Files
nexus/sreweekly/articles/285/09-tlds-putting-the-fun-in-the-top-of-the-dns.html
2026-09-12 17:23:01 +08:00

1163 lines
44 KiB
HTML

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html lang="en">
<head>
<title>TLDs -- Putting the '.fun' in the top of the DNS</title>
<meta http-equiv="content-type" content= "text/html; charset=utf-8">
<meta name="robots" content="noai,noimageai">
<meta property="og:url" content="https://www.netmeister.org/blog/tlds.html">
<meta property="og:title" content="TLDs -- Putting the '.fun' in the top of the DNS">
<meta property="og:description" content="Everybody knows the small number of top-level
domains in the DNS: .com, .org, .net, .gov,
.verm&ouml;gensberatung and .&#x9999;&#x6E2F;. Let's look
at what else we find at the top!">
<meta property="og:image" content="https://www.netmeister.org/blog/images/tlds.png">
<link rel="made" href="mailto:jschauma@netmeister.org">
<link rel="alternate" type="application/rss+xml" title="Signs of Triviality" href="https://www.netmeister.org/blog/rss.xml">
<link rel="stylesheet" type="text/css" href="blog.css">
</head>
<body>
<h1>Signs of Triviality</h1>
<em>Opinions, mostly my own, on the importance of being and other things.</em>
<hr class="noshade" style="width:100%;">
<small>
[<a href="../index.html">homepage</a>]&nbsp;
[<a href="index.html">blog</a>]&nbsp;
[<a href="mailto:jschauma@netmeister.org">jschauma@netmeister.org</a>]&nbsp;
[<a href="https://mstdn.social/@jschauma">@jschauma</a>]&nbsp;
[<a href="rss.xml">RSS</a>]
</small>
<input type="checkbox" id="theme-checker" hidden>
<div class="container">
<label class="switch" for="theme-checker" title="Dark/Light mode">
<span class="slider round"></span>
</label>
</div>
<hr class="noshade" style="width:100%;">
<h2>TLDs -- Putting the '.fun' in the top of the DNS</h2>
<table border="0" width="75%">
<tr>
<td>
<p><small>August 12th, 2021</small></p>
<p>The Domain Name System or DNS is a never-ending
source of amusement and amazement. If you have been
dealing with just about anything related to operations
on the internet, you know that it's always the DNS in
the end, what with its <a href="dns-rrs.html">almost
100 different resource records</a> and, uhm, shall we
say, "interesting" <a
href="doh-dot-dnssec.html">security threat
model</a>.</p>
<p>But today, let's talk about <em>Top-Level
Domains</em>, or <em>TLD</em>s. You know,
<code>.com</code>, <code>.org</code>, <code>.net</code>,
<code>.gov</code>, <code>.verm&ouml;gensberatung</code> and
<code>.&#x9999;&#x6E2F;</code> -
those guys. As you know, the entire domain <em>name space</em>
consists of a tree of <em>domain names</em>; the
(common) root of the DNS tree is <code>.</code> (dot), and
the tree sub-divides into <em>zones</em> consisting of
<em>domains</em> and <em>sub-domains</em>:<p>
<center><img src="images/tlds.png" alt="A tree graph of the
DNS space, showing the common TLDs and select
sub-domains."></center>
<p>Okay, so far, so good. With <a
href="https://datatracker.ietf.org/doc/html/rfc920">RFC920</a>,
we got the initial set of top level domains:</p>
<table border="1">
<tr>
<td width="20%"><code><a href="https://home.dotgov.gov/">.gov</a></code></td>
<td>Government, any government related domains meeting the second level requirements.</td>
</tr>
<tr>
<td><code><a href="https://net.educause.edu/">.edu</a></code></td>
<td>Education, any education related domains meeting the second level requirements.</td>
</tr>
<tr>
<td><code><a href="https://www.verisign.com/en_US/domain-names/com-domain-names/index.xhtml">.com</a></code></td>
<td>Commercial, any commercial related domains meeting the second level requirements.</td>
</tr>
<tr>
<td><code><a href="https://www.iana.org/domains/root/db/mil.html">.mil</a></code></td>
<td>Military, any military related domains meeting the second level requirements.</td>
</tr>
<tr>
<td><code><a href="https://thenew.org/org-people/">.org</a></code></td>
<td>Organization, any other domains meeting the second level requirements.</td>
</tr>
<tr>
<td><code><a href="https://www.verisign.com/en_US/domain-names/net-domain-names/index.xhtml">.net</a></code></td>
<td>Initially intended for network organizations;
not mentioned in RFC920, but created in 1985</td>
</tr>
</table>
<p>&nbsp;</p>
<p>Oh, and:</p>
<h2 id="arpa"><code>.arpa</code></h2>
<table border="1">
<tr>
<td><code><a href="https://www.iana.org/domains/arpa">.arpa</a></code></td>
<td><em>Temporary</em>; The current ARPA-Internet hosts.</td>
</tr>
</table>
<p><br>That's right: <code>.arpa</code> was <em><a
href="/twitter/713903333375868928">supposed
to be temporary</a></em>:</p>
<blockquote class="pretty">
"After a short period of initial experimentation, all
current ARPA-Internet hosts will select some domain
other than ARPA for their future use. The use of ARPA
as a top level domain will eventually cease." -- <a
href="https://datatracker.ietf.org/doc/html/rfc920">RFC920</a>
</blockquote>
<p>Yeah, well, we all know how <a
href="/twitter/450441590302318592">temporary</a>
temporary solutions are. And so today, we continue
to use <code>.arpa</code> for, e.g., reverse mapping of IP
addresses to names via the <code>.in-addr.arpa</code> and
<code>.ip6.arpa</code> second-level domains. But
<code>.arpa</code> is used for a lot more:
<code>as112.arpa</code> (<a
href="https://www.rfc-editor.org/rfc/rfc7535.html">RFC7535</a>,
effectively <a
href="https://www.rfc-editor.org/rfc/rfc1918">RFC1918</a>
reverse resolution; see also <a
href="https://www.as112.net/">https://www.as112.net/</a>),
<code>e164.arpa</code> (<a
href="https://www.rfc-editor.org/rfc/rfc6116.html">RFC6116</a>
/ <a href="dns-rrs.html#naptr">NAPTR</a> records),
<code>home.arpa</code> (<a
href="https://www.rfc-editor.org/rfc/rfc8375.html">RFC8375</a>,
non-unique use in residential home network),
<code>in-addr-servers.arpa</code> and
<code>ip6-servers.arpa</code> (<a
href="https://www.rfc-editor.org/rfc/rfc5855.html">RFC5855</a>,
name servers for the <code>in-addr.arpa</code> and
<code>ip6.arpa</code> domains), <code>ipv4only.arpa</code>
(<a
href="https://www.rfc-editor.org/rfc/rfc7050.html">RFC7050</a>,
detecting DNS64 and IPv6 Prefixes),
<code>iris.arpa</code> (<a
href="https://www.rfc-editor.org/rfc/rfc4698.html">RFC4698</a>,
for locating Internet Registry Information Services),
as well as <code>uri.arpa</code> and <code>urn.arpa</code>
(<a
href="https://www.rfc-editor.org/rfc/rfc3405.html">RFC3405</a>
for resolving Uniform Resource Identifiers / <a
href="dns-rrs.html#naptr">NAPTR</a>).</p>
<p><small>Note: the <tt>arpa</tt> zone is served from
all root servers except the <a
href="https://j.root-servers.org/">J Root</a>, which,
per <a
href="https://datatracker.ietf.org/doc/html/rfc2870">RFC2870</a>,
should not "provide secondary service for any zones
other than the root and root-servers.net zones".
