I was a DNS registry system admin at Nominet, the .uk registry, from 2017 to 2019. What follows about ICANN is all public record and I have linked the lot. Where I am talking from the job instead, I say so.

Ask most engineers who runs DNS and you get one of two answers. Either a shrug, or something about thirteen root servers. Both are wrong, and the second is wrong in a more interesting way, because it points at the machines instead of at the file.

Control of DNS is not distributed across thirteen servers. It sits in one text file, and in the handful of outfits that decide what goes into it, edit it, sign it, and publish it. Everything else in the system — every resolver, every registrar, every zone you have ever run — is downstream of that file and takes its authority from it.

This post is about who holds that file, what the 2016 handover actually transferred, and what the people holding it have done with it. The machinery underneath — what a registry actually is, how names get into it, and who can take one away — is the follow-up.

Before ICANN, It Was a Phone Call

None of the current arrangement is inevitable, and the history says what ICANN was actually built to fix.

To begin with there was no DNS at all. From 1972 there was one text file, HOSTS.TXT, holding every machine name on the ARPANET and the address it lived at. It was kept at Stanford Research Institute by Elizabeth Feinler and her team, and if you wanted your machine in it you rang the Network Information Center during office hours and asked. Everybody else fetched the file now and then and hoped it was current.

That does not scale, and by the early 1980s it plainly was not. DNS was built to replace it — a tree, delegated downwards, so that no single office had to hold the whole list.

Somebody still had to hold the top of the tree. For years that somebody was one man. Jon Postel, at the University of Southern California, ran the name and number assignments on US government research money. IANA — the Internet Assigned Numbers Authority — was not an institution at that point. It was Postel and a handful of colleagues, and it worked because the people running the network trusted him.

Money arrived in 1993, when the National Science Foundation contracted InterNIC — Network Solutions among them — to handle registration. On 14 September 1995 free registration ended. Network Solutions charged $50 a year on a two-year minimum, and 30% of it went to a government fund that a court later ruled an illegal tax. One company, one price, nowhere else to go, and by 1997 an antitrust suit.

Then in January 1998 Postel did the thing that tells you what the root’s authority is actually made of.

He emailed eight of the twelve root server operators, on nothing but his own standing, and asked them to point their servers at IANA’s machine instead of Network Solutions’. All eight did it. For about a week the authoritative root of the internet was wherever Jon Postel had asked people to look.

He called it a test. Plenty of people read it as a demonstration — that the root belonged to the engineers who built it rather than to a government contractor. The response settles which reading Washington took. Ira Magaziner, the presidential adviser on the matter, told Postel he would never work on the internet again. The test was reversed.

ICANN was incorporated in California that September. Postel died the following month.

So the arrangement this post is about was built to fix two real problems: a namespace being sold by an unaccountable monopolist, and a root whose authority rested on one man being widely trusted. Both were real problems. ICANN was the answer to them.

Two Codes That Outlived the Rule

Two loose ends from that era before moving on, because between them they say more about how this system really works than anything in ICANN’s bylaws does.

The UK took the wrong code and kept it.

RFC 920, in October 1984, said country top-level domains would be taken from the two-letter codes in ISO 3166. The United Kingdom’s ISO 3166 code is GB. By the rule as written, the UK’s domain should be .gb.

It is not, because the UK got there first. JANET, the academic network, had already settled on uk as its top-level identifier a few months before the ISO-derived list was drawn up, and .uk was registered on 24 July 1985. .gb was assigned as well, on the understanding that .uk would migrate across to it in time.

The migration never happened. Nobody made it happen. .gb then sat in the root for four decades having picked up, in its whole life, one second-level domain — hmg.gb, for Her Majesty’s Government — which was barely used. ISO eventually bent around the fact on the ground and exceptionally reserved UK at the United Kingdom’s request.

Nobody was robbed, incidentally. UK was not another country’s code — it is exceptionally reserved in ISO 3166 for the United Kingdom, at the United Kingdom’s own request, and no other state ever had a claim on it. That is exactly why nobody forced the issue: there was no injured party to complain.

Which is what makes it worth telling. The ISO 3166 rule is rigid for anybody trying to get in: no entry on the list, no country-code domain. That is why territories lobby to be added to ISO 3166 in the first place, and why places without recognition have no ccTLD at all. For an incumbent already in the root, the same rule turned out to be a suggestion.

There is even a fair argument the UK ended up with the better name. GB is Great Britain, which leaves out Northern Ireland. UK does not. The non-compliant code describes the state more accurately than the compliant one would have.

And the Soviet Union is still in the root. This one is stranger.

.su was delegated to the Soviet Union on 19 September 1990. The Soviet Union ceased to exist fifteen months later.

It is still there. Thirty-five years after the state it belongs to stopped existing, .su is live and taking registrations — something over 111,500 names as of May 2025, administered from Moscow.

The rule says ccTLDs come from ISO 3166. ISO 3166 does not list the Soviet Union. And it is not as though the rule was never applied: .dd for East Germany and .yu for Yugoslavia both went when those states did. .su was the one that did not, and nobody has ever been able to explain the difference in terms of the rule.

What it became is predictable enough. When .ru tightened its registration checks in late 2011, the trade moved next door. Malicious sites in .su doubled in 2011 and doubled again in 2012, which is the same story as the cheap new gTLDs and the free ccTLDs later in this post: abuse is a fluid, and it flows to wherever the checks are weakest.

Two country codes, then, that outlived the rule that produced them. .uk because nobody made an incumbent move, .su because nobody made a delegation go when its country did. In both cases the rulebook is clear and in both cases it went unenforced, because enforcing it would have meant taking something away from somebody who already had it.

That is the whole character of authority in DNS, visible before ICANN existed, and as such none of what follows should surprise you.

What that answer turned out to be is the rest of this post.

The Eighteen Years to the Handover

ICANN was incorporated in California on 30 September 1998 and immediately signed a Memorandum of Understanding with the US Department of Commerce. It did not begin independent and grow American. It was American from the first day, by construction, and the arrangement was renewed in one form or another for eighteen years.

