Latest news of the domain name industry

Recent Posts

First dot-brand of the year self-terminates

It’s been almost 10 months since ICANN last received a demand from a dot-brand registry operator to terminate its contract, but 2026 has now had its first such request.

Networking gear maker Juniper Networks has asked for its .juniper gTLD to be deleted. No specific reason was given.

You might think that a dot-brand ducking out before we’ve had a chance to see what the current batch of applicants — applying during the current new gTLD application window that closes August 12 — could be seen as a harsh commentary on the dot-brand concept.

But that’s not quite the case here. Juniper got acquired by Hewlett Packard Enterprise last year and is being folded into the HPE brand, a transition that includes the move from juniper.net to hpe.com.

.juniper was never actively used. It was running on Identity Digital’s back-end.

Comment Tagged: , ,

The Tax Man to get domain takedown powers

The Tax Man is going to get powers to ask for domains to be taken down in the UK, according to local registry Nominet.

His Majesty’s Revenue and Customs is set to be added to Nominet’s list of approved law enforcement agencies under its Criminal Practices Policy, enabling it to ask for domains to be suspended if it suspects criminal behavior.

The policy is essentially a trusted notifier program where LEAs are given the benefit of the doubt when it comes to takedown requests. Nominet conducts some sanity checks and will give the registrant 48 hours notice before it suspends their name unless it thinks the name poses and imminent risk.

Nominet said that HMRC was being onboarded because it’s already getting similar legal powers under the recent UK Crime and Policing Act, which became law in April.

The law gives statutory takedown powers to a number of LEAs that were already entrusted by the Nominet self-regulatory policy, such as the Financial Conduct Authority and the Gambling Commission.

A Nominet spokesperson said the HMRC was being added to the list to advise on issues where “domains are being used for HMRC impersonation, phishing or other tax-related scams to the public”.

Comment Tagged: , , ,

Afnic: all your overseas territories are belong to us

French ccTLD registry Afnic has taken over management of three more ccTLDs assigned to France’s overseas territories, meaning it now looks after all eight such TLDs, according to the company.

Afnic is now running .gf (Guyana), .gp (Guadeloupe) and .mq (Martinique), in addition to the .pm (Saint-Pierre and Miquelon), .re (Réunion), .tf (French Southern and Antarctic Lands), .wf (Wallis and Futuna) and .yt (Mayotte) domains it has been managing for years.

After the technical transition, expected to conclude this year, Afnic’s policies will come into effect and some small rule changes will apply to .gf, .mq, and .gp.

First, no one or two-character new domain registrations will be allowed.

Second, no new third-level regs under zones such as .com.gp, .net.gp, and .org.gp will be permitted, though existing regs will be grandfathered.

The takeovers were ordered by government decree in June.

1 Comment Tagged: , , ,

.ru ready to crash as Draconian new rules come in

One of the world’s most-popular ccTLDs could be on the verge of losing a substantial number of domains after extremely strict eligibility requirements come in to force just weeks from now.

Registrants of new and existing .ru domains will need to prove their identity via a system administered by the Russian government from September 1 or risk losing their names.

In addition, only Russian-registered companies are authorized to act as registrars, on a list managed by government-selected non-profit entities. That rule came into effect in March.

Machine-translated, the law that was signed by President Putin last December states:

Domain names are registered in accordance with the domain name registration rules only after the person in whose name the domain name is registered has completed identification using the Unified Identification and Authentication System.

The identification system referred to here is also called Gosuslugi or ESIA. It’s the government-run program that enables Russian citizens to access government services online.

Signing up for Gosulgi requires government-issued documentation such as a passport or social security number. Foreigners resident in Russia are able to obtain documentation, but the process is much more complex.

In a recent interview, Coordination Center for TLD RU director Andrey Vorobyov said the move was designed to help prevent fraud and abuse in Russia-focused ccTLDs.

.ru is the 11th-largest TLD and the fifth-largest ccTLD after China, Germany, UK and (barely) the Netherlands, with 6,137,523
registered domains as of today. .РФ has 805,571 and .su (representing the former Soviet Union) has 110,369.

If .ru follows the trend set by other ccTLDs, it could be ready to fall off a cliff. When China’s CNNIC introduced similar rules in 2010, it lost millions of names.

While most Russians already have a Gosuslugi account, foreign-based .ru registrants could find themselves unable to sign up or decide they are unwilling to hand over their ID to the Russian government.

