617 lines
31 KiB
Markdown
617 lines
31 KiB
Markdown
# TLDs — Putting the ‘.fun’ in the top of the DNS
|
||
|
||
- **期号**: SRE Weekly Issue #285(2021-08-29)
|
||
- **作者**: Jan Schaumann
|
||
- **链接**: https://www.netmeister.org/blog/tlds.html
|
||
|
||
## 简介
|
||
|
||
> .io, assigned to the British Indian Ocean Territory is almost exclusively used by annoying startups for content completely unrelated to the islands.
|
||
|
||
Remember, it’s all fun and games until the random country you’ve attached your business to has an outage in their TLD DNS infrastructure.
|
||
|
||
## 正文
|
||
|
||
[
|
||
|
||
| August 12th, 2021 The Domain Name System or DNS is a never-ending source of amusement and amazement. If you have been dealing with just about anything related to operations on the internet, you know that it's always the DNS in the end, what with its [almost 100 different resource records](https://www.netmeister.org/dns-rrs.html) and, uhm, shall we say, "interesting"[security threat model](https://www.netmeister.org/doh-dot-dnssec.html) . But today, let's talk about *Top-Level Domains* , or*TLD* s. You know,`.com` ,`.org` ,`.net` ,`.gov` ,`.vermögensberatung` and`.香港` - those guys. As you know, the entire domain*name space* consists of a tree of*domain names* ; the (common) root of the DNS tree is`.` (dot), and the tree sub-divides into*zones* consisting of*domains* and*sub-domains* :  Okay, so far, so good. With [RFC920](https://datatracker.ietf.org/doc/html/rfc920) , we got the initial set of top level domains: Oh, and: `.arpa` |
|
||
|
||
| [.gov](https://home.dotgov.gov/) | Government, any government related domains meeting the second level requirements. |
|
||
| [.edu](https://net.educause.edu/) | Education, any education related domains meeting the second level requirements. |
|
||
| [.com](https://www.verisign.com/en_US/domain-names/com-domain-names/index.xhtml) | Commercial, any commercial related domains meeting the second level requirements. |
|
||
| [.mil](https://www.iana.org/domains/root/db/mil.html) | Military, any military related domains meeting the second level requirements. |
|
||
| [.org](https://thenew.org/org-people/) | Organization, any other domains meeting the second level requirements. |
|
||
| [.net](https://www.verisign.com/en_US/domain-names/net-domain-names/index.xhtml) | Initially intended for network organizations; not mentioned in RFC920, but created in 1985 |
|
||
|
||
| [.arpa](https://www.iana.org/domains/arpa) | *Temporary* ; The current ARPA-Internet hosts. |
|
||
|
||
|
||
That's right: `.arpa` was *[supposed
|
||
to be temporary](https://www.netmeister.org/twitter/713903333375868928)*:
|
||
|
||
"After a short period of initial experimentation, all
|
||
current ARPA-Internet hosts will select some domain
|
||
other than ARPA for their future use. The use of ARPA
|
||
as a top level domain will eventually cease." -- [RFC920](https://datatracker.ietf.org/doc/html/rfc920)
|
||
|
||
Yeah, well, we all know how [temporary](https://www.netmeister.org/twitter/450441590302318592)
|
||
temporary solutions are. And so today, we continue
|
||
to use `.arpa` for, e.g., reverse mapping of IP
|
||
addresses to names via the `.in-addr.arpa` and
|
||
`.ip6.arpa` second-level domains. But
|
||
`.arpa` is used for a lot more:
|
||
`as112.arpa` ([RFC7535](https://www.rfc-editor.org/rfc/rfc7535.html),
|
||
effectively [RFC1918](https://www.rfc-editor.org/rfc/rfc1918)
|
||
reverse resolution; see also [https://www.as112.net/](https://www.as112.net/)),
|
||
`e164.arpa` ([RFC6116](https://www.rfc-editor.org/rfc/rfc6116.html)
|
||
/ [NAPTR](https://www.netmeister.org/dns-rrs.html#naptr) records),
|
||
`home.arpa` ([RFC8375](https://www.rfc-editor.org/rfc/rfc8375.html),
|
||
non-unique use in residential home network),
|
||
`in-addr-servers.arpa` and
|
||
`ip6-servers.arpa` ([RFC5855](https://www.rfc-editor.org/rfc/rfc5855.html),
|
||
name servers for the `in-addr.arpa` and
|
||
`ip6.arpa` domains), `ipv4only.arpa`
|
||
([RFC7050](https://www.rfc-editor.org/rfc/rfc7050.html),
|
||
detecting DNS64 and IPv6 Prefixes),
|
||
`iris.arpa` ([RFC4698](https://www.rfc-editor.org/rfc/rfc4698.html),
|
||
for locating Internet Registry Information Services),
|
||
as well as `uri.arpa` and `urn.arpa`
|
||
([RFC3405](https://www.rfc-editor.org/rfc/rfc3405.html)
|
||
for resolving Uniform Resource Identifiers / [NAPTR](https://www.netmeister.org/dns-rrs.html#naptr)).
