> Unfortunately there doesn't seem to be a way to tell ICANN that .lan has been widely used

ICANN isn't the DNS police, and lobbying them is pointless. We should campaign for open-source router projects[0], commercial hardware developers[1], DNS resolver developers, and major providers[2] to collectively designate commonly used private TLDs such as .home, .lan, .intranet, and .private as non-resolvable in public DNS.

Local resolution would continue to work, but these names would never be forwarded upstream. With sufficient adoption, we'd establish a de facto reservation and make the TLDs commercially worthless, regardless of what ICANN decides.

--

[0] There is precedence here. OpenWrt already reserves .lan in its default dnsmasq configuration.

[1] There is precedence here. GL.iNet inherits from its OpenWrt roots. Ubiquiti uses .lan as the default in its AmpliFi products. MikroTik documents it as part of its network-discovery mechanism.

[2] I'm thinking of Cloudflare, Quad9, and others.

> ICANN isn't the DNS police

ICANN and IANA very much are the DNS police. As a matter of fact, IANA maintains a list of special-use domains - though, despite its widespread use, .lan is not on the list - and these domains will get rejected from gTLD applications outright. The last thing I want is to require each recursive resolver to have their own idea of what should and shouldn't be resolved.

On a related note, Google owns a registry (CRR) and a recursive resolver (8.8.8.8) that's commonly used by default or as fallback. Letting them ban entire TLDs would be a massive conflict of interest.

ICANN only have enforcement power over registries and registrars. They have no enforcement power over hardware vendors, software vendors or public resolvers.

What I implied (but failed to emphasise) is that what I'm calling for is already in de-facto effect, with multiple software and hardware vendors treating .lan as not publicly resolvable. What you describe as "the last thing [you] want" is already happening; my proposal is for more of the same.

It is valid to note that ICANN could abuse their contractual arrangements with resolvers who also operate registrars, but this would be an illegal intimidation tactic. It would not be a conflict of interest for Google to act if part of a wider campaign involving other parties.

ICANN _are_ the DNS police? They author DNS RFCs, they manage namespace delegation.

Community groups can make their own competing DNS hierarchy and governing body and perhaps should but I don't think saying ICANN aren't responsible here is reasonable.

ICANN are the registry police, not the resolver police. I am proposing that resolvers wield their influence, not registries/registrars.

Formal objections require standing, procedural compliance and fees. Demanding monetary payment in order to issue an objection means that ICANN not acting as a responsible party in my view.