Rendered at 09:45:52 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
mzajc 18 hours ago [-]
Posting because OpenWRT, possibly others as well, assign .lan names to devices on the LAN by default. People who make use of this might want to follow the application, and, if it goes through, either change the name or make sure queries can't get incorrectly get sent to upstream resolvers.
Regarding that last point, I've had issues with dnsmasq in the past where it was remotely resolving domains even when they were configured to resolve locally. For .lan domains, this could be disastrous because I often send plaintext traffic to them. I did submit a fix/workaround[0], but it's still something to look out for. If anyone knows more about this issue or other ways queries could leak, please share!
It looks like as part of the process, they delegate the prefix in global DNS and see how much traffic it currently gets; if it gets too much it will be classified as "high-risk" which at least makes things harder. Which is to say, we want as much leakage as possible to hopefully make ICANN think twice about approving this.
This test is poorly designed for .lan because the opposite problem is more likely: that many people using .lan will have any resolution attempts swallowed by their routers. This is certainly true for OpenWrt and GL.iNet. It may be true for Unifi AmpliFi, which reserves .lan by default. It's potentially true for other vendors when .lan is configured as the local domain (which many online guides suggest people do).
gclawes 18 hours ago [-]
RFC 8375: Special-Use Domain 'home.arpa.' is supposed to be used for this.
RFCs were originally formalization of what was being used in practice, home.arpa was chosen apparently for reasons of beauracratic convenience rather than what would best serve existing users, who all would prefer .lan and continue to do so since that was published in 2018
gavinsyancey 11 hours ago [-]
I looked into the actual reasoning here:
- Originally, IETF specified .home, but never went through the process to add it to the list of reserved names.
- Someone applied for the .home gTLD, and while it ultimately didn't go through there was a while while it was up in the air. Due to this the homenet working group had to change gTLDs.
- They decided to switch to .homenet. However, because of DNSSEC, whatever they used would need an insecure delegation in the root zone or validating resolvers wouldn't be able to resolve it. Since IAB controls .arpa but IANNA controls the root and there was no process to ask IANNA for this, they eventually decided to use home.arpa instead.
> RFCs were originally formalization of what was being used in practice
You may be confusing it with the IETF’s policy.
In early days of the RFCs, most started out as proposals, often but not always with some existing implementation as a jumping-off point to conversation (hence the name). I no longer remember why they started to be numbered and tracked, as the process naturally preceded that.
You can verify what I say by just reading some old ones at the rfc editor site.
esskay 17 hours ago [-]
and most people dont use it because its an incredibly poor name.
lokoj 14 hours ago [-]
Why don't they just put home.arpa or .arpa in their search path?
penskymaterial 12 hours ago [-]
What, exactly, makes it poor? Be specific.
simondotau 11 hours ago [-]
I will be very specific about why it is poor. The specific reason is my home network is not the Advanced Research Projects Agency.
brookst 11 hours ago [-]
having two levels, for one. "arpa" not being remotely memorably to non-technical people, for another.
GuB-42 11 hours ago [-]
- WTF is arpa? (in reality, I know, but there are better names than an obscure reference to internet prehistory)
- it is a second-level domain, why?
- 9 characters (home.arpa) is a lot
I kind of understand the motivation, it is a "technical" domain since it doesn't represent something in the global DNS registry, so it gets the .arpa TLD. However, that's reasoning that it out of touch from normal users. Normal users don't want to be exposed to the technicalities of DNS when they enter something in the address bar, and "myserver.lan" is more meaningful than "myserver.home.arpa", and giving meaningful names is the whole point of DNS.
joquarky 7 hours ago [-]
It feels like a choice that was made at the end of a very long meeting about much more important topics.
denkmoon 11 hours ago [-]
The character count. lan is 3 char, home.arpa is 9. Subjectively, tt is also aesthetically unappealing.
I can't fucking _wait_ to type bender.home.arpa instead of bender.lan. Hyped.
_bernd 10 hours ago [-]
Then use search domain and let your DHCP and DHCP6 server hand that out to clients.
denkmoon 10 hours ago [-]
or we could just not publicly delegate a defacto private space?
Search domain is handy but it's ambiguous.
5 hours ago [-]
B1FF_PSUVM 10 hours ago [-]
> use search domain
I don't know what this means, and searching is thorny. Help?
Your DHCP/SLAAC RA tells clients "here is a list of search domains, when you attempt to query a bare name, also look for the name plus any suffixes listed in the search domain list". So on a system with "home.arpa" in the search domains, you can do something like 'ping myhost' and your system should attempt to resolve 'myhost.home.arpa'.
B1FF_PSUVM 8 hours ago [-]
Thanks, appreciated. Forgot that wiki is good at this (and TV series ;-)
pqb 17 hours ago [-]
It would be awesome if Ubiquity will actually follow this RFC too. The Amplifi product line from Ubiquity have `.lan` support but no `home.arpa`.
Ubiquiti aren't the only ones. OpenWrt (and, by extension, GL.iNet) explicitly refuses to forward .lan DNS queries to public resolvers. This is a good thing: "LAN" has a singular, unambiguous meaning that directly contradicts its use as a public TLD. The fact that we're even debating this is outrageous.
brookst 11 hours ago [-]
yeah I'm not going to tell my s/o to use plex.home.arpa. instead of plex.lan
c0l0 18 hours ago [-]
That's nice and all, but OpenWrt (and its use of .lan) predates this particular RFC by a rough 14 years.
