Top-level domain
Every website address, from the simplest blog to the largest corporation, ends with a specific sequence of letters—like .com, .org, or .gov. These unassuming suffixes are called Top-Level Domains, or TLDs, and they form the fundamental structure of the internet's naming system. Understanding TLDs reveals how the digital world is organized, regulated, and continuously evolving to connect us all. Top-Level Domains are the highest level of hierarchy in the internet's Domain Name System, essentially acting as the final category for any website address. TLDs are broadly categorized into country codes (ccTLDs) and generic types (gTLDs), with an ongoing expansion introducing hundreds of new options. The management and evolution of TLDs are overseen by global bodies like ICANN, ensuring the internet remains organized and accessible across diverse languages and regions.
AI Summary
Every website address, from the simplest blog to the largest corporation, ends with a specific sequence of letters—like .com, .org, or .gov. These unassuming suffixes are called Top-Level Domains, or TLDs, and they form the fundamental structure of the internet's naming system. Understanding TLDs reveals how the digital world is organized, regulated, and continuously evolving to connect us all.
- Top-Level Domains are the highest level of hierarchy in the internet's Domain Name System, essentially acting as the final category for any website address.
- TLDs are broadly categorized into country codes (ccTLDs) and generic types (gTLDs), with an ongoing expansion introducing hundreds of new options.
- The management and evolution of TLDs are overseen by global bodies like ICANN, ensuring the internet remains organized and accessible across diverse languages and regions.
The Internet's Address Book
Think of the internet like a massive, interconnected city. To find anything, you need an address. A Top-Level Domain, or TLD, is the final part of that address — the designation after the last dot, like the '.com' in 'wikipedia.com'. It's the highest level in the hierarchical structure of the Domain Name System, or DNS, after the invisible 'root' domain.
These critical TLDs are installed and maintained in the internet's 'root zone,' which is essentially the master index of all possible TLDs. Responsibility for managing most of these domains is delegated by ICANN, the Internet Corporation for Assigned Names and Numbers. ICANN, through its operational arm IANA, ensures this fundamental part of the internet stays organized and functional for billions of users worldwide.
A Brief History of Domains
When the Domain Name System was first conceived, the TLD space was organized quite simply. It comprised three main groups: 'Countries' for specific nations, 'Categories' for general purposes, and 'Multiorganizations' for international bodies. There was also a unique, temporary addition: the '.arpa' domain.
The '.arpa' domain was initially intended as a transitional tool, helping move from older ARPANET naming conventions to the new DNS system. Little did anyone know, it would become a permanent fixture, taking on a crucial behind-the-scenes role.
Different Flavors of TLDs
One of the most common types you'll encounter are Country Code Top-Level Domains, or ccTLDs. These are typically two-letter domains corresponding to ISO country codes, like '.de' for Germany or '.jp' for Japan. While most follow this standard, there are a few exceptions, such as '.uk' for the United Kingdom.
But what if a country uses a script other than Latin? Since 2009, nations with non-Latin scripts can apply for Internationalized Country Code Top-Level Domains, or IDN ccTLDs. These appear in web browsers in their native language or alphabet, making the internet truly global. Under the hood, however, they use a special encoding called Punycode to translate them into standard ASCII for the DNS.
ICANN began accepting applications for these IDN ccTLDs in late 2009, and the first ones were installed in May 2010. Among the pioneers were Arabic names for Egypt, Saudi Arabia, and the United Arab Emirates, ushering in a new era of internet accessibility for diverse linguistic communities. By that time, 21 countries representing 11 different scripts had already submitted applications.
Then there are Generic Top-Level Domains, or gTLDs, which were originally conceived as broader categories. The initial set included familiar names like '.gov' for government entities, '.edu' for educational institutions, '.com' for commercial use, '.mil' for military, '.org' for organizations, and '.net' for network infrastructure. Over time, new gTLDs like '.info' have been added to this expanding family.
The authoritative, up-to-date list of all TLDs currently active in the root zone is meticulously maintained and published by IANA. It's a living document, reflecting the continuous growth and evolution of the internet's naming landscape.
