ICANN approves shutdown of 3rd-level .name domains, risking hijacks

On 28 July 2026, ICANN approved a Verisign proposal to eliminate the entire 3rd level of the '.name' domain hierarchy, a change that will strip 22,000 registrants of the domains they hold under it. Verisign, which operates the '.name' registry, had submitted the plan on 15 April 2026, describing it as a simplification of registry administration.

The decision surfaced through a blog post from one of the affected registrants, who says they registered their own 3rd-level domain, neil.fraser.name, nearly twenty-five years ago, before YouTube, Facebook or smartphones existed, and registered a matching domain, beverly.fraser.name, for their daughter minutes after she was born. The author learned of ICANN's approval only a few days before publishing the post on 3 September 2026, when their domain registrar emailed them, weeks after the decision had already been made.

The author draws a distinction between '.name' 3rd-level domains and the informally resold 3rd-level domains found under some country-code addresses. They point to *.uk.co as an example: it is controlled by a private individual who bought the 'uk' domain from the country of Colombia and resells third-level names beneath it, so that all of those domains vanish if that individual does. '.name', the author says, was built exclusively as a 3rd-level system: anyone can register an xxx.yyy.name address through any accredited registrar, and it carries its own full whois record, just like a *.co.uk or *.ny.us address. The author adds that they originally chose '.name' partly because it was run by Global Name Registry rather than Verisign, a company they distrusted from past dealings; Verisign later acquired Global Name Registry, and the author writes that this original distrust was borne out by 'numerous lies' in Verisign's proposal to ICANN, without saying what those were.

The author lists three direct effects on their own domain: the website will disappear in February, despite being registered and paid for until 2040; the associated email address will stop working; and any IoT devices that depend on services hosted at the domain will become unusable, what the author calls 'bricks.'

A further, longer-term risk follows: once the 3rd-level domains are terminated, the author writes, it is assumed that the 2nd-level domains beneath them, such as fraser.name, will become available for anyone to register. Should someone other than the author register fraser.name, the author warns, that person could recreate and control neil.fraser.name, potentially hijacking hundreds of accounts tied to that email address, committing code under the author's authentication, or seizing control of IoT devices linked to it. The author adds that there is no way to enumerate every account, online or offline, opened with that address over the past quarter century.

The post closes with the author noting they are just one of 22,000 people set to lose their domains this way, adding, dryly, that 'this is going to be fun' and that it is 'time to lawyer up.'

Key facts

  • ICANN approved Verisign's proposal to eliminate every 3rd-level '.name' domain on 28 July 2026; Verisign had submitted the plan on 15 April 2026, presenting it as a simplification of registry administration.
  • The change affects 22,000 registrants, including the blog's author, whose own domain, neil.fraser.name, held for nearly 25 years, will vanish in February even though it is registered and paid for until 2040.
  • Beyond the website, the author's email address at the domain will stop working, and IoT devices that rely on services hosted there will become unusable.
  • Once 3rd-level '.name' domains are terminated, the 2nd-level domains beneath them (such as fraser.name) are expected to become available for anyone to register, which the author warns could let a new owner hijack hundreds of accounts tied to the old email address and take control of linked IoT devices.
  • The author says they originally chose '.name' because it was run by Global Name Registry rather than Verisign, a company they distrusted; Verisign has since acquired Global Name Registry.

Why it matters

ICANN's approval lets a private registry retroactively end a domain tier that registrants had paid, in the case described, through 2040, with the change reaching at least one affected registrant only as a routine email from their registrar, weeks after ICANN had already approved it. The case illustrates how much of a person's online identity, a website, an email address, code commits, and IoT device authentication, can depend on a domain name that a third party can retire on a timeline the registrant does not control, regardless of how long the domain has been in continuous use or how far in advance it was paid for.

Who it affects

The 3rd-level domains being eliminated belong to 22,000 registrants, all of whom will lose the specific address they registered, in the case described in the post, one held for nearly 25 years and used for a website, an email address, and API services. The risk widens the affected group further: anyone, individual or organization, who has ever accepted that email address for account recovery, authentication, or verification over that quarter century is a potential target if the domain is later re-registered by someone else, a population the author says cannot even be fully enumerated.

How to use it

The change comes with a concrete deadline in the author's account: the site is set to disappear in February, a cutoff that holds regardless of a registration already paid through 2040. Notice of the underlying decision reached the author only weeks after the fact and through an ordinary registrar email, arriving a few days before the 3 September post, well after ICANN's 28 July approval.

How solid is it

This is a first-person account from one of the registrants losing a domain, recounting what happened and what the author says they were told by their own registrar. The post states two key dates, Verisign's proposal on 15 April 2026 and ICANN's approval on 28 July 2026, but gives no source or methodology for its headline number, 22,000 affected registrants. It also says Verisign's proposal to ICANN contained 'numerous lies,' without specifying what those were.

Risks and caveats

The account comes from someone who stands to lose a domain they have held for 25 years, so characterizations like Verisign's 'numerous lies' reflect the author's own judgment about the proposal, not a specified charge, since the text does not say what the lies were. The most serious claim, that whoever registers the freed 2nd-level domain could hijack linked accounts and devices, is explicitly framed by the author as an assumption about what follows once 3rd-level domains are terminated, not a confirmed outcome. The text also does not explain ICANN's own reasoning for approving the proposal beyond Verisign's stated aim of simplifying administration, nor does it give a year for the February date on which the site is said to disappear.

“I'm just one of 22,000 people who will lose their domains. This is going to be fun. Time to lawyer up...”

— the post's author