Start with the thing it got right, because there is one and it matters.

In 1999 ICANN broke the registration monopoly. Network Solutions had been the only place to buy a .com; the Shared Registration System let other registrars sell names in the same zone, and the price came down and kept coming down. That is a real achievement, it is the reason a domain costs what it does today, and nothing later in this post cancels it.

Then the pattern that runs through everything else starts.

2000. ICANN held a global election in which internet users chose five board members directly. It was never repeated. The at-large structure that replaced it advises and does not vote. The first and last time the public got a binding say in ICANN, ICANN discontinued it.

2005. At the World Summit on the Information Society in Tunis, a large part of the world objected to the US holding the root. What came out was the Internet Governance Forum — an annual conference with no authority over anything. The root arrangement did not change.

2005. The .xxx affair, which ran for six years and is the sharpest single proof in this whole post that jurisdiction is not abstract. Socially conservative lobby groups in the United States pressed the Department of Commerce. The NTIA — the National Telecommunications and Information Administration, the arm of Commerce that held the agreement with ICANN — drafted letters to ICANN and, in its own words, marshalled its resources at ICANN. The board — which had been heading for approval — rejected the application, nine to five, then again eight to four, with the chairman and the CEO both reversing position. Viviane Reding, then the European commissioner responsible, called it the first clear case of political interference in ICANN by the US government. .xxx was finally approved in 2011, at which point the Department of Commerce announced it was disappointed.

An American domestic lobbying campaign, routed through an American federal agency, changed what top-level domains exist on the internet. No treaty, no court, no vote outside the United States.

2009. The Joint Project Agreement with Commerce was replaced by the Affirmation of Commitments, widely written up as ICANN becoming independent. The IANA functions contract stayed exactly where it was.

Then the thing that actually moved it, and it was nothing ICANN did.

2013. Edward Snowden. On 7 October, months into the disclosures, the leaders of ICANN, the Internet Engineering Task Force, the Internet Architecture Board (IAB), the World Wide Web Consortium, the Internet Society and all five regional internet registries published the Montevideo Statement, calling for the globalisation of ICANN and the IANA functions and citing, in terms, the damage that pervasive surveillance had done to global trust. The internet’s own technical leadership — ICANN’s chief executive among the signatories — said out loud that American stewardship had become a liability.

14 March 2014. NTIA announced its intent to transition its stewardship of the IANA functions.

1 October 2016. The contract expired.

So the handover was not earned and it was not granted on the merits. It was conceded, eighteen years in, because a US intelligence scandal made the existing arrangement politically indefensible and the technical community said so in public.

Which is worth holding onto when you read what the transition actually did.

What the 2016 Transition Changed, and What It Did Not

You will hear that the Americans handed over the internet in 2016. Anyone arguing that ICANN is an instrument of US control gets told this, and if they have got their facts wrong they lose the argument there. So get them right.

On 1 October 2016 the IANA functions contract between NTIA and ICANN expired and was not renewed. That was real. The US government no longer holds a contract giving it approval over root zone changes, and new bylaws created an Empowered Community with the theoretical ability to reject budgets and remove board members.

Here is what did not change, and it was not an oversight. It was written down as an objective.

The transition proposal stated that the legal jurisdiction in which ICANN resides was to remain unchanged. The new bylaws require ICANN to stay headquartered in California. The entire accountability structure built during the transition is built on California law. It works by making ICANN a Californian non-profit that Californian courts can be asked to hold to its own articles.

So after the great handover: ICANN is a California corporation, subject to US federal and Californian law, whose accountability mechanisms are enforceable in American courts and nowhere else, setting policy for a root zone edited and signed by an American company under an agreement with the American Department of Commerce.

The contract went. The jurisdiction was deliberately kept. And jurisdiction is the part that has teeth, because it does not require anyone to intervene. It applies automatically, all the time, by default.

The clearest demonstration is sanctions. OFAC — the Office of Foreign Assets Control, part of the US Treasury — runs American economic and trade sanctions, and decides who US persons and companies are allowed to do business with. ICANN is a California corporation, so OFAC binds it, and it constrains who ICANN may contract with and accredit.

Be precise about the scope: that reaches generic top-level domain (gTLD) registries and registrars, because those hold ICANN contracts. It does not reach country-code (ccTLD) operations, which sit outside ICANN’s contractual structure entirely. But the effect leaks well past the legal boundary, because registrars outside the United States have applied OFAC restrictions to their own customers under the mistaken assumption that holding an ICANN contract requires it, or simply by copying American registrant agreements. American foreign policy propagates down the registrar chain by imitation as much as by law.

There is no version of this in which the answer to “who controls DNS” does not begin with the United States.

Who that leaves able to do anything about an ICANN decision is the other half of the question, and it is better asked once there is a record to test it against. This post comes back to it at the end.

The Root Is a Text File

So much for who is in charge. Here is the thing they are in charge of, and you can just fetch it. ICANN publishes the root zone by zone transfer — AXFR, the DNS mechanism for copying a whole zone rather than one record — to anyone who asks, no credentials:

dig . AXFR @xfr.dns.icann.org

Right now that is 1,578,790 bytes across 24,886 lines. It contains 1,439 delegations — every top-level domain that exists — of which 1,350 carry a DS record — the delegation signer, the fingerprint that ties a child zone’s signing key into its parent — and are therefore part of the signed chain.

One and a half megabytes. The entire namespace of the internet, small enough to email.

That file is the whole of the root’s authority. A resolver starting cold knows nothing except the addresses in its root hints, and the moment it gets an answer it is following delegations out of that file and nowhere else. Change a delegation in it and you have changed where an entire country’s traffic goes. There is no second copy with a different opinion, no consensus protocol, no vote at resolution time. There is the file.

So the question “who controls DNS” reduces to a much narrower one: who can change that file, and who signs it afterwards.

Three Organisations Touch It

The answer is a chain of three, and it is worth being clear about which does what, because the distinctions are where all the arguments live.

PTI — Public Technical Identifiers, an ICANN affiliate — performs the IANA functions. It receives root zone change requests from TLD operators, checks them, and authorises them. This is the clerical layer, and deliberately so: the whole design intent is that IANA is a careful clerk with no discretion.

