ICANN approved a Verisign plan on July 28, 2026 to delete all 22,288 third-level .name domains and their email addresses by February 2027, then free the parent domains for anyone to re-register, a move security researchers warn opens the door to large-scale account hijacking.

Read the full story: ICANN Approves Wipeout of .name Domains, Inviting Hijacks →

Transcript

ICANN just approved deleting every third level dot name domain on the internet. Over twenty two thousand of them, gone by February. A Google engineer named Neil Fraser found his address, registered in 2002 and paid through 2040, is getting wiped anyway. Verisign filed the request in April calling it a cleanup. A Bulgarian registrar objected in July, saying the paperwork undercounted the damage. ICANN approved it three weeks later anyway. Here is the real danger. Once your subdomain dies, the parent domain goes back up for sale. Whoever buys it can recreate your old address and start catching your password resets and your email. Nobody hacked anything. The policy did it for them.