|
||
|
||
Note: the `arpa` zone is served from
|
||
all root servers except the [J Root](https://j.root-servers.org/), which,
|
||
per [RFC2870](https://datatracker.ietf.org/doc/html/rfc2870),
|
||
should not "provide secondary service for any zones
|
||
other than the root and root-servers.net zones".
|
||
Noted on [dns-operations@dns-oarc.net](https://lists.dns-oarc.net/pipermail/dns-operations/2021-December/021486.html).
|
||
|
||
`ccTLDs`
|
||
In addition to
|
||
these original TLDs, we also got the [country
|
||
code top-level domains](https://en.wikipedia.org/wiki/Country_code_top-level_domain), or *ccTLD*s:
|
||
|
||
The English two letter code (alpha-2) identifying a
|
||
country according the the ISO Standard for "Codes for
|
||
the Representation of Names of Countries". -- [RFC920](https://datatracker.ietf.org/doc/html/rfc920)
|
||
|
||
And this is where the fun begins, because of course
|
||
you are *always* operating on Layer 9, and
|
||
this list is necessarily somewhat fluid, as countries
|
||
change, are born, divided, or cease to exist:
|
||
|
||
[.ss](https://nic.ss/)
|
||
[.ge](https://nic.ge/)
|
||
[ISO-3166-1
|
||
Alpha 2 country code](https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2#GE) that previously used to
|
||
represent the Gilbert and Ellice Islands; the Ellice
|
||
Islands became Tuvalu, which, per country code
|
||
designation, got the rather valuable[.tv](https://www.verisign.com/en_US/domain-names/tv-domain-names/index.xhtml)
|
||
This TLD became so valuable that at some point 10% of the country's revenue came from royalties of`.tv` domains; Tuvalu used the money for the
|
||
marketing rights to allow them to pay the membership
|
||
dues for United Nations when they joined the UN in
|
||
2000!
|
||
- `.eh` has been reserved (but not been
|
||
assigned yet) as the ccTLD for the disputed "Western
|
||
Sahara" territory; in 2013, on April 1st,[CIRA](https://www.cira.ca/) , the Canadian
|
||
Internet Registration Authority (responsible for`.ca` ), announced that it would offer`.eh` names, because, you know, Canadians would
|
||
like that, eh?
|
||
- Some ccTLDs represent countries that other
|
||
countries don't acknowledge as existing. [.ps](https://www.pnina.ps/)
|
||
[PostScript](https://en.wikipedia.org/wiki/PostScript) programming language), recognized by[138
|
||
of the 193 UN members](https://en.wikipedia.org/wiki/International_recognition_of_the_State_of_Palestine) ;[.tw](https://rs.twnic.net.tw/)
|
||
[mere 14 countries recognize](https://worldpopulationreview.com/country-rankings/countries-that-recognize-taiwan) .
|
||
- Not all *cc* TLDs represent actual*countries* : Hong Kong has a ccTLD,[.hk](https://www.hkdnr.hk/en/)
|
||
[.mo](https://www.monic.mo)
|
||
[.uk](https://www.nominet.uk/)
|
||
`.gb` is assigned to Great Britain; England[doesn't even get a
|
||
ccTLD](http://doteng.org/) , and neither does Northern Ireland!
|
||
Similarly,[.eu](https://eurid.eu/en/)
|
||
`.eu` domains had their domains
|
||
suspended on January 1st, 2021, requiring proof of*European Economic Area* (EEA) citizenship to
|
||
avoid them being deleted in March 2021.
|
||
- When a country ceases to exist, its ccTLD is
|
||
normally retired:`.cs` (Czechoslovakia) became[.cz](https://www.nic.cz/)
|
||
[.sk](https://sk-nic.sk/)
|
||
`.dd` (East Germany) disappeared after the
|
||
reunification of Germany;`.yu` (Yugoslavia)
|
||
became[.si](https://www.registry.si)
|
||
[.hr](https://www.domene.hr/)
|
||
`.cs` assigned (but never used that, instead continuing to
|
||
use`.yu` ) before*they* split into[.rs](https://www.rnids.rs/en/)
|
||
[.me](https://domain.me/)
|
||
`.zr` (Zaire) became[.cd](https://conic.africa/)
|
||
However,[.su](http://www.fid.su/)
|
||
|
||
With ccTLDs having appealing two-letter names (gTLDs are a minimum of three characters), they lend themselves to so-called "domain hacks" to create words, to shorten URLs, or as a convenient way to jump on a popular trend, and many people began registering names in other countries' ccTLDs:
|
||
|
||
[.ag](http://www.nic.ag/)
|
||
`.ag` names for other entities may[even
|
||
carry legal risks](https://www.jurpc.de/jurpc/show?id=20040262) .
