Even that doesn't pass basic scrutiny. The same ambiguity can and always will exist with tim-apple.com and tim.apple.com - there's nothing here that needs fixing.
Even that doesn't pass basic scrutiny. The same ambiguity can and always will exist with tim-apple.com and tim.apple.com - there's nothing here that needs fixing.
I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real.
It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com
In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com
edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule
That is definitely not true. There are literally thousands if not tens of thousands of well known domains that do this. .co.uk is a very common example.
.name is still a weird edge case because of the naming rules. Whether or not all subdomains under doe.name belong to the same person depends solely on whether the first person registered "doe.name" (in which case they do) or "john.doe.name" (in which case they don't, and "doe.name" is excluded from purchase as a standalone domain).
I think the problem is that .co.uk, .gov.uk and so on are very well known in the UK.
The .name subdomain rules are not very well known anywhere.
How familiar are you with Serbian co.rs, org.rs, in.rs (individuals) and top-level .rs too? Will you confuse it with iz.rs giving free subdomains to individuals too ("iz" means from in Serbian)?
How about all the other 200+ country TLDs and rules for non-country TLDs?
The fact that multiple organizations need to keep a public list of known 3LDs proves it's the edge case, does it not?
"Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.
I can’t think of any prominent ones outside of country code domains.
You can almost guess someone's age from that alone - they're more rare, but long domain names still appear that encode a city and a state, and you could just "grab" the first part when signing up.
Outside of the context of ccTLDs and city.state.gov etc, I struggle to think of examples 3LD+ domains where they are owned and operated by completely different concerns than the parent. If at some point you could just register your own mysite.state.gov domains willy nilly that's probably before my initial time online around 2000.
Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.
Many services today support vanity domains - Google even has special support for it: https://publicsuffix.org/list/public_suffix_list.dat
All Indian banks use bankname.bank.in as their domain. I’m not sure who owns bank.in but this is a common suffix which is different from the .co.uk pattern.
I remember I had beach.santa-cruz.ca.us at one point registered to me. I owned beach.santa-cruz.ca.us, someone else owned santa-cruz.ca.us, yet someone else owned ca.us, and I believe Network Solutions took care of .us at the time.
You say "registered" to you as though this was via an official registrar but surely you mean that someone rented ca.us and decided on their own to lease out subdomains to people?
(Aside, I always see "owned" and "bought" but you can only ever "lease" under the ICANN system as the present situation so clearly demonstrates.)
Historically, xx.us (where xx is a two letter state code) domains have been owned* by the named US state, which then would issue subdomains on top. I believe this was originally planned and set up by ICANN themselves.
*: I realize that “owned” is a loaded word here, but (1) I’m referring to a registrar/issuer, which makes it yet more complicated as to how much “ownership” (de facto or otherwise) a given entity may have, and (2) I really don’t give a fuck about pedantic word choice if the meaning is unambiguous.
My aside wasn't intended to be pedantic, rather observing the apparent inconsistency in how it appears people think about these matters versus what the present situation illustrates the reality to be.
> but (1) I’m referring to a registrar/issuer, which makes it yet more complicated
We're also talking about a ccTLD which makes it even more complicated. AFAIK those fall entirely under the jurisdiction of the respective UN recognized government although I don't know how strong that agreement is in practice (treaty versus something else).
So at that point I guess we've roughly got ICANN -> US federal government -> CA state government -> registrar -> private party -> sublet.
The way it worked is that someone nominally representing the CA State Government had* ca.us, and they in turn gave* san-jose to someone who nominally represented San Jose, los-angeles to someone who nominally represented Los Angeles, santa-cruz to someone who nominally represented Santa Cruz, and so on. city-name.ca.us domains were still free (and charging for .com and .org domains was a new thing at the time); you would look in the zone file to see who owned* a given domain, email them with your nameserver names and IP, and they would add it to their zone.
This isn’t how things are done these days; names visible to the public are pretty much always in the form {domain}.{tld} or sometimes {name}.{domain}.{tld} (e.g. my own https://samboy.github.io). Registration is now done by bots and companies that spam you to death to try and get more money from you (the Internet wasn’t like that in the beach.santa-cruz.ca.us days). Domain names with multiple levels of delegation aren’t around they way they used to be.
* rented/leased/had control over/whatever
> This isn’t how things are done these days
The old locality domains still exist, and in many localities you can still register them today by the same "email a request to some sysadmin" process. https://news.ycombinator.com/item?id=48122635
Your beach.santa-cruz.ca.us domain is still in DNS, just with a broken delegation chain. You could reclaim it right now by setting up a nameserver at reality.samiam.org.
I’m amazed beach.santa-cruz.ca.us is still around. I’ve given it some SSL certs and have reclaimed it:
https://beach.santa-cruz.ca.us/
Thanks for checking the zone files of the parent domain to verify it’s still there.
Github Pages is probably the most well known one (on here).
I think geocities had this as well?
A lot of hosting services offer this in general. (eg render)
Tumblr? (Might not count as the control over the page is more limited. The subdomains "are" still tumblr.)
For reddits subdomains are redirects to subreddits of the same name, so I guess that doesn't count.
None of these examples are of actual separate registration/ownership of a 3LD from the parent 2LD. Cloudflare owns the domain for myproject.pages.dev and hosts all the relevant infra. Not to say that there isn't a different entity represented by the 3LD than the 2LD but it's not exactly the same.
