Having internal domain names owned by some guy on the internet has already compromised multiple corporate networks. See the talk from this guy:
https://www.romhack.io/wp-content/uploads/2025/10/Internal-D...
Having internal domain names owned by some guy on the internet has already compromised multiple corporate networks. See the talk from this guy:
https://www.romhack.io/wp-content/uploads/2025/10/Internal-D...
Even today when setting up greenfield networks, I generally use internal.company.com. It also lets you get public trusted SSL certificates so you don't have to deal with internal PKI.
at the very least, the .dev stuff should have had people second-guessing their usage of unreserved domains.
In time we'll see articles like "Don't register a .lan domain if you want people to visit your site"
throughout most of my career, there was no unreserved domain that felt safe. but especially after .dev.
That leaves .home.arpa, which is very awkward and only a thing since 2018 (my home network's use of .lan definitely predates this). Especially as a non US citizen. It also seemed so far that .lan was the "unofficial" gTLD to be used, since much software like OpenWRT was already using it anyway.
Either way: making .lan internet routable seems entirely unhinged to me. LAN has always been the acronym for Local Area Network. Why would anyone sane think that it is a good idea to make this into a gTLD that can be internet routable? The only way I see forward to do this justice, is to only allow RFC 1918 and IPv6 addresses that are within the assigned prefix for your router.
This seems like a worse version of allowing .zip to be a gTLD. Remember the idea of downloading something from https://github.com/[...]@evil.zip?
there is. it's .internal.
https://en.wikipedia.org/wiki/.internal
(note: i hope .lan does not get approved, but people have to understand that they are rolling dice when using unreserved names)
edit: fucking wild that this is downvoted into negatives. press the wiki link and read the first line if you don't believe me. in fact, i will quote it: "The name internal is reserved by ICANN "
That explains why I hadn't heard of this yet. My current incarnation of my internal network dates from ~april 2024.
.qm to .qz and .xa to .xz have always been implicitly reserved as TLDs that will never be globally-routable [0] [1], but these aren't exactly the most intuitive names so it's unsurprising that nobody uses them.
(".internal" as mentioned by the sibling comment [2] is the best choice these days, but its definition is somewhat recent.)
[0]: https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2#User-assign...
[1]: https://en.wikipedia.org/wiki/Country_code_top-level_domain#...
Home.arpa exists, or buy a domain and use that. Or pick something that’s not reserved and run the risk of this happening.
FTFY