Noted on <a
href="https://lists.dns-oarc.net/pipermail/dns-operations/2021-December/021486.html">dns-operations@dns-oarc.net</a>.</small></p>
<h2 id="cctlds"><code>ccTLDs</code></h2>
<p>In addition to
these original TLDs, we also got the <a
href="https://en.wikipedia.org/wiki/Country_code_top-level_domain">country
code top-level domains</a>, or <em>ccTLD</em>s:</p>
<blockquote class="pretty">
The English two letter code (alpha-2) identifying a
country according the the ISO Standard for "Codes for
the Representation of Names of Countries". -- <a
href="https://datatracker.ietf.org/doc/html/rfc920">RFC920</a>
</blockquote>
<p>
And this is where the fun begins, because of course
you are <em>always</em> operating on Layer 9, and
this list is necessarily somewhat fluid, as countries
change, are born, divided, or cease to exist:</p>
<a
href="https://ops-lessons.creator-spring.com/listing/osi-9-layer-model?product=663"><img
src="images/osi-stack2.png" alt="The OSI Stack with
the 'financial' and 'political' layers added and an
arrow pointing to the top: 'you are here'."
align="right" width="250" border="0"></a>
<ul>
<li><code><a
href="https://nic.ss/">.ss</a></code>, the ccTLD for
South Sudan was allocated in August 2011, but not
added to the root zone until February 2019, with
general availability of names in that domain
only starting in September 2020.</li>
<li><code><a href="https://nic.ge/">.ge</a></code>, the
ccTLD for Georgia (the country, not the US state) uses
the <a
href="https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2#GE">ISO-3166-1
Alpha 2 country code</a> that previously used to
represent the Gilbert and Ellice Islands; the Ellice
Islands became Tuvalu, which, per country code
designation, got the rather valuable <code><a
href="https://www.verisign.com/en_US/domain-names/tv-domain-names/index.xhtml">.tv</a></code>
ccTLD.<br><br>
This TLD became so valuable that at some point 10%
of the country's revenue came from royalties of
<code>.tv</code> domains; Tuvalu used the money for the
marketing rights to allow them to pay the membership
dues for United Nations when they joined the UN in
2000!</li>
<li><code>.eh</code> has been reserved (but not been
assigned yet) as the ccTLD for the disputed "Western
Sahara" territory; in 2013, on April 1st, <a
href="https://www.cira.ca/">CIRA</a>, the Canadian
Internet Registration Authority (responsible for
<code>.ca</code>), announced that it would offer
<code>.eh</code> names, because, you know, Canadians would
like that, eh?</li>
<li>Some ccTLDs represent countries that other
countries don't acknowledge as existing. <code><a
href="https://www.pnina.ps/">.ps</a></code> is the ccTLD
for Palestine (not a sponsored TLD for the
(Turing-complete!) <a
href="https://en.wikipedia.org/wiki/PostScript">PostScript</a>
programming language), recognized by <a
href="https://en.wikipedia.org/wiki/International_recognition_of_the_State_of_Palestine">138
of the 193 UN members</a>; <code><a
href="https://rs.twnic.net.tw/">.tw</a></code> is
assigned for the Republic of China, aka Taiwan, which
a <a
href="https://worldpopulationreview.com/country-rankings/countries-that-recognize-taiwan">mere 14 countries recognize</a>.</li>
<li>Not all <em>cc</em>TLDs represent actual
<em>countries</em>: Hong Kong has a ccTLD, <code><a
href="https://www.hkdnr.hk/en/">.hk</a></code> as a
special administrative region of China (much like
<code><a href="https://www.monic.mo">.mo</a></code> for
Macao); <code><a
href="https://www.nominet.uk/">.uk</a></code> represents
the entire United Kingdom, while the, e.g., scarcely used
<code>.gb</code> is assigned to Great Britain; England
<a href="http://doteng.org/">doesn't even get a
ccTLD</a>, and neither does Northern Ireland!<br><br>
Similarly, <code><a
href="https://eurid.eu/en/">.eu</a></code> counts as a
ccTLD, representing, obviously, not a single country.