Verisign is the Root Zone Maintainer. It takes the authorised change, edits the zone file, signs it with the root zone signing key, and publishes it for distribution. Verisign is an American public company, and it does this under a Cooperative Agreement with the US Department of Commerce.

The root server operators then serve it. They are the least powerful part of the chain and the only part anyone has heard of.

Note where the discretion actually sits. Not with the operators. Not really with the clerk. It sits with whoever sets the policy that the clerk applies, which is ICANN, and with the company that holds the pen and the signing key, which is Verisign, under an agreement with the American government.

Ten of the Thirteen

The root server letters are worth listing in full, because people cite the number thirteen as though it implies dispersal:

LetterOperatorCountry
AVerisignUS
BUSC Information Sciences InstituteUS
CCogent CommunicationsUS
DUniversity of MarylandUS
ENASA Ames Research CenterUS
FInternet Systems ConsortiumUS
GUS Department of Defense (DISA)US
HUS Army Research LaboratoryUS
INetnodSweden
JVerisignUS
KRIPE NCCNetherlands
LICANNUS
MWIDE ProjectJapan

Thirteen letters, twelve organisations, because Verisign holds both A and J. Ten of the thirteen are operated from the United States. Two of them are the American military.

That is not a conspiracy, it is fossilised history. These are the institutions that were on the network in the 1980s and never left. But an accident of history that leaves the US military running two of the internet’s root servers is still the US military running two of the internet’s root servers, and it is a strange thing to describe as a global system.

The operators also have no meaningful contract binding them. ICANN does not employ them and cannot in any straightforward way remove them. They serve the root because they always have. The system’s stability at this layer rests on goodwill and nowt sturdier, which works right up until the day it doesn’t.

ICANN Does Not Run the Root Zone

This is the most important fact in the post and it is almost never said out loud, so it gets its own heading.

ICANN does not operate the root zone.

It decides what should go in it. It does not edit the file, it does not sign the file, and it does not serve the file. Verisign edits and signs. Twelve organisations serve. ICANN’s job is to say what the answer ought to be, and then get somebody else to make it so.

That split is the only thing keeping ICANN in check.

Picture it without the split. One body sets the policy, holds the pen, owns the signing key and runs the servers. Between deciding a thing and that thing being true everywhere on earth, there is no other party, no second pair of hands, and nobody in a position to say no. Whatever you think of ICANN’s record below, that arrangement would be worse.

As it is, there are three brakes. Not one of them is in a bylaw.

  • The file is public. Anyone can pull the root zone over AXFR — the command is at the top of this post — and diff it against yesterday’s. You cannot change a delegation quietly.
  • Somebody else has to make the change. The maintainer does the edit and the signing. That is one more organisation that has to agree to do it, and one more that could decline.
  • The operators serve by consent. As above, ICANN has no meaningful contract with the root server operators. They distribute the zone because they always have. Nothing obliges them to distribute anything — and as Postel showed in 1998, consent is movable by somebody they trust asking them nicely.

The last one is the real backstop, and it has been used one layer down within living memory. When Verisign wildcarded .com in 2003, the Internet Systems Consortium (ISC) shipped delegation-only in BIND and operators simply stopped honouring the answers. Nobody had to win an argument at a policy forum. The technical community’s ability to refuse is written down nowhere and everybody involved knows it is there.

Now the uncomfortable part, because this is thinner than it sounds.

Nobody designed this check. It is not a separation of powers, it is an accident of how the work got divided up in the 1990s, and the 2016 transition neither strengthened it nor wrote it down. There is no rule saying the body that sets policy may not one day also hold the pen.

And the party doing the checking is a commercial company that ICANN is doing business with. Verisign holds the root zone maintainer role, and the .com contract, and — as the rest of this post lays out — a $20 million agreement with ICANN signed in the same negotiation as a .com price rise. A check that depends on one party being willing to refuse the other stops working once the two of them are signing things together.

So the separation is the best thing about the current arrangement. It is also unwritten, unplanned, and held together by habit.

Selling the Namespace

Before any of the governance argument, something simpler shows what the people holding a piece of the namespace do with it when nothing stops them. It has happened repeatedly, at every layer, and the first time it happened at the top it lasted nineteen days.

On 15 September 2003 Verisign added a wildcard A record to the .com and .net zones:

*.com.  IN  A  64.94.110.11

That address reverses to sitefinder.verisign.com. From that moment, every name in .com and .net existed. Every typo, every unregistered domain, every malformed string, every expired name — all of them resolved, to a Verisign search page carrying Verisign’s advertising.

Why This Is Not an Advertising Story

The complaints at the time were mostly about the ads, and they missed the point. NXDOMAIN is not a user-experience feature. It is a load-bearing protocol signal, and an enormous amount of software above DNS is built on being able to ask “does this name exist?” and get a truthful answer.

Delete the negative answer and things break in ways that have nothing to do with browsers.

Mail was the worst of it, and it is the part people still get wrong. Verisign did not publish a wildcard MX record. It did not need to. RFC 5321 §5.1 says that when an MX lookup returns nothing, the sender falls back to the domain’s address record and treats it as an implicit MX at preference 0. Verisign had just given every non-existent domain in .com an address record. So every MTA on the internet — every mail transfer agent, every machine that relays mail — following the standard correctly, now had a mail exchanger for soemcompany.com — and it was Verisign’s box.

Connect to port 25 and it answered:

220 snubby2-wceast Snubby Mail Rejector Daemon v1.3 ready

Verisign’s stated intent was reasonable enough: reject the mail immediately so it did not sit in queues worldwide. The implementation was not. Snubby only gave up after the sending MTA had transmitted the message body, and returned a code that most MTAs read as a transient failure — so instead of an instant bounce, mail to mistyped addresses was retried for days before dying. Verisign later swapped it for a Postfix-based responder after operators complained on the NANOG list.