|
||
[.ai](http://nic.com.ai/)
|
||
`.ai` also
|
||
is notable in that as a TLD it nevertheless has both
|
||
an`A` and`MX` record, meaning you could
|
||
have a functional email address like`hal@ai` .
|
||
([Email addresses are difficult to
|
||
validate, it turns out.](https://www.netmeister.org/email.html) )
|
||
[.am](https://www.amnic.net/)
|
||
[instagr.am](https://instagr.am)
|
||
[.at](https://www.nic.at/en)
|
||
[donteat.at](http://donteat.at/)
|
||
[.be](https://www.dnsbelgium.be/)
|
||
[youtu.be](https://youtu.be) links.
|
||
[.by](https://www.cctld.by/)
|
||
*Bayern* )
|
||
[.cm](https://netcom.cm)
|
||
[.co](https://www.go.co/)
|
||
- `.cx` was assigned to the Christmas Island,
|
||
and appears currently to be defunct, but it did have
|
||
the significant glory of once having been the home of`goatse.cx` ([Wikipedia](https://en.wikipedia.org/wiki/Goatse.cx) ).
|
||
[.im](https://www.nic.im/home.mth)
|
||
[.io](https://www.nic.io/)
|
||
[.la](https://www.la/)
|
||
[mzl.la](https://mzl.la) or Tesla's[ts.la](https://ts.la)
|
||
[.me](https://domain.me/)
|
||
`cg.yu` ) became one of the most popular TLDs
|
||
and is used for link shorteners like Facebook's[fb.me](https://fb.me) , Google's[g.me](https://g.me) or GoDaddy's[go.me](https://go.me) .
|
||
Yahoo used to use`me.me` for its "[Yahoo!
|
||
Meme](https://en.wikipedia.org/wiki/Yahoo!_Meme) microblogging site"; after it shut that
|
||
service, it returned the domain to the registry, and
|
||
it's now, what else, a[Meme
|
||
search engine](https://me.me) .
|
||
[.ms](https://www.mninet.ms/)
|
||
[nyti.ms](https://nyti.ms) link
|
||
shortener.
|
||
- Python nerds on the internet register names in
|
||
Paraguy's ccTLD ([.py](https://www.nic.py/)
|
||
[.rs](https://www.rnids.rs/en/)
|
||
- The editor wars have been decided at the TLD
|
||
level: [.vi](https://secure.nic.vi/)
|
||
`.emacs` does not
|
||
(`emacs.vi` , however, does).
|
||
|
||
Now one noteworthy aspect here is that since the
|
||
ccTLDs are administered by the given country, they may
|
||
be subject to (and enforce) different requirements.
|
||
Some domains can only be registered by entities
|
||
residing within the given country, others, like the
|
||
[.cat](https://domini.cat/)[dotCAT
|
||
foundation](https://xn--fundaci-r0a.cat/) to promote the Catalan language, may
|
||
stipulate the language or content of the domains.
|
||
|
||
Lybia, with the ever so popular [.ly](https://www.nic.ly/)[Violet
|
||
Blue](https://twitter.com/violetblue)'s `vb.ly` domain, [objecting
|
||
to the content](https://www.pcmag.com/archive/libya-seizes-url-shortener-vbly-255360). In a similar manner, Colombia
|
||
could choose to break just about all of Twitter (which
|
||
uses the [t.co](https://t.co)[goo.gl](https://goo.gl)
|
||
links.
|
||
|
||
In addition to the original TLDs and the
|
||
ccTLDs, in the late 1980s InterNIC added
|
||
`.nato`, but that was later replaced by
|
||
`.nato.int`, with the new `.int` TLD
|
||
being added in 1988 for intergovernmental
|
||
organizations.
|
||
|
||
In 2000, [ICANN](https://www.icann.org/), who had by
|
||
then taken over the administration of domain names,
|
||
added seven more TLDs: [.aero](https://information.aero/)[.biz](https://registry.godaddy/)[.coop](https://identity.coop/)[.info](https://afilias.info/)[.museum](https://welcome.museum/)[.name](https://www.verisign.com/en_US/domain-names/name-domains/index.xhtml)[.pro](https://registry.pro/)[sponsored
|
||
top-level domains](https://en.wikipedia.org/wiki/Sponsored_top-level_domain)" (sTLDs), but only received a
|
||
handful of proposals, ultimately adding [.asia](https://www.dot.asia/)[.cat](https://domini.cat/)[.jobs](https://secure.jobs/)[.mobi](https://dotmobi.mobi/)[.post](https://www.upu.int/en/Universal-Postal-Union/Activities/Digital-Services/-POST-Domain)[.tel](https://www.do.tel/)[.travel](https://www.travel.domains/)[.xxx](https://icmregistry.com/)
|
||
|
||
Sponsored TLDs being somewhat restricted in scope
|
||
and use, ICANN then went for another round of
|
||
accepting proposals for new, *generic* TLDs
|
||
(gTLDs), this time with a price tag of $185,000 per
|
||
TLD. In 2012, it processed 1,930 applications: 101
|
||
from Google (under the name [Charleston Road
|
||
Registry Inc.](https://www.registry.google/) ([see
|
||
also](https://www.netmeister.org/twitter/992417858226450432)), including [`.lol`,
|
||
`.google`, `.dog`, and `.foo`](https://blog.google/inside-google/company-announcements/expanding-internet-domain-space/)
|
||
(`.lol` was ultimately registered by [Uniregistry](https://en.wikipedia.org/wiki/Uniregistry), now owned by GoDaddy), 76 from Amazon, 11 from Microsoft and 307
|
||
from the "[Donuts](https://donuts.domains/)" domain name
|
||
registry.
