A .horse by any other name — Sources
External companion to the long-read. Citation chain for every load-bearing claim, organised by section. Derived figures carry their method; unverified claims are marked.
§1 Sixteen hundred envelopes
Application window: 30 April – 12 August 2026, 105 days. ICANN New gTLD Program site. https://newgtldprogram.icann.org/en/application-rounds/round2
More than 1,600 primary applications received; the majority submitted in the final days; more than 1,100 included a secondary replacement-string application. ICANN announcement, 13 August 2026. https://www.icann.org/en/announcements/details/icann-2026-round-closes-with-more-than-1600-new-gtld-applications-13-08-2026-en
2012 round: 1,930 applications. ICANN 2012 application statistics. The denominator for the smaller-queue comparison.
Evaluation fee $227,000 per application; payment due within seven days of invoice, by 19 August 2026. ICANN announcements 13 July and 13 August 2026; Gilbert + Tobin client note, August 2026. https://www.gtlaw.com.au/insights/icanns-new-gtld-program-2026-round-what-you-need-to-know
Reveal Day no later than nine weeks after close, approximately mid-October 2026; timeline announcement mid-September 2026. ICANN announcement, 13 August 2026.
Private contention resolution prohibited in 2026; the only routes are community priority evaluation or an ICANN-run auction; communications between contending applicants are banned from Reveal Day until contract or withdrawal, with violations risking disqualification, fee loss and penalties. 2026 Applicant Guidebook (V2-2026.04.24), §5.2.3, via Gilbert + Tobin. Analytical note: auction-only contention resolution routes contention money to ICANN rather than between applicants. The 2012 private auctions moved money between applicants; 2026 removes that option.
Replacement strings: more than 1,100 of the 1,600+ applications carry one; the swap window is 14 days after Reveal. ICANN announcement 13 August 2026; Applicant Guidebook §5.1.
234 contention sets in 2012, of which 16 reached an ICANN auction. CircleID, 19 August 2026: “in that year 234 strings were up for grabs but only 16 of them ended up in an ICANN auction.”
ICANN expects more auctions this round. ICANN auction RFP project overview, 1 April 2026: “expects there will be a higher volume of ICANN auctions in the 2026 Round.” The predicted consequence stated in ICANN’s own procurement language.
Refund schedule: $147,500 refunded to ten days after String Confirmation (about 65 per cent), $79,500 to the start of evaluation (35 per cent), and 20 per cent — about $45,400 — from the start of evaluation to contract. An auction loser sits in the third window: it recovers roughly $45,400 and forfeits roughly $181,600. ICANN gTLD Evaluation Fee FAQ (newgtldprogram.icann.org); Applicant Guidebook §3.3.3.1; ICANNWiki. Copy desk: the $147,550 figure circulating in trade coverage is the first-window refund, not a loss. It is frequently reported as the amount an unsuccessful applicant forfeits, which inverts it. The prose uses the recovery figure.
Entry cost of the round, approximately $500m. Derived: $363m in evaluation fees invoiced by ICANN (1,600 × $227,000) plus roughly $100m in estimated legal and advisory preparation, at a conservative £60,000-plus per application against 2012-era norms. The arithmetic is stated in the prose. Unverified: the $100m preparation figure is an estimate, not a sourced total, and is labelled as an estimate in the prose. The $363m is invoiced rather than banked — fees are partly refundable at the withdrawal stages above.
Applicant Support Program: 75 applications from 27 countries, against capacity for roughly 40 to 45 supported applicants, up from three in 2012. ICANN Board resolutions, 26 March 2026.
The Board approved up to $4.9–5m from 2012 auction proceeds to part-fund 2026 Applicant Support Program applicants; supported applicants receive bid credits in contention auctions. ICANN Board resolutions, 26 March 2026.
2012 auctions of last resort: 16 auctions, approximately $225m in proceeds. The 2012 Applicant Guidebook required proceeds be “reserved and earmarked until the uses of funds are determined.” ICANN Board approved resolutions, 26 March 2026.