I hope the gTLD application gets struck down.
pwdisswordfishq 17 hours ago [-]
God forbid OpenWrt ever receives an update or something.
free_bip 17 hours ago [-]
You know, just because it's in an RFC doesn't mean it's actually practical. 'home.arpa' is significantly worse than every other option.
c0l0 17 hours ago [-]
If you actually think it's a trivial affair to change a well-established default with more than 20 years of history that is, on top of all other difficulties that such a change typically encompasses, used to identify and name things, I hereby beg you to never design or provide any kind of infrastructure.
jamesnorden 15 hours ago [-]
An update wouldn't change all the existing configurations.
stop50 18 hours ago [-]
Internal. is also an valid option.
I moved everything there about a year ago
Looking at your links, subjective and legacy considerations aside, .alt per RFC 9476[1] seems as good a choice as .lan.
Personally, I just use a registered domain for this purpose, as they're cheap enough to not care (last I checked, I pay $10–20/domain/year for registrations, depending on registrar and TLD, and $0.21/zone/month for hosting public zones on Google Cloud).
A registered domain has the added benefit that you can use the same namespace for externally accessible services. I personally do this (using Cloudflare Tunnels, not open ports).
18 hours ago [-]
deno 17 hours ago [-]
But what if my LAN is in the garage?
9 hours ago [-]
bandie91 12 hours ago [-]
well then it's a home for your lan.
greatgib 11 hours ago [-]
But why is it that nowadays, it's enough for a vulture corporation to have enough money to be able to privatize a part of the "web" that is in common usage (in the sense of common good) since so long?
It should be logical even without thinking that the request have to be rejected.
fridder 12 hours ago [-]
.internal as well I believe
montecarl 17 hours ago [-]
This reminds me of when I used to do IT work for small businesses in college. One printing company I worked for, had about 100 computers on their network, and was using public ipv4 addresses, that they did not own, on their internal network. I forget what range they were using now. But imagine seeing a DHCP server handing out addresses like 142.250.110.1/16 on a LAN and the public ip being something totally different.
It was funny, because when I brought it up to them, it was hard to articulate why it was a problem and I couldn't convince them it was worth the effort of trying to fix. They never ran into a specific issue due to this while I was there but it felt so gross.
masfuerte 17 hours ago [-]
The problem is that they wouldn't be able to talk to any internet service that legitimately used those addresses. Whether that was likely to be a problem very much depends on whose addresses they were.
irusensei 17 hours ago [-]
When I was working with Linux based kiosks and PoS systems I had a good share of issues with the Microsoft MVP signature use of .local on their forests. Back then their training material recommended .local for Active Directory services.
penskymaterial 12 hours ago [-]
Pretty sure MS's official documentation always strongly suggested using a real domain you own for AD.
jasomill 10 hours ago [-]
Specifically, either a registered name or a subdomain of a registered name reserved for this purpose, because the A records for the apex should or must — I don't remember which, but it's definitely the default configuration — point to the domain controllers, and you probably don't want to host your public web site on the same addresses as your DCs (or for that matter, your internal and public records necessarily hosted on the same server).
Historically (20+ years ago), some Microsoft documentation suggested .local as an example of an unregistered domain that could be used for this purpose, which was problematic when .local was subsequently reserved for multicast DNS.
antonkochubey 12 hours ago [-]
In the UK, Virgin Media uses UK Ministry of Defence's 25.0.0.0/8 for CGNAT
jasomill 11 hours ago [-]
Given that there don't appear to be any BGP announcements for 25.anything, is it possible that the MoD uses this address range internally, or not at all, and has agreed to continue to do so?
Brian_K_White 17 hours ago [-]
It's always hard because when you contrive possible examples of how it goes wrong, every single example sounds contrived because of course they are contrived.
Sure one day your printer might start spewing random json code meant for some microservice of the rightful IP owner.
Sure the IP's might be owned by the Air Force and one day they might start getting traffic from your pos ipad that they decide looks like an attempt to attack one of their internal secret networks...
Sure one day traffic meant to go to your printer ends up flooding and dossing a windmill controller, preventing the rightful operators from turning it the right direction during bad weather and causing $25M damage...
And of course the real failures are more like, only people from the Maldives can't send email to your email server, a failure with no impact.
deno 17 hours ago [-]
There's a good reason to do this if you can't be certain what reserved subnets are used in a given network and you absolutely need a static ip for some reason.
At least that's the conclusion I've arrived at at some point, but I don't remember what was the exact use case anymore.
However there are still several global IPv4 ranges that are not local reserved ranges but are effectively reserved and you could use them if you really want to without any issues.
boredatoms 16 hours ago [-]
.lan should just become reserved
simondotau 9 hours ago [-]
Given that the plain text meaning of .lan is even more unambiguous than .home, it's overwhelmingly likely that .lan will suffer the same fate, where delegation was "indefinitely deferred".
alwa 18 hours ago [-]
This seems like a good time to educate myself about the application (and objection) process.
The bureaucracy seems precision-engineered to stultify, but apparently the public have 104 days after “String Confirmation Day” (17th Nov; capitalization theirs) to lodge objections, assuming the “GAC” doesn’t beat them to it…
…welp, hope somebody more organized (and better-funded) than I can organize an objection. Much as I feel like I’m giving up my right to gripe by assuming somebody else will come along to do the weeding.
This may very well end up to be determined too risky to be delegated, like .corp, .home and .mail in 2018.
gavinsyancey 12 hours ago [-]
There's a short list of grounds they will consider for an objection, and none of them are applicable here. Paraphrasing your second link, they only allow:
- "String Confusion" -- looks or sounds like an existing (approved or being applied for) gTLD. Must be filed by whoever owns (or is applying for) that gTLD.
- "Legal Rights" -- someone else owns a trademark this would violate. Must be filed by whoever's legal rights would be violated.