Anti-spam broke at the same time, and more quietly. Checking whether a sender’s domain actually exists was, and still is, one of the cheapest and most effective filtering heuristics available. Overnight, every domain in the two largest TLDs existed. The check returned true for everything and stopped discriminating.

And everything else that speaks DNS but not HTTP — mail relays, FTP clients, networked printers, monitoring systems — stopped getting “no such host” and started getting a web server, which mostly manifested as timeouts and hangs rather than clean failures. A dead name now looked like a broken service.

One company added one record to one zone file and changed the failure semantics of the internet.

What Stopped It

Not governance. Engineering, and then a threat.

ISC shipped a delegation-only feature in BIND within days, letting operators discard synthesised answers from TLD zones — the technical community routing around the registry rather than appealing to anyone. Plenty of ISPs deployed it.

ICANN asked Verisign to suspend the service. On 21 September Verisign refused. ICANN then demanded it on 3 October, with the contractual consequences made explicit, and Verisign pulled the records on 4 October 2003. The IAB published its architectural objection to registry wildcards, and ICANN’s own Security and Stability Advisory Committee reported on 9 July 2004 that the service should never have been deployed without review and that registries should phase wildcards out.

Then Verisign sued ICANN, on 27 February 2004, arguing that ICANN had exceeded its authority by stopping it. The case was mostly dismissed that August, and the remainder settled on 1 March 2006 — a settlement that gave Verisign a new .com registry agreement.

Read that sequence once more. The registry monetised the namespace it was contracted to operate, refused to stop, was forced to stop, sued the body that forced it, and came out of the settlement holding a renewed contract for the most valuable TLD in existence. It still holds it. It is the same company that today edits and signs the root zone.

Then Everyone Else Did It Anyway

Stopping the registry did not stop the idea, it just moved it one hop down. If the authoritative server will not lie about non-existence, the resolver will.

From August 2006 Earthlink began redirecting NXDOMAIN responses to Barefruit, serving search pages and ads. Paxfire sold the same thing, and additionally redirected certain typed keywords to paying advertisers. Comcast’s “Domain Helper” did it at scale. In the UK, BT and Virgin Media both ran it. The economics are irresistible from an ISP’s side: mistyped domains are free inventory generated by your own customers’ fingers.

The failure modes were worse than Verisign’s, because a resolver sees every query, not just one TLD. Barefruit’s implementation would hijack NXDOMAIN for private address space, breaking split-horizon lookups and VPN behaviour on corporate networks. Dan Kaminsky demonstrated cross-site scripting (XSS) against the redirect pages themselves, because now every non-existent hostname in the world resolved to attacker-reachable HTML served in a context the browser associated with somebody else’s domain. Monetising the error case had turned a failed lookup into an XSS surface.

The Protocol Fix

Two things closed it off, and both are worth noting because they are the shape of every real fix in DNS: make the lie detectable, then make it contractual.

DNSSEC provides authenticated denial of existence. NSEC and NSEC3 records let a signed zone prove that a name does not exist, and a validating resolver will reject a synthesised answer in its place. Non-existence stopped being the one answer nobody could verify. It is not airtight — a resolver that strips signatures on the way past can still rewrite the answer, which is exactly why validating on the client rather than trusting the resolver matters, and it is the argument this site has already made at length.

And ICANN, to its credit, did learn this one. Specification 6 of the new gTLD registry agreement flatly prohibits wildcards, synthesised records and redirection for unregistered names, and requires authoritative servers to return Name Error, RCODE 3. Every one of the 1,200 strings from the 2012 round is contractually barred from doing what Verisign did to .com.

That is a real improvement, and it is worth being exact about what produced it: not the governance process, but nineteen days of visible breakage in 2003 that were embarrassing enough to be written into a contract a decade later.

And None of It Touched the Country Codes

Specification 6 binds gTLDs. It binds them because they sign a registry agreement with ICANN, and that agreement is the lever.

A ccTLD signs nothing of the kind. No registry agreement, no Specification 6, no compliance function, no fee. Nothing in ICANN’s rulebook governs how a country-code registry operates its zone — which is why both of the things below were possible, and why nobody was in a position to stop them.

That is not the same as saying ICANN is absent, and I want to be precise about where it sits, because I spent two years on the receiving end of it.

What ICANN holds over a ccTLD is the delegation itself. Every NS record, every piece of glue, every DS record and every contact change for .uk lives in the root zone, and the only route into the root zone is an IANA change request — verified against the registered administrative and technical contacts, and processed on IANA’s schedule rather than yours. Under RFC 1591 IANA also decides, in the last resort, who holds the delegation at all. Redelegations are rare. They are not hypothetical.

So a country-code registry is sovereign over how it runs, and completely dependent on a third party for anything that has to be visible in the root. The moments you most need a change to land — a nameserver moving, a key rollover whose DS has to be published before the old one goes — are exactly the moments you are waiting on somebody else’s queue. That is a live operational dependency rather than a governance abstraction, and it is a subject for the follow-up.

Now notice what that combination produces. ICANN’s grip on a ccTLD is tight precisely where it inconveniences a registry that is behaving, and absent precisely where it might have restrained one that is not. It can hold up your DS record. It could not stop Cameroon pointing an entire top-level domain at an advertising page.

So the practice never stopped. It just moved somewhere the contract did not reach.

Cameroon wildcarded an entire top-level domain to farm typos.

In August 2006 the .cm registry pointed every unregistered name in the zone at a parking page of paid search links. There is nothing subtle about the play: .cm is .com with the o missed, so the target market was the fat-finger rate of the largest TLD in existence, and the operator was a government agency — ANTIC, under Cameroon’s Ministry of Posts and Telecommunications.

It paid well. NameJet reported over $500,000 of .cm sales on the first day and more than $2 million in the first week; hotels.cm went for $81,100 in 2009. It also did exactly what you would expect to the safety of the zone, because inbound typo traffic is the ideal delivery channel for a hostile download. In December 2009 McAfee rated .cm the riskiest TLD in the world, with 36.7% of its sites assessed as posing a risk.

Verisign was forced to unwind the same trick in nineteen days. Cameroon ran it for years. The difference is not that one was worse. The difference is that one had signed a contract.

