Bali to apply for .bali, and the dot is delightful
The regional government of the Indonesian province of Bali is to formally announce an application for the .bali top-level domain at ICANN 87 in October, according to a local report.
Governor Wayan Koster said the local government is supporting a bid for .bali, according to IndoBaliNews
It’s not clear from the report whether the government is the applicant or merely signing off on an application by a third party, which is a necessity under ICANN’s rules regarding geographic strings.
What makes the proposal for .bali uniquely interesting — delightful, even — is that the dot also has meaning.
The Balinese word “dot” means “want”, so it’s not too much of a stretch to interpret .bali as “I want Bali”. The marketing is built-in.
This is handy given that tourism apparently accounts for 80% of Bali’s economy.
According to DI Stringtel, the only significant wrinkle to the application would be that Bali is also the name of a small town in Rajasthan, India, which also enjoys geographic protection.
.bali is only the third geographic gTLD to be announced that I’m aware of. The other two were .india and .bharat, both of which were announced by the Indian national registry, NIXI.
As I reported last year, the two Indian bids would likely be rejected because there’s a hard ban on country names under ICANN’s rules.
Bali will host ICANN’s Annual General Meeting in October, following the postponement of the Oman meeting.
ICANN board seat up for grabs
ICANN’s Country Code Names Supporting Organization has put out a call for nominations for candidates to potentially replace one of its current directors on the ICANN board next year.
It’s the seat currently held by Byron Holland of .ca registry CIRA. His first term on the board is up at next year’s AGM — the ccNSO starts its election process well in advance — and he’s eligible to be nominated again for another term.
The only people not eligible are those hailing from the Latin America and Caribbean region. That’s because the ccNSO has geographical diversity rules and its other director, Patricio Poblete, is from Chile.
Nominations must be submitted before the end of August 13, with voting taking place in November. A formal appointment will be made before the end of April 30 next year, with the successful candidate taking their seat at the end of the ICANN 90 public meeting in early November 2027.
Only representatives of ccTLD managers that are members of the ccNSO may be nominated. Further details have been published here.
Ireland’s .ie formally changes hands
IE Domain Registry has formally taken the reins at .ie after a decision by ICANN’s board of directors.
The board voted last week to redelegate Ireland’s ccTLD to the company that has in effect been in control of it since the turn of the century.
From the late 1980s, .ie was formally delegated to University College Dublin, which started subcontracting its management to IEDR in 2000.
The redelegation by IANA, now formally approved by ICANN, appears to be a formality, with ICANN saying no significant concerns raised by the university or local internet community.
.web could be a huge payday for Verisign
.web entered the root zone this week, ending over a quarter-century of drama over the once-coveted gTLD, and now it looks like it could be immediately worth tens of millions to its new registry.
Verisign got it, of course, seemingly by paying off the company, Altanovo Domains, that has been doggedly pursuing it through ICANN’s quasi-judicial complaints procedures for the last decade.
The company said in a statement: “The delegation of .web follows the successful resolution of all previous disputes related to the generic top-level domain (gTLD), the details of which are confidential.”
Now it seems Verisign is going to use its newfound freedom — the .web registry is not subject to the same feature and pricing controls as .com — to milk it for all it’s worth.
The company told analysts last night that it’s going to launch .web later this year with its mandatory sunrise period for trademark holders, followed by a Limited Registration Period for existing .com registrants.
CEO Jim Bidzos said: “We intend to run an LRP, and the rules that we will use is we will give all of our holders of .com registrations, the opportunity to come and get the same registration in .web before we open registrations for general availability.”
That could be incredibly lucrative. If, say, Verisign charges about $15 per domain per year, and about 1% of .com domains have their matching .web names registered, you’re looking at about $25 million a year of high-margin revenue added to the top line immediately.
I’m plucking those numbers out of thin air, of course. Verisign has not revealed its pricing for .web, and there’s no way of telling how for sure many .com owners will want to defensively register .web equivalents for, as Bidzos put it, “a companion website”.
The fact that .net has been stagnant for over a decade may prove informative — registrants’ mindset of “must get the matching .net and .org”, which was prevalent in the pre-2012 world, is not standard when hundreds of other gTLDs are available.
Verisign also revealed that some .web domains will carry premium prices, which could also prove to be a windfall, particularly if the premium fees carry over into renewal pricing, which the company is now able to do.
