ICANN has approved a request from Verisign to delete every third-level .name domain, addresses like john.doe.name, about 22,000 of them, including registrations paid for until 2040. Many registrants learned about it on September 3, 2026, from a Google engineer's blog post. If you own a domain, or log in anywhere with an email address on someone else's domain, this is a case study in who actually holds the keys to your name on the internet.
TL;DR
- On April 15, 2026, Verisign asked ICANN to discontinue third-level .name registrations. The only benefit it listed: "increase efficiency for the operation of the .name TLD."
- ICANN approved it on May 7 and published the letter on July 28. About 22,000 names will be deleted after at least 90 days' notice, which points to February 2027.
- The request form asks what effect the change has on the life cycle of domain names. Verisign's answer: "None."
- The bigger risk is what comes after: once
neil.fraser.nameis gone, whoever registersfraser.namecould rebuild it and receive its email, including password resets. - Verisign reported $435 million in revenue last quarter. The 22,000 names are about 0.012 % of its 179 million .com and .net domains.
What is a .name domain?
.name launched in January 2002, run by Global Name Registry under a 2001 agreement with ICANN (Wikipedia). It was built for people, not companies, and at launch it sold only third-level names: first.last.name. The second level, last.name, was shared, so john.doe.name and jane.doe.name could belong to two unrelated people, each with an email address to match. Second-level registrations like john.name came in 2004. Verisign bought Global Name Registry in 2008.
| Level | Example | Who controls it |
|---|---|---|
| Top-level domain | .name |
Verisign, under contract with ICANN |
| Second level | fraser.name |
shared, held by the registry |
| Third level | neil.fraser.name |
the individual registrant |
The marketing was explicit. Global Name Registry's consumer page, archived in June 2002, promised a "Web address for life" and said: "As your .name can be registered for up to 10 years and ownership is renewable, your .name really can be yours for life." Wikipedia now records that "Third-level domains were originally marketed as being 'for life'", in the past tense.
Neil Fraser's .name termination post
Neil Fraser registered neil.fraser.name in 2002. His "New Domain!" post of February 19, 2002 says it was "Time to move to a new domain, one that will not obsolesce quite so quickly". It carries his website, his email and APIs for his IoT devices, and it is "registered and paid for until 2040". He also registered beverly.fraser.name minutes after his daughter was born.
His post ".name Termination" says the website "vanishes in February", the email goes with it, and the devices "become bricks". "I'm just one of 22,000 people who will lose their domains." It ends: "Time to lawyer up..." On Hacker News it reached 2,213 points and 538 comments.
One detail stings more than the rest: Fraser picked .name in 2002 because it was not run by Verisign. Six years later Verisign bought the registry.
How Verisign got ICANN to approve it
Registry operators change their services through ICANN's Registry Services Evaluation Process (RSEP). Verisign's request, filed April 15, 2026, asks to "discontinue third level domain name registrations due to declining usage and limited registrar support", adds that "existing third level domain names will be terminated", and lists the benefit in one sentence:
The timeline section promises registrars at least 90 days' notice plus a 30-day reminder, after which the names "will be deleted". Then question 2.1:
The rest of the form follows the same pattern. Technical concerns raised: "No." Effect on competition: "No, there will be no effect on competition." The quality-assurance plan: "internally tested prior to discontinuation."
ICANN approved on May 7. Its July 28 letter says Verisign consulted "the registrars that manage the majority of the user base", and they "did not identify any security, stability or competition issues". Registrants were not asked; a footnote explains that "registrars manage the registrar-registrant relationship(s)". ICANN also says its review "is limited to" security, stability and competition, and "does not extend to other potential impacts". Losing your email address is an other potential impact.
"The majority not in use" is Verisign's claim, relayed by ICANN, with no method published. Fraser's site has 24 years of posts.
Can a registrant appeal to ICANN?
One tried. Doytchin Spiridonov filed Reconsideration Request 26-2 on June 2. ICANN's Board Accountability Mechanisms Committee made its recommendation on August 24, and Domain Name Wire reported the request was "on track to be denied".
The reasoning, as quoted by commenters on HN and Domain Name Wire: "Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle." ICANN "was aware that discontinuation… would result in the termination of approximately 22,000 third-level domain registrations and of email services/addresses." It knew, and it approved.
There is precedent for ICANN stopping Verisign. In September 2003, Site Finder redirected every non-existent .com and .net name to a Verisign search page. ICANN demanded it be shut down, and Verisign complied 19 days later. That was about technical stability of the DNS, which is inside ICANN's checklist. This one is not.
Why deleting a domain is a hijack risk
A domain that stops resolving is an outage. A domain that can come back under a new owner is a security problem. Fraser describes the second case: once the third-level names are deleted, the vacant second level fraser.name presumably becomes registrable. Whoever registers it can recreate neil.fraser.name, run a mail server for it, and, in his words, "hijack hundreds of accounts" and "commit code with my authentication".
The mechanism is ordinary. Most services treat control of an email address as proof of identity:
- The attacker registers the freed second-level name and publishes MX records for the old third-level name.
- They request a password reset at a service where the old address is the login or the recovery email.
- The reset mail arrives at their server. Whatever the account holds, they now hold.