|
||
|
||
The list of ultimately approved domains included a
|
||
number of geographic TLDs (*geoTLD*s), adding
|
||
domains for certain cities (e.g., [.berlin](https://dot.berlin/)[.london](https://domains.london/)[.nyc](https://www.ownit.nyc/)[.paris](http://bienvenue.paris)[.tokyo](https://hello.tokyo/)[.cymru](https://www.nominet.uk/)[.scot](https://dot.scot/)[.wales](https://www.nominet.uk/)*still* doesn't get its own
|
||
TLD, while, e.g., New Zealand ([.nz](https://dnc.org.nz/)[.kiwi](https://hello.kiwi/)[.africa](https://registry.africa/)[.lat](https://www.nic.lat/)
|
||
|
||
But of course people went a bit nuts, too: many
|
||
brands applied for `.<brand>` and got
|
||
into various arguments over who should own the given
|
||
TLD. For example, [Amazon](https://www.amazon.com) applied for
|
||
(and was given) [.amazon](https://www.amazonregistry.com/)[objection
|
||
of several nations of, well, the Amazon](https://www.bbc.com/news/business-47794353); and
|
||
multiple applications for entirely generic terms had
|
||
to be [sorted
|
||
out](https://gtldresult.icann.org/applicationstatus/stringcontentionstatus).
|
||
|
||
One of those was the [.secure](https://nic.secure/)[Alex
|
||
Stamos](https://en.wikipedia.org/wiki/Alex_Stamos) of (then) Artemis Internet as a TLD that
|
||
would enforce [certain
|
||
minimum security requirements](https://arstechnica.com/information-technology/2012/05/my-own-private-internet-secure-tld-floated-as-bad-guy-free-zone/); ultimately,
|
||
`.secure` was assigned to Amazon.
|
||
|
||
Eventually, [ICANN
|
||
added 1239 new TLDs](https://newgtlds.icann.org/en/program-status/delegated-strings) to the DNS, bestowing upon us
|
||
such important TLDs as, e.g., `.beer`,
|
||
`.cloud`, `.dot`, `.duck`,
|
||
`.foo`, `.google`, `.rocks` and
|
||
`.sucks`, `.travelersinsurance`, and
|
||
`.yahoo`.
|
||
|
||
But of course some TLDs then go under again: [.wed](https://icannwiki.org/.wed)[ICANN
|
||
EBERO](https://www.icann.org/resources/pages/ebero-2013-04-02-en) and some names remain in use (e.g., [get.wed](https://get.wed/index.html), albeit
|
||
with an invalid certificate).
|
||
|
||
Finally, the perhaps most generic TLD,
|
||
`.gdn` (Global Domain Name) was added in
|
||
2014.
|
||
|
||
Even before the landrush for the new gTLDs, ICANN
|
||
approved the introduction of [internationalized
|
||
domain name](https://en.wikipedia.org/wiki/Internationalized_domain_name) (IDN) TLDs, and many ccTLDs added TLDs
|
||
using their respective languages and alphabets
|
||
(including right-to-left!), represented within the DNS
|
||
using [Punycode](https://en.wikipedia.org/wiki/Punycode).
|
||
|
||
| **DNS name** | **IDN ccTLD** | **Country/Region** | **Language** | **Other ccTLD** |
|
||
| xn--lgbbat1ad8j | .الجزائر | Algeria | Arabic | `.dz` |
|
||
| xn--fiqs8s | .中国 | China | Chinese (Simplified) | `.cn` |
|
||
| xn--qxa6a | .ευ | European Union | Greek | `.eu` |
|
||
| xn--4dbrk0ce | .ישראל | Israel | Hebrew | `.il` |
|
||
| xn--o3cw4h | .ไทย | Thailand | Thai | `.th` |
|
||
|
||
(See [Wikipedia's
|
||
full table](https://en.wikipedia.org/wiki/Country_code_top-level_domain#Internationalized_ccTLDs) for all IDN ccTLDs.)