- "Limited Public Interest" -- the gTLD is immoral under recognized principles of international law. I have no idea when this could be applicable.
- "Community" -- An established community organization believes the group this gTLD is intended to target will object to it. This seems more like a vehicle for e.g. Little People of America to let ICANN know that ".midget" would be offensive.
Unfortunately there doesn't seem to be a way to tell ICANN that .lan has been widely used and will break things in a way they will listen to.
simondotau 11 hours ago [-]
> Unfortunately there doesn't seem to be a way to tell ICANN that .lan has been widely used
ICANN isn't the DNS police, and lobbying them is pointless. We should campaign for open-source router projects[0], commercial hardware developers[1], DNS resolver developers, and major providers[2] to collectively designate commonly used private TLDs such as .home, .lan, .intranet, and .private as non-resolvable in public DNS.
Local resolution would continue to work, but these names would never be forwarded upstream. With sufficient adoption, we'd establish a de facto reservation and make the TLDs commercially worthless, regardless of what ICANN decides.
--
[0] There is precedence here. OpenWrt already reserves .lan in its default dnsmasq configuration.
[1] There is precedence here. GL.iNet inherits from its OpenWrt roots. Ubiquiti uses .lan as the default in its AmpliFi products. MikroTik documents it as part of its network-discovery mechanism.
[2] I'm thinking of Cloudflare, Quad9, and others.
mzajc 11 hours ago [-]
> ICANN isn't the DNS police
ICANN and IANA very much are the DNS police. As a matter of fact, IANA maintains a list of special-use domains - though, despite its widespread use, .lan is not on the list - and these domains will get rejected from gTLD applications outright. The last thing I want is to require each recursive resolver to have their own idea of what should and shouldn't be resolved.
On a related note, Google owns a registry (CRR) and a recursive resolver (8.8.8.8) that's commonly used by default or as fallback. Letting them ban entire TLDs would be a massive conflict of interest.
simondotau 9 hours ago [-]
ICANN only have enforcement power over registries and registrars. They have no enforcement power over hardware vendors, software vendors or public resolvers.
What I implied (but failed to emphasise) is that what I'm calling for is already in de-facto effect, with multiple software and hardware vendors treating .lan as not publicly resolvable. What you describe as "the last thing [you] want" is already happening; my proposal is for more of the same.
It is valid to note that ICANN could abuse their contractual arrangements with resolvers who also operate registrars, but this would be an illegal intimidation tactic. It would not be a conflict of interest for Google to act if part of a wider campaign involving other parties.
denkmoon 11 hours ago [-]
ICANN _are_ the DNS police? They author DNS RFCs, they manage namespace delegation.
Community groups can make their own competing DNS hierarchy and governing body and perhaps should but I don't think saying ICANN aren't responsible here is reasonable.
simondotau 9 hours ago [-]
ICANN are the registry police, not the resolver police. I am proposing that resolvers wield their influence, not registries/registrars.
Formal objections require standing, procedural compliance and fees. Demanding monetary payment in order to issue an objection means that ICANN not acting as a responsible party in my view.
Faelian2 18 hours ago [-]
It's a shame that ICANN did get so greedy and put everyone at risk.
Having internal domain names owned by some guy on the internet has already compromised multiple corporate networks. See the talk from this guy:
As former AD person and dealing with that several companies, the recommendation for internal network DNS has long been subdomain.company.com that is not on public internet.
Even today when setting up greenfield networks, I generally use internal.company.com. It also lets you get public trusted SSL certificates so you don't have to deal with internal PKI.
Faelian2 17 hours ago [-]
`.internal` and `.local` are safe and won't be used in the future. There are reserved for internal networks
john_strinlai 17 hours ago [-]
while .local is reserved, it's reserved for mDNS, and should be avoided on things like active directory. using an internal subdomain of a registered public domain is best practice. .internal is also okay.
john_strinlai 17 hours ago [-]
im not super keen on all of these gTLDs, but anyone choosing to use .lan should have been aware of the risks of using an unofficial/unreserved domain.
at the very least, the .dev stuff should have had people second-guessing their usage of unreserved domains.
kokx 13 hours ago [-]
Then why hasn't there been a gTLD reserved for local use? The only ones that are reserved are .local and .home.arpa. .local is out, since it is entirely for use with mDNS / Bonjour.
That leaves .home.arpa, which is very awkward and only a thing since 2018 (my home network's use of .lan definitely predates this). Especially as a non US citizen. It also seemed so far that .lan was the "unofficial" gTLD to be used, since much software like OpenWRT was already using it anyway.
Either way: making .lan internet routable seems entirely unhinged to me. LAN has always been the acronym for Local Area Network. Why would anyone sane think that it is a good idea to make this into a gTLD that can be internet routable? The only way I see forward to do this justice, is to only allow RFC 1918 and IPv6 addresses that are within the assigned prefix for your router.
This seems like a worse version of allowing .zip to be a gTLD. Remember the idea of downloading something from https://github.com/[...]@evil.zip?
gucci-on-fleek 12 hours ago [-]
> Then why hasn't there been a gTLD reserved for local use?
.qm to .qz and .xa to .xz have always been implicitly reserved as TLDs that will never be globally-routable [0] [1], but these aren't exactly the most intuitive names so it's unsurprising that nobody uses them.
(".internal" as mentioned by the sibling comment [2] is the best choice these days, but its definition is somewhat recent.)