The Enduring Anomaly: .arpa
Let's revisit '.arpa' — the very first Internet top-level domain. Despite its initial temporary status, it proved too vital to retire. Today, '.arpa' is exclusively dedicated to critical internet infrastructure purposes. It facilitates essential functions like reverse DNS lookups, allowing IP addresses to be translated back into domain names.
For instance, '.in-addr.arpa' is used for IPv4 reverse DNS, and '.ip6.arpa' for IPv6. Other uses include the Dynamic Delegation Discovery System and telephone number mapping. Its persistence and specialized role mean that for historical reasons, it's sometimes unofficially considered a generic top-level domain.
Domains You Can't Use
Not all domain names are meant for public use. The Internet Engineering Task Force, or IETF, has reserved a special set of domain names specifically for documentation, testing, and other non-production uses. These are explicitly defined in various RFCs, or Request for Comments documents, like RFC 2606.
These reserved names should never appear in a live, global network environment. They prevent conflicts and ensure that examples given in technical manuals or software development don't accidentally route traffic to real websites. Think of them as placeholders, vital for stability but never meant for actual browsing.
Ghost Domains of the Internet
The internet's history is also dotted with TLDs that no longer exist, often due to geopolitical changes. In the late 1980s, for example, '.nato' was created for the North Atlantic Treaty Organization. However, it was soon superseded by the more general '.int' TLD for international organizations, and '.nato' was removed in 1996.
Many country codes have also vanished with their nations. The former Czechoslovakia used '.cs' (now '.cz' and '.sk'), East Germany had '.dd' (now '.de'), and Yugoslavia used '.yu' (now several new ccTLDs for successor states). Yet, in a fascinating historical quirk, the '.su' TLD for the Soviet Union remains active today, despite the Soviet Union's collapse decades ago.
The Expanding Universe of TLDs
The early 2000s saw a significant expansion in the number of gTLDs. ICANN deliberated and eventually introduced domains like '.aero', '.biz', '.coop', '.info', '.museum', '.name', and '.pro'. There was also a major push for a TLD specifically for adult content, leading to the eventual launch of '.xxx' in 2011 after years of debate.
The appetite for new domains continued to grow. In 2008, ICANN launched a groundbreaking program to introduce
This bold initiative paved the way for hundreds of new gTLDs, vastly expanding the options available beyond the traditional '.com' or '.org'. On June 13, 2012, ICANN announced nearly 2,000 applications for these new top-level domains, with the first seven — including '.bike', '.clothing', and '.guru' — being released in 2014.
Rejected Ideas
Not every proposed TLD makes it through the application process. Some, like '.home' and '.corp', were rejected due to potential 'name collision' conflicts. These domains were already widely used in internal, private networks, and introducing them globally could have caused significant internet stability and security issues.
The complexities of these 'name collision' issues were thoroughly investigated by Interisle Consulting at ICANN's request. Their report highlighted the intricate challenges of expanding the TLD space without disrupting existing private network configurations, underscoring the delicate balance in managing the internet's global infrastructure.
The Curious Case of Dotless Domains
Within the Domain Name System, every TLD is a 'node' with its own set of records. This means, theoretically, you could query '.org' itself and get information directly. This unique aspect led to the concept of 'dotless domains' — where a website or email could exist directly at the TLD level, like 'http://example/' or 'user@example'.
However, ICANN and the Internet Architecture Board have strongly advised against dotless domains, citing them as a security risk and other concerns. For instance, the Security and Stability Advisory Committee argues that email protocols generally require at least two labels in an email address, meaning emails to 'user@example' would likely be rejected.
As a result, ICANN passed a resolution in 2013 prohibiting the creation of dotless domains for gTLDs. Yet, for ccTLDs, which often fall under their respective country's jurisdiction, there have been historical and ongoing examples of dotless domains, showcasing the varied governance across the global internet.
Mandatory Apex Records for New TLDs
To prevent future name collisions and provide a standardized response for newly registered TLDs, ICANN introduced a specific requirement in 2014. New TLDs must implement mandatory 'apex' DNS records for at least 90 days after their creation. These records act as placeholders, indicating the TLD is active but not yet hosting specific services.