Also I would not consider the examples of tumblr and reddit to be relevant. A person's blog on myprofile.tumblr.org is still the tumblr organization. This would be true for reddit even if they didn't redirect. Reddit admins moderate content on all subreddits.
I see, that's a valid way to think of domain ownership.
When I read > I have been taught and tell my users to check the domain to verify a website is real.
I was thinking more of control of the content as "ownership" of the domain.
The point on hosting providers is well taken. You do have to consider x.pages.dev as the wild west not cloudflare of course. One difference though is you will never receive an email from x.pages.dev asking you to do something. The domain ownership still does play a part.
You can buy example.it.com on many registrars. Someone bought it.com and operates it like a TLD.
Interesting. I do wonder how many people outside scammers and squatters buy them. I'd rather have an .xyz or .biz address personally.
This seems largely country dependent with some exceptions.
In the US, once upon a time, elementary/middle/highschools might be attached to something like schoolname.district.state.gov. But now, even my local area school now has a .com. It seems that older hierarchy style is falling out of fashion for smaller/shorter domains across public services, schools, government agencies, etc.
Now here it seems to be either a .com, .gov, .org, or a totally different and newer tld. Even .net has fallen out of fashion.
Good article on this by a fellow hner
https://computer.rip/2025-11-11-dot-us.html
The writing was on the wall when Pennsylvania switched their license plates from www.state.pa.us to visitpa.com
Looking at the threads below, very few people are discussing technical things in dns terms like zone or nameserver.
Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with.
Then when you consider DNS is fundamental infrastructure and people build secure things on top of it, (ahem DNS challenges for certs), it's remarkable that anyone would want or desire edge cases.
This doesn't seem like a problem if you exclusively support 3LDs and don't let anyone register 2LDs.
Yet that is a problem the owner of such a domain has freely entered into by buying that domain, it's their right to keep it despite this apparent problem, if they wish.
Understood, and .name isn't being used enough in business to worry about 'the effect it will have on my users'. Just pointing out that it doesn't work like the 'norm' (although I guess it's not quite as unique as I thought, either)
There are still exceptions to this like .co.uk and many others.
Hello sysadmin. Good luck navigating the internet.
What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List
It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.
The .name mess is not in the public suffix list.
https://github.com/publicsuffix/list/issues/2306 for more discussion.
The public suffix list is a half assed bandaid over a fundamentally broken system.
I appreciate this, and yeah the government/education ones slipped my mind, but I stand by the fact that the reason a list needs to be kept in the first place is because this is the edge case and not the norm.
True, they can’t outright prevent the ambiguity, but much fewer people will go to the trouble of establishing such subdomains when the option isn’t directly offered by the registrar.
This is my theory because, a priori, 3LDs should be more profitable than 2LDs, because with 3LDs John Doe and Jane Doe don’t have to compete over doe.name, but instead can each separately purchase john.doe.name and jane.doe.name. Apparently, however, that’s not a benefit of 3LDs in practice, which leads me to conclude that john-doe.name and jane-doe.name just sell better.
Prior to reading the OP blog post, I had never looked into the particular rules that .name has.
To me, prior to knowing how it works, I would have assumed that either
a) john.doe.name would be a subdomain that someone who was just starting out had gotten for free supported by ads. Similar to having johndoe.freewebs.com back in the day. Not something most people would use for anything professional.
or,
b) doe.name was registered by one of the people in a family of Doe’s where every Doe is pretty closely related. For example, John of john.doe.name and Jane of jane.doe.name are husband and wife, or third cousins, or what have you. Most of the content, I would assume, is mostly about things that relate to the family. Like maybe one guy is doing a family genealogy project tracing the roots of this little cluster of Doe’s back in time and has made a site covering the findings from his research. And another one probably has some photo albums with pictures of like previous Thanksgivings and other family get togethers. In other words, nothing I would care about unless I was in their family or a very close friend of the family.
I would not have guessed that .name 3LDs worked the way that it did if I hadn’t read about it.
And on the other hand, if I saw just www.doe.name or johndoe.name, I would not make such assumptions. It would be not much different than seeing www.doe.com or johndoe.com respectively. I would just assume that .com was already taken and therefore they used .name, or that they happened to like the .name TLD because it emphasises that their site has their name as domain name.
> This is my theory because, a priori, 3LDs should be more profitable than 2LDs,
3LDs are less valuable. In a market of many different tlds, why register foo.bar.name when you could get foobar.name or foobar.something_else
Because your name is John Doe and not JohnDoe.
Your name is also not John.Doe.
Mr. Fraser registered neil.fraser.name in 2002, when 2nd level registration under .name was unavailable; fraser.com had been registered in 1996 and neilfraser.com in 2000; he may have been able to get .org or .net, their registration dates are later, but they may have been registered and there was a gap --- my personal domain shows a creation date of 2003, but I registered it much earlier and abandoned it, but got it back after it was registered and then abandoned by someone else.
.name added 2nd level registration in 2004 and it seems to be vastly preferred. .us added 2nd level registration in 2002 and it was vastly preferred to the locality based naming. People don't want to have to educate their contacts about "weird" domains, which includes having an "extra" dot in your hostname.