(note: i hope .lan does not get approved, but people have to understand that they are rolling dice when using unreserved names)
edit: fucking wild that this is downvoted into negatives. press the wiki link and read the first line if you don't believe me. in fact, i will quote it: "The name internal is reserved by ICANN "
kokx 13 hours ago [-]
> Introduced 29 July 2024; 2 years ago
That explains why I hadn't heard of this yet. My current incarnation of my internal network dates from ~april 2024.
simondotau 9 hours ago [-]
The only ones rolling dice here is anyone attempting to use the .lan TLD for public services, given that OpenWrt (and by extension most GL.iNet products) will not publicly resolve .lan under their default configuration.
gchamonlive 17 hours ago [-]
Pihole here will still serve .lan internal domains. Anyone that registers .lan globally are the ones guilty of using a culturally busy domain that was unreserved before.
In time we'll see articles like "Don't register a .lan domain if you want people to visit your site"
steventhedev 12 hours ago [-]
My personal head canon is that ICANN told Google they had to open registration or someone who would open it up would get it
delecti 17 hours ago [-]
Eh, maybe someone spinning up a brand new environment using it in 2026 should have known better. But you don't have to go that far back to reach a point where the current list of gTLDs would make .lan feel safe.
john_strinlai 17 hours ago [-]
>But you don't have to go that far back to reach a point where the current list of gTLDs would make .lan feel safe.
throughout most of my career, there was no unreserved domain that felt safe. but especially after .dev.
cloudie78 31 minutes ago [-]
Okay I think this is one of those situations where we should harness our collective autism and prevent the gTLD from going through. As others have pointed out there seems to be a mechanism for objecting.
Just purely from common sense perspective why the fuck should .lan be something that’s an internet/public TLD? Hello? LOCAL Area Network?
While we’re at it let’s update a few RFCs. Plus I don’t want to find out what organisations use .lan for their networks and what will end up leaking to the internet as a consequence of this.
There's an "Objections" section on the website which currently says:
> Objections for this Application have not yet been published. Information will be added when it becomes available. Please check back periodically for updates.
How does this work? Who can submit an objection? Can I submit one as someone with .lan domains inside my home network?
vekntksijdhric 18 hours ago [-]
This is a security issue for many devices. What could possibly go wrong overriding a tld used for internal networking....
dwedge 12 hours ago [-]
This being on the front page at the same time as the coffee machine sending 1TB of data, and the icann application being submitted by Coffee Danger LLC is just beautiful
jeroenhd 18 hours ago [-]
You would hope someone would finally learn after .dev and .local started getting used.
irusensei 18 hours ago [-]
RFC 6762 reserves the .local. TLD for Multicast DNS. There are no reservations for .lan. so something like home.arpa. should be used instead.
procone 17 hours ago [-]
router.home vs router.home.arpa
.home.arpa is so clunky. Why do I have to put the acronym of a US military project in my domain to access resources on my own local network?
Yes, I know that organization was central to the development of the l Internet, but it's not relevant as a domain 40 years later.
0x457 17 hours ago [-]
I just bought mysefl a '.casa' domain, got wildcard cert for it from lets encrypt and haven't bothered with any of these. Downside, if internet goes down resolver stops, but thats why I have local NS mirror and all DNS queries go through my resolver.
irusensei 17 hours ago [-]
You can buy a cheap domain to make sure no one else uses it and just roll it on your lan. Throw some DNS ACME challenges and you have valid certificates too.
procone 17 hours ago [-]
Why should I have to purchase something (yearly subscription, mind) in order to access something that is potentially half a meter away?
This is not how anything should work.
john_strinlai 14 hours ago [-]
you dont have to. .internal is fine.
luckman212 7 hours ago [-]
yep, I supply 2 search domains via DHCP option 119: .lan and .internal
guess I'll be migrating things 100% over to internal...
sieve 11 hours ago [-]
I do it for the LE certificate. But "cheap" is subjective. Domain registration and management should not be as expensive as it is. Nothing the registrar or registry does could be worth $8/10/200 a year with guaranteed 5-10% price increases every year. It is a grift.
john_strinlai 17 hours ago [-]
router.internal avoids the military arconym
jstarks 18 hours ago [-]
What could go wrong using tlds that were not explicitly reserved for internal use?
alerighi 18 hours ago [-]
Beside the fact that was standard or not it made sense to use .lan domain for local devices, and a lot of router sold were configured with that domain for resolving local network hosts.
To me is a very bad idea to implement this proposal, it should instead be standardized and reserved for internal usage as a fix. There were even RFC like https://www.rfc-editor.org/info/rfc6762/#appendix-G that suggested their usage for local devices in a network.
What is the point of selling the .lan domain, except for making money at the expense of a security risk for millions of networks that already use that domain for internal hosts?
BTW to me there was never any sense to add new TLD domain despite country code. They decided to render internet less secure, by giving scammers infinite TLD to register they scam domain like "apple.lan", with the sole purpose of making for them easy money.
denkmoon 12 hours ago [-]
not putting lan in the most recent update to the reserved private namespace was a massive miss. It is defacto a reserved private namespace.
gavinsyancey 11 hours ago [-]
This has been widely used since before there were any TLDs explicitly reserved for internal use.
18 hours ago [-]
davidcollantes 18 hours ago [-]
Indeed. It akin to an application for a .local TLD.
john_strinlai 18 hours ago [-]
>It akin to an application for a .local TLD.
it is not, as .local is designated as a special-use domain name and .lan is not.
gertrunde 17 hours ago [-]
While you're not wrong, I suspect that .lan sees more real world usage than .local
It may not be an official standard, but it does have some weight as a de-facto standard.
