DEFEND IP Act: the unified US site-blocking bill covers DNS but exempts VPNs — and lets operators buy their way out
On 24 September 2026 Representatives Zoe Lofgren and Ben Cline, with Senators Thom Tillis, Chris Coons, Marsha Blackburn and Adam Schiff, introduced the DEFEND IP Act of 2026 — the merged, bicameral successor to Lofgren’s FADPA and Tillis’s Block BEARD. It arrives ten days after Darrell Issa’s competing H.R. 10364, and unlike that bill, its text is public. Read against the draft it replaces, the details are more interesting than the announcement.
Two stages, one new section
The Act inserts §502A into the Copyright Act. A rightsholder or exclusive licensee first petitions a US district court to designate a foreign online location as a “foreign digital piracy site” — a public site operated from outside the US (or whose location cannot be determined) identifiable by IP addresses or domains. Designation lasts 360 days.
Then, in a second step, the petitioner asks the same court to direct named service providers to take “reasonable measures” to prevent US users from reaching it. Those orders run one year, renewable in one-year increments, and the court weighs burden on the provider, harm to the petitioner, technical feasibility, risk of interfering with lawful material, the public interest, and whether less burdensome means exist.
Who is in, and who is expressly out
“Service provider” means a broadband provider with at least 50,000 subscribers, or a provider of public domain name resolution services with annual revenue above $100 million — which is Google and Cloudflare, and not much else.
The exclusions are the story. The definition expressly does not include entities providing DNS resolution “exclusively through encrypted DNS protocols”, entities that “exclusively provide virtual private network services”, or premises operators such as coffee shops, libraries and universities. After Issa’s draft reached resolvers, after Paris ordered ProtonVPN, CyberGhost and ExpressVPN to block, and after Google told the European Commission that DNS and VPN blocking is “unbalanced and ineffective”, the drafters carved the most contested categories out of the statute rather than leaving them to judicial discretion.
The escape hatch nobody is talking about
Section (b)(5) is the most consequential paragraph for enforcement strategy. A court may not issue a designation — and may rescind an existing one — if the site’s operator appears within the 20-day window, submits to the court’s jurisdiction for all related claims, posts a bond sufficient to satisfy any judgment, and complies with any order to cease the activity.
In other words, blocking is the sanction for staying anonymous and offshore. An operator willing to identify itself, accept US jurisdiction and put up money cannot be blocked — it gets a normal lawsuit instead. That is a deliberate due-process design, and it also means the regime’s real target is the actor who cannot afford to be found.
Mirrors, and who carries the risk of error
For anyone fighting clone and mirror farms, subsection (g) matters: if a designated site “is accessible or has been reconstituted at a different domain name or Internet Protocol address, or has engaged in circumvention techniques that render the initial order ineffective”, the petitioner can move to amend the order. This is dynamic relief on the rightsholder’s motion, closer to the Belgian rolling-blocklist model than to a one-shot injunction.
The allocation of error risk is notably different from Issa’s draft. Orders may not prescribe specific technical measures. Providers have no duty to investigate whether the listed domains are accurate, may rely on the petitioner’s information, and are immune from liability — even where a site “was inaccurately identified in the order”. Instead, the petitioner must verify accuracy on an ongoing basis and update the court. But there is no compensation clause: where Issa’s framework offered wrongly blocked third parties up to $250,000 from the rightsholder, DEFEND IP gives them only the right to move to modify or rescind the order. Providers can recover direct compliance costs — not capital expenditure, overhead or legal fees.
Every order, amendment and rescission is reported to the Register of Copyrights and published on the Copyright Office website. §512 safe harbour is untouched.
What this means for you
For brand owners the practical reading is that US blocking is now a serious prospect with a defined shape. Two bills are live, four senators across both parties are behind this one, and two of the key sponsors — Tillis and Issa — leave at the end of this Congress, which concentrates minds. If §502A passes in this form, rightsholders gain a mirror-aware, court-supervised blocking remedy in the largest market, with published orders and no technical mandate for providers to fight over.
Two caveats worth holding onto. The bond-and-appear escape means well-funded infringers with lawyers will convert blocking petitions into ordinary litigation, so the tool works best against exactly the anonymous, offshore operators our work already targets. And the absence of a compensation clause shifts overblocking risk onto whoever gets caught by an inaccurate listing — if your business shares infrastructure or has domains resembling an infringer’s, monitoring the Copyright Office register becomes part of routine hygiene.
Counsel’s note. Most rightsholders will read this as permission to wait for a better tool. That is the wrong lesson from a bill that is one of two competing drafts, unscored, unmarked-up and facing the same coalition that killed SOPA. Note what the drafters themselves assumed: the regime only bites operators who will not appear, submit and post a bond — which is precisely the population that already ignores your notices. The working method does not change while Congress argues: map the actor, hit the host, the registrar, the CDN account and the payment rail, and build the evidence record that will make a §502A petition trivial to draft if the Act ever passes. We broke that sequence down in our guide to finding the real host behind Cloudflare.