1. Sixteen hundred envelopes

On 12 August, ICANN closed the application window for its latest expansion of the Internet’s namespace: more than 1,600 applications for new generic top-level domains (gTLDs): the strings to the right of the final dot. The list is expected by mid-October, on what ICANN calls Reveal Day. The 2012 round drew 1,930 applications, delegated some 1,200 registries, and enriched the Internet with the likes of .photography, .sucks, .plumbing and .horse. Fourteen years later, the queue came back some 300 applications smaller, at roughly double the fee.

The rules of this round route its economics through ICANN. In 2012, applicants mostly settled contention privately and losers were usually paid by the winner. The 2026 guidebook bans private settlement; the one valve left is swapping to a pre-nominated replacement string, and 1,100 of the 1,600 applications carry one. This is a genuine reform, aimed at a decade of applications filed in order to be paid to lose. Whatever survives the swap exits through ICANN’s auction, at the higher volume the organisation’s own tender expects. An auction loser recovers only a fifth of its fee under the refund schedule — forfeiting some $180,000. Losing, once a business model, is now a fee. And where the auction proceeds go, the guidebook does not say. The 2012 promise to ring-fence proceeds took eight years of community process to become a grants programme, a slice of which now part-funds this round’s 75 supported applicants, up from three last time; the 2026 text does not start even that clock.

Roughly half a billion dollars is already spent regardless of outcome: at least $363m in evaluation fees invoiced by ICANN (at $227,000 per application), plus perhaps another $100m in legal and consulting preparation across the queue. The auctions to come will move money rather than burn it, from applicants to an organisation with no stated obligation about where it goes next. The expansion must deliver half a billion in value to the Internet just to recover what the paperwork has consumed so far. Who ultimately pays is murkier. Portfolio registries recover from registrants; defensive applicants recover from no one; what the expansion costs for everyone else on the Internet appears nowhere.

Then there is .horse. Delegated in 2014 and marketed to trainers and breeders, the zone sustains around 4,900 registrations today. Sub-$2 promotions swelled the zone to about 5,600 by 2023, standard renewal fees then shrank it by 40 per cent, and the next promotion refilled it. Nothing is wrong with .horse. It is the bare version of a TLD: a string, a price list, and a hope, now priced at $227,000 a throw, sixteen hundred times over. Whether the Internet gains anything from sixteen hundred more of them is not a matter of taste; the last batch was formally audited.

2. The defused audit

The 2012 case for expansion was written into ICANN’s bylaws as a testable claim: more competition, more consumer choice, and with a mandated review to test the outcome. The reviewers reported in 2018, and the table of contents of the report alone gives the verdict: partway through, they added whole chapters on DNS abuse, on costs to trademark holders, and on domain parking. The audit of competition and choice turned out to concern crime and emptiness, and who was compelled to pay for both. On the programme’s flagship safeguard, the report concluded that it “has made defensive registrations a less efficient means of protection”; on competition, the commissioned economics could find no constraint on legacy pricing. The benefit column, in ICANN’s own accounting, stayed blank.

The report carried an enforcement mechanism, on paper: prerequisite recommendations were to be implemented before any next round. Instead the ICANN board only accepted 6 of 35 “subject to costing and implementation considerations”, parked 17 in a newly invented “pending” status, and in July 2024 was still resolving the 4 that called for collecting pricing data. Six years after the auditors asked, the data needed to measure the programme’s first stated purpose, competition, remained ungathered. The audit of the round now under way has been scheduled with similar care: it begins only after the new round has been running for two years.

The market, meanwhile, returned its own verdict on competition: consolidation. A registry owes ICANN a $25,000 fixed fee before any operating cost. A zone of a few thousand names cannot carry that, so the 2012 additions became shelf stock. Donuts absorbed Rightside and Afilias to become Identity Digital; GoDaddy bought the portfolio containing .horse. Just ten registries now hold 90 per cent of all new-gTLD names, and the other 458 share the rest. The survivors’ economics are audited, unlike everything else here. Verisign, the incumbent the expansion was supposed to discipline, reported 2025 operating income of $1.12bn on revenue of $1.66bn, a 68 per cent margin, attributing growth primarily to price rises taken to the extent its ICANN agreements permit. A programme sold as competition produced a second oligopoly beneath the first, and the party assigned to measure the difference never built the ruler.