2012 auctions grossed $240.6m, $233.5m net; the proceeds became the ICANN Grant Program, which held $217m as of mid-2023. webhosting.today, 17 August 2026.
The 2026 Applicant Guidebook contains no earmarking or proceeds-use provision equivalent to 2012’s. Guidebook V2-2026.04.24, Module 5, read directly: the auction sections are 5.6.1 Overview, 5.6.2 Scheduling, 5.6.3 Method, 5.6.4 Winning Bids Payments and 5.6.5 ASP Bid Credits, with no proceeds or earmarking section. Corroborated by webhosting.today, 17 August 2026, which read the module in full — it “covers auction mechanics and the refund of a winning bid, and stops there” — and by ICANN’s auction RFP, which is silent on the destination of proceeds.
The 2012 precedent for proceeds latency: auction money raised in 2014–2016 became the Grant Program only when the Board adopted the CCWG recommendations in June 2022, roughly eight years later. ICANN Board resolution, 12 June 2022; webhosting.today dates.
.horse: applied for in the 2012 round by Minds + Machines (Top Level Domain Holdings); registry agreement 21 November 2013; delegated to the root in March 2014; general availability 15 September 2014; transferred to Registry Services, LLC (GoDaddy Registry) 14 September 2021; open registration at roughly $24–34 a year; marketed to “equine industry professionals… trainers, breeders, bloggers, horse enthusiasts.” IANA root database; ICANNWiki; ICANN registry agreement page. https://www.iana.org/domains/root/db/horse.html
.horse zone: 4,872 registrations as of June 2026. The five-year path runs 2,895 (June 2021) → 4,715 (2022) → 5,582 peak (2023) → 3,495 (2024, down 37.4 per cent) → 3,319 (2025) → 4,872 (2026, up 46.8 per cent). The boom was driven by sub-$2 first-year promotions; the collapse came at the standard $20–30 renewal. DNS.Coffee data via NamePros analysis, 13 June 2026. https://www.namepros.com/threads/horse-gtld-generic-top-level-domain.1389844/ Analytical note: the tasting mechanism in miniature, inside one TLD, in the 2020s — §1’s exhibit prefigures §3.
.horse aftermarket: five publicly recorded sales in twelve years, ranging $220 to $5,700 — guy.horse at $5,700, horse.horse at $2,000, icelandic.horse at $1,000. NameBio via the same NamePros thread.
Round count. ICANN-era expansions run: the 2000 proof-of-concept round (.biz, .info, .name, .pro, .aero, .coop, .museum, delegated 2001–02); the 2003–04 sponsored round (.mobi, .travel, .jobs, .cat, .asia, with .xxx approved in 2011); 2012; and 2026. The prose says “latest” rather than an ordinal, because “third” and “fourth” both depend on whether the sponsored round counts. ICANN’s own framing, “New gTLD Program: 2026 Round,” counts rounds of the Program only.
§2 The defused audit
The CCT Review: ICANN Bylaws s4.6(d) mandated a review of whether gTLD expansion promoted competition, consumer trust and consumer choice. ICANN. https://www.icann.org/resources/reviews/specific-reviews/cct
Final Report submitted 8 September 2018, with 35 recommendations, some designated prerequisites to future application rounds. ICANN public comment proceeding, 8 October 2018.
The prerequisite framing, verbatim: “Prerequisite: Must be implemented prior to the launch of subsequent procedures for new gTLDs.” ICANN CCT implementation plan, 23 August 2019 (PDF).
The second draft report (November 2017) added sections on DNS abuse, costs to trademark holders, parking and consumer choice. ICANN proceedings. The four topics the review itself found necessary to add are the four topics of this essay.
Board action, 1 March 2019 (resolutions 2019.03.01.03 and .04): accepted six recommendations — 1, 17, 21, 22, 30 and 31 — “subject to costing and implementation considerations”; placed 17 in pending status; passed the remainder through to community groups. ICANN public comment proceeding, September 2019; Board materials.
