Domain Trustee Service: Register restricted ccTLDs
Some of your best markets will not let you register a domain. No local address, no ccTLD. A Trustee Service is how you get in without opening a company.
Published by
Simone Catania
Date
A country-code domain can be the fastest route into a new market, or a locked door. When the registry demands a local address or a local company you do not have, a Trustee Service is usually how you get in.
That single problem lands on three desks at once. Legal wants to know who holds title and what happens in a dispute. IT needs to understand the renewal and continuity dependencies. Digital and market-expansion teams want speed without creating a hidden liability. This guide covers all three, starting with the question that tends to stall the decision: if the trustee’s details sit in the registration record, who owns the domain?
What a domain Trustee Service is
A domain Trustee Service is a local intermediary that satisfies a registry’s local presence requirement, so you can register a country-code domain you would otherwise be ineligible for. The trustee supplies the local address or legal entity the registry insists on. You remain the party that controls and benefits from the domain.
Two confusions are worth clearing up first, because both are common. A domain trustee has nothing to do with the financial or estate-planning kind of trustee. That trustee manages assets for a beneficiary under a trust. A domain trustee exists for one purpose, which is to meet a registry’s eligibility rules.
Nor is it WHOIS privacy. A privacy service hides your contact details in public lookups but does nothing to make you eligible. If a registry requires a local presence, privacy leaves you locked out. The two are not alternatives: one conceals data you are already entitled to hold, the other supplies data you are missing.
Why registries require a local presence
A local presence requirement is a registry policy that ties a ccTLD to its country by demanding that the registrant have some form of local connection. Registries impose these rules deliberately: to keep registrants legally reachable inside the national jurisdiction, to keep domains within reach of tax and consumer-protection law, and to protect the meaning of the national namespace. A .br or a .it is supposed to signal a real connection to that country.
One point trips up enterprise teams regularly. ICANN accreditation does not govern ccTLD eligibility. ICANN’s policy framework applies to generic TLDs. Country-code TLDs are run by national registry operators who set their own rules independently, so your registrar being ICANN-accredited says nothing about whether you can register a given ccTLD. The registry’s own published policy is the only source of truth.
What registries ask for varies, and the type of requirement decides whether a Trustee Service is enough. There are three bands:
- No local requirement. Anyone can register. Most gTLDs and many open ccTLDs.
- Local address or authorised contact. A trustee or local agent satisfies the rule.
- Registered in-country legal entity. Only a real local company qualifies, sometimes with a local tax or business identifier. A trustee providing an address is not enough.
Who owns a domain held under a Trustee Service
Here is the answer legal counsel is looking for. When the arrangement is documented in a written trustee agreement, you are the beneficial owner of the domain, not the trustee. The trustee holds a local role on paper to satisfy the registry. Economic and legal ownership stays with you.
That answer depends entirely on the agreement behind it, so it is worth being precise about what happens.
Two models, set by the registry. A trustee can appear either as the registrant of record, with its name in the registrant field, or as an administrative or authorised local contact, with you remaining the registrant. The second carries less risk on its face, but the first is often unavoidable, because many registries insist the registrant itself be local. This is not a preference you get to exercise. It also has a practical consequence: where the trustee has to be recorded as the holder, changing to another trustee contact later counts as a registrant change, and some registries bill it as one.
What the public record shows. Under GDPR and data minimisation, public lookups expose far less personal data than they once did. Where data is shown, the trustee’s local details may appear as registrant or contact. That is expected and correct. What WHOIS and RDAP never show is the trustee agreement establishing you as beneficial owner. The public record satisfies the registry, and the contract protects you.
What the agreement must contain. Three obligations do the real work:
- the trustee transfers or releases the domain on your instruction, unconditionally;
- the trustee may not use, sell, encumber or assert any claim over the domain;
- the trustee forwards any legal or official correspondence it receives to you, within a defined timeframe.
Get those in writing and the trustee is a nominal holder, nothing more. The danger is never the trustee model itself. It is an undocumented arrangement where a third party is listed as registrant with no contract binding them. For any enterprise domain, treat the absence of a binding agreement as a dealbreaker.