But due to Brexit, British citizens who had
registered <code>.eu</code> domains had their domains
suspended on January 1st, 2021, requiring proof of
<em>European Economic Area</em> (EEA) citizenship to
avoid them being deleted in March 2021.</li>
<li>When a country ceases to exist, its ccTLD is
normally retired:<code>.cs</code> (Czechoslovakia) became
<code><a href="https://www.nic.cz/">.cz</a></code> (Czech
Republic) and <code><a
href="https://sk-nic.sk/">.sk</a></code> (Slovakia);
<code>.dd</code> (East Germany) disappeared after the
reunification of Germany; <code>.yu</code> (Yugoslavia)
became <code><a
href="https://www.registry.si">.si</a></code>
(Slovenia), <code><a
href="https://www.domene.hr/">.hr</a></code> (Croatia),
and Serbia and Montenegro, which had had <code>.cs</code>
assigned (but never used that, instead continuing to
use <code>.yu</code>) before <em>they</em> split into
<code><a href="https://www.rnids.rs/en/">.rs</a></code>
(Serbia) and <code><a
href="https://domain.me/">.me</a></code>
(Montenegro); <code>.zr</code> (Zaire) became <code><a
href="https://conic.africa/">.cd</a></code> (Democratic
Republic of the Congo).<br><br>
However, <code><a
href="http://www.fid.su/">.su</a></code>, the ccTLD for
the former Soviet Union, assigned a mere 15 months
before that Union was dissolved back in 1990, still
remains in active use.</li>
</ul>
<h2 id="domain-hacks">ccTLD Domain Hacks and Governance</h2>
<p>With ccTLDs having appealing two-letter names
(gTLDs are a minimum of three characters), they
lend themselves to so-called "domain hacks" to create
words, to shorten URLs, or as a convenient way to jump
on a popular trend, and many people began registering
names in other countries' ccTLDs:</p>
<ul>
<li><code><a href="http://www.nic.ag/">.ag</a></code>,
the ccTLD for Antigua and Barbuda is often used in
German speaking countries, where "AG" is an
abbreviation of "Aktiengesellschaft" (a private
limited / joint stock company), and use of
<code>.ag</code> names for other entities may <a
href="https://www.jurpc.de/jurpc/show?id=20040262">even
carry legal risks</a>.</li>
<li><code><a href="http://nic.com.ai/">.ai</a></code>, the
ccTLD for Anguilla, is used for extra leet effect in
artificial intelligence marketing. <code>.ai</code> also
is notable in that as a TLD it nevertheless has both
an <code>A</code> and <code>MX</code> record, meaning you could
have a functional email address like <code>hal@ai</code>.
(<a href="email.html">Email addresses are difficult to
validate, it turns out.</a>)</li>
<li><code><a href="https://www.amnic.net/">.am</a></code>
(Armenia) is used by, e.g., <a
href="https://instagr.am">instagr.am</a></li>
<li><code><a href="https://www.nic.at/en">.at</a></code>
(Austria) is used for things like, e.g., <a
href="http://donteat.at/">donteat.at</a></li>
<li><code><a
href="https://www.dnsbelgium.be/">.be</a></code> is used
by, e.g., Google to shorten <a
href="https://youtu.be">youtu.be</a> links.</li>
<li><code><a href="https://www.cctld.by/">.by</a></code>
(Belarus) is frequently used for sites relating to the
German state of Bavaria (<em>Bayern</em>)</li>
<li><code><a href="https://netcom.cm">.cm</a></code>
(Cameroon) and <code><a
href="https://www.go.co/">.co</a></code> (Colombia) are
frequently used by typo-squatters to catch traffic
from people fat-fingering ".com".</li>
<li><code>.cx</code> was assigned to the Christmas Island,
and appears currently to be defunct, but it did have
the significant glory of once having been the home of
<code>goatse.cx</code> (<a
href="https://en.wikipedia.org/wiki/Goatse.cx">Wikipedia</a>).</li>
<li><code><a
href="https://www.nic.im/home.mth">.im</a></code> (Isle
of Man) is used for various instant messaging domain
hacks.</li>
<li><code><a href="https://www.nic.io/">.io</a></code>,
assigned to the British Indian Ocean Territory is
almost exclusively used by annoying startups for
content completely unrelated to the islands.</li>
<li><code><a href="https://www.la/">.la</a></code> (Laos) is
commonly used for Louisianna or Los Angeles related
domains as well as random domain hacks, like, e.g.,
Mozilla's link shortener <a
href="https://mzl.la">mzl.la</a> or Tesla's <a
href="https://ts.la">ts.la</a></li>
<li><code><a href="https://domain.me/">.me</a></code>
(Montenegro, which up until 2007 had been using
<code>cg.yu</code>) became one of the most popular TLDs
and is used for link shorteners like Facebook's <a
href="https://fb.me">fb.me</a>, Google's <a
href="https://g.me">g.me</a> or GoDaddy's <a
href="https://go.me">go.me</a>.<br><br>
Yahoo used to use <code>me.me</code> for its "<a
href="https://en.wikipedia.org/wiki/Yahoo!_Meme">Yahoo!
Meme</a> microblogging site"; after it shut that
service, it returned the domain to the registry, and
it's now, what else, a <a href="https://me.me">Meme
search engine</a>.</li>
<li><code><a href="https://www.mninet.ms/">.ms</a></code>
(Montserrat) is, of course, used by Microsoft, sites
in the US state of Mississippi, and by, e.g., the New
York Times for its <a
href="https://nyti.ms">nyti.ms</a> link
shortener.</li>
<li>Python nerds on the internet register names in
Paraguy's ccTLD (<code><a
href="https://www.nic.py/">.py</a></code>), Rust nerds
in Serbia's <code><a
href="https://www.rnids.rs/en/">.rs</a></code>.</li>
<li>The editor wars have been decided at the TLD
level: <code><a
href="https://secure.nic.vi/">.vi</a></code> exists
(U.S. Virgin Islands), but <code>.emacs</code> does not
(<code>emacs.vi</code>, however, does).</li> </ul>
<figure style="center;"><img src="images/world-cctlds.png" border="0"
align="center" alt="Worldmap showing company logos
pointing to the countries in which their vanity or
domain hack domains are registered" width="800"/>
</figure>
<p>Now one noteworthy aspect here is that since the
ccTLDs are administered by the given country, they may
be subject to (and enforce) different requirements.