3. Bottom feeding

What does a cheap, unpoliced namespace option attract? The purest form of this ran twenty years ago: the so-called domain name tasting. ICANN policy long allowed a five-day grace period in which a new domain registration could be returned for a full refund, a courtesy meant for typos. Speculators, however, noticed that five free days was ample time to measure a domain’s advertising yield: register, park, count the clicks, keep what pays. The test cost nothing, so the testing was unbounded. In January 2007 alone, 51 million .com and .net names were registered and 48 million of them, roughly 94 per cent, were deleted inside the window. By volume, for a period, tasting simply was the registration system, with everyone else a rounding error. The remedy was twenty cents: from 2008, ICANN’s transaction fee became non-refundable on excessive grace-period deletions. Deletions fell 99.7 per cent and the industry vanished. Any unpriced option on the namespace will be industrialised by actors who bear none of the costs. The twenty-cent cure worked because twenty cents is infinite against a free option; against a business that clears more than $1.50 a name, $1.50 is noise. The namespace has only ever been priced against the registry’s cost of goods, never against the abuse yield.

Tasting’s descendants fill the 2012 zones. The spectrum runs from outright phishing through typosquatting, spam infrastructure and click arbitrage: behaviour that is exploitative rather than indictable, extracting small sums from other people’s traffic, other people’s brands and other people’s inattention. Interisle Consulting’s study of the 2025 registration market estimated that at least 10 per cent of all gTLD registrations that year, plausibly nearer 20 per cent, some 16.8 million names, were purchased by actors whose domains ended up on security blocklists. Certain registries and registrars saw 50 to 80 per cent of their new registrations blocklisted. Five registrars accounted for half of the total. Contractual obligations to act on DNS abuse entered the registry and registrar agreements in 2024, so the 2025 figures describe the first full year under them. ICANN’s own commissioned research had flagged the pattern years earlier: abuse rising in new gTLDs while flat in legacy ones, concentrated in a handful of strings where it constitutes the business model. Around 10 to 20 per cent of the industry’s registration income arrives from this end of the market, at full price and entirely voluntarily. Whether the money that pays for the registration is the buyer’s own is a question nobody is required to ask at checkout.

The rest of the expansion’s output is nothing at all, and even that nothing has a structure. At the 2012 round’s peak, tracking services classified more than 65 per cent of new-gTLD names as parked or non-resolving. Parking is the gTLD programme one level down: a cottage industry that registers a promising name in the hope of extracting rent from it some day, and monetises the wait with advertising. Much of the genuinely empty remainder is defence against that industry: names registered so that nobody else can park them. The industry’s own measurements find the same pattern wherever registration economics operate. CENTR, the association of European country-code registries, classifies what a resolving domain shows: across its members’ zones, 43 per cent substantial content, 27 per cent parked or holding pages, 31 per cent nothing at all. That classification only counts domains that resolve at all. SIDN, the Dutch registry, asks the harder question: how many registrations amount to an actual site? The share of the Dutch market’s 9 million registered names resolving to actual content: about 18 per cent. SIDN also now pays registrars a rebate for domains that are demonstrably used: a registry conceding, in its fee schedule, that registration and use have come apart.

Strip out the extractive and the dormant, and the genuine use that 1,600 applicants are bidding $227,000 apiece to serve is a modest fraction of what the registration numbers promise. None of it adds a redeeming quality of its own: it feeds on traffic, brands and inattention, or it simply sits.

4. Nobody’s name on anything

Why does bottom feeding stay cheap? Partly because an initial domain registration costs less than a coffee. Mostly because, for seven years, effectively nobody’s name has been on anything.

In June 2003, Europe’s data-protection authorities formally advised ICANN that individuals should be able to register domains without their details on a public register, drawing the line between natural persons, whom the law protects, and legal persons, whom it does not, even back then. Nothing structurally changed in the following fifteen years while the ICANN community argued endlessly about WHOIS. Then, in the single fortnight before GDPR enforcement in May 2018, ICANN adopted an emergency specification — and sued a German registrar on enforcement day to compel it to keep collecting registrant data. The common story is that ICANN scrubbed WHOIS; the organisation that went to court did so to keep the data. The scrubbing was, however, done by the registrars and registries, and they redacted past the law’s edge. Legal persons went dark too, though the regulators had drawn precisely that distinction in 2003. Distinguishing registrant types costs money; blanket redaction is free; and blanket redaction happens to make abuse attribution, trademark enforcement and accuracy auditing somewhere between expensive and impossible. The outcome, by Interisle’s count: nearly 90 per cent of gTLD domains today carry no identifying contact information.

The EU’s NIS2 directive imposes the industry’s first know-your-customer regime — verified registration data, published legal-person records, 72-hour access for substantiated requests — legislated rather than produced by the community process that owned the problem. In those same years, the community process wrote non-custody into its own rulebook. ICANN’s Registration Data Policy, a consensus policy in force since August 2025, defines a Minimum Data Set under which registrant name, organisation, address, phone and email need not be transferred to the registry at all unless the registry requires them: a thin registry by default, adopted by policy while parliaments legislated verification. The law walks toward accuracy; the industry walks away from custody.