Tokelau became the largest country-code domain on earth by giving names away.

Tokelau is a New Zealand territory in the South Pacific with a population of about 1,500 people. Its ccTLD, .tk, was operated by Freenom, which gave registrations away for nothing. By 2016 it was the most-registered country-code domain in the world at 31,311,498 names — a figure that comes, as it happens, from a world map published by Nominet.

Free was not free. Freenom’s terms required a free domain to carry regular traffic, and provided that if the redirect stopped working — or if the name started drawing visitors worth having — the registry could take it back and serve its own advertising on it. That is the whole business, and it is more elegant than Verisign’s. Do not try to guess which names are valuable. Give away the entire namespace at zero marginal cost, let the world discover the valuable ones for you, then repossess those and monetise the traffic. Roughly one sixth of Tokelau’s annual income came from it.

The externality landed on everybody else. Free registration with no verification is the ideal input to bulk abuse — the same economics as the cheap new gTLDs, taken all the way to zero. By the time Meta filed suit, Freenom’s five free ccTLDs — .tk, .ml, .ga, .cf, .gq — were the source of more than half of all new phishing domains coming out of country-code TLDs.

What stopped it is the part that matters here.

Not ICANN, which had no contract and no standing. Not Tokelau, which was collecting a sixth of its national income. Not New Zealand. Meta’s lawyers, in the Northern District of California, in March 2023, on cybersquatting and trademark claims.

Freenom halted new registrations within days. Phishing originating from those extensions fell from over 60% to under 15%. Freenom settled in February 2024 and left the domain business, and by that March around 12.6 million domains — 99% of its portfolio — had stopped resolving.

One corporation’s legal department, in one American court, removed twelve and a half million names from the internet. No governance body in the history of DNS has ever exercised that much authority over the namespace, and it did not do it through governance.

Which is the third time in this post that the answer to “what actually enforces anything here” has turned out to be a court in California — and the second time that the enforcement was a private party acting in its own commercial interest, which happened on that occasion to coincide with everyone else’s.

And .uk is a ccTLD too. Same absence of any contract governing how the zone is run, same absence of Specification 6, same freedom to wildcard it or give the namespace away. It did neither. It ran an abuse process instead.

Which is where the tidy division stops being tidy, and it is worth spoiling deliberately.

Nominet does not only run .uk. It runs generic top-level domains too — its own, and several dozen more on behalf of other operators — and for those it signs the ICANN registry agreement like anybody else, Specification 6 and continuous monitoring included. On its own platform the un-contracted zone was outnumbered by roughly thirty to one.

So ICANN’s requirements reached .uk anyway. Not by authority, which it did not have, but because nobody sanely runs two operational regimes side by side to preserve an exemption for one zone. You build the strict thing once and run everything on it.

It is the same shape as the OFAC problem earlier: ICANN’s formal reach stops at the contract, and its actual reach carries on past it, propagated by operators for whom complying everywhere is cheaper than maintaining the distinction. The set of registries effectively governed by ICANN is materially larger than the set that has signed anything.

That estate, what it was like to run, and what happened to Nominet afterwards is its own post.

Which leaves the question this post keeps arriving at from different directions: when the contracts do not reach, what actually stops a registry doing owt it likes?

A follow-up will answer it from inside Nominet — the publication pipeline, EPP (the protocol registrars use to create and change names in a registry) and the economics underneath it, signing at registry scale, and who can really take a name away. This post is about the layer above it, and the layer above it does not come out well.

The Money

The next charge is simpler and needs less interpretation.

The Product They Invented

In 2012 ICANN opened applications for new generic top-level domains. Anyone could apply to run a new string to the right of the dot, for a non-refundable-in-large-part evaluation fee of $185,000.

It received 1,930 applications. That is over $350 million in evaluation fees, collected before a single string was delegated. Applicants who withdrew early got some of it back on a sliding scale; the great majority of it stayed.

ICANN described the fee as cost recovery.

Then, where two applicants wanted the same string and would not settle privately, ICANN auctioned it between them and kept the proceeds, which came to another $240,590,128. So the programme charged you to apply, and charged you again to win.

Ask the question that should have been asked in 2008: what problem was this solving?

The stated case was competition, choice and innovation. Fourteen years on, the results are measurable. Around 1,200 strings were delegated. As of August 2026 there are 1,112 new gTLDs holding about 48.7 million domains between them — against .com alone at more than ten times that. The incumbent monopoly was not disturbed in the slightest. It got a price rise instead.

The choice argument fails on its own evidence. 34% of the 2012 applications were for .brand strings — a company applying for its own trademark, largely so that nobody else could have it. Those are not new choices for anybody. Many were never used at all. McDonald’s never launched .mcdonalds. Intel took delivery of .intel in July 2016 and terminated it in November 2020, Symantec gave up .symantec two months earlier, and SC Johnson applied for eight strings — .scjohnson, .raid, .glade, .off, .duck among them — then terminated the lot in January 2022. Six years after the application window, more than one in ten new gTLDs had still not launched, 144 had not reached a sunrise period, and L’Oréal was sitting on strings it had never announced any plan for.

That is a lot of dead namespace. Here is why it does not bother ICANN.

Under the base registry agreement a gTLD operator pays ICANN a fixed fee of $25,000 a year, plus $0.25 per registration — but only once the TLD passes 50,000 transactions in a quarter. Below that threshold there is no transaction fee at all.

Read what that means. ICANN’s income from a top-level domain with zero names in it is exactly the same as from one with forty thousand: $25,000 a year, every year, for a delegation nobody uses. A dead string is not a failure on ICANN’s books. It is an annuity with no support burden.

There was no financial reason for ICANN to care whether any of this worked, and it is hard to find evidence that it did.

What the Internet Got Instead

The programme did produce one measurable effect, and it is not the one in the prospectus.

The new strings that did sell, sold on price. Registries with no brand and no natural demand competed the only way available to them, at a dollar or less a name, in bulk, with minimal checks. That is a product, and it found its market.