Some domains can only be registered by entities
residing within the given country, others, like the
<code><a href="https://domini.cat/">.cat</a></code> domain
sponsored by the <a
href="https://xn--fundaci-r0a.cat/">dotCAT
foundation</a> to promote the Catalan language, may
stipulate the language or content of the domains.</p>
<p>Lybia, with the ever so popular <code><a
href="https://www.nic.ly/">.ly</a></code> ccTLD did in
2010 shut down <a
href="https://twitter.com/violetblue">Violet
Blue</a>'s <code>vb.ly</code> domain, <a
href="https://www.pcmag.com/archive/libya-seizes-url-shortener-vbly-255360">objecting
to the content</a>. In a similar manner, Colombia
could choose to break just about all of Twitter (which
uses the <code><a href="https://t.co">t.co</a></code> domain name to wrap every
single link on its platform); Greenland could shut down
Google's <a href="https://goo.gl">goo.gl</a>
links.</p>
<h2 id="gtlds">Generic TLDs (gTLDs)</h2>
<p>In addition to the original TLDs and the
ccTLDs, in the late 1980s InterNIC added
<code>.nato</code>, but that was later replaced by
<code>.nato.int</code>, with the new <code>.int</code> TLD
being added in 1988 for intergovernmental
organizations.</p>
<p>In 2000, <a
href="https://www.icann.org/">ICANN</a>, who had by
then taken over the administration of domain names,
added seven more TLDs: <code><a
href="https://information.aero/">.aero</a></code>,
<code><a href="https://registry.godaddy/">.biz</a></code>,
<code><a href="https://identity.coop/">.coop</a></code>,
<code><a href="https://afilias.info/">.info</a></code>,
<code><a
href="https://welcome.museum/">.museum</a></code>,
<code><a
href="https://www.verisign.com/en_US/domain-names/name-domains/index.xhtml">.name</a></code>,
and <code><a href="https://registry.pro/">.pro</a></code>.
It then began soliciting proposals for "<a
href="https://en.wikipedia.org/wiki/Sponsored_top-level_domain">sponsored
top-level domains</a>" (sTLDs), but only received a
handful of proposals, ultimately adding <code><a
href="https://www.dot.asia/">.asia</a></code>, <code><a
href="https://domini.cat/">.cat</a></code>, <code><a
href="https://secure.jobs/">.jobs</a></code>, <code><a
href="https://dotmobi.mobi/">.mobi</a></code>, <code><a
href="https://www.upu.int/en/Universal-Postal-Union/Activities/Digital-Services/-POST-Domain">.post</a></code>,
<code><a href="https://www.do.tel/">.tel</a></code>,
<code><a
href="https://www.travel.domains/">.travel</a></code>,
and <code><a
href="https://icmregistry.com/">.xxx</a></code>.</p>
<p>Sponsored TLDs being somewhat restricted in scope
and use, ICANN then went for another round of
accepting proposals for new, <em>generic</em> TLDs
(gTLDs), this time with a price tag of $185,000 per
TLD. In 2012, it processed 1,930 applications: 101
from Google (under the name <a
href="https://www.registry.google/">Charleston Road
Registry Inc.</a> (<a
href="/twitter/992417858226450432">see
also</a>), including <a
href="https://blog.google/inside-google/company-announcements/expanding-internet-domain-space/"><code>.lol</code>,
<code>.google</code>, <code>.dog</code>, and <code>.foo</code></a>
(<code>.lol</code> was ultimately registered by <a href="https://en.wikipedia.org/wiki/Uniregistry">Uniregistry</a>, now owned by GoDaddy), 76 from Amazon, 11 from Microsoft and 307
from the "<a
href="https://donuts.domains/">Donuts</a>" domain name
registry.</p>
<p>The list of ultimately approved domains included a
number of geographic TLDs (<em>geoTLD</em>s), adding
domains for certain cities (e.g., <code><a
href="https://dot.berlin/">.berlin</a></code>, <code><a
href="https://domains.london/">.london</a></code>,
<code><a href="https://www.ownit.nyc/">.nyc</a></code>,
<code><a href="http://bienvenue.paris">.paris</a></code>,
or <code><a
href="https://hello.tokyo/">.tokyo</a></code>),
countries that previously did not have a ccTLD (e.g.,
<code><a href="https://www.nominet.uk/">.cymru</a></code>,
<code><a href="https://dot.scot/">.scot</a></code>, and
<code><a href="https://www.nominet.uk/">.wales</a></code>,
although England <em>still</em> doesn't get its own
TLD, while, e.g., New Zealand (<code><a
href="https://dnc.org.nz/">.nz</a></code>) now got a
second: <code><a
href="https://hello.kiwi/">.kiwi</a></code>), and
broader geographic regions (e.g., <code><a
href="https://registry.africa/">.africa</a></code> or
<code><a href="https://www.nic.lat/">.lat</a></code>).</p>
<p>But of course people went a bit nuts, too: many
brands applied for <code>.&lt;brand&gt;</code> and got
into various arguments over who should own the given
TLD. For example, <a
href="https://www.amazon.com">Amazon</a> applied for
(and was given) <code><a
href="https://www.amazonregistry.com/">.amazon</a></code>
over the <a
href="https://www.bbc.com/news/business-47794353">objection
of several nations of, well, the Amazon</a>; and
multiple applications for entirely generic terms had
to be <a
href="https://gtldresult.icann.org/applicationstatus/stringcontentionstatus">sorted
out</a>.</p>
<p>One of those was the <code><a
href="https://nic.secure/">.secure</a></code> domain,
which had been proposed by one <a
href="https://en.wikipedia.org/wiki/Alex_Stamos">Alex