I've tried briefly to try and find some numbers to back that up, but can't find much beyond apple's bonjour vs consumer routers - although I've seen companies with AD domains using .lan as well. (Although, I've also seen companies using 1.0.0.0/8 for their internal addressing...)
simondotau 9 hours ago [-]
I've habitually used .home since 2014 when its ICANN delegation was indefinitely deferred.
john_strinlai 17 hours ago [-]
it definitely gets used, and i hope that the application is denied, but i also hope this is another wake up call for people that pick unreserved domains.
denkmoon 10 hours ago [-]
Wake up to what? The fact ICANN have failed in their governance responsibilities by not encoding a widely used defacto private namespace into the reserved namespace RFC and considering delegating it publicly?
john_strinlai 9 hours ago [-]
whether you consider this a failure of ICANN or not is completely beside the point.
if you choose to use an unreserved domain, you are choosing to accept the risk of something like this happening. take ownership of your choices. "but other people use it" is not a great defense.
seanw444 18 hours ago [-]
This was my first thought as well. Yikes.
dijit 17 hours ago [-]
I'm still seething about `.dev`.
For those not in the know, Google lobbied ICANN to get the name and in their application they stated (repeatedly) that the intent was to buy it so that it could be reserved; as .dev was already used by developers and if someone bought it for commercial purposes it would harm the developer community.[0]
.... they then proceeded to start selling them.
Leading to all kinds of issues, the exact issues that they raised...
Your linked icann doc is huge, but from skimming it the top portions seem to describe google’s intent to use it themselves for hosting their own projects and services.
xd1936 12 hours ago [-]
Didn't know this history. Thanks for educating me.
denkmoon 12 hours ago [-]
Same. An I use .lan internally. I'm tilted.
yegle 17 hours ago [-]
> RFC 8375 defines the intranet domain as .home.arpa, but ICANN in 2024 says it should use .internal instead. Is ICANN not choosing .lan or .home because these two domains might still fetch a good price?
My tweet on Sep 26, 2026
dwedge 12 hours ago [-]
This being on the front page at the same time as the coffee machine sending 1TB of data, and the icann application being submitted by Coffee Danger LLC is just beautiful
Also see a .bldg application, which also might conflict with some legacy naming schemes.
bombcar 17 hours ago [-]
Can I get a group of Ians and register .Ian?
eugenekay 12 hours ago [-]
You can apply for any gTLD string for any reason, the hard part is the application fee: USD$227,000.
iaaan 6 hours ago [-]
The one downside of being named Ian is being predisposed to misread lowercased "LAN"
gertrunde 17 hours ago [-]
The way they've filled out the application surprises me.
There are questions that literally say as part of the question "Choose Yes or No", so they've answered "true"...
And Q165 is fun: "Is it likely that consumers will face significant risks if domain names in the TLD(s) in the application are abused?" Answer: "No"
procone 18 hours ago [-]
gTLDs were a mistake. I say that as an owner of several domains with gTLDs.
There's almost no value.
Large businesses almost never use them. The potential for scams / phish / etc are now limitless.
SahAssar 11 hours ago [-]
Do you also think that of the original 7 gTLDs (.com, .edu, .gov, .int, .mil, .net, and .org)?
simondotau 8 hours ago [-]
They make sense given the history of the Internet, but not in hindsight. Most obviously, .gov, .edu and .mil should be under the .us TLD, but obviously the inventor's prerogative applies.
It's arguably defensible to have a limited number of non-geographic TLDs. "Dot com" was an aesthetic as much as a technical decision. I wonder though, if .com/net/org had never existed, we would have a different sense of aesthetic around domain names, and there's no reason to think that it would be any better or worse than what we have now.
miladyincontrol 9 hours ago [-]
Granted I'm someone using a normal TLD across my lan, but I do find it funny some suggesting those obscure alternative ones that are like 50% longer than my entire FQDN.
I'd imagine you're hard pressed to get people to commit to something so lengthy and unmemorable.
ectospheno 17 hours ago [-]
The .lan domain has been on an rpz blocklist along with several other commonly used names in my networks for quite some time. I have no plans for that domain to ever successfully resolve regardless of whether or not it goes live.
0x0 17 hours ago [-]
I've been using a single letter "fake" tld for my internal LAN DNS zone. Looks like ICANN requires 3+ letters in tld applications, so hopefully should be safe for quite a while.
veyh 15 hours ago [-]
If that were to ever change, I bet there's a certain billionaire who'd be very interested in the .x gTLD.
SahAssar 11 hours ago [-]
First ever pTLD?
p1mrx 18 hours ago [-]
When ICANN reserved .internal a couple years ago, I was saying they should just flip and truncate it to .lan(retni) so everyone's happy.
deno 17 hours ago [-]
Why would you even want something like “lan” as a global TLD? Does it mean something else than the obvious?
Fortunately there’s no need to speculate as the application explains this clearly:
AGB Q118: What is the meaning/definition of the applied-for gTLD string?
Answer: Lan commonly refers to a broadly recognized term used across a wide range of contexts.
notpushkin 17 hours ago [-]
Man, my whole life I’ve identified with, related to, and wished to finally just be associated with “the concept represented by the applied-for string”!
saghm 17 hours ago [-]
Debian should apply for this so they can take advantage of case insensitivity and sans-serif fonts so to let people go to DEB.lAN to view their website
gertrunde 17 hours ago [-]
21 separate applications for some variation on .agent/.agentic
I'm guessing that'll end up being expensive for someone...
wolttam 10 hours ago [-]
Aw man, my beloved .lan for my home network
LtdJorge 10 hours ago [-]
Nooo, don't break my home domain :(
moecables 17 hours ago [-]
I'm out of the loop on this, can someone explain who this is and why this is bad?
gavinsyancey 12 hours ago [-]
.lan is widely used (by OpenWRT and Ubiquity and likely others) by home / SMB routers, where all connected devices will automatically be assigned hostname.lan. Technically, .home.arpa and/or .internal are designated for this, but .home.arpa is pretty clunky and they're very new (.home.arpa is from 2018 and .internal from 2024). Usage of .lan for this predates either.
yonatan8070 5 hours ago [-]
For example I use a PiHole with local DNS records for my services like immich.lan, paperless.lan, etc.
