Legal escrow, explained simply.
The moment a case is confirmed malicious or phishing, OpenShield automatically sends a formal legal notice — backed by verifiable header evidence — to the domain's owner, registrar, and host, and gives them a fair window to act voluntarily. That window is longer for large, well-lawyered providers and shorter for known bulletproof hosts.
A public, uncapped escrow pot opens immediately, alongside a job board where verified local law firms can bid to take the case. The lowest qualified bid is automatically awarded the moment the pot can cover it — no committee, no delay.
Money only ever moves on proof. The retained firm is paid the exact amount on their invoice only after they submit a court order, a registrar suspension notice, or another verifiable proof of enforcement. OpenShield keeps a small platform fee (2%) on a successful payout only — never upfront, never on a failed case.
If the provider complies voluntarily before a firm is ever retained, or if money is left over after a payout, the balance rolls forward into the next worst offender's pot — nothing is wasted, and the pressure keeps building.
Once a domain is taken down, we keep watching it — every 12 hours — until the registrar's own records show the registration has lapsed, so a spammer can't just wait us out and quietly turn it back on.