Stamos</a> of (then) Artemis Internet as a TLD that
would enforce <a
href="https://arstechnica.com/information-technology/2012/05/my-own-private-internet-secure-tld-floated-as-bad-guy-free-zone/">certain
minimum security requirements</a>; ultimately,
<code>.secure</code> was assigned to Amazon.</p>
<p>Eventually, <a
href="https://newgtlds.icann.org/en/program-status/delegated-strings">ICANN
added 1239 new TLDs</a> to the DNS, bestowing upon us
such important TLDs as, e.g., <code>.beer</code>,
<code>.cloud</code>, <code>.dot</code>, <code>.duck</code>,
<code>.foo</code>, <code>.google</code>, <code>.rocks</code> and
<code>.sucks</code>, <code>.travelersinsurance</code>, and
<code>.yahoo</code>.</p>
<p>But of course some TLDs then go under again: <code><a
href="https://icannwiki.org/.wed">.wed</a></code>, for
example, was delegated, but the company that had
applied for this name apparently didn't pay up, and
ICANN terminated the registry agreement. However, the
TLD remains in the root; it appears to now be operated
by <a
href="https://www.icann.org/resources/pages/ebero-2013-04-02-en">ICANN
EBERO</a> and some names remain in use (e.g., <a
href="https://get.wed/index.html">get.wed</a>, albeit
with an invalid certificate).</p>
<p>Finally, the perhaps most generic TLD,
<tt>.gdn</tt> (Global Domain Name) was added in
2014.</p>
<h2 id="idns">Internationalized TLDs</h2>
<p>Even before the landrush for the new gTLDs, ICANN
approved the introduction of <a
href="https://en.wikipedia.org/wiki/Internationalized_domain_name">internationalized
domain name</a> (IDN) TLDs, and many ccTLDs added TLDs
using their respective languages and alphabets
(including right-to-left!), represented within the DNS
using <a
href="https://en.wikipedia.org/wiki/Punycode">Punycode</a>.</p>
<table border="1">
<tr>
<td><b>DNS name</b></td>
<td><b>IDN ccTLD</b></td>
<td><b>Country/Region</b></td>
<td><b>Language</b></td>
<td><b>Other ccTLD</b></td>
</tr>
<tr>
<td>xn--lgbbat1ad8j</td>
<td>.&#x627;&#x644;&#x62C;&#x632;&#x627;&#x626;&#x631;</td>
<td>Algeria</td>
<td>Arabic</td>
<td><code>.dz</code></td>
</tr>
<tr>
<td>xn--fiqs8s</td>
<td>.&#x4E2D;&#x56FD;</td>
<td>China</td>
<td>Chinese (Simplified)</td>
<td><code>.cn</code></td>
</tr>
<tr>
<td>xn--qxa6a</td>
<td>.&#x3B5;&#x3C5;</td>
<td>European Union</td>
<td>Greek</td>
<td><code>.eu</code></td>
</tr>
<tr>
<td>xn--4dbrk0ce</td>
<td>.&#x5D9;&#x5E9;&#x5E8;&#x5D0;&#x5DC;</td>
<td>Israel</td>
<td>Hebrew</td>
<td><code>.il</code></td>
</tr>
<tr>
<td>xn--o3cw4h</td>
<td>.&#xE44;&#xE17;&#xE22;</td>
<td>Thailand</td>
<td>Thai</td>
<td><code>.th</code></td>
</tr>
</table>
<p>(See <a
href="https://en.wikipedia.org/wiki/Country_code_top-level_domain#Internationalized_ccTLDs">Wikipedia's
full table</a> for all IDN ccTLDs.)</p>
<p> But IDNs are not only for ccTLDs: many of the new
gTLDs also include various Unicode characters, such
as, e.g., <code>.&#x441;&#x430;&#x439;&#x442;</code>
("website"),
<code>.&#x5927;&#x4F17;&#x6C7D;&#x8F66;</code>
("volkswagen"),
<code>.&#x30D5;&#x30A1;&#x30C3;&#x30B7;&#x30E7;&#x30F3;</code>
("fashion"),
<code>&#x627;&#x628;&#x648;&#x638;&#x628;&#x64A;&#x200E;.</code>
("Abu Dhabi"), and, of course,
<code>.verm&ouml;gensberatung</code> ("wealth management /
advice").</p>
<p>Note that with IDNs, you can mix an IDN
second-level with a non-IDN top-level or vice versa.
Due to the resulting <a
href="https://en.wikipedia.org/wiki/IDN_homograph_attack">IDN
Homograph Attack</a> vector, browsers <a
href="https://web.archive.org/web/20110102051140/http://blogs.msdn.com/b/ie/archive/2006/07/31/684337.aspx">stopped
rendering the IDNs</a> and now always <a
href="https://www.wordfence.com/blog/2017/04/chrome-firefox-unicode-phishing/">display them as
Punycode</a>.</p>
<h2 id="special">Special Use Domains</h2>
<p>In addition to all that, there is also a small
number of so-called "special use domains", of which
<code>.arpa</code> (already <a href="#arpa">discussed
above</a>) is just one. These are:</p>
<ul>
<li><code>.example</code> -- intended for use in
documentation, tutorials, and testing; defined,
together with <code>example.com</code>,
<code>example.net</code>, and <code>example.org</code> in <a
href="https://datatracker.ietf.org/doc/html/rfc6761">RFC6761</a>.</li>
<li><code>.invalid</code> and <code>.test</code> -- for testing and
documentation, originally defined in <a
href="https://datatracker.ietf.org/doc/html/rfc2606">RFC2606</a>.</li>
<li><code>.local</code> -- usually used for
zero-configuration networking (<a
href="https://datatracker.ietf.org/doc/html/rfc6762">RFC6762</a>).</li>
<li><code>.localhost</code> -- reserved since
traditionally <code>.localhost</code> existed in, e.g.,
<code>/etc/hosts</code> for the loopback address (<a
href="https://datatracker.ietf.org/doc/html/rfc2606">RFC2606</a>).
Note: <code>.localdomain</code> is <em>not</em> reserved,
and use of <code>localhost.localdomain</code> can lead to
unexpected results if your stub resolver expands
this.</li>
<li><code>.onion</code> -- used by <a
href="https://www.torproject.org/">Tor</a> (<a
href="http://2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion/">.onion
service address</a>) and defined in <a
href="https://datatracker.ietf.org/doc/html/rfc7686">RFC7686</a>.