|
||
|
||
But IDNs are not only for ccTLDs: many of the new
|
||
gTLDs also include various Unicode characters, such
|
||
as, e.g., `.сайт`
|
||
("website"),
|
||
`.大众汽车`
|
||
("volkswagen"),
|
||
`.ファッション`
|
||
("fashion"),
|
||
`ابوظبي.`
|
||
("Abu Dhabi"), and, of course,
|
||
`.vermögensberatung` ("wealth management /
|
||
advice").
|
||
|
||
Note that with IDNs, you can mix an IDN
|
||
second-level with a non-IDN top-level or vice versa.
|
||
Due to the resulting [IDN
|
||
Homograph Attack](https://en.wikipedia.org/wiki/IDN_homograph_attack) vector, browsers [stopped
|
||
rendering the IDNs](https://web.archive.org/web/20110102051140/http://blogs.msdn.com/b/ie/archive/2006/07/31/684337.aspx) and now always [display them as
|
||
Punycode](https://www.wordfence.com/blog/2017/04/chrome-firefox-unicode-phishing/).
|
||
|
||
In addition to all that, there is also a small
|
||
number of so-called "special use domains", of which
|
||
`.arpa` (already [discussed
|
||
above](https://www.netmeister.org#arpa)) is just one. These are:
|
||
|
||
- `.example` -- intended for use in
|
||
documentation, tutorials, and testing; defined,
|
||
together with`example.com` ,`example.net` , and`example.org` in[RFC6761](https://datatracker.ietf.org/doc/html/rfc6761) .
|
||
- `.invalid` and`.test` -- for testing and
|
||
documentation, originally defined in[RFC2606](https://datatracker.ietf.org/doc/html/rfc2606) .
|
||
- `.local` -- usually used for
|
||
zero-configuration networking ([RFC6762](https://datatracker.ietf.org/doc/html/rfc6762) ).
|
||
- `.localhost` -- reserved since
|
||
traditionally`.localhost` existed in, e.g.,`/etc/hosts` for the loopback address ([RFC2606](https://datatracker.ietf.org/doc/html/rfc2606) ).
|
||
Note:`.localdomain` is*not* reserved,
|
||
and use of`localhost.localdomain` can lead to
|
||
unexpected results if your stub resolver expands
|
||
this.
|
||
- `.onion` -- used by[Tor](https://www.torproject.org/) ([.onion
|
||
service address](http://2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion/) ) and defined in[RFC7686](https://datatracker.ietf.org/doc/html/rfc7686) .
|
||
Note: this "TLD" is*not* entered into the DNS,
|
||
but following work by[Jim McCoy](https://twitter.com/mccoy) and[Alec
|
||
Muffett](https://twitter.com/alecmuffett) leading to[CA/B
|
||
Forum Ballot 144](https://cabforum.org/2015/02/18/ballot-144-validation-rules-dot-onion-names/) , you*can* get a valid
|
||
x509 certificate from public CAs. (For a while, Tor
|
||
also used to use the[.exit](<https://en.wikipedia.org/wiki/.onion#.exit_(defunct_pseudo-top-level_domain)>)
|
||
- Not all networks may use the standard DNS root
|
||
([ICANN
|
||
is not pleased](https://www.icann.org/resources/pages/unique-authoritative-root-2012-02-25-en) ),
|
||
and so of course all bets are off if you are on a
|
||
network using an[alternative
|
||
DNS root](https://en.wikipedia.org/wiki/Alternative_DNS_root) . Some TLDs in such networks include(d)[.bitnet](https://en.wikipedia.org/wiki/BITNET)
|
||
[.csnet](https://en.wikipedia.org/wiki/.csnet)
|
||
[.oz](https://en.wikipedia.org/wiki/MHSnet)
|
||
`.oz.au` ),[.uucp](https://en.wikipedia.org/wiki/UUCP)
|
||
[.i2p](https://en.wikipedia.org/wiki/I2P)
|
||
- Some TLDs are effectively split-horizon, only
|
||
exposing some parts to the public internet.
|
||
`.kp` , the ccTLD assigned for North Korea
|
||
serves the North Korea internal-only[Kwangmyong
|
||
network](<https://en.wikipedia.org/wiki/Kwangmyong_(network)>) .
|
||
- China uses the [.chn](https://zh.wikipedia.org/wiki/.chn)
|
||
[for
|
||
its Internet of Things](http://www.chinaiptoday.com/post.html?id=405) . This domain relies on the
|
||
use of an alternate DNS root as well, and is*not* found in the common root.