October 2020 (resolution 2020.10.22.04): 11 of the 17 pending recommendations were ready for action; six remained pending. ICANN resolution tracker.
July 2024: the Board was still resolving the remaining four — recommendations 2 to 5, covering wholesale, transactional and retail pricing and secondary-market data collection. Board special meeting materials, 29 July 2024. Analytical note: the data needed to assess competition — the programme’s first stated purpose — was still unimplemented five years after the report and under two years before the 2026 window opened.
Recommendation 17 — collect and publicise the chain of parties responsible for registrations — was declared complete “according to current policy requirements,” with “no further implementation work planned.” ICANN blog, 20 August 2020. Completed by redefinition; ties directly to §4.
The second CCT review is deferred: proposed to start only once the next round has been in operation for two years, measured from 500 delegations. Bylaws amendment public comment, February 2026.
Registry concentration: 68,567,829 new-gTLD domains across 1,110 TLDs and 468 registries, with the top ten registries holding 89.8 per cent. Grouped by parent, the Identity Digital shells — Binky Moon, Dog Beach, Afilias, Monolith — hold roughly 13.5 per cent across 264 TLDs. A single operator, Jiangsu Bangning, holds 12.19 per cent with one TLD (.top); ShortDot holds 7.93 per cent with five. ntldstats.com/registry, retrieved 20 August 2026.
Verisign (NASDAQ: VRSN) FY2025: revenue $1,656.6m, operating income $1,121.0m — a 67.7 per cent operating margin — on 173.5m .com and .net names, with growth “primarily due to .com and .net price increases.” The 10-K records that fees are “determined pursuant to our agreements with ICANN.” More than $1.1bn was returned to shareholders in 2025. VRSN 10-K FY2025 and Q4 release. The pure-registry benchmark, self-reported; cited in the prose as a legacy control group rather than as evidence about new gTLDs.
GoDaddy (NYSE: GDDY) FY2025: revenue $4,951.1m, operating income $1,127.3m — a 23 per cent margin — with Core Platform (domains) at $3.1bn and roughly 81m domains under management, about 21 per cent of the world’s ~387m. GDDY 10-K FY2025 and Q4 release, the latter citing Verisign’s DNIB for the world total. A mixed registrar-and-registry business, labelled as such in the prose.
Consolidation: Donuts absorbed Rightside (2017) and Afilias (2020), rebranding as Identity Digital; GoDaddy acquired Neustar’s registry business (2020) and the MMX/Minds+Machines portfolio, including .horse (2021). Unverified: the acquisition years are drawn from trade coverage and have not been checked against the companies’ own announcements.
Every gTLD registry pays ICANN a fixed annual fee of $25,000, plus per-transaction fees above a threshold, before backend registry services, compliance and TMCH obligations. ICANN base Registry Agreement. Unverified: the fee schedule wording has not been re-checked against the current agreement. Analytical note: at roughly 5,000 names a TLD cannot clear its own fixed costs as a standalone business. .horse, at 4,872 names, exists as an inventory line in a portfolio registry.
The Ethos/Identity Digital sequence. November 2019: the Internet Society agrees a $1.13bn sale of the Public Interest Registry (.org) to Ethos Capital. 30 April 2020: ICANN withholds consent, citing a “heavily indebted for-profit entity” with no public-interest mandate. Ethos’s 2020 investment in Donuts funds the Donuts–Afilias acquisition that December. January 2021: Ethos takes control of Donuts from Abry — Erik Brooks and Fadi Chehadé had led Abry’s 2018 Donuts deal before founding Ethos, and Chehadé is a former ICANN CEO. June 2022: the rebrand to Identity Digital, under CEO Akram Atallah, former president of ICANN’s Global Domains Division. ICANN board materials; Ethos press release 31 March 2021; Domain Name Wire, 22 January 2021; EFF. Unverified: the executive biographies are drawn from secondary compilations rather than primary bios. Analytical note: blocked from one legacy TLD on public-interest grounds; controlling the largest new-gTLD portfolio fourteen months later through a structure facing no equivalent scrutiny; two ICANN alumni at the helm.