OutOfHere 15 hours ago [-]
We need to separate competitive gTLDs from those whose registration is controlled uncompetitively. Very few, e.g. .xyz, are competitive.
17 hours ago [-]
ChrisArchitect 17 hours ago [-]
Related:
ICANN Reveals 2026 Round Applications for New Generic Top-Level Domains
.lan is shorter, and has been widely used for many years (since before .internal or .home.arpa were "standardized")
phs318u 6 hours ago [-]
.lan is indicative of topology not necessarily of accessibility.
.internal is all about the boundary between inside and the public internet, regardless of how you define ‘inside’.
gavinsyancey 49 minutes ago [-]
Also, .internal was specified two years ago. .lan has been in use for decades.
unleaded 18 hours ago [-]
..Why? Just to annoy people?
vetrom 17 hours ago [-]
The applicant appears to be an agglomeration of LLCs and legal diversions to hide responsible parties. It does lead me to assumptions about their motivations, whomever they may be.
Source: the application refers to multiple layers of LLC ownership, and the responsible parties listed are general counsels at some IP financialization company, "Identity Digital"
hdgvhicv 17 hours ago [-]
To sell to scammers for lots of money
Group_B 17 hours ago [-]
so so dumb. Pure greed. This is going to cause so many issues
montjoy 17 hours ago [-]
No.
tvbusy 12 hours ago [-]
Good luck with that. We'll see who is stupid enough to buy a .lan domain and never get visitors.
yonatan8070 5 hours ago [-]
I mean, aside from people who regularly browse HN and have OpenWRT routers and home servers, would "Normies" have any issue with browsing to some-website.lan?
I don't really see what website would use it though. Maybe for networking companies like mikrotik.lan or self hosted services like immich.lan?
childintime 15 hours ago [-]
Every year around $4B is spent on websites. Where is the money going, who's getting rich?
It's monopolies like Verisign (of the .com tld) that have luxurious profits. No competition, plus they are allowed to raise their prices above inflation while their infrastructure costs go down every year.
"America" has our best interests at heart /s
akerl_ 11 hours ago [-]
This feels like a really weird comment on a post about gTLDs that exist in parallel to .com
Regarding that last point, I've had issues with dnsmasq in the past where it was remotely resolving domains even when they were configured to resolve locally. For .lan domains, this could be disastrous because I often send plaintext traffic to them. I did submit a fix/workaround[0], but it's still something to look out for. If anyone knows more about this issue or other ways queries could leak, please share!
[0]: https://github.com/openwrt/openwrt/pull/18610
https://icannwiki.org/Name_Collision_Risk_Management_Framewo...
This test is poorly designed for .lan because the opposite problem is more likely: that many people using .lan will have any resolution attempts swallowed by their routers. This is certainly true for OpenWrt and GL.iNet. It may be true for Unifi AmpliFi, which reserves .lan by default. It's potentially true for other vendors when .lan is configured as the local domain (which many online guides suggest people do).
https://www.rfc-editor.org/info/rfc8375/
- Originally, IETF specified .home, but never went through the process to add it to the list of reserved names.
- Someone applied for the .home gTLD, and while it ultimately didn't go through there was a while while it was up in the air. Due to this the homenet working group had to change gTLDs.
- They decided to switch to .homenet. However, because of DNSSEC, whatever they used would need an insecure delegation in the root zone or validating resolvers wouldn't be able to resolve it. Since IAB controls .arpa but IANNA controls the root and there was no process to ask IANNA for this, they eventually decided to use home.arpa instead.
https://mailarchive.ietf.org/arch/msg/homenet/8cfJkr7SPMaPS4...
RFC 8244 is an interesting read on the topic: https://datatracker.ietf.org/doc/rfc8244/
You may be confusing it with the IETF’s policy.
In early days of the RFCs, most started out as proposals, often but not always with some existing implementation as a jumping-off point to conversation (hence the name). I no longer remember why they started to be numbered and tracked, as the process naturally preceded that.
You can verify what I say by just reading some old ones at the rfc editor site.
- it is a second-level domain, why?
- 9 characters (home.arpa) is a lot
I kind of understand the motivation, it is a "technical" domain since it doesn't represent something in the global DNS registry, so it gets the .arpa TLD. However, that's reasoning that it out of touch from normal users. Normal users don't want to be exposed to the technicalities of DNS when they enter something in the address bar, and "myserver.lan" is more meaningful than "myserver.home.arpa", and giving meaningful names is the whole point of DNS.
I can't fucking _wait_ to type bender.home.arpa instead of bender.lan. Hyped.
Search domain is handy but it's ambiguous.
I don't know what this means, and searching is thorny. Help?
Your DHCP/SLAAC RA tells clients "here is a list of search domains, when you attempt to query a bare name, also look for the name plus any suffixes listed in the search domain list". So on a system with "home.arpa" in the search domains, you can do something like 'ping myhost' and your system should attempt to resolve 'myhost.home.arpa'.
[0]: https://amplifi.com/
I hope the gTLD application gets struck down.
* https://en.wikipedia.org/wiki/.internal
Other special use domains:
* https://en.wikipedia.org/wiki/Special-use_domain_name
* https://en.wikipedia.org/wiki/Top-level_domain#Reserved_doma...