Note: this "TLD" is <em>not</em> entered into the DNS,
but following work by <a
href="https://twitter.com/mccoy">Jim McCoy</a> and <a
href="https://twitter.com/alecmuffett">Alec
Muffett</a> leading to <a
href="https://cabforum.org/2015/02/18/ballot-144-validation-rules-dot-onion-names/">CA/B
Forum Ballot 144</a>, you <em>can</em> get a valid
x509 certificate from public CAs. (For a while, Tor
also used to use the <code><a
href="https://en.wikipedia.org/wiki/.onion#.exit_(defunct_pseudo-top-level_domain)">.exit</a></code>
pseudo TLD; this is no longer supported.)</li>
<li>Not all networks may use the standard DNS root
(<a
href="https://www.icann.org/resources/pages/unique-authoritative-root-2012-02-25-en">ICANN
is not pleased</a>),
and so of course all bets are off if you are on a
network using an <a
href="https://en.wikipedia.org/wiki/Alternative_DNS_root">alternative
DNS root</a>. Some TLDs in such networks include(d)
<code><a
href="https://en.wikipedia.org/wiki/BITNET">.bitnet</a></code>,
<code><a
href="https://en.wikipedia.org/wiki/.csnet">.csnet</a></code>,
<code><a
href="https://en.wikipedia.org/wiki/MHSnet">.oz</a></code>
(from ACSnet, now moved into <code>.oz.au</code>), <code><a
href="https://en.wikipedia.org/wiki/UUCP">.uucp</a></code>
(if you remember that), and <code><a
href="https://en.wikipedia.org/wiki/I2P">.i2p</a></code>
(the aptly named "Invisible Internet Project").</li>
<li>Some TLDs are effectively split-horizon, only
exposing some parts to the public internet.
<code>.kp</code>, the ccTLD assigned for North Korea
serves the North Korea internal-only <a
href="https://en.wikipedia.org/wiki/Kwangmyong_(network)">Kwangmyong
network</a>.</li>
<li>China uses the <code><a
href="https://zh.wikipedia.org/wiki/.chn">.chn</a></code>
domain internally <a
href="http://www.chinaiptoday.com/post.html?id=405">for
its Internet of Things</a>. This domain relies on the
use of an alternate DNS root as well, and is
<em>not</em> found in the common root.</li>
</ul>
<h2 id="zones">TLD Zone files</h2>
<p>The DNS is an inherently <em>public</em> system
(modulo alternate root shenenigans or split-horizon
games). The <a
href="https://www.iana.org/domains/root/db">root zone
itself</a> continues to be available for download via
<a
href="ftp://rs.internic.net/domain/root.zone">FTP</a>
or <a
href="https://www.internic.net/domain/root.zone">HTTPS</a>
and so we can easily extract the full count of all
TLDs:</p>
<div style="text-align: center;"><pre class="code">
$ curl https://www.internic.net/domain/root.zone |
awk '{if ($4 == "NS") { print $1;}}' | sort -u | wc -l
1499
</pre></div>
<p>Processing the simple zone file, we find that most
TLDs are two- (248) or three- (222) letter TLDs;
that there are 154 IDN TLDs; that there are TLDs
starting with every letter of the alphabet ('s'
being the most popular one); that the longest TLD is
<code style="white-space:nowrap;">verm&ouml;gensberatung</code> (24
characters in punycode:
<code>xn--vermgensberatung-pwb</code>).</p>
<p>But what about all the individual TLD zone files?
Since that data is also public in nature, we should be
able to get and process it as well. And for the ICANN
assigned new gTLDs, this is indeed the case: ICANN
offers the <a
href="https://czds.icann.org/">Centralized Zone Data
Service</a>, where you can apply to gain access to all
gTLD zone files. For some domains the access is
granted almost instantly, for others it takes a few
days.</p>
<p>Now for the ccTLDs, however, there unfortunately is
<em>no</em> equivalent service, although there's a
(rather short) list of ccTLD zone sources <a
href="https://jpmens.net/2021/05/18/dns-open-zone-data/">here</a> as well as <a href="https://github.com/jschauma/tld-zoneinfo">here</a>;
some registries let you <code>AXFR</code> the domain
(e.g., <code><a
href="https://www.internet.ee/domains/ee-zone-file">.ee</a></code>,
<code><a
href="https://www.switch.ch/open-data/#tab-c5442a19-67cf-11e8-9cf6-5254009dc73c-3">.ch</a></code>
and <code><a
href="https://www.switch.ch/open-data/#tab-c5442a19-67cf-11e8-9cf6-5254009dc73c-3">.li</a></code>,
<code><a href="https://zonedata.iis.se/">.se</a></code>
and <code><a
href="https://zonedata.iis.se/">.nu</a></code>), some
provide a list of names (e.g., <code><a
href="https://sk-nic.sk/subory/domains.txt">sk</a></code>
or <code><a
href="https://home.dotgov.gov/data/">.gov</a></code>),
but otherwise it's up to you to contact the registry
in question and plead your case. Yes, for each of the
over 300 domains -- good luck! (I've collected what I
found out about each <a
href="https://github.com/jschauma/tld-zoneinfo">here</a>.)</p>
<p>Given how difficult it is to get to all the public
data, it's then no surprise that several businesses
are making good money by <a
href="https://zonefiles.io/cctld-domains/">selling you
that access</a> or by providing <a
href="https://stats.centr.org/stats/global">TLD
reports</a>.</p>
<h2 id="stats">Some stats</h2>
<p>After having requested access to all gTLD zone
files and having received most of them (several are
still pending), I looked around a bit, seeking
entertaining stats. One thing to note is that a
large number of zones (230) do not have <em>any</em> names
defined (other than, say, a NIC <code>NS</code> record) --
TLDs registered purely as a brand or placeholder, I
suspect. Over 360 zones have fewer than 10 records,
over 470 fewer than 100.</p>
<p>Zones that <em>are</em> actually used include the
expected variety of silly names, including very long
domain names:</p>
<div style="text-align: center;"><pre class="code">
accountantaccountantaccountantaccountantaccountantaccountant.accountant
artartartartartartartartartartartartartartartartartartartartart.art
yoyoyodogillbestraightwithyouicanttellifthatsatattoooranartisti.art
barbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbar.bar
clickclickclickclickclickclickclickclickclickclickclickclick.click
ahndung-von-verkehrsordnungswidrigkeiten-mit-unfallfolge.cologne.