§3 Bottom feeding
January 2007: 51m .com and .net registrations against 48m deleted within the add grace period — about 94 per cent. The net increase was 3m. ICANN study via Computerworld, 2008. For comparison, in January 2005, 1.7m were registered and 41 per cent deleted. https://www.computerworld.com/article/2538892/
Ten organisations accounted for 95 per cent of all deletions — 45,450,897 of 47,824,131. ICANN study via The Register, 30 January 2008.
Add grace period mechanics: a five-day full-refund window intended for typos and errors; the kiting variant re-registered on expiry. GNSO AGP Limits Policy. https://gnso.icann.org/en/group-activities/inactive/2008/domain-tasting
The fix: ICANN made the $0.20 transaction fee non-refundable on excess AGP deletions. Final Draft Report on Domain Tasting, 8 February 2008; the FY2009 budget measure; the AGP Limits Policy consensus policy. Stites & Harbison note; ICANN AGP policy page.
Result: AGP deletions fell by 99.7 per cent. ICANN status report, “The End of Domain Tasting,” 12 August 2009, via ICANNWiki. Analytical note: a twenty-cent price signal ended a fifty-million-domain-a-month industry within months. The precedent is load-bearing for the whole essay — unpriced namespace options get industrialised, priced ones stop.
SADAG study (ICANN-commissioned, SIDN Labs and TU Delft, final 2017, covering October 2013 to October 2016): a clear upward trend in absolute phishing and malware domains in new gTLDs, while legacy gTLDs remained relatively constant. SIDN Labs. https://www.sidnlabs.nl/a/weblog/sidn-labs-and-tu-delft-deliver-final-report-for-icann-study-
SADAG: a third of the 1,200-plus new gTLDs generated no abuse reports, while at least 10 per cent of all abused domain names were concentrated in 15 new gTLDs. SIDN Labs, Highlights of 2017. https://www.sidnlabs.nl/en/news-and-blogs/highlights-of-2017
Interisle, “Malicious Registrations in the Domain Name Market” (June 2026): malicious actors purchased at least 10 per cent of 2025 gTLD registrations, projected to reach 20 per cent — roughly 16.8m domains. Some registries and registrars had more than 50 per cent, and up to 80 per cent, of their 2025 new registrations blocklisted. Five registrars accounted for 50 per cent of all blocklisted gTLD domains, and several registries received hundreds of thousands to more than a million malicious registrations each. The report ties its findings to the new open gTLDs arriving from 2027. Interisle; press release via natlawreview.com. https://interisle.net/cybercriminaldomaindemand Copy desk: the prose describes these registrations as “purchased by actors whose domains ended up on security blocklists.” That phrasing deliberately straddles Interisle’s malicious-registration estimate and its blocklist-based methodology, which are two different measures.
Interisle Phishing Landscape 2025: 77 per cent of phishing domains were maliciously registered, up 36 per cent year on year, across roughly 2m attacks — up 180 per cent since 2021. https://interisle.net/insights/phishing-landscape-2025-an-annual-study-of-the-scope-and-distribution-of-phishing
Interisle Phishing Landscape 2023: 90 per cent of phishing domains in new gTLDs sat in just 25 of them. Interisle news summary.
Interisle 2026: malicious registrations in the new-gTLD segment have historically concentrated in fewer than 50 gTLDs, and in some of them nearly all phishing domains are attacker-registered. https://interisle.substack.com/p/phishing-landscape-2026-malicious
ntldstats, November 2016: more than 65 per cent of new gTLD domains parked — a broad definition covering parking nameservers, no servers, no record, redirects and non-resolving names. TheDomains, 3 November 2016.