There is also a browser-side wrinkle. Browsers use the Public Suffix List to decide where one site ends and the next begins. How to list the shared .name second levels is still an open issue there, titled "How should we handle the 2LDs of the .name TLD?". Where a shared level is not listed as a public suffix, browsers treat fraser.name as one registrable site, so its future owner sits on the same side of the cookie boundary as every name below it.
What .name owners and developers should do
If you own a third-level .name, or any domain you do not control at the registry level:
- Move your logins first, the website second. Change the email on every account that uses the domain, starting with your email provider, GitHub, your registrar, banks and anything with admin rights.
- Replace recovery addresses and keys. Remove the old address as a recovery option, and re-check commit signing and any SSH or API keys tied to it.
-
Check your registration record. Third-level .name names have their own WHOIS at
whois.nic.name, e.g.whois -h whois.nic.name neil.fraser.name; HN user iminatx confirmed Fraser's name has a full record there. - Register at the second level next time. Anything below it belongs to someone else, however long you prepay.
If you run a service: treat a login email on a domain that later expires or changes hands as a takeover vector. Re-verify old accounts before sending sensitive resets, and offer passkeys or second factors that do not depend on the mailbox.
Why would Verisign bother?
The money is not the reason. Verisign's Q2 2026 results show $435 million in quarterly revenue, $296 million in operating income and 179.1 million .com and .net domains. 22,000 .name names are about 0.012 % of that base. CEO Jim Bidzos celebrated "100% availability for the .com and .net domain name resolution system" for 29 years in the same report. The same company carries $1.45 billion in deferred revenue, which is prepaid registrations, the same kind of prepayment the .name registrants made.
The stated reason is efficiency. ICANN's process had no place to weigh the cost to the people who paid.
Also in this episode: Audacity 4.0, Qwen on Cerebras, Antigravity
Audacity 4.0 shipped as a rebuild on Qt, with a dark theme, workspaces and a new .aup4 format that converts .aup3 one way. Not in 4.0 yet: MIDI and time tracks, the mixer, the macro manager, VAMP and LADSPA plugins. The release notes: "we had the audacity to change the Audacity logo."
Qwen 3.8 27B on Cerebras runs at about 1,500 tokens a second for $0.99 in and $1.49 out per million tokens (docs). The top HN comment pointed out that the developer tier's 150,000 tokens-per-minute cap "means that it's likely unusable for many coding tasks": at full speed you hit it in 100 seconds.
Google Antigravity's terms. Gergely Orosz posted that if Google suspects third-party usage, "they can suspend your Google account", not only Antigravity. "One reason to NOT use Antigravity."
Verdict: REVERT
I stamped it REVERT. Stopping new third-level registrations is a registry's call. Deleting names people paid for until 2040, and then freeing the parent domain so a stranger can rebuild their email address, is not efficiency. It is a hijack with a filing number, approved by a checklist that has no line for it.
FAQ
Are all .name domains being deleted?
No. Only third-level names like john.doe.name. Second-level names like john.name are not affected.
When will third-level .name domains stop working?
Verisign must give registrars at least 90 days' notice plus a 30-day reminder. Neil Fraser's post says February 2027; no exact date has been published.
Why did ICANN approve it?
Its review only covers security, stability and competition, and registrars reported no issues there. The letter says the review "does not extend to other potential impacts".
Sources
- Neil Fraser, ".name Termination": https://neil.fraser.name/news/2026/09/03/
- Neil Fraser, "New Domain!" (2002): https://neil.fraser.name/news/2002/02/19/
- Hacker News discussion: https://news.ycombinator.com/item?id=49550772
- Verisign RSEP request, April 15 2026: https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2026013-name-request-15-04-2026-en.pdf
- ICANN letter to Verisign, July 28 2026: https://itp.cdn.icann.org/en/files/consensus-policies/fessenden-to-kane-2-28-07-2026-en.pdf
- ICANN Reconsideration Request 26-2: https://www.icann.org/resources/pages/reconsideration-26-2-spiridonov-request-2026-06-04-en
- Domain Name Wire: https://domainnamewire.com/2026/09/03/third-level-dot-name/
- Global Name Registry, June 2002 (Wayback Machine): https://web.archive.org/web/20020609132126/http://nic.name/consumer/summary_main.html
- Wikipedia, .name: https://en.wikipedia.org/wiki/.name
- Wikipedia, Site Finder: https://en.wikipedia.org/wiki/Site_Finder
- Verisign Q2 2026 results: https://markets.financialcontent.com/stocks/article/bizwire-2026-7-23-verisign-reports-second-quarter-2026-results
- Public Suffix List issue 2306: https://github.com/publicsuffix/list/issues/2306
- Audacity 4.0.0 release: https://github.com/audacity/audacity/releases/tag/Audacity-4.0.0
- Cerebras model catalog: https://inference-docs.cerebras.ai/models/overview
- Gergely Orosz on Antigravity: https://x.com/GergelyOrosz/status/2095453567955968398
This article expands on an episode of **The Daily Diff, a five-minute daily video on what shipped and what broke in tech.
Watch the episode · Subscribe on YouTube · the written diff lands in your inbox every morning at thedailydiff.dev.



Top comments (0)