tools effectively can strengthen prevention and disruption.

Balancing faster action with unintended impacts

Another important part of the discussion was risk.

Acting earlier and more broadly can prevent harm, but it can also increase the chance of disrupting legitimate websites, services or users. Participants considered how approaches such as verification, review, temporary measures, remediation and feedback could support faster intervention while managing false positives.

This reflects a broader challenge in tackling scams: technical capability to take action does not always mean an organisation has the evidence, authority or expertise to determine whether that action is appropriate.

Continuing the conversation

The inaugural Australian IIF was a first step strengthening scam prevention and mitigation across organisational and technical boundaries, while complementing work already underway through government, law enforcement and industry initiatives.

Following the Australian IIF, auDA is exploring practical follow-up on existing tools and capabilities, reporting and evidence handovers, risk and false positives, and shared Australian insights with the Global IIF (the group developing technical solutions to respond to scams). auDA plans to reconvene the Australian IIF in early-mid 2027.

For auDA, this work complements our ongoing efforts to keep .au secure and trusted and combat scams and DNS abuse, while recognising that scams extend well beyond any single domain name or layer of the internet.

Tackling them effectively requires coordinated action across the ecosystem. That cross-sector collaboration is central to building more secure, trusted online experience for Australians.

Join more than 6,714 members and help us shape the .au

Join now