Some registrars, such as Com Laude, are looking into ways to get around the rules with local presence services.

Comment Tagged: ,

Google adds .here and .eat to launch roster

Google has added the long-dormant gTLDs .here and .eat to its 2026 launch timetable, synchronized with the previously announced launch of .fly.

The company has told ICANN that it plans to runs its sunrise periods alongside .fly’s from September 1 until November 9, with general availability following immediately November 10.

All three gTLDs are expected to be open, with no eligibility requirements.

Google has had control over these domains for well over a decade. It’s perhaps informative that the application for .here talks up the potential for location-based services pointing to “the success of FourSquare and Groupon”, two companies whose stars are substantially less bright 14 years later.

.eat will compete against the likes of Identity Digital’s .cafe (which has roughly 25,000 names in its zone today), Punto 2012’s .rest (97,000 names), and Internet Naming Co’s .food (23,000 names).

Comment Tagged: , , , , ,

“Bulletproof” registrar gets third ICANN bollocking

Trustname.com, a company that advertises itself as a privacy-devoted “bulletproof” registrar, is still refusing to suspend domain names used for phishing, malware, and payment card theft fast enough, according to ICANN.

The Org has sent its third notice of contract breach in five weeks and given Estonia-based Trustname, also known as Fewmoretaps, until August 6 to come back into compliance or lose its accreditation.

ICANN’s notice is focused on one domain this time, which it said was confirmed as hosting “phishing, payment‑card harvesting, and malicious client‑side code” about a week ago.

Trustname confirmed the domain, which Compliance did not name, as abusive on July 11, but it remained up until July 14 when the registrar correctly applied the clientHold suspension status after repeated nagging from ICANN, according to the notice.

“The actions the Registrar took were not prompt,” ICANN said, calling this a violation of Section 3.18.1 of the Registrar Accreditation Agreement.

Compliance first publicly reported Trustname’s alleged sins on June 10, accusing the company of dragging its feet and allowing abusive registrants to transfer their domains out rather than immediately suspending them.

Comment Tagged: , , , , , ,

Cybercrime link as t.me gets taken down

Speculation is rampant online right now after t.me, the domain used for short links by the messaging service Telegram, was apparently taken down by the .me registry, affecting as many as a billion users.

t.me seems to have gone dark shortly before 2000 UTC on Monday evening, with Whois/RDAP records showing it is now placed on serverHold status, which usually indicates a registry-level suspension and removal from the .me zone.

The suspension means that millions of short links using t.me are no longer functioning when clicked, leading instead to NXDOMAIN errors. Substituting t.me for telegram.me can be used as a workaround; the longer domain remains unsuspended.

.me is the ccTLD for Montenegro and is managed by local firm doMEn, which is mostly a partnership between US-based domain giants GoDaddy and Identity Digital.

Telegram and doMEn’s partners have yet to publicly address the outage, leading to a great deal of speculation online.

The most plausible explanation put forward so far but not yet confirmed is that the takedown relates to an order issued Monday by the US government’s Office of Foreign Assets Control, which has broad powers to sanction organizations and individuals it believes are linked to crime and terrorism.

OFAC, in an advisory that otherwise largely targets Cuban-linked entities, sanctioned domains and cryptocurrency wallets linked to First VPN Service (1VPNS), which it said was a Ukraine-based cybercrime group selling anonymity services to ransomware attackers and others.

OFAC said: “Numerous ransomware groups have purchased infrastructure from 1VPNS, which they have leveraged in attacks on U.S. companies and institutions—including to hide the origins of their attacks, deploy malware, and manage exfiltrated data.”

The July 13 order sanctioned three 1VPNS domain names — 1vpns.com, 1vpns.net, and 1vpns.org — that had in fact already been taken down by a Europol-led law enforcement operation in May.

But also on the list is the URL t.me/FirstVPNService. The equivalent telegram.me URL was not listed.

This has led to the suspicion that the t.me suspension is a classic case of government using a jurisdictional sledgehammer to crack an overseas nut — ordering doMEn’s US-based registry partners to take down the whole of t.me rather than asking Dubai-based Telegram to take down the specific offending URL or group.

Identity Digital, which holds the pen on .me domain edits, would have been powerless to resist an order from its own government.