Which ccTLDs require a Trustee Service
Readers usually arrive wanting a list, so here is a cross-section by world region. Two caveats apply. Registries revise these rules, so verify against live policy before you commit a market-launch timeline. And the requirement type matters more than the extension, because it determines whether a trustee is a solution or a dead end.
| Region | ccTLD | Requirement type | What the registry requires |
|---|---|---|---|
| Europe | .de | None at registration | German recipient for service of documents, on DENIC request |
| Europe | .eu | Nexus | EU or EEA citizenship, residence, or establishment |
| Europe | .hu | Local address or contact | Local agent for foreign registrants |
| Europe | .rs | Local address or contact | Serbian presence |
| Europe | .ee | Local address or contact | Local administrator |
| Europe | .ba | Local address or contact | Bosnian presence |
| Europe | .it | Nexus | Registrant based in the EU or EEA |
| Europe | .no | Entity-level | Organisation registered in Norway, or Norwegian resident |
| Europe | .ru | Identity verification | No local presence, but from 1 September 2026 the domain administrator must be identity-verified through Russia's state ESIA (Gosuslugi) system |
| Asia-Pacific | .jp | Local address or contact | Japanese presence, with stricter rules for organisational tiers |
| Asia-Pacific | .kr | Local address or contact | Korean presence for most registration types |
| Asia-Pacific | .sg | Entity-level | Local company or qualifying local agent |
| Asia-Pacific | .my | Entity-level for commercial use | Malaysian presence |
| Asia-Pacific | .id | Local address or contact | Indonesian presence, documentation varies |
| Asia-Pacific | .au | Nexus | Australian presence plus a connection to the name itself |
| Asia-Pacific | .cn | Entity-level and verification | Local entity for most uses, plus identity verification |
| Americas | .br | Entity-level | Brazilian entity or individual with a local tax ID |
| Americas | .ar | Local address or contact | Argentine presence |
| Americas | .py | Local address or contact | Paraguayan presence |
| Americas | .ca | Nexus | Canadian Presence Requirements must be met |
| Americas | .us | Nexus | A qualifying US connection |
| Africa and Middle East | .ma | Local address or contact | Moroccan presence for some registration types |
The .de case: a requirement that surfaces later, not at registration
There is a persistent myth that you need a trustee, or a German address, to hold a .de domain. You do not, and as a German registrar and DENIC member we can be precise about why.
You can own a .de domain from anywhere in the world. What § 3 (4) of the DENIC domain conditions requires is narrower and conditional. If the domain holder is not based in Germany, then on request from DENIC the holder has two weeks to name a Germany-based recipient for the service of documents, a Zustellungsbevollmächtigter. That party holds the powers of an authorised recipient under § 184 of the German Code of Civil Procedure. A name and a street address are required, and a PO box does not satisfy the rule.
The distinction matters operationally. This is not a box to tick at registration. It is a latent obligation that activates when a third party wants to serve legal documents on you, which is the worst possible moment to discover it.
DENIC also used to require an administrative contact, the Admin-C, who effectively had to be reachable in Germany. That role was abolished in 2018 as a consequence of the GDPR, and the authorised-recipient mechanism replaced the function it had served for foreign holders.
The mechanism has been tested in court. In January 2025 the Landgericht Düsseldorf (Az. 38 O 162/24) confirmed that serving a claim on a recipient named under § 3 (4) validly reaches a domain holder based abroad. It is not a formality.
In trustee terms, this sits closer to the local-contact model than to trustee-as-registrant. You remain the registrant and owner of your .de domain, and you are satisfying a reachability rule rather than an eligibility rule. Treating .de as needing a full trustee arrangement is usually both inaccurate and more expensive than necessary, though the service exists for holders who cannot produce a German recipient when asked.
A Trustee Service is a recurring annual fee, charged per domain, on top of the domain’s own registration fee. It is not folded into the registration price and it is not a one-time setup charge. You pay for the domain, and you pay separately to keep it eligible.
The fee varies by extension because the local obligation varies. Where the trustee provides an address, the cost is modest. Where the local role carries more legal weight, it rises. There is no single trustee price.
The continuity risk is the part IT owners need to plan for. The service is tied to the domain’s ongoing eligibility, so it renews alongside the domain. If it expires, the domain can fall out of eligibility and the registry may suspend or delete it. An expired trustee arrangement can take a live domain out of compliance without any visible warning, and with it your website, your email and any certificates anchored to that name.
Transfers, disputes and legal notices
A trustee-held domain behaves like any other domain in most respects. Three governance points differ.