Verisign research, 2014: 41 per cent of new gTLD registrations parked with pay-per-click advertising; 10 per cent redirects. Domain Incite, 13 August 2014.
TUM study (September 2023 scan): 58.5m of 334m domains — 17.5 per cent — parked, stated as an explicit lower bound. Between 20 and 30 per cent of .com, .net and .org are parked, with no decline over time. APNIC blog; Zirngibl et al., TMA 2022. https://blog.apnic.net/2023/11/08/the-prevalence-of-domain-parking/
.science: only 16 per cent of web domains had a primary function and 8.5 per cent were scholarly, the rest empty, non-academic or dubious — the gTLD “used to acquire false authority or better search positioning.” arXiv 2102.05706.
CENTR TLD Market Report (2025): across European ccTLD zones, 43 per cent substantial content, 27 per cent limited content (parked or holding), 31 per cent no functioning web content. SSL adoption runs 78 per cent among substantial-content domains against 17 per cent among limited-content ones. The industry association’s own measurement. https://stats.centr.org/public/tld_market_report
SIDN, “De ene extensie is de andere niet” (August 2025, on Dataprovider data): 1.65m unique active websites in the Netherlands across all extensions — excluding redirects, parking, placeholders and under-construction pages, counting only multi-page sites with their own content — against roughly 9m registered domain names, about 18 per cent. The registry’s own measurement of its own market. https://www.sidn.nl/nieuws-en-blogs/de-ene-extensie-is-de-andere-niet
SIDN operates an active-usage incentive: registrar rebates conditional on domains being actively used, across business, content, forum and e-commerce categories, plus DNSSEC coverage. Realtime Register knowledge base, documenting the registrar-facing terms. Analytical note: a registry paying for use is the structural admission that registration and use have decoupled.
“Parking Sensors” (ACM, 2015): typosquatted domains increased by orders of magnitude after the introduction of new gTLDs, with mass registrars profiting from brands’ inability to defend at scale. Cited from the published abstract.
On the structure of the dormant pile. The prose treats parking as the gTLD programme one level down — speculative rent extraction on names — and genuinely empty registrations as largely defensive against parking and squatting. Unverified: this is stated in the prose as analysis, not as a sourced finding. It is consistent with the Verisign 2014 figure above and with the defensive-registration data in §4; the TUM/APNIC parking taxonomy distinguishes monetised parking from reserved or blank names.
§4 Nobody’s name on anything
WP29 Opinion 2/2003 (WP76, 13 June 2003) on data protection principles and WHOIS directories: “It should in any case be possible for individuals to register domain names without their personal details appearing on a publicly available register.” The opinion already distinguished natural persons from companies and other legal persons. EC archive; text via ipjustice.org. https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/index_en.htm
Concerns reiterated to ICANN in 2006, including a Privacy Commissioner of Canada letter of 12 July 2006 proposing tiered access. ICANN GAC WHOIS and data-protection page.
WP29 letter, 6 December 2017: concerns about unlimited WHOIS publication had been expressed “since 2003”; “While this comes late and an earlier reaction to the WP29 advice could have helped to avoid the current state of uncertainty.” The letter also held that ICANN and the registries were likely joint controllers, and that consent under the Registrar Accreditation Agreement was conditional and therefore invalid under GDPR Article 7. https://www.icann.org/en/system/files/correspondence/falque-pierrotin-to-chalaby-marby-06Dec17-en.pdf
April–May 2018: ICANN and the US Commerce Secretary sought a GDPR enforcement moratorium; the data protection authorities refused, in a WP29 guidance letter of 11 April 2018. ICANN announcement, 12 April 2018; CircleID, 13 April 2018.
The Temporary Specification was adopted by the ICANN Board on 17 May 2018 and took effect on 25 May 2018, redacting registrant name, street, city, phone and email from public view. ICANN Temp Spec page; Lexology, 14 May 2018.