* https://datatracker.ietf.org/doc/html/rfc6761
Personally, I just use a registered domain for this purpose, as they're cheap enough to not care (last I checked, I pay $10–20/domain/year for registrations, depending on registrar and TLD, and $0.21/zone/month for hosting public zones on Google Cloud).
[1] https://www.rfc-editor.org/rfc/rfc9476
It should be logical even without thinking that the request have to be rejected.
It was funny, because when I brought it up to them, it was hard to articulate why it was a problem and I couldn't convince them it was worth the effort of trying to fix. They never ran into a specific issue due to this while I was there but it felt so gross.
Historically (20+ years ago), some Microsoft documentation suggested .local as an example of an unregistered domain that could be used for this purpose, which was problematic when .local was subsequently reserved for multicast DNS.
Sure one day your printer might start spewing random json code meant for some microservice of the rightful IP owner.
Sure the IP's might be owned by the Air Force and one day they might start getting traffic from your pos ipad that they decide looks like an attempt to attack one of their internal secret networks...
Sure one day traffic meant to go to your printer ends up flooding and dossing a windmill controller, preventing the rightful operators from turning it the right direction during bad weather and causing $25M damage...
And of course the real failures are more like, only people from the Maldives can't send email to your email server, a failure with no impact.
At least that's the conclusion I've arrived at at some point, but I don't remember what was the exact use case anymore.
However there are still several global IPv4 ranges that are not local reserved ranges but are effectively reserved and you could use them if you really want to without any issues.
The bureaucracy seems precision-engineered to stultify, but apparently the public have 104 days after “String Confirmation Day” (17th Nov; capitalization theirs) to lodge objections, assuming the “GAC” doesn’t beat them to it…
https://newgtldprogram.icann.org/en/application-rounds/round...
…of course there’s a “filing fee,” priced in “hours of a panel of lawyers’ time,” to lodge such an objection…
https://newgtldprogram-2026-agb.icann.org/en/8-module-4-comm...
…welp, hope somebody more organized (and better-funded) than I can organize an objection. Much as I feel like I’m giving up my right to gripe by assuming somebody else will come along to do the weeding.
This may very well end up to be determined too risky to be delegated, like .corp, .home and .mail in 2018.
- "String Confusion" -- looks or sounds like an existing (approved or being applied for) gTLD. Must be filed by whoever owns (or is applying for) that gTLD.
- "Legal Rights" -- someone else owns a trademark this would violate. Must be filed by whoever's legal rights would be violated.
- "Limited Public Interest" -- the gTLD is immoral under recognized principles of international law. I have no idea when this could be applicable.
- "Community" -- An established community organization believes the group this gTLD is intended to target will object to it. This seems more like a vehicle for e.g. Little People of America to let ICANN know that ".midget" would be offensive.
Unfortunately there doesn't seem to be a way to tell ICANN that .lan has been widely used and will break things in a way they will listen to.
ICANN isn't the DNS police, and lobbying them is pointless. We should campaign for open-source router projects[0], commercial hardware developers[1], DNS resolver developers, and major providers[2] to collectively designate commonly used private TLDs such as .home, .lan, .intranet, and .private as non-resolvable in public DNS.
Local resolution would continue to work, but these names would never be forwarded upstream. With sufficient adoption, we'd establish a de facto reservation and make the TLDs commercially worthless, regardless of what ICANN decides.
--
[0] There is precedence here. OpenWrt already reserves .lan in its default dnsmasq configuration.
[1] There is precedence here. GL.iNet inherits from its OpenWrt roots. Ubiquiti uses .lan as the default in its AmpliFi products. MikroTik documents it as part of its network-discovery mechanism.
[2] I'm thinking of Cloudflare, Quad9, and others.
ICANN and IANA very much are the DNS police. As a matter of fact, IANA maintains a list of special-use domains - though, despite its widespread use, .lan is not on the list - and these domains will get rejected from gTLD applications outright. The last thing I want is to require each recursive resolver to have their own idea of what should and shouldn't be resolved.
On a related note, Google owns a registry (CRR) and a recursive resolver (8.8.8.8) that's commonly used by default or as fallback. Letting them ban entire TLDs would be a massive conflict of interest.
What I implied (but failed to emphasise) is that what I'm calling for is already in de-facto effect, with multiple software and hardware vendors treating .lan as not publicly resolvable. What you describe as "the last thing [you] want" is already happening; my proposal is for more of the same.
It is valid to note that ICANN could abuse their contractual arrangements with resolvers who also operate registrars, but this would be an illegal intimidation tactic. It would not be a conflict of interest for Google to act if part of a wider campaign involving other parties.
Community groups can make their own competing DNS hierarchy and governing body and perhaps should but I don't think saying ICANN aren't responsible here is reasonable.
Formal objections require standing, procedural compliance and fees. Demanding monetary payment in order to issue an objection means that ICANN not acting as a responsible party in my view.
Having internal domain names owned by some guy on the internet has already compromised multiple corporate networks. See the talk from this guy:
https://www.romhack.io/wp-content/uploads/2025/10/Internal-D...
Even today when setting up greenfield networks, I generally use internal.company.com. It also lets you get public trusted SSL certificates so you don't have to deal with internal PKI.
at the very least, the .dev stuff should have had people second-guessing their usage of unreserved domains.
That leaves .home.arpa, which is very awkward and only a thing since 2018 (my home network's use of .lan definitely predates this). Especially as a non US citizen. It also seemed so far that .lan was the "unofficial" gTLD to be used, since much software like OpenWRT was already using it anyway.