Transfers. You can transfer a trustee-held domain, but the trustee arrangement is part of its eligibility, so it either travels with the domain or has to be re-established at the destination. Confirm how coverage will continue before you initiate. A clean transfer that lands the domain at a registrar with no trustee coverage breaks eligibility on arrival.
Disputes. In a UDRP or ADR case, the party with the real interest in the domain, the beneficial owner, is the real respondent rather than the nominal trustee. Your agreement should reflect that, so a complaint is handled by, and any decision binds, the actual owner. For a practitioner’s view of how these cases run, our interview on the UDRP with WIPO’s Charlotte Spencer is a useful companion read.
Legal notices. The trustee or authorised recipient receives them, which is the point of the local role. The obligation to lock down is prompt forwarding, with a specified timeframe. A served document that never reaches you can produce a default judgment or a lost dispute.
On the data side, two things are worth stating plainly. GDPR is why the trustee’s details rather than yours may be what the public sees. And the reachability logic behind rules such as NIS2 is served, not undermined, by having a documented local recipient. Neither framework conflicts with a trustee arrangement, provided the arrangement is documented and the data flows are clear.
How to choose a provider
The gaps between Trustee Services are the gaps that cause problems later. Five criteria separate them:
- The written agreement. Read it. It must establish you as beneficial owner, grant unconditional transfer or release rights, bar the trustee from using the domain, and require prompt forwarding of legal notices.
- Breadth of covered TLDs. A provider covering only a handful of extensions forces you to fragment governance across vendors.
- Transparent per-TLD pricing. You should see the fee per extension, not discover it at checkout.
- Handling of legal notices. Ask how they are forwarded and how quickly.
- A documented exit process. The provider should make leaving straightforward rather than obstruct it.
- Automation. Provisioning and renewing Trustee Services by hand across dozens of restricted TLDs does not scale. Platform and API access lets you manage trustee coverage in the same workflow as the rest of the portfolio, which for any real portfolio is not a nice-to-have.
Trustee Service or local legal entity?
The choice comes down to what the registry requires and which internal pressure dominates.
A Trustee Service fits when you need speed and cannot wait to stand up a company, when the registration is single-market or defensive so a full local entity would be disproportionate, and when the registry’s requirement is an address or a local contact.
A local legal entity fits when you have durable operations in the country, when you need permanence and unmediated control, and when the registry accepts nothing less than a registered in-country entity. It solves eligibility completely, but it is slow, expensive and carries ongoing corporate, tax and filing obligations.
A Trustee Service is a legitimate, registry-recognised mechanism when properly documented. The risk lies in the paperwork, not the model. Never accept an arrangement where a third party is the registrant without a binding agreement making you the beneficial owner with an unconditional right to take the domain back. Get that right and a Trustee Service is what it should be: a controlled way into markets that would otherwise stay closed.
Register ccTLDs with the Trustee Service
Restricted ccTLDs are often the markets where a brand is least protected, because registering there looks harder than it is. InterNetX offers one of the largest TLD portfolios on the market, with ccTLDs across every world region, and our Trustee Service covers the extensions that would otherwise require a local company. Register the ccTLDs your expansion plan needs, keep them in one place, and manage eligibility, renewals and DNS from a single EU-based platform.
Frequently asked questions
A domain Trustee Service provides a local address or entity in a country whose registry requires one, allowing a foreign registrant to hold a ccTLD there. The trustee satisfies the registry’s eligibility rule while you keep control of the domain and remain its beneficial owner under a written agreement.
Yes, provided there is a written trustee agreement. The trustee may appear in the registration record to satisfy the registry, but the agreement establishes you as beneficial owner and obliges the trustee to transfer or release the domain on your instruction. Without that agreement, ownership is not protected.
Where data is displayed, the trustee’s local details may appear as registrant or contact, depending on the registry’s model. Public lookups show far less personal data than they once did under GDPR, and they never show the private trustee agreement that establishes your beneficial ownership.
Usually not. There is no local presence requirement to register or hold a .de domain. If you are based outside Germany, DENIC can require you to name a Germany-based recipient for the service of documents within two weeks of being asked, and a Trustee Service can cover that if you cannot supply one.
It is a recurring annual fee per domain, charged on top of the registration fee, and it varies by extension according to how much the local obligation involves. It has to be renewed for as long as you need the local presence, because the domain’s eligibility depends on it.
A country-code extension is read as a signal of local relevance by both search engines and users, which is one reason restricted markets are worth entering properly rather than skipping.