A quiet change to the .name domain registry has ignited a loud debate over DNS stability, legacy accounts, and whether deleting old third-level names could expose thousands of users to account takeover. The issue surfaced after software engineer Neil Fraser said his nearly 25-year-old domain is scheduled for deletion following approval by ICANN, with critics arguing that the move could turn dormant names into tools for identity theft.
What changed in .name
The controversy centers on a registry update submitted by Verisign to ICANN through the Registry Services Evaluation Policy on April 15, 2026. According to the approved service change, decided in late July, Verisign is discontinuing third-level registrations in the .name top-level domain, including the long-standing first.last.name structure.
Verisign said the format has seen declining use and limited registrar support. In practical terms, new third-level registrations will be rejected through EPP transactions, and existing active third-level registrations will be deleted after a minimum 90-day notice period to registrars.
The change does not shut down the entire .name TLD. Verisign will continue to support standard second-level registrations such as example.name, which have been available since 2004. Existing second-level domains are not affected by the termination of the older third-level system.
Why the decision matters for legacy registrants
The most immediate impact falls on an estimated 22,000 registrants who adopted third-level .name addresses after the TLD launched in 2001 under Global Name Registry. For those users, the domains are not just old web addresses. They can also anchor email accounts, automated workflows, and other systems that still depend on stable DNS records.
Fraser’s example drew attention because it highlights the lifespan mismatch between domain policy and real-world usage. A domain registered nearly 25 years ago can still be embedded in passwords resets, mailing lists, personal identity records, and services that have not been updated in years. When a domain disappears, the consequences can extend far beyond a broken website.
- Long-running websites may stop resolving.
- Mail servers tied to the domain may no longer function.
- IoT or automation systems may lose their DNS endpoints.
- Password reset flows may become unreliable or insecure.
The security concern: released domains can be reused
The sharpest criticism is about what happens after a third-level registration is deleted. Fraser warned that the parent second-level domains may become available for public registration, creating an opportunity for a malicious buyer to control DNS records associated with legacy addresses.
That matters because DNS ownership can translate into practical control over identity-linked services. If someone acquires a released second-level domain, they may be able to configure mail and web records in ways that intercept communications, reset passwords, and hijack accounts associated with the older address. In other words, a domain that was once tied to a real person can become a takeover vector if the release process is not carefully managed.
Online discussion on Hacker News and Mastodon quickly focused on that risk. Commenters criticized Verisign’s filing, which reportedly stated that registrars had identified no security, stability, or resiliency concerns, and they questioned ICANN’s approval of a change that invalidates paid, active domains.
Reaction from engineers and the wider technical community
Some observers described the outcome as “identity theft-as-a-service,” arguing that orphaned email addresses could become targets for automated abuse. Others said the policy creates a dangerous precedent for registry stewardship, especially when the affected domains have been in use for decades.
One recurring argument was that if third-level names are being retired, registries should protect existing delegations rather than fully releasing them. Suggested alternatives included freezing existing names in a read-only maintenance mode or reserving the associated second-level domains permanently so they cannot be re-registered by the public.
Fraser, for his part, posted bluntly: “I’m just one of 22,000 people who will lose their domains. This is going to be fun. Time to lawyer up…” The comment reflects a broader concern among registrants that the decision may have been made without sufficient consideration for the downstream effects on users who have relied on these addresses for years.
ICANN approval, registry policy, and the notice period
At the center of the dispute is not a security flaw in DNS itself, but a policy decision about how a registry may manage a legacy namespace. ICANN’s role in approving the service change gives the move formal legitimacy, but it also places the organization under scrutiny from registrants who believe their existing services should be preserved.
Verisign’s plan includes a minimum 90-day notice period for registrars before the deletions take effect. That provides a transition window, but it does not solve the larger problem for users whose systems depend on the old addresses. If the underlying domain is removed and later re-registered by someone else, the old identity relationship can become dangerous rather than merely broken.
The fact that the policy leaves second-level .name domains intact may seem like a compromise, but it is exactly that split that raises concern. A structure originally designed for personal naming can leave behind a trail of addressable identities, and the deletion of legacy subdomains may turn those names into assets that can be reused by strangers.
What affected domain owners may do next
With deletion notices beginning to roll out, affected owners are now weighing options. According to the report, some are considering administrative appeals or legal challenges that could force ICANN and Verisign to add defensive protections before the legacy domains are taken offline.
At minimum, the dispute illustrates how legacy DNS policy can collide with modern security expectations. A domain name is not just a string in a registry; it can be part of someone’s identity infrastructure. When that name is retired, the question is not only whether the web address still works, but whether the retirement process introduces new ways for accounts and communications to be compromised.
For now, the case has become a cautionary example for registry operators and platform owners alike: when old namespaces are cleaned up, the security model has to account for everything that might still be attached to them.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 9, 2026 at 10:34 pm
0 views