While the takedown will doubtless be raised in ongoing policy discussions about when it is appropriate for a registry or registrar to suspend a domain over DNS abuse concerns, it’s less clear whether it will play into the Montenegro government’s nascent efforts to exert more local control over .me.

2 Comments Tagged: , , , , , , ,

ICANN rules could hamper agentic AI domain regs

Kevin Murphy, July 13, 2026, Domain Policy

Bulk registration of domain names is likely to become more difficult under policy proposals being considered in ICANN, potentially limiting the potential of agentic AI.

The Generic Names Supporting Organization is in the very early stages of a Policy Development Process that aims to “introduce friction” into bulk registration shopping carts for untrusted registrants.

The PDP was initially conceived last year as targeting API-based registrations, which are believed to be often used by Bad Guys to bulk-register domains for abusive purposes like malware and spam.

But the first version of the draft charter that will govern the PDP is now using “technology neutral” language, recognizing that APIs may not be as relevant in future. Bots and agentic AI are not directly mentioned, but it’s clearly what the authors have in mind.

The charter states:

This PDP would seek to introduce a requirement to put safeguards in place to ensure that registrants, particularly new or untrusted accounts, cannot immediately access domain name registrations at scale until they have demonstrated basic trustworthiness.

Quite how the limits would be put in place, what “at scale” means numerically, and how “trustworthiness” would be defined and earned, are all issues that would have to be hashed out by the PDP working group.

Whatever rules are created would be binding on all ICANN-accredited registrars and their resellers.

The PDP working group has yet to be created, and it seems the absolute earliest any agreed policy could be approved by ICANN would be the end of next year, with the rules coming into effect perhaps the following year.

The PDP is set to be the second of the Domain Abuse Mitigation efforts that began last year under pressure from governments and others and studies such as ICANN’s INFERMAL, which discovered that registrars with freely available APIs were far more likely to be abused by ne’er-do-wells.

2 Comments Tagged: , , , ,

A dot-brand walks into a bar

Kevin Murphy, July 7, 2026, Gossip

“He doesn’t need a VPN, his network works above the DNS. Do you know what the DNS is?”

When he said it, the 80-year-old barfly I found myself in a long conversation with at the weekend had no idea what I do for a living.

He was not a technical guy. Long-retired, his career had been in a completely different field. He was bragging about one of his high-flying relatives’ technical nous and impressive homeworking set-up.

The “above the DNS” stuff was how this set-up had been translated for him by another relative.

I told him I know a thing or two about DNS (two things!) and explained how it works and why what he just said didn’t make much sense to me. I told him about the root, Verisign, .com, ICANN, and so on.

“He doesn’t need any of that stuff,” he reiterated. “His network works above the DNS.”

About 10 minutes of head-scratching later, the penny finally dropped. Dude was talking about a dot-brand. Like working on a corporate network running a dot-brand was somehow escaping the DNS altogether.

As soon as I had that epiphany, and because I already knew what industry the relative worked in, and which country he came from, I was able to, from my knowledge of the root zone, correctly identify his employer.

I felt pretty smug about that, truth be told.

While a lot of dot-brands obtained in 2012 still remain dormant, some are in use, even if only or primarily internally, and it turns out some have their enthusiastic — proud, even — advocates in random bars at the ass-end of nowhere.

It’s only anecdotal evidence, but if even non-techie retirees in small-town ex-pat bars kinda know what dot-brands are and why they are useful, even if some of the technical details escape them, I wonder whether the concept is approaching mainstream.

1 Comment Tagged:

.dot is coming very soon

New new gTLD registry Dish DBS has revealed the launch dates for its .dot gTLD, and it’s coming pretty soon.

Information filed with ICANN shows that .dot is due to go to sunrise in just a couple weeks — from July 21 to October 19 — with a 12-day Early Access Period where early adopters can pay premium prices starting the next day.

General availability is scheduled for November 2. Pricing has not been revealed.

If you’re wondering about making a play for dot.dot, forget about it — the registry is using that as its primary domain for the gTLD.

The space will be open to all, with Dish describing it as “designed for builders and the things they create… products, communities, brands, or ideas worth a name of their own”.

It’s Dish’s second gTLD launch this year after .latino, which went GA on June 12.

.latino hasn’t exactly leapt out of the gates — it has fewer than 800 names in its zone file today and Google results are showing mainly a TLD-hopping movie piracy site and a Vietnamese gambling site.

1 Comment Tagged: , , , ,