For example, if you tried to access 'http://.bar' (before .bar was fully populated), these records would direct you to a specific IP address: 127.0.53.53. This particular loopback address is a clever mnemonic, chosen because DNS uses port 53. It signals a DNS-related problem, helping diagnose issues when a TLD is newly created or still in its transitional phase.
Echoes of a Different Internet: Pseudo-Domains
Before the internet as we know it dominated, several widespread computer networks like BITNET, CSNET, and UUCP connected academics and professionals. These networks weren't directly interoperable with the nascent internet, but they exchanged mail through special gateways. For routing purposes, email addresses on these networks often used suffixes like '.bitnet', '.oz', or '.uucp'.
These 'pseudo-domains' never existed in the official public Domain Name System of the internet; they were purely for internal network routing. Most of these networks have since faded into history. While UUCP still sees some use in areas with less developed internet infrastructure, it has largely transitioned to using standard Internet domain names, leaving pseudo-domains as fascinating historical relics.
However, the concept isn't entirely gone. Modern anonymity networks, for instance, utilize their own forms of pseudo-domains. Tor, for a long time, used the '.onion' pseudo-domain for its 'hidden services,' accessible only through a Tor client. In 2015, '.onion' was officially reserved, giving it a recognized, albeit special, status. Similarly, I2P uses '.i2p', and Namecoin uses '.bit' for their unique decentralized naming systems.
Article
Top-level domain
A top-level domain (TLD) is one of the domains at the highest level in the hierarchical Domain Name System of the Internet after the root domain. The top-level domain names are installed in the root zone of the name space. For all domains in lower levels, it is the last part of the domain name, that is, the last non-empty label of a fully qualified domain name. For example, in the domain name www.example.com, the top-level domain is .com. Responsibility for management of most top-level domains is delegated to specific organizations by the ICANN, an Internet multi-stakeholder community, which operates the Internet Assigned Numbers Authority (IANA), and is in charge of maintaining the DNS root zone.
History
Top-level domain
Originally, the top-level domain space was organized into three main groups: Countries, Categories, and Multiorganizations. An additional temporary group consisted of only the initial DNS domain, .arpa, and was intended for transitional purposes toward the stabilization of the domain name system.
Types
Top-level domain
As of 2015, IANA distinguishes the following groups of top-level domains:
• Infrastructure top-level domain (ARPA): This group consists of one domain, the Address and Routing Parameter Area. It is managed by IANA on behalf of the Internet Engineering Task Force for various purposes specified in the Request for Comments publications. • Generic top-level domains (gTLD): Top-level domains with three or more characters • Generic restricted top-level domains (grTLD): These domains are managed under official ICANN-accredited registrars. • Sponsored top-level domains (sTLD): These domains are proposed and sponsored by private agencies or organizations that establish and enforce rules restricting the eligibility to use the TLD. Use is based on community theme concepts; these domains are managed under official ICANN accredited registrars. • country-code top-level domains (ccTLD): Two-letter domains established for countries or territories. With some historical exceptions, the code for any territory is the same as its two-letter ISO 3166 code. • Internationalized country code top-level domains (IDN ccTLD): ccTLDs in non-Latin character sets (e.g., Arabic, Cyrillic, Greek, Hebrew, or Chinese). • Test top-level domains: These domains were installed under .test for testing purposes in the IDN development process; these domains are not present in the root zone.
Countries are designated in the Domain Name System by their two-letter ISO country code; there are exceptions, however (e.g., .uk). This group of domains is, therefore, commonly known as country-code top-level domains (ccTLD). Since 2009, countries with non–Latin-based scripts may apply for internationalized country code top-level domain names, which are displayed in end-user applications in their language-native script or alphabet, but use a Punycode-translated ASCII domain name in the Domain Name System.
Generic top-level domains (formerly categories) initially consisted of .gov, .edu, .com, .mil, .org, and .net. More generic TLDs have been added, such as .info.
The authoritative list of current TLDs in the root zone is published at the IANA website at https://www.iana.org/domains/root/db/ as well as tlds-alpha-by-domain.txt.
