Latest news of the domain name industry

Recent Posts

Freenom is back, but no longer free

Controversial domain registry Freenom has returned, barely two and a half years after Facebook owner Meta sued it into the ground in a massive cybersquatting lawsuit.

But the company seems to have abandoned the free domains business model it pioneered that led to spammers registering millions of abusive domains and huge reputational harm.

Freenom was — and appears to still be — the registry operator for .tk, the ccTLD for Tokelau. It also ran four African ccTLDs: Equatorial Guinea (.gq), Central African Republic (.cf), Mali (.ml), Gabon (.ga).

Today, its web site is offering domains in .tk, .cf and .gq for sale, with a starting price of €8.22 per year.

In 2023, Mali and Gabon moved their ccTLDs to away from Freenom, with .ga going to Afnic and .ml going in-house. It was reported that CAR and Equitorial Guinea had also severed ties, but that does not appear to be the case.

Freenom appears to be starting from scratch — while .tk at one point had over 40 million registered domains, today potentially high-value dictionary keywords are available again.

A DI reader confirmed that he was able to register a short, rather nice keyword .tk for the €8.22 base price earlier this week.

Many keyword domains I checked are also being offered without premium pricing, while others carry higher price tags. For example, football.tk is being offered for €86.08 and whiskey.tk is listed at €1,739.13, while vodka.tk carries the base price.

Domains such as facebooklogin.tk also appear to be available.

Freenom’s original business model saw it primarily give domains away for free, then seize them to monetize their traffic as they expired or, more commonly, were suspended for abuse.

Actually charging for domain names will certainly help reduce Freenom’s exposure to the kind of abuse that caused Meta to file a $500 million cybersquatting lawsuit against it in early 2023.

When Freenom settled the case a year later, it said it had “independently decided to exit the domain name business, including the operation of registries”. The move reportedly made a noticeable dent in the prevalence of cybercrime.

The company also lost its ICANN registrar accreditation, meaning it became unable to sell domains in gTLDs. It gTLD registrations were transferred to Gandi.

But now Freenom is back in the domain game, albeit seemingly with a different, more conventional business model.

First dot-brand of the year self-terminates

It’s been almost 10 months since ICANN last received a demand from a dot-brand registry operator to terminate its contract, but 2026 has now had its first such request.

Networking gear maker Juniper Networks has asked for its .juniper gTLD to be deleted. No specific reason was given.

You might think that a dot-brand ducking out before we’ve had a chance to see what the current batch of applicants — applying during the current new gTLD application window that closes August 12 — could be seen as a harsh commentary on the dot-brand concept.

But that’s not quite the case here. Juniper got acquired by Hewlett Packard Enterprise last year and is being folded into the HPE brand, a transition that includes the move from juniper.net to hpe.com.

.juniper was never actively used. It was running on Identity Digital’s back-end.

The Tax Man to get domain takedown powers

The Tax Man is going to get powers to ask for domains to be taken down in the UK, according to local registry Nominet.

His Majesty’s Revenue and Customs is set to be added to Nominet’s list of approved law enforcement agencies under its Criminal Practices Policy, enabling it to ask for domains to be suspended if it suspects criminal behavior.

The policy is essentially a trusted notifier program where LEAs are given the benefit of the doubt when it comes to takedown requests. Nominet conducts some sanity checks and will give the registrant 48 hours notice before it suspends their name unless it thinks the name poses and imminent risk.

Nominet said that HMRC was being onboarded because it’s already getting similar legal powers under the recent UK Crime and Policing Act, which became law in April.

The law gives statutory takedown powers to a number of LEAs that were already entrusted by the Nominet self-regulatory policy, such as the Financial Conduct Authority and the Gambling Commission.

A Nominet spokesperson said the HMRC was being added to the list to advise on issues where “domains are being used for HMRC impersonation, phishing or other tax-related scams to the public”.

Afnic: all your overseas territories are belong to us

French ccTLD registry Afnic has taken over management of three more ccTLDs assigned to France’s overseas territories, meaning it now looks after all eight such TLDs, according to the company.

Afnic is now running .gf (French Guiana), .gp (Guadeloupe) and .mq (Martinique), in addition to the .pm (Saint-Pierre and Miquelon), .re (Réunion), .tf (French Southern and Antarctic Lands), .wf (Wallis and Futuna) and .yt (Mayotte) domains it has been managing for years.