Verisign obtained the rights to .web in 2016 when it secretly bankrolled a company called Nu Dot Co, which had applied for the gTLD, in an ICANN-managed auction that saw a $135 million winning bid.
The clandestine nature of the proxy bidding was a huge source of controversy, and the runner-up bidder, Altanovo (then part of Afilias, spun out as an indie after Identity Digital acquired it) started filing ICANN complaints not long after.
While published ICANN documentation does not yet reflect it, it looks like Altanovo has yanked its Independent Review Process complaint against Verisign, with Verisign’s statement strongly suggest it was paid to do so.
I suspect Verisign was eager to bring .web to market to get some form of mind-share advantage before the gTLDs currently being applied for in the 2026 round start to come to market in a couple years. For Altanovo, patience may have meant profit.
Many in the industry, myself included, assumed a decade ago that Verisign’s primary goal in obtaining .web was defensive — it wanted to keep what it saw as .com’s strongest competitor out of the hands of its rivals and would probably just leave it dormant.
That may or may not have been true at the time, but based on current evidence it looks like that’s no longer the plan, if it ever was. Verisign’s talking about a launch before the end of the year.
“Bulletproof” registrar gets third ICANN bollocking
Trustname.com, a company that advertises itself as a privacy-devoted “bulletproof” registrar, is still refusing to suspend domain names used for phishing, malware, and payment card theft fast enough, according to ICANN.
The Org has sent its third notice of contract breach in five weeks and given Estonia-based Trustname, also known as Fewmoretaps, until August 6 to come back into compliance or lose its accreditation.
ICANN’s notice is focused on one domain this time, which it said was confirmed as hosting “phishing, payment‑card harvesting, and malicious client‑side code” about a week ago.
Trustname confirmed the domain, which Compliance did not name, as abusive on July 11, but it remained up until July 14 when the registrar correctly applied the clientHold suspension status after repeated nagging from ICANN, according to the notice.
“The actions the Registrar took were not prompt,” ICANN said, calling this a violation of Section 3.18.1 of the Registrar Accreditation Agreement.
Compliance first publicly reported Trustname’s alleged sins on June 10, accusing the company of dragging its feet and allowing abusive registrants to transfer their domains out rather than immediately suspending them.
ICANN rules could hamper agentic AI domain regs
Bulk registration of domain names is likely to become more difficult under policy proposals being considered in ICANN, potentially limiting the potential of agentic AI.
The Generic Names Supporting Organization is in the very early stages of a Policy Development Process that aims to “introduce friction” into bulk registration shopping carts for untrusted registrants.
The PDP was initially conceived last year as targeting API-based registrations, which are believed to be often used by Bad Guys to bulk-register domains for abusive purposes like malware and spam.
But the first version of the draft charter that will govern the PDP is now using “technology neutral” language, recognizing that APIs may not be as relevant in future. Bots and agentic AI are not directly mentioned, but it’s clearly what the authors have in mind.
The charter states:
This PDP would seek to introduce a requirement to put safeguards in place to ensure that registrants, particularly new or untrusted accounts, cannot immediately access domain name registrations at scale until they have demonstrated basic trustworthiness.
Quite how the limits would be put in place, what “at scale” means numerically, and how “trustworthiness” would be defined and earned, are all issues that would have to be hashed out by the PDP working group.
Whatever rules are created would be binding on all ICANN-accredited registrars and their resellers.
The PDP working group has yet to be created, and it seems the absolute earliest any agreed policy could be approved by ICANN would be the end of next year, with the rules coming into effect perhaps the following year.
The PDP is set to be the second of the Domain Abuse Mitigation efforts that began last year under pressure from governments and others and studies such as ICANN’s INFERMAL, which discovered that registrars with freely available APIs were far more likely to be abused by ne’er-do-wells.
Google names the dates for .fly launch
Google seems to have accelerated its launch plans for .fly, one of the 2012-round gTLDs it’s been sitting on for over a decade.
The company’s registry division has notified ICANN that it plans to open its mandatory sunrise period for .fly on September 1 and keep it open until November 9.
General availability for the gTLD, which according to its 2012 application will be open to all with no eligibility restrictions, seems to have been scheduled for November 10.
Earlier documentation filed with ICANN showed early 2027 launch dates.
The original application states that the namespace is intended for, as you might expect, airlines and the travel industry. As such, it would compete with the likes of .travel and .aero.
Google has already registered get.fly to itself, but the name does not yet appear to resolve.
