Paid for 25 Years, Erased in Months: VeriSign Terminates All .name Third-Level Domains

Paid for 25 Years, Erased in Months: VeriSign Terminates All .name Third-Level Domains

Domain NamesVeriSignICANNInternet Governance

Sources:HN + web research

25 Years of History, Wiped Out in Six Months

Neil Fraser is an engineer at Google. In 2002, he registered neil.fraser.name to establish a permanent and stable presence on the Internet—anchoring his personal website, primary email address, API server, and IoT devices to the domain. Minutes after his daughter was born, he also registered beverly.fraser.name. His domain registration fees were fully prepaid all the way through 2040.

In late August 2026, Fraser received a sudden notification from his registrar: VeriSign had decided to discontinue all third-level domain services under the .name top-level domain. Every .name address under his account would cease functioning in February 2027. It mattered little how many years had been paid in advance—when the registry pulls the plug, the service simply ends.

.name Domain Termination Diagram Figure: Diagram of the .name third-level domain termination process. Source: Domain Name Wire

Approved Before Users Ever Knew

The timeline reveals a striking procedural opacity. On April 15, 2026, VeriSign submitted a Registry Services Evaluation Policy (RSEP) request to ICANN, proposing the complete destruction of the third-level hierarchy within .name to “simplify administration.” ICANN approved the proposal on July 28 after just three and a half months of review. Fraser and tens of thousands of other domain holders learned of the impending shutdown only in late August, when registrars finally began emailing notifications.

In its RSEP filing, VeriSign informed ICANN that approximately 22,000 third-level .name registrations remained, asserting that “many of which are not in use.” That single phrase became the core justification for wiping out the entire namespace. A monopoly registry eliminated 22,000 registration records on the vague assertion that “many” were idle—and ICANN never questioned the data or asked how many were actively powering critical personal infrastructure.

The Hijacking Risk: Abandoned Domains Threaten Decades of Accounts

The termination of third-level domains introduces security vulnerabilities far more dangerous than broken web links. Once neil.fraser.name is decommissioned, the second-level domain fraser.name will become available for public registration. Anyone could spend a few dollars to scoop up fraser.name and immediately recreate the neil.fraser.name email inbox.

Once an attacker seizes that inbox, they can use automated “Forgot Password” workflows to systematically take over every service tied to it: code commit authorizations, cloud management consoles, server credentials, and IoT device administration. Fraser openly acknowledged that he cannot even enumerate every account—online and offline—registered with that email over the past quarter-century. The blast radius of this attack surface is vast enough that even the victim cannot measure its limits.

Domain Registration Hierarchy Coverage Figure: Domain registration hierarchy and .name TLD coverage. Source: NameOcean

Feasible Community Alternatives Ignored by VeriSign

Discussions across Hacker News and Lobsters quickly formed a pragmatic consensus: freeze new third-level registrations, grandfather existing active users, and allow sole third-level domain holders to transition to the corresponding second-level domain. This path is technically straightforward and carries minimal operational cost. Yet affected users revealed that despite requesting this exact transition over the past 15 years, VeriSign had repeatedly rejected every application.

The tech community also pointed out a clear commercial motive. The third-level structure of .name created naming collisions and ambiguity between formats like john.doe.name and john-doe.name. By wiping out the third-level namespace, VeriSign clears the deck to sell vacated second-level names as premium real estate. While the official justification cites “administrative simplification,” the question of who profits from this cleanup has an obvious answer.

ICANN Approves the Termination and Recommends Dismissing Appeals

An affected registrant has already filed a formal Reconsideration Request with ICANN challenging the decision. However, ICANN staff published an official recommendation: dismiss the request.

The institutional power dynamics here are stark. VeriSign operates as a monopoly registry, ICANN rubber-stamps its contractual requests, and registrars serve as passive messengers to customers. The registrant’s sole recourse is a reconsideration filing, which ICANN’s own bureaucracy recommends shutting down. A registration contract paid through 2040 carries zero binding weight in this governance structure. In legal reality, domain registration is not ownership but a lease: the registry is the landlord, ICANN is the property management, and tenants lack even a tenant union.

Your Domain Was Never Your Property

Fraser’s ordeal exposes an uncomfortable reality long overlooked by developers and internet users alike: registrants do not own domains; they merely hold a revocable license. Standard registry terms have always granted operators the right to terminate services. For twenty-five years, that contractual clause lay dormant—until now. VeriSign pulled the trigger, ICANN signed off, and 22,000 third-level domains will be purged in February 2027, irrespective of how many decades were paid in advance. In the DNS hierarchy, “your” domain was always on loan from the registry. And what is borrowed can be reclaimed whenever the landlord sees fit.

References:

  • Neil Fraser’s News
  • Domain Name Wire
  • Domain Incite
  • HN Discussion (item?id=49550772)