ICANN signed off on a plan that deletes every third-level ".name" domain on the internet, less than a month after a formal complaint said Verisign had misstated how many people it would affect. On July 28, 2026, the organization approved Verisign's request to terminate all 22,288 registrations in the format xxx.yyy.name, killing the websites and email addresses attached to them and, security researchers warn, handing an opening for large-scale account hijacking once the underlying domains go back up for sale.

The story only reached a wide audience this week because one of those 22,288 registrants is Neil Fraser, a Google engineer known for building the Blockly visual-programming editor and the widely-used diff-match-patch library. He registered neil.fraser.name in 2002, before YouTube or Facebook existed, and used it as his homepage, his email address and an API host for a quarter century. On September 3 he published an account of finding out his domain is scheduled to disappear in February 2027, despite being paid up through 2040. It hit the front page of Hacker News within the hour.

RelatedAn Anonymous Account Is Dumping Zero-Days Into the Open. That Should Worry Everyone.

What did Verisign actually propose?

On April 15, 2026, Verisign filed a Registry Services Evaluation Process request, internally numbered rsep-2026013, asking ICANN for permission to stop selling third-level .name registrations and delete the ones that already exist. The stated reason was administrative simplicity: third-level names are a relic of how .name launched in 2002, run at the time by Global Name Registry rather than Verisign, specifically so people could register personal addresses like john.smith.name with a full public WHOIS record, unlike the resold subdomains you see under domains such as uk.co. Verisign eventually acquired Global Name Registry and inherited a service that, by its own account, sees little modern demand and limited registrar support.

What makes the RSEP filing contentious is a claim buried inside it. Bulgarian registrar employee Doytchin Spiridonov filed a formal Request for Reconsideration with ICANN on July 2, arguing Verisign's paperwork asserted there would be no effect on the "life cycle of domain names," a statement he calls impossible to square with deleting over 22,000 of them. His research turned up the exact figure ICANN was working from, plus a detail that made the story sticky: 37 of the affected addresses belong to people named Kevin. ICANN approved the RSEP anyway, 26 days after his objection was filed.

  • 22,288 domains in the xxx.yyy.name format are scheduled for deletion, confirmed by both Verisign's filing and Spiridonov's independent count.
  • Termination is expected as early as February 2027, regardless of how far in advance a registrant paid.
  • A Request for Reconsideration was filed against the decision on July 2, 2026, before ICANN's July 28 approval, and does not appear to have changed the outcome.
  • Once a third-level domain is deleted, its parent second-level domain becomes available for anyone to register, which is where the hijacking risk comes from.
How deleting a .name third-level domain enables hijacking A third-level domain like neil.fraser.name is terminated, freeing the second-level domain fraser.name for anyone to register. Whoever registers it can recreate the exact third-level address and take over accounts, email and devices still trusting it. neil.fraser.name your 3rd-level domain Verisign deletes fraser.name 2nd-level, now vacant anyone registers New owner: fraser.name recreates neil.fraser.name at will WHAT A HIJACKED ADDRESS UNLOCKS Email-based password resets Code-signing and commit authentication Linked IoT device accounts Any service that trusts the old address genztech.blog
Fig 1 Deleting the third-level domain does not just take a website offline. It frees the second-level domain for anyone to buy, and whoever buys it can rebuild the exact old address and inherit every account, credential and device still pointed at it.

Why is this a security problem and not just a shutdown?

Domain-based identity assumes continuity: an email address stays yours because you keep renewing the domain under it. The .name termination breaks that assumption from the outside. A registrant who dutifully renewed through 2040, as Fraser did, still loses the address in February 2027, and has no way to stop someone else from registering the freed-up parent domain the moment it opens. That new owner does not need to guess a password or exploit a bug. They just recreate the subdomain and start receiving whatever the old owner's inbox used to receive, including password-reset links for any account that still lists that address as a recovery method.

This is not a hypothetical failure mode. Security researchers have spent years cataloguing "dangling domain" attacks, where an expired or deprovisioned address gets re-registered and used to take over cloud accounts, developer tooling and email. What is unusual here is the scale: this is not neglect by individual registrants, most of whom paid to keep their domains active. It is a policy decision that manufactures 22,288 dangling domains on one fixed date, a far richer target than the scattered abandoned subdomains attackers usually have to go hunting for.

  1. 2002.name launches as a personal 3rd-level namespace. Run by Global Name Registry, later acquired by Verisign, with full public WHOIS records unlike resold subdomains.
  2. Apr 15, 2026Verisign files RSEP 2026013. Requests permission to stop selling and delete existing 3rd-level .name registrations.
  3. Jul 2, 2026Reconsideration request filed. Doytchin Spiridonov disputes Verisign's "no effect" claim, citing 22,288 affected domains.
  4. Jul 28, 2026ICANN approves the RSEP. The termination proceeds despite the pending objection.
  5. Sep 3, 2026Neil Fraser publishes his account. Reaches the Hacker News front page and brings general attention to the decision.
  6. Feb 20273rd-level .name domains terminated. Websites and email addresses stop resolving; parent 2nd-level domains open for registration.

Who gets hurt, and what should they do?

Anyone with a working xxx.yyy.name address is affected, but the damage lands hardest on people who used theirs the way Fraser did: as a long-lived personal identity tying together email, code hosting and device accounts. There is no public tool to enumerate every account ever opened with a given .name address, so registrants cannot audit their way to full safety before February. The realistic options are narrower: migrate the address on every account you can identify before the domain dies, and treat any account you cannot migrate as potentially exposed once the old address is gone, since you no longer control what happens to mail sent to it.

RelatedOne GitHub issue, RCE on Claude Code and Gemini CLI runners

The wider lesson travels well beyond .name's 22,288 registrants. Any identity built on a domain you do not fully control, including a subdomain issued by a registrar, employer, or platform, carries the same risk if that party ever decides to stop supporting it. A renewal receipt paid through 2040 turned out not to be the protection Fraser assumed it was.

What to watch · through Feb 2027
  • Does the reconsideration request change anything? ICANN approved the RSEP with Spiridonov's objection still open. Whether that process forces a delay or a migration path is the clearest near-term signal.
  • Does Verisign offer a paid migration path? Letting affected registrants convert to a 2nd-level .name registration, rather than losing the address outright, would defuse most of the hijacking risk without reversing the shutdown.
  • Will attackers pre-register the highest-value freed domains? Watch whether well-known 3rd-level addresses (like Fraser's) attract registration attempts the moment the zone clears in February.
  • Does another legacy TLD service face the same RSEP treatment? .name is not the only registry running an underused legacy feature; this case sets a template other registries can point to.

Our take

ICANN's process worked exactly as designed, and that is the uncomfortable part. Verisign filed a request, a public comment period ran, a registrant objected with real numbers, and the organization approved it anyway on schedule. Nobody broke a rule. But a process that can delete 22,288 working domains, paid and renewed in good faith, on the strength of an administrative filing that undersold its own impact, is a process worth being afraid of if you have ever built anything on a domain you do not personally control. The security risk here is not exotic. It is the oldest trick in domain security, an abandoned address falling into new hands, deployed at a scale that turns individual bad luck into a structural event. Whether ICANN or Verisign offers a real migration path before February will decide whether this becomes a footnote or a case study.

Primary sources

Original analysis by GenZTech, based on primary ICANN filings and firsthand registrant accounts.