New gTLD Application for .lan
newgtldprogram-aps.icann.org
newgtldprogram-aps.icann.org
Regarding that last point, I've had issues with dnsmasq in the past where it was remotely resolving domains even when they were configured to resolve locally. For .lan domains, this could be disastrous because I often send plaintext traffic to them. I did submit a fix/workaround[0], but it's still something to look out for. If anyone knows more about this issue or other ways queries could leak, please share!
I hope the gTLD application gets struck down.
* https://en.wikipedia.org/wiki/.internal
Other special use domains:
* https://en.wikipedia.org/wiki/Special-use_domain_name
* https://en.wikipedia.org/wiki/Top-level_domain#Reserved_doma...
Personally, I just use a registered domain for this purpose, as they're cheap enough to not care (last I checked, I pay $10–20/domain/year for registrations, depending on registrar and TLD, and $0.21/zone/month for hosting public zones on Google Cloud).
[0]: https://amplifi.com/
- it is a second-level domain, why?
- 9 characters (home.arpa) is a lot
I kind of understand the motivation, it is a "technical" domain since it doesn't represent something in the global DNS registry, so it gets the .arpa TLD. However, that's reasoning that it out of touch from normal users. Normal users don't want to be exposed to the technicalities of DNS when they enter something in the address bar, and "myserver.lan" is more meaningful than "myserver.home.arpa", and giving meaningful names is the whole point of DNS.
I can't fucking _wait_ to type bender.home.arpa instead of bender.lan. Hyped.
Search domain is handy but it's ambiguous.
I don't know what this means, and searching is thorny. Help?
Your DHCP/SLAAC RA tells clients "here is a list of search domains, when you attempt to query a bare name, also look for the name plus any suffixes listed in the search domain list". So on a system with "home.arpa" in the search domains, you can do something like 'ping myhost' and your system should attempt to resolve 'myhost.home.arpa'.
You may be confusing it with the IETF’s policy.
In early days of the RFCs, most started out as proposals, often but not always with some existing implementation as a jumping-off point to conversation (hence the name). I no longer remember why they started to be numbered and tracked, as the process naturally preceded that.
You can verify what I say by just reading some old ones at the rfc editor site.
- Originally, IETF specified .home, but never went through the process to add it to the list of reserved names.
- Someone applied for the .home gTLD, and while it ultimately didn't go through there was a while while it was up in the air. Due to this the homenet working group had to change gTLDs.
- They decided to switch to .homenet. However, because of DNSSEC, whatever they used would need an insecure delegation in the root zone or validating resolvers wouldn't be able to resolve it. Since IAB controls .arpa but IANNA controls the root and there was no process to ask IANNA for this, they eventually decided to use home.arpa instead.
https://mailarchive.ietf.org/arch/msg/homenet/8cfJkr7SPMaPS4...
RFC 8244 is an interesting read on the topic: https://datatracker.ietf.org/doc/rfc8244/
It should be logical even without thinking that the request have to be rejected.
It was funny, because when I brought it up to them, it was hard to articulate why it was a problem and I couldn't convince them it was worth the effort of trying to fix. They never ran into a specific issue due to this while I was there but it felt so gross.
Historically (20+ years ago), some Microsoft documentation suggested .local as an example of an unregistered domain that could be used for this purpose, which was problematic when .local was subsequently reserved for multicast DNS.
At least that's the conclusion I've arrived at at some point, but I don't remember what was the exact use case anymore.
However there are still several global IPv4 ranges that are not local reserved ranges but are effectively reserved and you could use them if you really want to without any issues.
Sure one day your printer might start spewing random json code meant for some microservice of the rightful IP owner.
Sure the IP's might be owned by the Air Force and one day they might start getting traffic from your pos ipad that they decide looks like an attempt to attack one of their internal secret networks...
Sure one day traffic meant to go to your printer ends up flooding and dossing a windmill controller, preventing the rightful operators from turning it the right direction during bad weather and causing $25M damage...
And of course the real failures are more like, only people from the Maldives can't send email to your email server, a failure with no impact.
https://icannwiki.org/Name_Collision_Risk_Management_Framewo...
This test is poorly designed for .lan because the opposite problem is more likely: that many people using .lan will have any resolution attempts swallowed by their routers. This is certainly true for OpenWrt and GL.iNet. It may be true for Unifi AmpliFi, which reserves .lan by default. It's potentially true for other vendors when .lan is configured as the local domain (which many online guides suggest people do).
Arguably that's on them, but .lan seems much more controversial and I really hope ICANN does the right thing here and at least declares it permanently reserved/non-registerable.
Once that happens, browsers and other stakeholders could then consider allowing self-signed TLS certificates, maybe with TOFU semantics, for .lan hosts, ideally together with .local mDNS ones.
The bureaucracy seems precision-engineered to stultify, but apparently the public have 104 days after “String Confirmation Day” (17th Nov; capitalization theirs) to lodge objections, assuming the “GAC” doesn’t beat them to it…
https://newgtldprogram.icann.org/en/application-rounds/round...