25 May 2018: ICANN filed suit in Germany against EPAG (Tucows) to force continued collection of full WHOIS data. ICANN GAC page. Analytical note: ICANN org fought to keep collecting; the contracted parties’ cheapest compliance path was blanket redaction, well beyond the natural-person scope the authorities had distinguished since 2003. Fifteen years of ignored warnings, then over-compliance in a fortnight.
Outcome: nearly 90 per cent of gTLD domain names carry no identifying contact information in RDDS. Interisle study, via CircleID and DNIB.
ICANN Registration Data Policy: a GNSO consensus policy published 21 February 2024 and effective 21 August 2025. Under the Minimum Data Set, registrant name, organisation, postal address, phone and email may be excluded or redacted rather than transferred to the registry unless the registry requires them; admin and billing contact requirements were eliminated entirely. ICANN announcements, 21 February 2024 and 21 August 2025; policy text; Openprovider and CentralNic implementation notes.
NIS2 (Directive (EU) 2022/2555, 14 December 2022), Article 28: registries and registration-service providers — including resellers and privacy or proxy services — must collect and maintain accurate and complete registration data, maintain publicly available verification policies and procedures, publish non-personal registration data without undue delay, and answer substantiated access requests within 72 hours. Recital 112 places legal-person data outside GDPR protection. Directive text via nis-2-directive.com and streamlex.eu; dotmagazine analysis.
Industry response: since NIS2’s adoption, PIR and Identity Digital have adopted “thin” WHOIS, ceasing to collect registration data at the registry level. DNS Research Federation explainer, December 2024. https://dnsrf.org/blog/nis2-and-domain-names---an-explainer Copy desk: a widely repeated version of this list includes Google Domains. Google Domains was a registrar, sold to Squarespace in 2023; Google’s registry is Charleston Road Registry. It does not belong in a list of registries and has been left out. Analytical note: the regulation moves toward data accuracy; major registries move away from holding data.
On payment-side identity. The prose treats criminals as paying customers, plausibly using stolen instruments: with no registration-time KYC, a stolen card is indistinguishable from a legitimate one until chargeback. Unverified: stated in the prose as a plausibility anchored to the verification vacuum above. Registrar chargeback data is unpublished.
§5 The toll booth
TMCH mechanics: mandated by ICANN for all new gTLDs; a registration fee per mark, excluding agent fees; grants sunrise access and claims notices; sunrise and claims are limited to identical matches; a minimum 30-day sunrise. Kelley Drye advisory; ICANN TMCH pages.
TMCH fees are pass-through: ICANN invoices the registries and pays the TMCH provider. ICANN TMCH FAQ.
Independent TMCH review (Analysis Group, draft July 2016, revised February 2017): could not conclude whether claims notices deter infringing registrations, but noted they may deter good-faith registrations. The safeguard’s own reviewers could not demonstrate the benefit. https://newgtlds.icann.org/en/reviews/tmch/
DuPont’s comment on the TMCH strawman, 15 January 2013: it “would much prefer a solution that vitiates the need for defensive registrations from the outset.” Registries and registrars supported sunrise notifications — “essentially mandatory advertising for the new gTLDs,” in ICANN’s own public-comment report wording. ICANN Report of Public Comments, TMCH Strawman, 20 March 2013.
INTA/Nielsen survey (2017, for the CCT): 90 per cent of brand owners registering in new gTLDs did so defensively; roughly 75 per cent of dispute cases involve privacy- or proxy-registered domains; enforcement costs increased in new domains. INTA Cost Impact Survey; CCT GAC presentation; CCT Final Report. Based on 33 complete responses — a small sample, stated as such in the prose.
CCT Final Report: “the Program has made defensive registrations a less efficient means of protection”; trademark holders are shifting spend to monitoring and alternatives; WIPO 2017 data is “a strong indication that there is proportionately more trademark infringement in new gTLDs than in legacy TLDs”; defensive registration is bimodally distributed across trademark holders. CCT Final Report PDF; ICANN blog, 7 March 2017.