0-------------------------------------------------------------0.com.
thelongestdomainnameintheworldliterallynobodycangetalongeronexd.community
you-know-you-are-pretty-gosh-darned-cute-do-you-wanna-go-on-a.date.
lololololololololololololololololololololololololololololololol.fun.
gayfriendlyconvenientaffordabletrendyhairsalonsindowntowntoront.mobi
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww.org
partypartypartypartypartypartypartypartypartypartypartyparty.party
runrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrun.run
thehighestthemostvaluableandthemostexpensivedomainnameofalltime.top
this-crazy-url-is-definitely-one-of-the-longest-adresses-in-the.world.
rindfleischetikettierungsuberwachungsaufgabenubertragungsgesetz.xyz
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.xyz.
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz.zone
</pre></div>
<p>...and so on and so on. Per <a
href="https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4">RFC1035</a>,
the maximum size of a DNS label is 63 octets (note:
<em>octets</em>, not <em>characters</em>, which is why
the <a
href="https://devblogs.microsoft.com/oldnewthing/20120412-00/?p=7873">maximmum
length of a domain name is 253 characters</a>), which
explains why there are no <em>longer</em> second-level
domains, although it doesn't explain why people insist
on registering over 1700 such names.</p>
<p>Of the 987 zones I looked at, the top ten zones
based on number of domains were:</p>
<table border="1">
<tr>
<td width="10%"><b>Rank</b></td>
<td><b>TLD</b></td>
<td><b># of domains</b></td>
</tr>
<tr>
<td>1</td>
<td><code>.com</code></td>
<td>155,883,253</td>
</tr>
<tr>
<td>2</td>
<td><code>.net</code></td>
<td>13,291,304</td>
</tr>
<tr>
<td>3</td>
<td><code>.org</code></td>
<td>10,424,321</td>
</tr>
<tr>
<td>4</td>
<td><code>.info</code></td>
<td>3,859,083</td>
</tr>
<tr>
<td>5</td>
<td><code>.xyz</code></td>
<td>3,128,897</td>
</tr>
<tr>
<td>6</td>
<td><code>.online</code></td>
<td>1,811,807</td>
</tr>
<tr>
<td>7</td>
<td><code>.top</code></td>
<td>1,200,953</td>
</tr>
<tr>
<td>8</td>
<td><code>.site</code></td>
<td>1,067,408</td>
</tr>
<tr>
<td>9</td>
<td><code>.shop</code></td>
<td>907,239</td>
</tr>
<tr>
<td>10</td>
<td><code>.app</code></td>
<td>722,140</td>
</tr>
</table>
<br/>
<p>You can find a more complete breakdown of regularly
updated statistics for all TLDs <a
href="/tldstats/">here</a>.</p>
<p>(Note that not all TLDs are treated the same across
the internet. Despite being rather popular, the
<tt>.xyz</tt> domain appears to have a poor score in
many automated domain reputation systems, which may
lead to <a
href="https://www.spotvirtual.com/blog/the-perils-of-an-xyz-domain/">all
sorts of unexpected problems</a> for your
business.)</p>
<p>For my own entertainment, I wrote a <a
href="/misc/zonestats.pl">shabby little perl script</a> to run over a
zone file and produce some additional numbers:</p>
<div style="text-align: center;"><pre class="code">
$ gzcat net.txt.gz | perl -T zonestats.pl
Total number of records: 34658946
Total number of names: 13291304
Total number of different record types: 7
ns: 32819414
rrsig: 759035
ds: 414744
nsec3: 379518
a: 270671
aaaa: 15543
soa: 1
Top ten name lengths:
9: 2839977
10: 2836099
8: 2783467
11: 2648213
7: 2496883
12: 2404541
6: 2205730
13: 2159827
14: 1886160
15: 1585087
Longest name: 000000000000000000000000000000000000000000000000000000000000001.net. (63)
There are 134 names with 63 chars in this domain.
Total number of unique name servers: 689703
The three most popular name servers found in this zone are:
dns1.registrar-servers.com.: 298617
dns2.registrar-servers.com.: 298352
jm2.dns.com.: 239693
The most popular domains in which the nameservers are:
domaincontrol.com: 6200836
googledomains.com: 1485364
dns.com: 908420
This domain contains names including the following dirty words:
shit: 8732
fuck: 8057
tits: 2351
piss: 844
cunt: 575
motherfucker: 86
cocksucker: 16
$ </pre></div>
<p>The "<a
href="https://en.wikipedia.org/wiki/Seven_dirty_words">seven
dirty words</a>" domains are of course full of
mismatches, but it looks like most zones contain
more or less the same percentage of dirty domain
names: somewhere between 0.006% and 0.008% of the
total; <code>.xxx</code> predictably ranks a bit higher
here, but not all that much at only 0.1% of all
names.</p>
<h2 id="psl">Public Suffix List</h2>
<p>
Now all of the above is good fun, but why would you
want to know whether a given string is a TLD?
Wouldn't it be trivially the right-most label of the
fully-qualified domain name (FQDN)?</p>
<p>Strictly speaking: yes. However, consider that
many TLDs are not generic in nature, meaning people
cannot simply register <em>any</em> name under the
given TLD. ccTLDs, being managed by individual
registries, each may have unique requirements and
regulations, and it is a common practice for these
registries to enforce a <a
href="https://en.wikipedia.org/wiki/Second-level_domain">second-level
domain hierarchy</a>, replicating or mirroring to some
degree the top-level hierarchy.</p>
<p>For example, and perhaps most widely known, the
<code>.uk</code> TLD uses <code>.ac.uk</code> (for academic
institutions), <code>.co.uk</code> (for commercial
entities), <code>.gov.uk</code>, <code>.net.uk</code>,
<code>.org.uk</code>, and so on. How many such
second-level domains are reserved depends on each TLD;
Brazil (<code>.br</code>), for example, has <a
href="https://registro.br/dominio/categorias/">over
100</a>.</p>
<p><a href="https://xkcd.com/2347/"><img
src="images/xkcd-2347.png" width="250" alt="XKCD Comic
2347 modified: A complex infrastructure resting on a
fragile pole labeled 'A flimsy txt file manually
maintained and copied into place from some random
location on the internet'."