|
||
|
||
The DNS is an inherently *public* system
|
||
(modulo alternate root shenenigans or split-horizon
|
||
games). The [root zone
|
||
itself](https://www.iana.org/domains/root/db) continues to be available for download via
|
||
[FTP](ftp://rs.internic.net/domain/root.zone)
|
||
or [HTTPS](https://www.internic.net/domain/root.zone)
|
||
and so we can easily extract the full count of all
|
||
TLDs:
|
||
|
||
```
|
||
$ curl https://www.internic.net/domain/root.zone |
|
||
awk '{if ($4 == "NS") { print $1;}}' | sort -u | wc -l
|
||
1499
|
||
```
|
||
Processing the simple zone file, we find that most
|
||
TLDs are two- (248) or three- (222) letter TLDs;
|
||
that there are 154 IDN TLDs; that there are TLDs
|
||
starting with every letter of the alphabet ('s'
|
||
being the most popular one); that the longest TLD is
|
||
`vermögensberatung` (24
|
||
characters in punycode:
|
||
`xn--vermgensberatung-pwb`).
|
||
|
||
But what about all the individual TLD zone files?
|
||
Since that data is also public in nature, we should be
|
||
able to get and process it as well. And for the ICANN
|
||
assigned new gTLDs, this is indeed the case: ICANN
|
||
offers the [Centralized Zone Data
|
||
Service](https://czds.icann.org/), where you can apply to gain access to all
|
||
gTLD zone files. For some domains the access is
|
||
granted almost instantly, for others it takes a few
|
||
days.
|
||
|
||
Now for the ccTLDs, however, there unfortunately is
|
||
*no* equivalent service, although there's a
|
||
(rather short) list of ccTLD zone sources [here](https://jpmens.net/2021/05/18/dns-open-zone-data/) as well as [here](https://github.com/jschauma/tld-zoneinfo);
|
||
some registries let you `AXFR` the domain
|
||
(e.g., [.ee](https://www.internet.ee/domains/ee-zone-file)[.ch](https://www.switch.ch/open-data/#tab-c5442a19-67cf-11e8-9cf6-5254009dc73c-3)[.li](https://www.switch.ch/open-data/#tab-c5442a19-67cf-11e8-9cf6-5254009dc73c-3)[.se](https://zonedata.iis.se/)[.nu](https://zonedata.iis.se/)[sk](https://sk-nic.sk/subory/domains.txt)[.gov](https://home.dotgov.gov/data/)[here](https://github.com/jschauma/tld-zoneinfo).)
|
||
|
||
Given how difficult it is to get to all the public
|
||
data, it's then no surprise that several businesses
|
||
are making good money by [selling you
|
||
that access](https://zonefiles.io/cctld-domains/) or by providing [TLD
|
||
reports](https://stats.centr.org/stats/global).
|
||
|
||
After having requested access to all gTLD zone
|
||
files and having received most of them (several are
|
||
still pending), I looked around a bit, seeking
|
||
entertaining stats. One thing to note is that a
|
||
large number of zones (230) do not have *any* names
|
||
defined (other than, say, a NIC `NS` record) --
|
||
TLDs registered purely as a brand or placeholder, I
|
||
suspect. Over 360 zones have fewer than 10 records,
|
||
over 470 fewer than 100.
|
||
|
||
Zones that *are* actually used include the
|
||
expected variety of silly names, including very long
|
||
domain names:
|
||
|
||
accountantaccountantaccountantaccountantaccountantaccountant.accountant
|
||
artartartartartartartartartartartartartartartartartartartartart.art
|
||
yoyoyodogillbestraightwithyouicanttellifthatsatattoooranartisti.art
|
||
barbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbarbar.bar
|
||
clickclickclickclickclickclickclickclickclickclickclickclick.click
|
||
ahndung-von-verkehrsordnungswidrigkeiten-mit-unfallfolge.cologne.
|
||
0-------------------------------------------------------------0.com.
|
||
thelongestdomainnameintheworldliterallynobodycangetalongeronexd.community
|
||
you-know-you-are-pretty-gosh-darned-cute-do-you-wanna-go-on-a.date.
|
||
lololololololololololololololololololololololololololololololol.fun.
|
||
gayfriendlyconvenientaffordabletrendyhairsalonsindowntowntoront.mobi
|
||
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww.org
|
||
partypartypartypartypartypartypartypartypartypartypartyparty.party
|
||
runrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrunrun.run
|
||
thehighestthemostvaluableandthemostexpensivedomainnameofalltime.top
|
||
this-crazy-url-is-definitely-one-of-the-longest-adresses-in-the.world.
|
||
rindfleischetikettierungsuberwachungsaufgabenubertragungsgesetz.xyz
|
||
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.xyz.
|
||
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz.zone
|
||
|
||
...and so on and so on. Per [RFC1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4),
|
||
the maximum size of a DNS label is 63 octets (note:
|
||
*octets*, not *characters*, which is why
|
||
the [maximmum
|
||
length of a domain name is 253 characters](https://devblogs.microsoft.com/oldnewthing/20120412-00/?p=7873)), which
|
||
explains why there are no *longer* second-level
|
||
domains, although it doesn't explain why people insist
|
||
on registering over 1700 such names.