5. The toll booth

The industry’s oldest adage says expansion is necessary because all the good names are taken. The adage is true; the interesting part is who has taken them. The occupied namespace decomposes into three holdings: trademarks, attempts to extract rent, and insurance taken out against those attempts. A good name is a word people already know, and each such word belongs to somebody in trademark terms, or sits parked awaiting a payday, or was registered by that same somebody precisely so that it could not be parked. A new suffix creates no new names; it reprints the same contested dictionary under another roof and restarts the same three-way land rush above it, trademark holders pushed through the gate first in a sunrise period, with speculators close behind and defence mopping up the rest. The market has settled where a domain’s value sits: left of the dot, almost entirely.

Shakespeare’s Juliet held that a rose by any other name would smell as sweet, and the aftermarket, four centuries on, agrees with her. A memorable name commands a premium under nearly any suffix; the suffixes themselves compete to zero: anyone not precious about the string to the right of the dot can register a first year under dozens of them for less than a fiver, some for under $2. Bulk malicious registration shops at exactly these prices. An expansion premised on selling suffixes therefore has one dependable customer class built into its geometry: the unwilling.

The gate is a paid one. Sunrise admits trademark holders ahead of the public, verified at a fee per mark, and the toll presents per brand, per string, in perpetuity: pay now to register defensively or pay later to dispute. Intellectual property law requires holders to take an active stance. The review team’s survey found 90 per cent of brand owners’ new-gTLD registrations were defensive, and ICANN’s own report of public comments records why the safeguard persists: sunrise notification enjoyed the industry’s broadest support “since it is essentially mandatory advertising for the new gTLDs”.

When a booth’s traffic disappoints, the toll rises on whoever remains inside. In 2017, Uniregistry raised prices on sixteen of its underperforming strings by up to 3,000 per cent: .flowers went from $18 to $100 wholesale, and its founder, Frank Schilling, stated “If you have a space with only 5,000 registrations, you need to have a higher price point to justify its existence.” The alternative, he noted, was to sell. Registrars revolted and the increases were partially grandfathered; a few years later he sold, and .flowers registrants renew today at $103.50 under a new owner.

The 2026 queue is already partly disclosed. Two applicants have come forward claiming a fifth of it between them: some 340 strings, $77m in fees paid. Their lists read as an inventory of whatever current culture might pay rent on: .llm, .agi, .btc, .kek, .anime, .weed. A third applicant raised $10m before Reveal Day for the express purpose of winning an auction, for .factory, that does not even exist yet. The disclosed queue, so far, is the undiluted speculative core. Voluntary disclosure selects for applicants who want the attention; brands and non-Latin-script applicants tend not to issue press releases, and Reveal Day will show the full extent.

This machinery survives for a structural reason. On the record, ICANN has repeatedly tried to do the right thing. It sued to keep collecting registration data, and it blocked the private-equity purchase of .org on public-interest grounds. But it operates the gTLD namespace, the part that the well-organised stakeholder communities make their money with, under effective capture. Policy is made by consensus among stakeholders, including the contracted parties whose revenue the policy governs, and a consensus process cannot adopt rules against the interests of those whose consent it requires. The stakeholder list is unambiguous: the largest new-gTLD portfolio, Identity Digital, belongs to a private-equity firm co-founded by a former ICANN chief executive and is run by the former head of ICANN’s own domains division.

6. The border checkpoint

A toll booth and a border checkpoint are the same installation: a barrier, a booth, someone at the window. The difference is what the person in the booth is doing: collecting, or checking. Nearly every registry chose collecting. The ones that chose checking supply the single demonstrated answer to what a top-level domain could give the Internet that it does not already have.

The web’s encryption has a first-contact problem: HTTPS protects every visit except the first. Preloading into the browsers can close that gap, and a registry can close it by preloading its entire TLD. Of the 1,200 strings delegated in 2012, only a countable handful ever did. Google preloaded all 45 of its strings in 2017, with .app and .dev on the list before a single registration happened and enforcement real enough to break developers’ casual .dev test setups. Google paid $25m at ICANN auction for .app: the one winning bid on the books with an engineering rationale; at one large registrar, a .app domain renews today at $14.93, a seventh of what empty .flowers charges. Preloading, however, has an expiry date: browsers are closing the same gap themselves with HTTPS-first defaults.

