News3 hours ago

ICANN Approved Deleting 22,288 Domains and Its Own Rules Barred It From Asking Who Lived There

Verisign asked to switch off third-level .name domains, ICANN approved it in 22 days, and roughly 22,288 registrations die around February 2027. We read the approval letter, and the review process is structurally incapable of considering the registrants.

The WJS Desk

Sep 5, 2026 · 6 min read

Photo by wal_ 172619 on Pexels

On 3 September a post titled ".name Termination" hit the Hacker News front page and stayed there, collecting 1,970 points and 486 comments. The author, Neil Fraser, has used neil.fraser.name for close to 25 years. In his words it "has been the home of this website, my email address, and a server for APIs." Around February 2027 it stops resolving.

The reason is not an expiry, a payment failure or a policy breach. Verisign, which operates the .name registry, asked ICANN for permission to switch off third-level registrations entirely. ICANN said yes on 7 May 2026, 22 days after the request landed. We went and read the approval letter rather than the coverage, because the interesting part is not that this happened. It is that the process worked exactly as written.

What actually shipped, and it is a letter

The primary document is a three-page PDF dated 28 July 2026, from Amanda Fessenden, ICANN's Vice President for GDD Accounts and Services, to Patrick S. Kane, Senior Vice President of Naming Services at Verisign. It carries RSEP ID #01581614.

The timeline it records:

  • 15 April 2026: Verisign submits a Registry Services Evaluation Policy (RSEP) request to discontinue third-level .name registrations.
  • 7 May 2026: ICANN approves it.
  • 8 May 2026: The approval is posted to ICANN's RSEP Process webpage.
  • 28 July 2026: ICANN issues this letter as public notice, in lieu of a contract amendment, because the .NAME Registry Agreement is up for renewal.

The mechanism is blunt. Per the letter, "Extensible Provisioning Protocol (“EPP”) transactions will no longer accept any new registrations at the third level for the .NAME gTLD and existing third-level domain name registrations will be deleted."

Verisign's stated reasons: "limited registrar support of the service and declining usage of third-level domains," noting "that, while there are approximately 22,000 third-level domain registrations, the majority of those domains are not in use." It also told ICANN the change "will increase efficiency for the operation of the .name TLD."

The number is bigger than Verisign's number

Verisign said "approximately 22,000." Doytchin Spiridonov, who works for the Bulgarian registrar Dom.bg and holds at least three third-level .name domains himself, pulled the .name zone file and counted. His figure is 22,288. He also counted 37 of them belonging to people named Kevin, which is the detail that makes the abstraction land.

Spiridonov filed Reconsideration Request 26-2 on 2 June 2026, arguing the change "may adversely affect my ability to continue holding these registrations, may require migration to alternative services, may result in financial loss associated with prepaid registration periods." ICANN's own letter acknowledges the pending request. Reporting on the filing describes it as on track to be denied.

His sharpest point is about a single form answer. Verisign's RSEP submission was asked what effect the proposed service would have on the life cycle of domain names, and answered: "None. There will not be any effect on the life cycle of domain names." The proposed service is the deletion of 22,288 domains.

The notice schedule does not reach you. The letter commits Verisign to give registrars a minimum of 90 days notice, a 30-day reminder, and customer service support throughout. Registrars, not registrants. Footnote 1 handles the rest: "With regard to communications with registrants, registrars manage the registrar-registrant relationship(s)." Whether Fraser hears about this from anyone other than Hacker News is between him and his registrar.

The part that is nobody's fault, which is worse

It is tempting to read this as ICANN rubber-stamping a lucrative cleanup. The letter argues against that reading, and it does so in its own words.

Under the RSEP, an ICANN Consensus Policy, a registry operator "at any time may decide to change the architecture or operation of an existing TLD registry service or introduce a new TLD registry service." ICANN's evaluation is then limited to assessing whether the change "(i) could raise significant Security or Stability issues or (ii) could raise significant competition issues." Security or stability findings go to the Registry Services Technical Evaluation Panel. Competition findings go to government competition authorities.

And then the letter says the quiet part out loud:

"ICANN's evaluation of a request pursuant to the RSEP is limited by the language of the RSEP and does not extend to other potential impacts of the proposed implementation of a new registry service or proposed discontinuation of an existing registry service."

There are three questions on the form. "What happens to the 22,288 people using this?" is not one of them, and ICANN wrote down that it is not allowed to become one. Verisign also noted it had consulted the registrars managing most of the third-level user base, and that those registrars "did not identify any security, stability or competition issues." Of course they did not. That is not what registrars were asked either.

On Hacker News, user swiftcoder put the gap plainly: "You'd think changes like this would need to go through a public comment period with the affected users (much like city planning decisions do)."

What developers should actually take from this

Two things, and only one of them is about .name.

The first is prepaid time is not a guarantee. Fraser writes that his domain is "registered and paid for until 2040." A commenter, elashri, pulled the whois and posted a registry expiration of 2036-01-29, so the exact horizon is arguable. The direction is not: money in the registry's hands through the next decade did not buy a veto, and the RSEP does not treat prepaid terms as a stability issue.

The second is the security wrinkle, and it is the one we had not seen covered. Fraser's stated fear is that after termination someone else registers fraser.name at the second level and "would be able to recreate and control neil.fraser.name," hijacking "hundreds of accounts that are linked to that address." That is a real attack, and the thread turned up why it is worse than it looks.

Commenter CodesInChaos checked the Public Suffix List and found *.name is not a wildcard entry. Commenter akersten went to the PSL issue tracker and quoted the maintainers: "We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't."

Read that against the registry's structure. .name allowed both second-level and third-level registrations, so joe.smith.name and john.smith.name could belong to strangers while smith.name belonged to a third party. Without a wildcard PSL entry, browsers do not treat smith.name as a public suffix boundary. As commenter xg15 worked through in the thread, that means cookie and origin isolation between third-level .name siblings was never reliable. The hijack risk Fraser is worried about post-termination is a sharper version of a risk that has been sitting there for years.

Where this goes

The precedent worth watching is .org. In 2019 ICANN was set to approve the transfer of the .org registry to the private equity firm Ethos Capital, and then California's Attorney General at the time, Xavier Becerra, wrote a letter urging ICANN to reject it. The deal died. A Hacker News commenter, NewJazz, raised exactly this route: write to the California AG, because ICANN is a California nonprofit and that is the pressure that has actually worked before.

That is the real lesson here, and it is not a comfortable one. The accountability mechanism built for this, the Request for Reconsideration, has been filed and is reportedly heading for denial. The mechanism that worked last time was a state law enforcement officer with no formal role in the process at all.

We have no test to run on this one and no benchmark to report. What we did was read the letter, and the letter is the story: a review that is explicitly scoped to exclude the people affected will keep producing approvals like this one, correctly, on schedule, and with the form filled in properly.

Share

22,288 domains die around February 2027, including 37 owned by people named Kevin. ICANN's own letter says its review "does not extend to other potential impacts." #DNS #ICANN #WebSecurity

Never miss a ship

The best stuff that shipped this week, delivered every Thursday. Free, no spam. We read all the boring stuff so you get the fun parts.

Keep reading