…of course there’s a “filing fee,” priced in “hours of a panel of lawyers’ time,” to lodge such an objection…
https://newgtldprogram-2026-agb.icann.org/en/8-module-4-comm...
…welp, hope somebody more organized (and better-funded) than I can organize an objection. Much as I feel like I’m giving up my right to gripe by assuming somebody else will come along to do the weeding.
This may very well end up to be determined too risky to be delegated, like .corp, .home and .mail in 2018.
- "String Confusion" -- looks or sounds like an existing (approved or being applied for) gTLD. Must be filed by whoever owns (or is applying for) that gTLD.
- "Legal Rights" -- someone else owns a trademark this would violate. Must be filed by whoever's legal rights would be violated.
- "Limited Public Interest" -- the gTLD is immoral under recognized principles of international law. I have no idea when this could be applicable.
- "Community" -- An established community organization believes the group this gTLD is intended to target will object to it. This seems more like a vehicle for e.g. Little People of America to let ICANN know that ".midget" would be offensive.
Unfortunately there doesn't seem to be a way to tell ICANN that .lan has been widely used and will break things in a way they will listen to.
ICANN isn't the DNS police, and lobbying them is pointless. We should campaign for open-source router projects[0], commercial hardware developers[1], DNS resolver developers, and major providers[2] to collectively designate commonly used private TLDs such as .home, .lan, .intranet, and .private as non-resolvable in public DNS.
Local resolution would continue to work, but these names would never be forwarded upstream. With sufficient adoption, we'd establish a de facto reservation and make the TLDs commercially worthless, regardless of what ICANN decides.
--
[0] There is precedence here. OpenWrt already reserves .lan in its default dnsmasq configuration.
[1] There is precedence here. GL.iNet inherits from its OpenWrt roots. Ubiquiti uses .lan as the default in its AmpliFi products. MikroTik documents it as part of its network-discovery mechanism.
[2] I'm thinking of Cloudflare, Quad9, and others.
ICANN and IANA very much are the DNS police. As a matter of fact, IANA maintains a list of special-use domains - though, despite its widespread use, .lan is not on the list - and these domains will get rejected from gTLD applications outright. The last thing I want is to require each recursive resolver to have their own idea of what should and shouldn't be resolved.
On a related note, Google owns a registry (CRR) and a recursive resolver (8.8.8.8) that's commonly used by default or as fallback. Letting them ban entire TLDs would be a massive conflict of interest.
What I implied (but failed to emphasise) is that what I'm calling for is already in de-facto effect, with multiple software and hardware vendors treating .lan as not publicly resolvable. What you describe as "the last thing [you] want" is already happening; my proposal is for more of the same.
It is valid to note that ICANN could abuse their contractual arrangements with resolvers who also operate registrars, but this would be an illegal intimidation tactic. It would not be a conflict of interest for Google to act if part of a wider campaign involving other parties.
Community groups can make their own competing DNS hierarchy and governing body and perhaps should but I don't think saying ICANN aren't responsible here is reasonable.
Formal objections require standing, procedural compliance and fees. Demanding monetary payment in order to issue an objection means that ICANN not acting as a responsible party in my view.
The most valuable parties to sway wouldn't even be Google or Cloudflare. As registrars as well as resolvers, I've no serious expectation that they'd stick their neck out. Ubiquiti might though.
Having internal domain names owned by some guy on the internet has already compromised multiple corporate networks. See the talk from this guy:
https://www.romhack.io/wp-content/uploads/2025/10/Internal-D...
at the very least, the .dev stuff should have had people second-guessing their usage of unreserved domains.
In time we'll see articles like "Don't register a .lan domain if you want people to visit your site"
throughout most of my career, there was no unreserved domain that felt safe. but especially after .dev.
That leaves .home.arpa, which is very awkward and only a thing since 2018 (my home network's use of .lan definitely predates this). Especially as a non US citizen. It also seemed so far that .lan was the "unofficial" gTLD to be used, since much software like OpenWRT was already using it anyway.
Either way: making .lan internet routable seems entirely unhinged to me. LAN has always been the acronym for Local Area Network. Why would anyone sane think that it is a good idea to make this into a gTLD that can be internet routable? The only way I see forward to do this justice, is to only allow RFC 1918 and IPv6 addresses that are within the assigned prefix for your router.
This seems like a worse version of allowing .zip to be a gTLD. Remember the idea of downloading something from https://github.com/[...]@evil.zip?
there is. it's .internal.
https://en.wikipedia.org/wiki/.internal
(note: i hope .lan does not get approved, but people have to understand that they are rolling dice when using unreserved names)
edit: fucking wild that this is downvoted into negatives. press the wiki link and read the first line if you don't believe me. in fact, i will quote it: "The name internal is reserved by ICANN "
That explains why I hadn't heard of this yet. My current incarnation of my internal network dates from ~april 2024.