There is a deeper repair that does not expire, and it is unique to TLDs. The web trusts some 150 certificate authorities equally, and any of them can sign for any name; Certificate Transparency means a rogue certificate is now detectable, but detection is not prevention. Prevention exists: a CAA record (RFC 8659), published at the TLD’s apex, names which authorities may issue beneath it, and every accredited CA is bound to honour it — one record, set once, constraining every name under the suffix. Almost no registry has set one. And beneath both mechanisms sits the one property that no browser, protocol or certificate authority can ever supply on a registrant’s behalf: verified identity at registration. fTLD’s .bank admits only financial institutions whose charters are verified with their regulators, re-verifies every registrant at least every two years, mandates DNSSEC and enforced email authentication, and prohibits proxy registration outright: a zone where somebody’s name is, by rule, on everything. A suffix operated with an engineering agenda closes trust gaps that no individual website can close for itself.

Both examples are gates: the whole idea of a checkpoint. Google’s preloaded strings are private namespace operated by the most powerful company on the web; .bank is a chartered-institution club with a membership test, run by a consortium of banking trade associations, priced beyond the entrants the competition rhetoric was supposed to admit. The checkpoint model is not open. But the distinction the programme has never drawn is not between open and closed: sunrise is a gate too, and nobody asks what that one is for either. The distinction is between gates that are required to declare their purpose and gates that are not. Google’s gate publishes what it checks and every registrant beneath it inherits the benefit; .bank’s gate states whom it excludes and why; sunrise’s gate exists, on the record of ICANN’s own public comments, as mandatory advertising. The question a merit test would ask is not whether there is a gate. It is what happens at it, and for whose benefit.

Nothing in the 2026 guidebook asks an applicant what its string will do for anyone under it. The one use of a TLD that benefits every registrant is the use almost nobody is applying for.

7. What happens at your booth

The materials for a better test are all there. Tasting proved the registration system obeys price signals when the price is material to the business being priced out: twenty cents ended a fifty-million-name-a-month industry that cleared almost nothing per name. NIS2 proved accountability can be legislated when the community process declines to produce it. Google proved a TLD can be operated as infrastructure. Pricing works, accountability is legislatable, merit exists: what has never existed is anyone asking for them at the point of application.

Asking would mean three questions, put to each of the applications when the list is published. Who benefits from this string besides its registry? What happens at the booth: what policy will the operator enforce, and what binds it to keep enforcing when enforcement costs revenue? Whose name will be on the registrations? The guidebook gives these questions no home. What it provides instead runs from String Confirmation Day, a fortnight after Reveal: a public comment forum and, in parallel, a 104-day window for formal objections. Objections can be on four grounds: string confusion, legal rights, limited public interest, community. And it provides one office built for exactly the first question. The Independent Objectors — an office of three that ICANN was, as of midsummer, still recruiting — will file limited-public-interest and community objections on behalf of no client but the Internet’s users. They begin an eighteen-month engagement this October, their budget drawn from auction proceeds. The only party in the process paid to ask who benefits besides the registry is paid out of the money collected during the deconflicting. Three people, a fixed budget and 1,600 applications to read.

The strings with good answers are disproportionately the ones that generated no abuse reports; the strings without answers were delegated by the hundreds, at a documented cost in phishing, compelled fees and dead zones that ICANN’s reviewers spent three years itemising and no one has ever fully counted.

The strongest objection to this prescription was made inside ICANN long ago. A benefit test for applications was considered and deliberately rejected, on the ground that the moment the domain name root operator grades purpose it becomes a content gatekeeper. The queue of governments and lawyers wanting to borrow that lever forms the same afternoon. The objection is right about approval and wrong about the alternative. Requiring an application to state who benefits, and publishing the answer, grades nothing. The application form already interrogates finances, background and geography without anyone calling it censorship, and the guidebook already contains the machinery for answers to bind: voluntary commitments that become contract terms, and a dispute procedure that enforces them. Nobody needs ICANN to judge a string’s purpose. What is asked is that the purpose be stated where the Internet can read it: the gate declared, not graded. And if a captured process cannot adopt even a disclosure rule against its parties’ interests, the precedent is recent: the last time the community declined to produce accountability, parliaments produced it instead. A disclosure obligation on who a namespace serves is the same shape of requirement as NIS2’s, with the same available author.

The plain purpose is to extract rent; the programme exists to create new places to put a toll booth. The burden of proof therefore belongs where the benefit is claimed. Applicants assert that their strings add something to the Internet, while the audited record says the default is a toll booth, and an undisclosed cost to the ecosystem. The applications deserve to be read as claims requiring evidence, rather than revenue requiring processing.

Juliet’s position was that the name adds nothing to the thing. This round has bet half a billion dollars against her so far, and the returns from the previous bet are in. Juliet won. The one exception, a suffix operated as a patch for the web’s fundamentally broken trust model, remains undersold and generally misunderstood, and it is precisely what the application form never asks about. Sixteen hundred envelopes are waiting in Los Angeles. The interesting question is not what they say. It is what nobody requires them to say.