title="With apologies to Randall Munroe"
align="right" border="0"></a>
Now within the context of, for example, HTTP
cookies or x509 TLS certificates, it's rather
important that an entity cannot use a wildcard to
match an entire TLD, but how does a browser know
whether <code>foo.example</code> is a reserved
second-level domain, or simply a normal domain
registered by some entity? Should a website be able to
set a cookie for <code>foo.example</code>? Should it be
able to get a certificate for
<code>*.foo.example</code>? There is no programmatic way
to determine this.</p>
<p>To solve this problem, the good folks over at
Mozilla started putting together a list of these TLDs
and "effective TLDs", known as the <a
href="https://publicsuffix.org/">Public Suffix
List</a>. That's right, it's another one of those
manually compiled and maintained text files we like to
build the internet infrastructure on!</p>
<p><a
href="https://publicsuffix.org/list/public_suffix_list.dat">This
lists</a> consists of over 9,000 prefixes, and is used
by all of the popular browsers to restrict cookie
scope as well as for various UI features.</p>
<p>Google uses <a
href="https://developers.google.com/search/docs/advanced/crawling/managing-multi-regional-sites#generic-domains">similar
heuristics</a> based on a domain name's TLD to
determine whether to offer users different language
versions of their content and other geo-targeting.
Within that context, Google treats some ccTLDs (such
as, e.g., <code>.io</code>, <code>.me</code>, <code>.tv</code>
etc.) as if they were gTLDs rather than as indicators
of geographic location.</p>
<p>Finally, the <a
href="https://hstspreload.org/">HSTS Preload list</a>
baked into browsers like Chrome and Firefox to enforce
<a
href="https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security">HTTP
Strict Transport Security</a> includes a number of
TLDs and public prefixes:</p>
<div style="text-align: center;"><pre class="code">
$ curl -O https://publicsuffix.org/list/public_suffix_list.dat
$ curl -O https://hg.mozilla.org/mozilla-central/raw-file/tip/security/manager/ssl/nsSTSPreloadList.inc
$ grep -v '^/' public_suffix_list.dat | grep . | sed -e 's/$/\./' | sort &gt; psl
$ sed -n -e 's/^\([^, ]*\), .*/\1\./p' nsSTSPreloadList.inc &gt; hsts
$ comm -1 -2 hsts psl | wc -l
73
$ </pre></div>
<p>That is, websites registered under any of these 73
prefixes, such as, e.g.,
<code>.app</code> or <code>.dev</code>, will always use HTTPS
when using the common, popular browsers that consume
this list.</p>
<h2 id="summary">Summary</h2>
<p>Well, there you go. Top-level domains are, it
turns out, a lot more complicated than what we
commonly think of. The internet being a truly global
network of networks with varied jurisdictions being in
control of parts of the whole continues to provide for
curious challenges and -- as anybody working in tech
knows -- you regularly run into weird scenarios that
trace back to the DNS.</p>
<p>Sometimes all the way to the<br>
<code style="white-space:nowrap;">toptoptoptoptoptoptoptoptoptoptoptoptoptoptoptoptoptoptoptop.top</code>.</p>
<p><small>August 12th, 2021</small></p>
<hr class="noshade" style="width:90%;">
<p><small>See also:</small></p>
<ul>
<li><small>Discussions</small>:</small>
<ul>
<li><small>Discussion on <a href="https://news.ycombinator.com/item?id=28166363">HackerNews</a></small></li>
<li><small>Discussion on <a href="https://lobste.rs/s/0ihysv">Lobsters</a> (using <code>.rs</code>!)</small></li>
<li><small>Discussion on <a href="https://www.reddit.com/r/programming/comments/p3ijvd/tlds_putting_the_fun_in_the_top_of_the_dns/">Reddit</a></small></li>
</ul>
</li>
<li><small>Additional resources:</small>
<ul>
<li><small><a href="/tldstats/">TLD Stats by domain count</a></small></li>
<li><small><a href="whois.html">WHOIS: Fragile, unparseable, obsolete... and universally relied upon</a></small></li>
<li><small><a href="hostnames.html">What's in a hostname?</a></small></li>
<li><small><a href="dns-rrs.html">(All) DNS Resource Records</a></small></li>
<li><small><a href="urls.html">URLs: It's complicated...</a></small></li>
<li><small><a href="email.html">Your E-Mail Validation Logic is Wrong</a></small></li>
<li><small><a href="dnssec-dane.html">New Adventures in DNSSEC and DANE</a></small></li>
<li><small><a href="doh-dot-dnssec.html">DNS Security: Threat Modeling DNSSEC, DoT, and DoH</a></small></li>
<li><small>Video series: The Domain Name System, <a href="https://youtu.be/-bpIT7M9i00">Part I</a>, <a href="https://youtu.be/z55ULZcKP8A">Part II</a>, <a href="https://youtu.be/XDJEJFVNoko">Part III</a></small></li>
<li><small><a href="nsauth-diversity.html">Who controls the internet?</a></small></li>
<li><small><a href="mx-diversity.html">Who reads your email?</a></small></li>
<li><small><a href="https://github.com/jschauma/tld-zoneinfo">Collected information about how to retrieve different zone data</a></small></li>
</ul>
</li>
</ul>
</td>
</tr>
</table>
<hr class="noshade" style="width:100%;">
<small>
&larr;[<a href="ddg-tor.html">DuckDuckGo Onion Search for Firefox</a>]
<div style="float: right;">[<a href="return-printf.html">There is no 'printf'.</a>] &rarr;</div>
</small>
<hr class="noshade" style="width:100%;">
<small>
[<a href="../index.html">homepage</a>]&nbsp;
[<a href="index.html">blog</a>]&nbsp;
[<a href="mailto:jschauma@netmeister.org">jschauma@netmeister.org</a>]&nbsp;
[<a href="https://mstdn.social/@jschauma">@jschauma</a>]&nbsp;
[<a href="rss.xml">RSS</a>]
</small>
<div class="container">
<label class="switch" for="theme-checker" title="Dark/Light mode">
<span class="slider round"></span>
</label>
</div>
<hr class="noshade" style="width:100%;">
</body>
</html>