|
||
|
||
Of the 987 zones I looked at, the top ten zones based on number of domains were:
|
||
|
||
| **Rank** | **TLD** | **# of domains** |
|
||
| 1 | `.com` | 155,883,253 |
|
||
| 2 | `.net` | 13,291,304 |
|
||
| 3 | `.org` | 10,424,321 |
|
||
| 4 | `.info` | 3,859,083 |
|
||
| 5 | `.xyz` | 3,128,897 |
|
||
| 6 | `.online` | 1,811,807 |
|
||
| 7 | `.top` | 1,200,953 |
|
||
| 8 | `.site` | 1,067,408 |
|
||
| 9 | `.shop` | 907,239 |
|
||
| 10 | `.app` | 722,140 |
|
||
|
||
You can find a more complete breakdown of regularly
|
||
updated statistics for all TLDs [here](https://www.netmeister.org/tldstats/).
|
||
|
||
(Note that not all TLDs are treated the same across
|
||
the internet. Despite being rather popular, the
|
||
`.xyz` domain appears to have a poor score in
|
||
many automated domain reputation systems, which may
|
||
lead to [all
|
||
sorts of unexpected problems](https://www.spotvirtual.com/blog/the-perils-of-an-xyz-domain/) for your
|
||
business.)
|
||
|
||
For my own entertainment, I wrote a [shabby little perl script](https://www.netmeister.org/misc/zonestats.pl) to run over a
|
||
zone file and produce some additional numbers:
|
||
|
||
$ gzcat net.txt.gz | perl -T zonestats.pl
|
||
Total number of records: 34658946
|
||
Total number of names: 13291304
|
||
Total number of different record types: 7
|
||
ns: 32819414
|
||
rrsig: 759035
|
||
ds: 414744
|
||
nsec3: 379518
|
||
a: 270671
|
||
aaaa: 15543
|
||
soa: 1
|
||
Top ten name lengths:
|
||
9: 2839977
|
||
10: 2836099
|
||
8: 2783467
|
||
11: 2648213
|
||
7: 2496883
|
||
12: 2404541
|
||
6: 2205730
|
||
13: 2159827
|
||
14: 1886160
|
||
15: 1585087
|
||
Longest name: 000000000000000000000000000000000000000000000000000000000000001.net. (63)
|
||
There are 134 names with 63 chars in this domain.
|
||
Total number of unique name servers: 689703
|
||
The three most popular name servers found in this zone are:
|
||
dns1.registrar-servers.com.: 298617
|
||
dns2.registrar-servers.com.: 298352
|
||
jm2.dns.com.: 239693
|
||
The most popular domains in which the nameservers are:
|
||
domaincontrol.com: 6200836
|
||
googledomains.com: 1485364
|
||
dns.com: 908420
|
||
This domain contains names including the following dirty words:
|
||
shit: 8732
|
||
fuck: 8057
|
||
tits: 2351
|
||
piss: 844
|
||
cunt: 575
|
||
motherfucker: 86
|
||
cocksucker: 16
|
||
$
|
||
|
||
The "[seven
|
||
dirty words](https://en.wikipedia.org/wiki/Seven_dirty_words)" domains are of course full of
|
||
mismatches, but it looks like most zones contain
|
||
more or less the same percentage of dirty domain
|
||
names: somewhere between 0.006% and 0.008% of the
|
||
total; `.xxx` predictably ranks a bit higher
|
||
here, but not all that much at only 0.1% of all
|
||
names.
|
||
|
||
Now all of the above is good fun, but why would you want to know whether a given string is a TLD? Wouldn't it be trivially the right-most label of the fully-qualified domain name (FQDN)?
|
||
|
||
Strictly speaking: yes. However, consider that
|
||
many TLDs are not generic in nature, meaning people
|
||
cannot simply register *any* name under the
|
||
given TLD. ccTLDs, being managed by individual
|
||
registries, each may have unique requirements and
|
||
regulations, and it is a common practice for these
|
||
registries to enforce a [second-level
|
||
domain hierarchy](https://en.wikipedia.org/wiki/Second-level_domain), replicating or mirroring to some
|
||
degree the top-level hierarchy.
|
||
|
||
For example, and perhaps most widely known, the
|
||
`.uk` TLD uses `.ac.uk` (for academic
|
||
institutions), `.co.uk` (for commercial
|
||
entities), `.gov.uk`, `.net.uk`,
|
||
`.org.uk`, and so on. How many such
|
||
second-level domains are reserved depends on each TLD;
|
||
Brazil (`.br`), for example, has [over
|
||
100](https://registro.br/dominio/categorias/).
|
||
|
||
Now within the context of, for example, HTTP
|
||
cookies or x509 TLS certificates, it's rather
|
||
important that an entity cannot use a wildcard to
|
||
match an entire TLD, but how does a browser know
|
||
whether 
|
||
|
||
`foo.example` is a reserved
|
||
second-level domain, or simply a normal domain
|
||
registered by some entity? Should a website be able to
|
||
set a cookie for `foo.example`? Should it be
|
||
able to get a certificate for
|
||
`*.foo.example`? There is no programmatic way
|
||
to determine this.