After the technical transition, expected to conclude this year, Afnic’s policies will come into effect and some small rule changes will apply to .gf, .mq, and .gp.

First, no one or two-character new domain registrations will be allowed.

Second, no new third-level regs under zones such as .com.gp, .net.gp, and .org.gp will be permitted, though existing regs will be grandfathered.

The takeovers were ordered by government decree in June.

.ru ready to crash as Draconian new rules come in

One of the world’s most-popular ccTLDs could be on the verge of losing a substantial number of domains after extremely strict eligibility requirements come in to force just weeks from now.

Registrants of new and existing .ru domains will need to prove their identity via a system administered by the Russian government from September 1 or risk losing their names.

In addition, only Russian-registered companies are authorized to act as registrars, on a list managed by government-selected non-profit entities. That rule came into effect in March.

Machine-translated, the law that was signed by President Putin last December states:

Domain names are registered in accordance with the domain name registration rules only after the person in whose name the domain name is registered has completed identification using the Unified Identification and Authentication System.

The identification system referred to here is also called Gosuslugi or ESIA. It’s the government-run program that enables Russian citizens to access government services online.

Signing up for Gosulgi requires government-issued documentation such as a passport or social security number. Foreigners resident in Russia are able to obtain documentation, but the process is much more complex.

In a recent interview, Coordination Center for TLD RU director Andrey Vorobyov said the move was designed to help prevent fraud and abuse in Russia-focused ccTLDs.

.ru is the 11th-largest TLD and the fifth-largest ccTLD after China, Germany, UK and (barely) the Netherlands, with 6,137,523
registered domains as of today. .РФ has 805,571 and .su (representing the former Soviet Union) has 110,369.

If .ru follows the trend set by other ccTLDs, it could be ready to fall off a cliff. When China’s CNNIC introduced similar rules in 2010, it lost millions of names.

While most Russians already have a Gosuslugi account, foreign-based .ru registrants could find themselves unable to sign up or decide they are unwilling to hand over their ID to the Russian government.

Some registrars, such as Com Laude, are looking into ways to get around the rules with local presence services.

Google adds .here and .eat to launch roster

Google has added the long-dormant gTLDs .here and .eat to its 2026 launch timetable, synchronized with the previously announced launch of .fly.

The company has told ICANN that it plans to runs its sunrise periods alongside .fly’s from September 1 until November 9, with general availability following immediately November 10.

All three gTLDs are expected to be open, with no eligibility requirements.

Google has had control over these domains for well over a decade. It’s perhaps informative that the application for .here talks up the potential for location-based services pointing to “the success of FourSquare and Groupon”, two companies whose stars are substantially less bright 14 years later.

.eat will compete against the likes of Identity Digital’s .cafe (which has roughly 25,000 names in its zone today), Punto 2012’s .rest (97,000 names), and Internet Naming Co’s .food (23,000 names).

Cybercrime link as t.me gets taken down

Speculation is rampant online right now after t.me, the domain used for short links by the messaging service Telegram, was apparently taken down by the .me registry, affecting as many as a billion users.

t.me seems to have gone dark shortly before 2000 UTC on Monday evening, with Whois/RDAP records showing it is now placed on serverHold status, which usually indicates a registry-level suspension and removal from the .me zone.

The suspension means that millions of short links using t.me are no longer functioning when clicked, leading instead to NXDOMAIN errors. Substituting t.me for telegram.me can be used as a workaround; the longer domain remains unsuspended.

.me is the ccTLD for Montenegro and is managed by local firm doMEn, which is mostly a partnership between US-based domain giants GoDaddy and Identity Digital.

Telegram and doMEn’s partners have yet to publicly address the outage, leading to a great deal of speculation online.

The most plausible explanation put forward so far but not yet confirmed is that the takedown relates to an order issued Monday by the US government’s Office of Foreign Assets Control, which has broad powers to sanction organizations and individuals it believes are linked to crime and terrorism.

OFAC, in an advisory that otherwise largely targets Cuban-linked entities, sanctioned domains and cryptocurrency wallets linked to First VPN Service (1VPNS), which it said was a Ukraine-based cybercrime group selling anonymity services to ransomware attackers and others.