Interisle’s Cybercrime Supply Chain 2025 study found that new gTLDs carried 47% of reported cybercrime domains while making up 12% of the domain market — roughly a sixfold over-representation. The same study recorded 19.5 million unique domains used in attacks, up 126% year on year, with 7.3 million of them registered in bulk. The common factor it identifies in the most-abused domains is that they are cheap.

ICANN did not create phishing. But it manufactured 1,200 new places to do it from, priced the entry so that the only viable strategy for most of them was volume at near-zero cost, and took a fixed fee from each regardless of what came out.

The programme’s own showpiece failure makes the point better than any statistic. .sucks was delegated to Vox Populi, which charged trademark owners $2,499 a name during sunrise — a price set exactly because brands would have to pay it to stop somebody else. ICANN’s response was to report the registry to the US Federal Trade Commission for predatory pricing. The FTC found no rules had been broken, and observed that ICANN had already ignored several concerns the FTC had raised about the new gTLD programme.

That is the whole thing in one episode. ICANN designs the programme, ignores the regulator’s warnings about it, delegates the string, takes the fee, and then complains to the regulator about the predictable result.

Applications for the next round opened in 2026. The fee is $227,000.

The Strings Too Dangerous to Delegate

One more thing the programme produced, and this one is for anybody who has ever built an internal network.

Organisations have always invented top-level domains for internal use, on the assumption that a name which does not exist publicly never will. .corp. .home. .mail. .local. Pick something, put it in your Active Directory, nobody outside can see it.

The 2012 round proposed to delegate some of those for real, at which point every one of those private assumptions becomes a live security problem: internal names start resolving to somebody else’s servers, queries that used to fail start leaking your internal structure to a registry, and certificates issued for internal names become certificates for names a stranger now controls.

Nobody had checked. It only surfaced because researchers measured what was actually being asked of the root, and found that .home and .corp were among the most queried strings in existence — heavily used names that had never been delegated to anyone. ICANN’s own Security and Stability Advisory Committee raised it in 2013, after the applications were in.

.corp, .home and .mail have never been delegated. They are still deferred, indefinitely, because delegating them would break too much. Three strings that were applied for and paid for turned out to be too dangerous to exist.

That is a programme that expanded the root without first establishing what the expansion would collide with, and found out afterwards from other people’s measurements. If you want the practical end of this, it is the reason making up an internal TLD is a bad idea — the namespace you invented is only private until somebody sells it.

The Auction Money

Between June 2014 and July 2016 those contention auctions collected that $240,590,128, roughly $233 million after auction costs.

This is money obtained by selling pieces of a namespace ICANN does not own and holds in trust. There is a defensible answer to what should happen to it, and the community set up a cross-community working group to find one.

While that working group was still sitting, ICANN’s board took $36 million of the proceeds and put it into ICANN’s own reserve fund, which was running $68 million short of its target. Not proposed — approved. And when the community objected, the position put to it was that the alternative was ICANN raising fees.

The working group carried on regardless. The board did not adopt its recommendations until June 2022 — six years after the last auction, during which ICANN held a quarter of a billion dollars of other people’s money and helped itself to $36 million of it while the people deciding what it was for were still in the room.

The .org Price Caps

In March 2019 ICANN proposed renewing the .org registry agreement with the price caps removed. The caps were the thing that stopped the operator of .org charging whatever it liked to the charities, NGOs and non-profits that had been told for twenty years that .org was where they belonged.

Public comment ran. 3,252 comments opposed removal. Six supported it. The opposition included NPR, the YMCA, C-SPAN, the National Geographic Society, AARP and the National Trust for Historic Preservation — not the usual domain-industry commenters, but precisely the constituency .org exists for.

On 1 July 2019 ICANN signed the agreement. No public announcement. Comparison of the signed text against the proposed text showed no changes made in response to the comment period. Not “some concerns addressed” — the same document.

If a public comment process can run 542 to 1 against and change not one word, it is not a consultation. It is a formality that produces a paper trail.

Then the Sale

In November 2019, four months later, the Internet Society announced it was selling Public Interest Registry — the non-profit operator of .org — to Ethos Capital, a private equity firm, for $1.135 billion.

The price cap removal is what made PIR worth $1.135 billion. A registry that cannot raise prices is an annuity. A registry that can is a growth asset. ICANN had converted the second into the first four months earlier, against unanimous objection, and the market had immediately priced it.

Ethos Capital had been established in May 2019. The domain ethoscapital.com was registered on 8 May 2019 by Fadi Chehadé, ICANN’s former CEO — the week of the deadline for ICANN staff to publish their report on removing the price caps. His name appeared nowhere on Ethos Capital’s website when the deal was announced. His involvement became public because of WHOIS data — the public register of who owns a domain, which the next section is about — and the irony writes itself. Ethos then confirmed he had advised on the transaction, and in July 2020 he became its co-CEO.

ICANN did eventually block the sale, in April 2020. It is fair to record that. It is also fair to record what preceded it: months of ICANN insisting the matter was mostly outside its remit, sustained public campaigning, letters from US senators, and finally a letter from the Attorney General of California warning ICANN off the deal and citing the lack of transparency around Ethos Capital.

ICANN was not the safeguard here. ICANN removed the caps that created the opportunity, and was itself stopped, at the last minute, by a state law officer — which is one more demonstration that the real accountability mechanism in this system is Californian jurisdiction rather than anything in the bylaws.

The Verisign Arrangement

This is the same counterparty as the wildcard, fifteen years on. In October 2018 NTIA and Verisign signed Amendment 35 to the Cooperative Agreement, lifting the .com price freeze and permitting increases of 7% a year in four years of every six.

That was the US government’s decision, not ICANN’s. But the increases still needed the .com registry agreement amended, and that is ICANN’s. In March 2020 ICANN agreed Amendment 3 — and alongside it a binding Letter of Intent under which Verisign pays ICANN $20 million over five years from 1 January 2021, for security and stability work.

Both things were negotiated before public comment opened. The comment period ran, was overwhelmingly hostile, and changed nothing — the same pattern as .org, in the same window, with the same result.