Either way: making .lan internet routable seems entirely unhinged to me. LAN has always been the acronym for Local Area Network. Why would anyone sane think that it is a good idea to make this into a gTLD that can be internet routable? The only way I see forward to do this justice, is to only allow RFC 1918 and IPv6 addresses that are within the assigned prefix for your router.
This seems like a worse version of allowing .zip to be a gTLD. Remember the idea of downloading something from https://github.com/[...]@evil.zip?
.qm to .qz and .xa to .xz have always been implicitly reserved as TLDs that will never be globally-routable [0] [1], but these aren't exactly the most intuitive names so it's unsurprising that nobody uses them.
(".internal" as mentioned by the sibling comment [2] is the best choice these days, but its definition is somewhat recent.)
[0]: https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2#User-assign...
[1]: https://en.wikipedia.org/wiki/Country_code_top-level_domain#...
[2]: https://news.ycombinator.com/item?id=50012163
Home.arpa exists, or buy a domain and use that. Or pick something that’s not reserved and run the risk of this happening.
there is. it's .internal.
https://en.wikipedia.org/wiki/.internal
(note: i hope .lan does not get approved, but people have to understand that they are rolling dice when using unreserved names)
edit: fucking wild that this is downvoted into negatives. press the wiki link and read the first line if you don't believe me. in fact, i will quote it: "The name internal is reserved by ICANN "
That explains why I hadn't heard of this yet. My current incarnation of my internal network dates from ~april 2024.
In time we'll see articles like "Don't register a .lan domain if you want people to visit your site"
throughout most of my career, there was no unreserved domain that felt safe. but especially after .dev.
Just purely from common sense perspective why the fuck should .lan be something that’s an internet/public TLD? Hello? LOCAL Area Network?
While we’re at it let’s update a few RFCs. Plus I don’t want to find out what organisations use .lan for their networks and what will end up leaking to the internet as a consequence of this.
> Objections for this Application have not yet been published. Information will be added when it becomes available. Please check back periodically for updates.
How does this work? Who can submit an objection? Can I submit one as someone with .lan domains inside my home network?
.home.arpa is so clunky. Why do I have to put the acronym of a US military project in my domain to access resources on my own local network?
Yes, I know that organization was central to the development of the l Internet, but it's not relevant as a domain 40 years later.
This is not how anything should work.
guess I'll be migrating things 100% over to internal...
To me is a very bad idea to implement this proposal, it should instead be standardized and reserved for internal usage as a fix. There were even RFC like https://www.rfc-editor.org/info/rfc6762/#appendix-G that suggested their usage for local devices in a network.
What is the point of selling the .lan domain, except for making money at the expense of a security risk for millions of networks that already use that domain for internal hosts?
BTW to me there was never any sense to add new TLD domain despite country code. They decided to render internet less secure, by giving scammers infinite TLD to register they scam domain like "apple.lan", with the sole purpose of making for them easy money.
it is not, as .local is designated as a special-use domain name and .lan is not.
It may not be an official standard, but it does have some weight as a de-facto standard.
I've tried briefly to try and find some numbers to back that up, but can't find much beyond apple's bonjour vs consumer routers - although I've seen companies with AD domains using .lan as well. (Although, I've also seen companies using 1.0.0.0/8 for their internal addressing...)
if you choose to use an unreserved domain, you are choosing to accept the risk of something like this happening. take ownership of your choices. "but other people use it" is not a great defense.
For those not in the know, Google lobbied ICANN to get the name and in their application they stated (repeatedly) that the intent was to buy it so that it could be reserved; as .dev was already used by developers and if someone bought it for commercial purposes it would harm the developer community.[0]
.... they then proceeded to start selling them.
Leading to all kinds of issues, the exact issues that they raised...
https://github.com/basecamp/pow/issues/397
https://github.com/laravel/valet/issues/433
https://danielbachhuber.com/switch-laravel-valet-from-dev-to...
https://community.localwp.com/t/dev-domain-doesnt-work/4277
https://forums.theregister.com/forum/all/2017/11/29/google_d...
[0]: https://gtldresult.icann.org/applicationstatus/applicationde...
My tweet on Sep 26, 2026
Also see a .bldg application, which also might conflict with some legacy naming schemes.
There are questions that literally say as part of the question "Choose Yes or No", so they've answered "true"...
And Q165 is fun: "Is it likely that consumers will face significant risks if domain names in the TLD(s) in the application are abused?" Answer: "No"
There's almost no value.
Large businesses almost never use them. The potential for scams / phish / etc are now limitless.
It's arguably defensible to have a limited number of non-geographic TLDs. "Dot com" was an aesthetic as much as a technical decision. I wonder though, if .com/net/org had never existed, we would have a different sense of aesthetic around domain names, and there's no reason to think that it would be any better or worse than what we have now.
Fortunately there’s no need to speculate as the application explains this clearly:
I'm guessing that'll end up being expensive for someone...
ICANN Reveals 2026 Round Applications for New Generic Top-Level Domains
https://news.ycombinator.com/item?id=49997301
https://www.icann.org/en/board-activities-and-meetings/mater...
.internal is all about the boundary between inside and the public internet, regardless of how you define ‘inside’.
Source: the application refers to multiple layers of LLC ownership, and the responsible parties listed are general counsels at some IP financialization company, "Identity Digital"
I don't really see what website would use it though. Maybe for networking companies like mikrotik.lan or self hosted services like immich.lan?
It's monopolies like Verisign (of the .com tld) that have luxurious profits. No competition, plus they are allowed to raise their prices above inflation while their infrastructure costs go down every year.
"America" has our best interests at heart /s