|
||
|
||
To solve this problem, the good folks over at
|
||
Mozilla started putting together a list of these TLDs
|
||
and "effective TLDs", known as the [Public Suffix
|
||
List](https://publicsuffix.org/). That's right, it's another one of those
|
||
manually compiled and maintained text files we like to
|
||
build the internet infrastructure on!
|
||
|
||
[This
|
||
lists](https://publicsuffix.org/list/public_suffix_list.dat) consists of over 9,000 prefixes, and is used
|
||
by all of the popular browsers to restrict cookie
|
||
scope as well as for various UI features.
|
||
|
||
Google uses [similar
|
||
heuristics](https://developers.google.com/search/docs/advanced/crawling/managing-multi-regional-sites#generic-domains) based on a domain name's TLD to
|
||
determine whether to offer users different language
|
||
versions of their content and other geo-targeting.
|
||
Within that context, Google treats some ccTLDs (such
|
||
as, e.g., `.io`, `.me`, `.tv`
|
||
etc.) as if they were gTLDs rather than as indicators
|
||
of geographic location.
|
||
|
||
Finally, the [HSTS Preload list](https://hstspreload.org/)
|
||
baked into browsers like Chrome and Firefox to enforce
|
||
[HTTP
|
||
Strict Transport Security](https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security) includes a number of
|
||
TLDs and public prefixes:
|
||
|
||
```
|
||
$ curl -O https://publicsuffix.org/list/public_suffix_list.dat
|
||
$ curl -O https://hg.mozilla.org/mozilla-central/raw-file/tip/security/manager/ssl/nsSTSPreloadList.inc
|
||
$ grep -v '^/' public_suffix_list.dat | grep . | sed -e 's/$/\./' | sort > psl
|
||
$ sed -n -e 's/^\([^, ]*\), .*/\1\./p' nsSTSPreloadList.inc > hsts
|
||
$ comm -1 -2 hsts psl | wc -l
|
||
73
|
||
$
|
||
```
|
||
That is, websites registered under any of these 73
|
||
prefixes, such as, e.g.,
|
||
`.app` or `.dev`, will always use HTTPS
|
||
when using the common, popular browsers that consume
|
||
this list.
|
||
|
||
Well, there you go. Top-level domains are, it turns out, a lot more complicated than what we commonly think of. The internet being a truly global network of networks with varied jurisdictions being in control of parts of the whole continues to provide for curious challenges and -- as anybody working in tech knows -- you regularly run into weird scenarios that trace back to the DNS.
|
||
|
||
Sometimes all the way to the
|
||
|
||
`toptoptoptoptoptoptoptoptoptoptoptoptoptoptoptoptoptoptoptop.top`.
|
||
|
||
August 12th, 2021
|
||
|
||
See also:
|
||
|
||
- Discussions:
|
||
|
||
- Discussion on [HackerNews](https://news.ycombinator.com/item?id=28166363)
|
||
- Discussion on [Lobsters](https://lobste.rs/s/0ihysv) (using`.rs` !)
|
||
- Discussion on [Reddit](https://www.reddit.com/r/programming/comments/p3ijvd/tlds_putting_the_fun_in_the_top_of_the_dns/)
|
||
- Discussion on
|
||
- Additional resources:
|
||
|
||
- [TLD Stats by domain count](https://www.netmeister.org/tldstats/)
|
||
- [WHOIS: Fragile, unparseable, obsolete... and universally relied upon](https://www.netmeister.org/whois.html)
|
||
- [What's in a hostname?](https://www.netmeister.org/hostnames.html)
|
||
- [(All) DNS Resource Records](https://www.netmeister.org/dns-rrs.html)
|
||
- [URLs: It's complicated...](https://www.netmeister.org/urls.html)
|
||
- [Your E-Mail Validation Logic is Wrong](https://www.netmeister.org/email.html)
|
||
- [New Adventures in DNSSEC and DANE](https://www.netmeister.org/dnssec-dane.html)
|
||
- [DNS Security: Threat Modeling DNSSEC, DoT, and DoH](https://www.netmeister.org/doh-dot-dnssec.html)
|
||
- Video series: The Domain Name System, [Part I](https://youtu.be/-bpIT7M9i00) ,[Part II](https://youtu.be/z55ULZcKP8A) ,[Part III](https://youtu.be/XDJEJFVNoko)
|
||
- [Who controls the internet?](https://www.netmeister.org/nsauth-diversity.html)
|
||
- [Who reads your email?](https://www.netmeister.org/mx-diversity.html)
|
||
- [Collected information about how to retrieve different zone data](https://github.com/jschauma/tld-zoneinfo)
|
||
|
||
←[
|