OFAC said: “Numerous ransomware groups have purchased infrastructure from 1VPNS, which they have leveraged in attacks on U.S. companies and institutions—including to hide the origins of their attacks, deploy malware, and manage exfiltrated data.”

The July 13 order sanctioned three 1VPNS domain names — 1vpns.com, 1vpns.net, and 1vpns.org — that had in fact already been taken down by a Europol-led law enforcement operation in May.

But also on the list is the URL t.me/FirstVPNService. The equivalent telegram.me URL was not listed.

This has led to the suspicion that the t.me suspension is a classic case of government using a jurisdictional sledgehammer to crack an overseas nut — ordering doMEn’s US-based registry partners to take down the whole of t.me rather than asking Dubai-based Telegram to take down the specific offending URL or group.

Identity Digital, which holds the pen on .me domain edits, would have been powerless to resist an order from its own government.

While the takedown will doubtless be raised in ongoing policy discussions about when it is appropriate for a registry or registrar to suspend a domain over DNS abuse concerns, it’s less clear whether it will play into the Montenegro government’s nascent efforts to exert more local control over .me.

.dot is coming very soon

New new gTLD registry Dish DBS has revealed the launch dates for its .dot gTLD, and it’s coming pretty soon.

Information filed with ICANN shows that .dot is due to go to sunrise in just a couple weeks — from July 21 to October 19 — with a 12-day Early Access Period where early adopters can pay premium prices starting the next day.

General availability is scheduled for November 2. Pricing has not been revealed.

If you’re wondering about making a play for dot.dot, forget about it — the registry is using that as its primary domain for the gTLD.

The space will be open to all, with Dish describing it as “designed for builders and the things they create… products, communities, brands, or ideas worth a name of their own”.

It’s Dish’s second gTLD launch this year after .latino, which went GA on June 12.

.latino hasn’t exactly leapt out of the gates — it has fewer than 800 names in its zone file today and Google results are showing mainly a TLD-hopping movie piracy site and a Vietnamese gambling site.

Verisign will kill off 37 Kevins (and 22,000 others), complaint claims

Verisign’s plans to shut down a bunch of legacy services in the .name gTLD has been challenged by a registrant who believes he will lose his domains and email addresses if the registry goes ahead.

Doytchin Spiridonov, who works for Bulgarian registrar Dom.bg, has filed a Request for Reconsideration with ICANN, asking it to reverse its approval of Verisign’s Registry Service Evaluation Process requests that would enable it to turn off services that have been running for over 20 years.

As I reported in May, Verisign wants to stop selling third-level domains and related email services in .name, bringing the zone into line with virtually ever other gTLD, and delete existing names and emails in the process.

Spiridonov, who owns at least three third-level names, did the legwork on the .name zone file and discovered 22,288 domains would be affected. That includes 37 of my fellow Kevins!

His RfR (pdf) makes the case that ICANN’s approval of Verisign’s request was pretty opaque, involving private meetings between company and Org over several months.

“The approvals may adversely affect my ability to continue holding these registrations, may require migration to alternative services, may result in financial loss associated with prepaid registration periods, and may cause operational disruption and loss of continuity of internet identity associated with the affected registrations,” he wrote.

He further claims that Verisign misrepresented the impact of the changes in its RSEP, in which it stated that “There will not be any effect on the life cycle of domain names”.

Spiridonov says that the deletion of 22,000 domains makes this claim plainly untrue.

His RfR will be handled by ICANN’s board of directors.

Google names the dates for .fly launch

Google seems to have accelerated its launch plans for .fly, one of the 2012-round gTLDs it’s been sitting on for over a decade.

The company’s registry division has notified ICANN that it plans to open its mandatory sunrise period for .fly on September 1 and keep it open until November 9.

General availability for the gTLD, which according to its 2012 application will be open to all with no eligibility restrictions, seems to have been scheduled for November 10.

Earlier documentation filed with ICANN showed early 2027 launch dates.

The original application states that the namespace is intended for, as you might expect, airlines and the travel industry. As such, it would compete with the likes of .travel and .aero.

Google has already registered get.fly to itself, but the name does not yet appear to resolve.