Ask
20
@rookmoor ·

Verisign ends third-level .name domains: 22,000 names deleted

Two reminders from the past month that owning a domain and controlling what it serves are separate things.

.name. On 15 April Verisign asked ICANN to discontinue third-level .name registrations, the neil.fraser.name style, along with the .name email forwarding service. ICANN approved both in May and issued the formal letters on 28 July. Existing third-level names get deleted, not just closed to new sign-ups. Verisign's stated reasons were limited registrar support and declining use: about 22,000 third-level registrations, most of them unused by its count. Registrars get at least 90 days of notice and a reminder at least 30 days before the cut.

One registrant, who has run his site, email and a few device APIs on his .name address for nearly 25 years, says it is paid up until 2040 and goes dark in February. He also points at the risk if the freed second-level names are later opened for registration: whoever takes fraser.name could recreate the old address and receive its password resets. A reconsideration request is still in front of the ICANN board, after the committee reviewing it recommended on 24 August that the approvals stand. Ordinary second-level domains like yourname.name are not affected.

Cloudflare. A site owner moved nameservers to Cloudflare to serve an R2 bucket from a subdomain and found a JavaScript analytics beacon injected into a site that had no JavaScript at all. It is documented behaviour: since 15 October 2025, Cloudflare Web Analytics is on by default for proxied sites on the free plan and opt-in on paid plans. Turning it off means adding the site in the Web Analytics dashboard and disabling it there.

13 answers Share
Report

Answering anonymously, a moderator will review it first.

  • @samirp · 3d ago · 3 replies

    What I took from it: an address you use for account recovery belongs on a second-level domain you hold directly, renewed years ahead, with registry lock if the TLD offers it. Anything else is a nickname.

    26
    Share
    Reply

    Answering anonymously, a moderator will review it first.

    Report
    • @thornbury · 3d ago · 2 replies

      Registry lock would not have helped a single person here. The registry changed the rules itself. Holding the second level protects you from a reseller disappearing, not from the operator.

      13
      Share
      Reply

      Answering anonymously, a moderator will review it first.

      Report
      • @samirp · 3d ago

        True. It shortens the list of people who can do this to you, which is about all anyone can do.

        9
        Share
        Reply

        Answering anonymously, a moderator will review it first.

        Report
  • @veraj · 5d ago · 3 replies

    Send a Content-Security-Policy with script-src 'self' from the origin and the beacon cannot run.

    18
    Share
    Reply

    Answering anonymously, a moderator will review it first.

    Report
    • @kittredge · 3d ago · 2 replies

      Only as long as the proxy leaves your headers alone. Anything terminating your TLS can rewrite a header as easily as a body. CSP stops accidents, not the party in the middle.

      14
      Share
      Reply

      Answering anonymously, a moderator will review it first.

      Report
      • @veraj · 2d ago

        Fair, and I will concede the principle. For this particular beacon it works in practice, the browser just refuses to load it. Disabling it in the dashboard is still the real fix.

        10
        Share
        Reply

        Answering anonymously, a moderator will review it first.

        Report
  • @ingrid_s · 3d ago · 2 replies

    Can the third-level holder claim the second level when this happens? There are families where one person is the only name under it.

    19
    Share
    Reply

    Answering anonymously, a moderator will review it first.

    Report
    • @thornbury · 3d ago

      Nothing in the approval letters reserves the second level for existing holders, and ICANN's own letter says its review does not extend to impacts beyond security, stability and competition. Ask your registrar in writing now, while there is still a notice period to argue in.

      15
      Share
      Reply

      Answering anonymously, a moderator will review it first.

      Report
  • @kittredge · 4d ago · 2 replies

    For anyone reading this in a panic: DNS-only records never touch your HTML. The beacon needs the proxied setting, the orange cloud.

    12
    Share
    Reply

    Answering anonymously, a moderator will review it first.

    Report
    • @rookmoor · 4d ago
      @rookmoor OP ·

      And a custom domain for an R2 bucket is served through that proxy, which is exactly how the original poster ended up proxied without thinking about the rest of the site.

      8
      Share
      Reply

      Answering anonymously, a moderator will review it first.

      Report
  • @veraj · 3d ago

    Paid until 2040, deleted in 2027. The renewal reminders will be the last thing that still works.

    6
    Share
    Reply

    Answering anonymously, a moderator will review it first.

    Report
  • @ansel_b · 3d ago · 2 replies

    Also this month: of 44,143 European companies with a detectable CDN, 89.6% were behind Cloudflare. A default flipped there reaches a lot of sites at once.

    9
    Share
    Reply

    Answering anonymously, a moderator will review it first.

    Report
    • @ingrid_s · 2d ago

      Of companies using a CDN at all, though. Anyone serving straight from their own origin is not in that number.

      7
      Share
      Reply

      Answering anonymously, a moderator will review it first.

      Report