Dot-brand attrition: more than 600 .brand applications in 2012, roughly 440 launched, fewer than 200 active today — “many applications were filed for primarily defensive purposes.” National Law Review, 10 March 2026. Analytical note: defence went all the way up the stack — brands bought entire TLDs defensively, then shut them.
“Intellectual property law requires holders to take an active stance.” Stated in the prose as a general principle: trademark holders must police use or risk dilution and abandonment arguments. Unverified: a practitioner formulation, offered as general principle rather than as a citation to a specific authority.
Uniregistry, March 2017: price increases of up to 3,000 per cent on 16 of its 27 TLDs, with .flowers going from $17.67 wholesale to $100. Domain Incite, 8 March 2017; Domain Name Wire price table, 9 March 2017.
Frank Schilling on the record: “If you have a space with only 5,000 registrations, you need to have a higher price point to justify its existence, just because running a TLD isn’t free.” The alternative to repricing “would be to sell.” Domain Incite interview.
Registrar revolt: GoDaddy stopped enabling registrations and transfers; Tucows/OpenSRS dropped nine TLDs “to protect you and your customers from unknowingly overpaying.” In April 2017 Uniregistry partially backtracked, grandfathering existing registrations in nine strings including .flowers. Domain Name Wire, 13 March and 3 April 2017; Domain Incite, 26 May 2017.
Exit: XYZ.com won 10 of 17 UNR TLDs at auction, including .flowers, .christmas, .guitars and .hosting; ICANN approved the transfers in March 2022, delayed over UNR’s simultaneous sale of matching Ethereum Name Service blockchain domains. Domain Incite, 21 March 2022.
Retail pricing, August 2026: .flowers at $103.50 registration and renewal — the 2017 hike persisting under XYZ ownership; .app at $14.93 renewal against $8.75 first year; .horse at $26.26 flat; .sucks at $205.46; .sexy at $2,575.18. Porkbun rate card. Single-registrar retail pricing, labelled as such in the prose.
The teaser-rate structure is industry-wide: dozens of strings at $1.34 to $2.57 for the first year against renewals ten to twenty times higher — .bond $1.34 to $15.96, .baby $1.54 to $52.01. Porkbun rate card.
§6 The border checkpoint
HSTS preloading at TLD level: hstspreload.org explicitly invites gTLD and ccTLD owners to preload entire TLDs — “robust security for the whole TLD… much simpler than preloading each individual domain.” The form is free and open to any registry. https://hstspreload.org/
Google added its TLDs — 45 announced in 2017 — to the HSTS preload list, with .app, .dev, .page, .new and .day preloaded before launch, making every registrant HTTPS-only from the first request and structurally excluding whole classes of downgrade and machine-in-the-middle attack. The SSL Store, 2017; Porkbun knowledge base; Wikipedia .dev.
.app: a record ICANN auction price of $25m in 2018, more than 250,000 registrations soon after general availability, preloaded zone-wide. MakeWay.World interview with Ben McIlwain, Google tech lead. Analytical note: the clearest merit-driven TLD purchase on record is also the record ICANN auction price — the exception that priced itself.
Google’s engineering rationale on the record: HTTPS alone is optional security; TLD-level preloading removes the optionality. Ben McIlwain, Google I/O and the MakeWay.World interview.
Side-effect evidence that the enforcement works: .dev preloading broke developers’ local .dev testing environments, because browsers refused non-HTTPS .dev. Wikipedia .dev.
fTLD’s .bank requirements: eligibility restricted to verified members of the banking community, with charter verification against the applicant’s regulator; mandatory re-verification every two years or at renewal; DNSSEC mandatory at all levels including in-zone name servers, so a name does not resolve without it; email authentication with DMARC p=reject mandatory; TLS 1.2 or above; multi-factor authentication for registration-data changes; proxy and privacy registration prohibited. fTLD preloaded both .bank and .insurance. fTLD security requirements page and FAQ PDFs; fTLD 2016 Security Requirements PDF; Lexology. Analytical note: .bank is the exact inversion of §4 — a zone where somebody’s name is, by rule, on everything. Preloading is a capability any registry can exercise, not a privilege of ownership.