.qm to .qz and .xa to .xz have always been implicitly reserved as TLDs that will never be globally-routable [0] [1], but these aren't exactly the most intuitive names so it's unsurprising that nobody uses them.
(".internal" as mentioned by the sibling comment [2] is the best choice these days, but its definition is somewhat recent.)
[0]: https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2#User-assign...
[1]: https://en.wikipedia.org/wiki/Country_code_top-level_domain#...
Home.arpa exists, or buy a domain and use that. Or pick something that’s not reserved and run the risk of this happening.
FTFY
Even today when setting up greenfield networks, I generally use internal.company.com. It also lets you get public trusted SSL certificates so you don't have to deal with internal PKI.
To me is a very bad idea to implement this proposal, it should instead be standardized and reserved for internal usage as a fix. There were even RFC like https://www.rfc-editor.org/info/rfc6762/#appendix-G that suggested their usage for local devices in a network.
What is the point of selling the .lan domain, except for making money at the expense of a security risk for millions of networks that already use that domain for internal hosts?
BTW to me there was never any sense to add new TLD domain despite country code. They decided to render internet less secure, by giving scammers infinite TLD to register they scam domain like "apple.lan", with the sole purpose of making for them easy money.
it is not, as .local is designated as a special-use domain name and .lan is not.
It may not be an official standard, but it does have some weight as a de-facto standard.
I've tried briefly to try and find some numbers to back that up, but can't find much beyond apple's bonjour vs consumer routers - although I've seen companies with AD domains using .lan as well. (Although, I've also seen companies using 1.0.0.0/8 for their internal addressing...)
if you choose to use an unreserved domain, you are choosing to accept the risk of something like this happening. take ownership of your choices. "but other people use it" is not a great defense.
.home.arpa is so clunky. Why do I have to put the acronym of a US military project in my domain to access resources on my own local network?
Yes, I know that organization was central to the development of the l Internet, but it's not relevant as a domain 40 years later.
This is not how anything should work.
guess I'll be migrating things 100% over to internal...
I've been bitten by this with my home router which uses <device>.fritz.box when somebody registered fritz.box.
> Objections for this Application have not yet been published. Information will be added when it becomes available. Please check back periodically for updates.
How does this work? Who can submit an objection? Can I submit one as someone with .lan domains inside my home network?
For those not in the know, Google lobbied ICANN to get the name and in their application they stated (repeatedly) that the intent was to buy it so that it could be reserved; as .dev was already used by developers and if someone bought it for commercial purposes it would harm the developer community.[0]
.... they then proceeded to start selling them.
Leading to all kinds of issues, the exact issues that they raised...
https://github.com/basecamp/pow/issues/397
https://github.com/laravel/valet/issues/433
https://danielbachhuber.com/switch-laravel-valet-from-dev-to...
https://community.localwp.com/t/dev-domain-doesnt-work/4277
https://forums.theregister.com/forum/all/2017/11/29/google_d...
[0]: https://gtldresult.icann.org/applicationstatus/applicationde...
My tweet on Sep 26, 2026
There are questions that literally say as part of the question "Choose Yes or No", so they've answered "true"...
And Q165 is fun: "Is it likely that consumers will face significant risks if domain names in the TLD(s) in the application are abused?" Answer: "No"
Also see a .bldg application, which also might conflict with some legacy naming schemes.
There's almost no value.
Large businesses almost never use them. The potential for scams / phish / etc are now limitless.
It's arguably defensible to have a limited number of non-geographic TLDs. "Dot com" was an aesthetic as much as a technical decision. I wonder though, if .com/net/org had never existed, we would have a different sense of aesthetic around domain names, and there's no reason to think that it would be any better or worse than what we have now.
Just purely from common sense perspective why the fuck should .lan be something that’s an internet/public TLD? Hello? LOCAL Area Network?
While we’re at it let’s update a few RFCs. Plus I don’t want to find out what organisations use .lan for their networks and what will end up leaking to the internet as a consequence of this.
Fortunately there’s no need to speculate as the application explains this clearly:
AGB Q118: What is the meaning/definition of the applied-for gTLD string?
Answer: Lan commonly refers to a broadly recognized term used across a wide range of contexts.I'm guessing that'll end up being expensive for someone...
ICANN Reveals 2026 Round Applications for New Generic Top-Level Domains
Source: the application refers to multiple layers of LLC ownership, and the responsible parties listed are general counsels at some IP financialization company, "Identity Digital"
https://www.icann.org/en/board-activities-and-meetings/mater...
.internal is all about the boundary between inside and the public internet, regardless of how you define ‘inside’.
I don't really see what website would use it though. Maybe for networking companies like mikrotik.lan or self hosted services like immich.lan?
It's monopolies like Verisign (of the .com tld) that have luxurious profits. No competition, plus they are allowed to raise their prices above inflation while their infrastructure costs go down every year.
"America" has our best interests at heart /s