A recent disclosure by software engineer Neil Fraser has brought scrutiny to a quiet regulatory change governing the .name top-level domain (TLD). Fraser announced on his personal website that his domain, registered nearly 25 years ago, is scheduled for deletion following approval from the Internet Corporation for Assigned Names and Numbers (ICANN).
The move stems from an ICANN Registry Services Evaluation Policy request submitted by registry operator Verisign on April 15, 2026. Under the approved service change(decision taken in late July), Verisign is discontinuing third-level domain registrations, structured as first.last.name, citing declining usage and limited registrar support. Operationally, EPP transactions will reject new third-level registrations, and all existing active registrations will be deleted following a minimum 90-day registrar notice period.
Importantly, the change does not decommission the entire .name TLD. Verisign will continue to support standard second-level domain registrations (such as example.name), which have been available since 2004. Existing second-level domains will remain unaffected by the termination.
However, the complete deletion of legacy third-level names directly impacts an estimated 22,000 registrants who adopted the structure when the TLD debuted in 2001 under Global Name Registry. Beyond the immediate disruption to long-running websites, mail servers, and IoT infrastructure, Fraser highlighted severe security ramifications: once third-level records are deleted, the parent second-level domains may become open for public registration. A malicious actor acquiring a released second-level domain could easily configure DNS records to intercept communications, reset passwords, and hijack accounts tied to legacy addresses.
Image Source: Generated with Gemini based on the explanations from https://neil.fraser.name/news/2026/09/03/
Online technical communities across Hacker News, and Mastodon reacted with alarm. Commenters heavily criticised both Verisign's filing—which claimed that registrars identified no security, stability, or resiliency concerns—and ICANN's approval of an action that invalidates paid, active domains. Several observers characterised the resulting fallout as identity theft-as-a-service, warning that orphaned email addresses will become prime targets for automated takeover. Engineers on Hacker News noted that the decision sets a damaging precedent for registry stewardship, arguing that Verisign should either freeze existing delegations into perpetual read-only maintenance mode or permanently reserve the associated second-level domains rather than releasing them into the wild.
Fraser: I'm just one of 22,000 people who will lose their domains. This is going to be fun. Time to lawyer up...
With registrar deletion notices rolling out, affected domain owners are evaluating whether administrative appeals or legal challenges can compel ICANN and Verisign to offer defensive protections before legacy domains go dark.