On issuance constraint. Roughly 150 root certificate authorities are trusted equally, and any of them can sign for any name. A TLD plus browser code can confine issuance below a suffix to one or a few chosen authorities — the durable trust-model patch that HTTPS-first defaults never deliver. Unverified: stated in the prose as mechanism rather than as a sourced claim. The supporting apparatus is CAA (RFC 8659) at registry scale, browser root-programme counts of roughly 150 across the major stores, DANE as the standards road, and DigiNotar as the compromise-of-one precedent.
Pre-Reveal disclosures: roughly 367 strings publicly claimed before Reveal Day, about a quarter of the round, all by voluntary disclosure. CircleID, 19 August 2026, via Domain Incite.
Link Freedom Group (Malta, operator of Nova Registry and .link): 316 confirmed strings at roughly $71.7m in fees — the largest bulk filing in the programme’s history. The categories run to AI and tech (.llm, .agi, .quantum, .robot), commerce (.cart, .merch, .mall), Internet culture (.lfg, .kek, .omg), crypto (.block, .btc, .coin, .nft) and infrastructure (.portal, .core, .internet, .url). CEO Vaughn Liley: “your place on the internet should actually be yours.” PRNewswire, 13 August 2026; Domain Incite.
Oinkadot (Porkbun’s Ray King and Dynadot’s Todd Han, independent of both registrars): 25 strings at roughly $5.675m — .anime, .weed, .zzz, .ghost, .glitch, .dragon and others. Domain Name Wire, 15 August 2026.
USA Made in America (Colin Campbell, formerly of .CLUB): .factory, financed by a private offering of up to $10m raised specifically to fund a potential auction. “Generic words that are strong can become valuable infrastructure.” GlobeNewswire, 14 August 2026.
No non-Latin strings appeared among the public announcements, despite internationalised domain names being a stated rationale of the round. CircleID and Domain Incite.
§7 What happens at your booth
Objection window: 104 days from String Confirmation Day, which is itself 14 days after Reveal following the Replacement Period. Application Comments run as a parallel forum, also 104 days from String Confirmation Day. The four objection grounds are string confusion, legal rights, limited public interest and community. 2026 Applicant Guidebook, Modules 1 and 4, §1.2.3.1.
Independent Objectors, 2026 round: an office of three including a chair, filing community and limited-public-interest objections and appeals “solely in the best interests of the public global Internet users,” on an 18-month commitment from around October 2026, “funded from the proceeds of” auctions. The Independent Objectors’ filing window is 111 days from String Confirmation Day — seven days beyond the public’s. ICANN expression-of-interest announcement, 9 March 2026, EOI PDF and project overview, plus extension notices.
As of midsummer 2026 the office had not been filled. No appointment announcement had been made as of 20 August 2026. The EOI portal failed on 30 May, closing 24 hours early, with the root cause unidentified in ICANN’s own disclosure of 30 June; the deadline was extended on 14 May and 18 June and then held open “until all roles have been filled.” Unverified: this is a moving fact. If appointments are announced after publication, the prose’s “an office of three that ICANN was, as of midsummer, still recruiting” describes the position as at August 2026 and not thereafter.
A note on what is not here
Two lines of research were scoped for this piece and left unfinished: the EPDP outcome and SSAD usage numbers that followed the WHOIS collapse in §4, and blocking-product volumes (DPML and equivalents) alongside UDRP and URS case counts since 2013 for §5. Neither is cited in the prose. Sunrise registration volumes exist in ICANN’s monthly registry transaction reports and in the Analysis Group TMCH review, and would sharpen §5 for anyone wanting to take the defensive-registration argument further.