Take the structure on its own terms. The body that decides whether a monopolist may raise prices negotiated, at the same time and with the same counterparty, a payment to itself. Public comment came afterwards and was decorative. Whatever the money is spent on, an arrangement in which the regulator is paid by the regulated in the same transaction as the price rise is one that no competent regulator would enter, and the word commenters reached for at the time — kickback — is the obvious one.

Wholesale .com has gone from $7.85 to $10.26 on the back of it, on a name with no technical need for a price rise and no competitor a registrant can move to.

Eight Countries Against One Company

If you want a single episode that shows who ICANN actually answers to, it is .amazon, and it ran for seven years.

Amazon the company applied for .amazon in the 2012 round. The Amazon Cooperation Treaty Organization objected — Bolivia, Brazil, Colombia, Ecuador, Guyana, Peru, Suriname and Venezuela, eight sovereign states whose territory the name describes and in which some 30 million people live. Their position was that a shared geographic and cultural name should not become one company’s private property.

They used the channel ICANN provides for governments. The Governmental Advisory Committee (GAC) issued consensus advice against the application, and in May 2014 ICANN’s board accepted it. The states had won, through the mechanism designed for exactly this.

Amazon filed an Independent Review Process (IRP) claim.

In 2017 the IRP panel ruled for Amazon. It found the board had acted inconsistently with ICANN’s own bylaws, held that the board cannot treat GAC consensus advice as conclusive, directed it to re-evaluate the applications on the merits, and ordered ICANN to reimburse Amazon $163,045.51 in costs.

In May 2019 ICANN concluded there was no public policy reason for the applications not to proceed. Amazon got .amazon.

Read the structure rather than the outcome, because the outcome is arguable and the structure is not.

Governments get the GAC, and the GAC advises. A corporation gets the Independent Review Process, and the IRP produces a binding declaration, a direction to the board, and a costs award. When those two channels met head-on, the panel’s finding was explicitly that the governmental one is not conclusive.

So ICANN does have a working accountability mechanism. It worked. It was used successfully by one of the largest companies on earth to overturn the collective objection of eight countries, and ICANN paid its legal costs for the privilege.

That is the same fact as the jurisdiction problem earlier in this post, wearing different clothes. The mechanisms are real, and they are shaped so that the parties who can afford to operate them are the ones who get results out of them. Eight governments could not make the advisory channel stick. One company made the legal channel work in three years.

The GDPR Fight: What ICANN Does When a Law Applies to It

The strongest evidence about an institution is not its mission statement. It is what it does the first time a rule it did not write is enforced against it.

For ICANN that moment was GDPR, and the record is unambiguous.

ICANN did not lack warning. It had, by The Register’s count, more than a decade of letters telling it that WHOIS — publishing the name, postal address, email and phone number of every domain registrant, to anyone, with no access control — was incompatible with European data protection law. GDPR itself was adopted in 2016 with a two-year runway specifically so that organisations could prepare. ICANN arrived at May 2018 with no compliant model.

What it did instead, in April 2018, was go to Brussels and ask the Article 29 Working Party for a one-year moratorium on enforcement, plus permission to keep publishing registrant email addresses in the meantime.

Sit with what that request actually is. Not an extension to file paperwork. A request that European regulators agree not to enforce a fundamental-rights regulation against one organisation and its global contracted parties, for a year, because that organisation had not got round to complying. There is no mechanism in GDPR to grant this. Data protection is a fundamental right under the Charter; no supervisory authority and not the European Data Protection Board has the power to suspend it for a single data controller. ICANN was not asking for a concession that was being withheld. It was asking for something that does not exist, having apparently not established whether it existed.

WP29 refused both asks. ICANN’s own summary of the meeting conceded that registrant, administrative and technical contact email addresses must be anonymised, and simply omitted any mention of the moratorium it had requested.

Then it sued.

On 25 May 2018, the day GDPR took effect, ICANN filed against EPAG — Tucows’ German registrar — in Bonn. EPAG had decided to stop collecting Admin-C and Tech-C contact details, on the grounds that collecting personal data it had no use for was exactly what GDPR prohibits. Tucows’ position was that in the overwhelming majority of registrations the registrant, admin and tech contacts are the same person anyway, so the collection was not merely unlawful, it was pointless.

ICANN’s legal theory was that GDPR’s “necessary for the performance of a contract” basis covered the collection, because ICANN’s own contract with the registrar required it. That is a remarkable argument: that an organisation can manufacture a lawful basis for processing other people’s personal data by writing a requirement to collect it into a contract with a third party. If it worked, Article 6(1)(b) would be a formality anyone could satisfy by drafting.

It did not work. ICANN lost in Bonn. It appealed. It lost again. In August 2018 the Cologne appellate court rejected it a third time, found the earlier rulings convincing, held there was no imminent emergency justifying an injunction, and — this is the part worth reading twice — refused ICANN’s request to refer the question to the Court of Justice of the European Union on the grounds that ICANN’s legal interpretation was not material to the decision. The court did not consider the argument close enough to be worth asking Luxembourg about.

ICANN spent members’ money trying to push the case to that court regardless. In 2019 it gave up on WHOIS entirely.

The technical outcome was correct — WHOIS as it existed should not have existed. But look at how it was reached. Ten years of warnings ignored. A request for an exemption from a fundamental right. Litigation against its own contracted party, filed on the day the law took effect, to establish that the law did not apply the way the regulators said it applied. Three defeats. Then capitulation.

That is not an organisation that misread a statute. It is an organisation that did not accept, until courts told it three times, that the law was addressed to it at all.

What It Cost Everyone Else

Most of this post is about what ICANN and the registries did. This is about who paid for it, because it was very rarely them.

Every .com registrant on earth pays the increase. Wholesale .com went from $7.85 to $10.26. Verisign’s own reporting puts the .com base at 163.6 million names as of 31 March 2026. Multiply the two and that rise is worth on the order of $394 million a year, taken from every registrant of a .com anywhere in the world, for a name that needed no technical change to justify it. A business in Lagos or Manila pays the same increase as one in Palo Alto, decided by an American agency and an American non-profit that took $20 million from the beneficiary in the same negotiation.