Harassment down, bitchiness up at ICANN
ICANN’s Ombuds dealt with 50% more cases in its last-reported year, with most of the growth attributable to community members who just can’t seem to get along.
In a recently published annual report (pdf), covering the period to the end of June 2025 (yes, it really is published a whole year after the fact), the Ombuds said that it opened 248 tickets in the year.
But 212 of those — basically the same as the previous year — were ruled “out of scope”, perhaps because they were requests for information or help rather that outright complaints.
The remaining 36, up from 24 in the prior year, were ruled “in-scope”. Eight of those cases were complaints.
The Ombuds splits cases into two buckets — “unfairness” and “interpersonal and relational”. Unfairness cases were flat at 16, but down as a percentage from 67% to 44% due to the interpersonal category growing from seven cases to 20.
The interpersonal bucket refers to how community members interact in their working groups and such. It covers harassment, conflict, uncivil language and behavior.
Combined, cases concerning these behaviors accounted for 56% of the total, but the Ombuds reported that only two of those were at the level of claims of harassment.
A free, ethical new gTLD? Shurely shome mishtake
Another new gTLD applicant has revealed its plans, this time for a namespace where domains are given away for free and the enemy is Big Tech.
The Human-Centered Computing Foundation, a non-profit founded in Colorado last November, says it plans to apply for .self in the current ongoing ICANN application round.
It says it has already been approved under ICANN’s Applicant Support Program, meaning its application costs will be deeply discounted from the $227,000 standard base fee.
The organization has published little information about its plans, other than to say .self will be “designed and implemented from the ground up to support self-hosting”.
HCCF says it opposes the “prevailing economic models of the digital age — surveillance capitalism and entrapping SaaS platforms” that “prioritize corporate shareholder value over the fundamental needs, privacy, and autonomy of the individual.”
Because the domains will be free, domain investors are not welcome.
The organization’s web site lists Riley O’Donnell and Lucas Silva as CEO and COO respectively.
A search on DI’s Stringtel tool show domains ending in “self” occur about as frequently as existing gTLDs “contractors”, “bike” and “tattoo”, with “yourself” and “myself” counting for about half of the volume.
“Bulletproof” registrar gets an ICANN bollocking
ICANN has slapped an intensely privacy-focused registrar that compares its stance on takedowns to Elon Musks with a lengthy breach-of-contract notice, claiming that the company is disregarding legitimate abuse reports for no good reason.
Estonia-based Fewmoretaps, which changed its brand to Trustname.com not long after its accreditation was approved in early 2024, has been friendly to malware distributors that use its services, according to ICANN.
The breach notice claims that Trustname, after it had discovered that an abuse report was valid and that one of its customers’ domains was being used to spread malware, did not suspend the domain as required.
Rather, it gave the registrant a three-day headsup to move their domain to another registrar, according to ICANN.
It additionally ignored multiple abuse reports, often for spurious reasons, the notice claims, often only taking action on abusive domains after ICANN Compliance itself got it touch.
Trustname says it is a “registrar built for businesses in competitive niches that often face false or bad-faith abuse reports” and makes hay out of the fact that it offers “bulletproof” privacy by masking registrants details behind two different proxy services located in different jurisdictions.
While the company’s web site claims ad nauseam that its services are not to be used for illegal purposes such as child abuse material and opioid sales, it boldly states that it “disregards” copyright infringement notices.
“Like Elon Musk, we have a strong aversion to individuals who exploit the DMCA, as we believe it lacks legal authority for the vast majority of the world’s population,” the site states.
IP matters are not covered by ICANN contracts, which defined abuse as malware, pharming, phishing and a subset of spam, of course.
Trustname’s site states that it will only take action against domains in “extreme scenarios”.
Such scenarios include “using your website to host illegal content (that we have confirmed after thorough investigations) and getting court orders from all three jurisdictions.”
The three jurisdictions are the US and Saint Kitts & Nevis, where its proxy partners are located, and its home nation of Estonia. Saint Kitts-based Harakiri (Perfect Privacy LLC) was specifically chosen because court orders are hard to come by there.
The company additionally states, in what could be interpreted as an admission of guilt by ICANN Compliance standards:
We will never take any action against a domain name simply because someone filed a complaint – even if your report indicates a violation of our terms. We will only be obligated to take action when we get the relevant court orders.
Trustname, which had fewer than 1,500 gTLD domains under management at the last count, has been given until July 1 to come back into compliance or risk losing its accreditation.






Recent Comments