The .org decision lands on charities worldwide. .org was sold to the non-profit sector for twenty years as the part of the namespace that belonged to them. Lifting the caps was a decision that whoever runs it may charge them what the traffic will bear. NPR and the YMCA can absorb that. A small NGO working on a grant cannot, and it was not asked either — 3,252 against, six in favour, signed without a word changed.

The abuse burden is carried by everyone who runs a mail server. New gTLDs are 12% of the market and 47% of reported cybercrime domains. Every one of those names arrives in somebody else’s inbox, somebody else’s abuse queue, somebody else’s fraud losses. ICANN collected $185,000 an application and collects $25,000 a year per string regardless. The cost of what the cheap strings then produced falls on every mail operator, every bank, every security team and every person taken in by a phishing page. That is an externality in the textbook sense, and the programme was designed without a line about who would bear it.

Site Finder broke failure semantics for the entire planet at once. This is worth stating plainly because it is easy to read as an American story. There is one root and one .com. When Verisign changed what a non-existent name does, it changed it for every network on earth simultaneously — including every network with no relationship to Verisign, no say in the decision, and no way out except patching their own resolvers, which is what a great many of them ended up doing.

WHOIS went dark on the people using it against abuse. Both harms here are real and both were avoidable. Publishing every registrant’s name, address, email and phone number to anyone who asked was a genuine, decades-long harm to people all over the world, and GDPR was right about it. But ICANN had more than ten years of warning and no plan, so May 2018 was not a managed move to tiered access. It was an abrupt shutdown. Anti-abuse researchers, security teams and law enforcement, including well outside Europe, lost a working tool overnight because ICANN spent the runway litigating instead of building the replacement. The exposure before and the vacuum after both belong to the same failure to prepare.

And 12.6 million names stopped resolving. The Freenom collapse was a good outcome for the phishing figures. It was not a good outcome for everyone using a free .tk or .ml because they could not spare $10 a year, and there were a great many of those, disproportionately in places where $10 is not nothing. When the only free namespace on the internet is also the most abused, the people who lose it when it goes are not the criminals. They moved to the next cheap thing the week after.

The shape is consistent. The decisions are made in California, the revenue is collected in California, and the costs are distributed globally to people with no vote, no contract and no court they can reach.

And Only in American Courts

Now the record is in, come back to the jurisdiction point from the start of this post, because it does more work than the incorporation does.

Everybody in the world is subject to what ICANN decides. The people who can do anything about it are the ones who can litigate in California.

Consider who that shuts out. A ccTLD operator in Cameroon. A registrant in Tehran whose domain got dropped because a registrar over-applied OFAC that never bound it. A registrar in Bonn — which is exactly why the fight between ICANN and EPAG had to be run as a German case on German law, and not as an ICANN accountability matter at all. Any small registry that cannot fund American counsel to argue a point of Californian non-profit law against an organisation with a nine-figure budget.

Then consider who it lets in. Every intervention in this post that actually changed something:

  • Site Finder ended when ICANN threatened Verisign’s contract — and Verisign’s reply was to sue in a US court, and to walk out of the settlement holding a renewed .com.
  • The .org sale was stopped after the Attorney General of California sent a letter.
  • Freenom stopped because Meta sued in the Northern District of California, and 12.6 million names went dark behind it.
  • .amazon went to Amazon because Amazon took ICANN through its own Independent Review Process and was awarded costs.

Four interventions that worked. Four American actors — one state law officer and three corporations. Not one of them a route available to anybody outside the United States, and in three of the four the thing that moved was a private company’s commercial interest, which on those occasions happened to point the same way as everybody else’s.

The community did raise this. A jurisdiction subgroup of the accountability working group spent Work Stream 2 on it and produced recommendations that left things roughly where they found them, which is unsurprising given the transition proposal had already ruled the one change that mattered out of scope before anybody sat down.

So global multi-stakeholder governance resolves, in the only place it can be tested, to this: you may sue in California, if you can afford to.

What the Record Actually Shows

Put them together, because separately each has an excuse and together they do not.

An organisation that had to be told three times by German courts that European law applied to it, having first asked those courts’ regulators to simply not enforce it.

An organisation that invented a product nobody had asked for, took more than $350 million in fees to consider applications for it, another $240 million auctioning the contested ones, and now collects $25,000 a year from top-level domains with nothing in them — while the strings that did sell became the cheapest place on the internet to buy a phishing domain.

An organisation whose public comment process has run 542 to 1 against and altered not one word of the document it was consulting on.

An organisation that lifted the price caps on the non-profit namespace four months before its former CEO’s private equity vehicle bid $1.135 billion for it, and that had to be stopped by a state Attorney General rather than by any mechanism of its own.

An organisation that took $20 million from the monopoly registrar in the same negotiation that let the monopoly registrar raise prices, and opened public comment afterwards.

An organisation that helped itself to $36 million of money it was holding in trust, while the group deciding what that money was for was still sitting.

And an organisation that settled a lawsuit from the registry which had hijacked the two largest zones on the internet by handing that registry a renewed contract for .com.

An organisation whose one working accountability mechanism was used by a trillion-dollar company to overturn the unanimous objection of eight countries, with costs awarded against ICANN.

An organisation that came within a committee report of delegating .corp and .home to strangers, and found out what that would break from somebody else’s measurements.

The consistent thread is not incompetence. Incompetence is random. This is directional: every one of these went the way of the incumbents, the money, and ICANN’s own institutional interest, and the participation mechanisms — comment periods, working groups, empowered communities — produced documentation rather than outcomes.

And this is the body that sets policy for the file. Not a standards body, not a court, not anything you elected. A California non-profit with a governance record like that, sitting on top of 1.5 megabytes of text that every network on earth resolves against.

The one thing standing between that record and the file is that ICANN does not hold the pen. It has to ask. Everything above is what an organisation does when it still has to ask — so the question worth carrying away is not whether ICANN behaves well. It plainly does not. It is what keeps the asking in place, given that nobody wrote it down and the party being asked is already on the payroll.