Internationalized country code TLDs
Top-level domain
An internationalized country code top-level domain (IDN ccTLD) is a top-level domain with a specially encoded domain name that is displayed in an end-user application, such as a web browser, in its language-native script or alphabet (such as the Arabic alphabet), or a non-alphabetic writing system (such as Chinese characters). IDN ccTLDs are an application of the internationalized domain name (IDN) system to top-level Internet domains assigned to countries, or independent geographic regions.
ICANN started to accept applications for IDN ccTLDs in November 2009, and installed the first set into the Domain Names System in May 2010. The first set was a group of Arabic names for the countries of Egypt, Saudi Arabia, and the United Arab Emirates. By May 2010, 21 countries had submitted applications to ICANN, representing 11 scripts.
Infrastructure domain
Top-level domain
The domain .arpa was the first Internet top-level domain. It was intended to be used only temporarily, aiding in the transition of traditional ARPANET host names to the domain name system. However, after it had been used for reverse DNS lookup, it was found impractical to retire it, and is used today exclusively for Internet infrastructure purposes such as in-addr.arpa for IPv4 and ip6.arpa for IPv6 reverse DNS resolution, uri.arpa and urn.arpa for the Dynamic Delegation Discovery System, and e164.arpa for telephone number mapping based on NAPTR DNS records. For historical reasons, .arpa is sometimes considered to be a generic top-level domain.
Reserved domains
Top-level domain
A set of domain names is reserved by the Internet Engineering Task Force as special-use domain names. The practice originated in RFC 1597 for reserved address allocations in 1994 and reserved top-level domains in RFC 2606 of 1999, with additional reservations in later RFCs. These reserved names should not be used in production networks that utilize the global domain name system.
<table><thead><tr><th>Domain</th><th>Reserved by</th><th>Reserved for</th></tr></thead><tbody><tr><td>.example</td><td>RFC 6761</td><td>use in examples</td></tr><tr><td>.invalid</td><td>RFC 6761</td><td>use in invalid domain names</td></tr><tr><td>.localhost</td><td>RFC 6761</td><td>avoiding conflict with the traditional use of localhost as a hostname</td></tr><tr><td>.test</td><td>RFC 6761</td><td>use in tests</td></tr><tr><td>.local</td><td>RFC 6762</td><td>link-local host names that can be resolved via the multicast DNS name resolution protocol</td></tr><tr><td>.onion</td><td>RFC 7686</td><td>self-authenticating names of Tor onion services</td></tr><tr><td>.internal</td><td>ICANN</td><td>private application use</td></tr><tr><td>.alt</td><td>RFC 9476</td><td>alternative (non-DNS) namespaces</td></tr></tbody></table>
Historical domains
Top-level domain
In the late 1980s, InterNIC created the .nato domain for use by NATO. NATO considered none of the then-existing TLDs as adequately reflecting their status as an international organization. Soon after this addition, however, InterNIC also created the .int TLD for the use by international organizations in general, and persuaded NATO to use the second level domain nato.int instead. The nato TLD, no longer used, was finally removed in July 1996.
Other historical TLDs are .cs for Czechoslovakia (now using .cz for Czech Republic and .sk for Slovakia), .dd for East Germany (using .de after reunification of Germany), .yu for SFR Yugoslavia and Serbia and Montenegro (now using .ba for Bosnia and Herzegovina, .hr for Croatia, .me for Montenegro, .mk for North Macedonia, .rs for Serbia and .si for Slovenia), .zr for Zaire (now .cd for the Democratic Republic of the Congo), and .an for Netherlands Antilles (now .aw for Aruba, .cw for Curaçao and .sx for Sint Maarten). In contrast to these, the TLD .su has remained active despite the collapse of the Soviet Union that it represents. Under the chairmanship of Nigel Roberts, ICANN's ccNSO is working on a policy for the retirement of ccTLDs that have been removed from ISO 3166.
Proposed domains
Top-level domain
Around late 2000, ICANN discussed and finally introduced .aero, .biz, .coop, .info, .museum, .name, and .pro TLDs. Site owners argued that a similar TLD should be made available for adult and pornographic websites to settle the dispute of obscene content on the Internet, to address the responsibility of US service providers under the US Communications Decency Act of 1996. Several options were proposed including xxx, sex and adult. The .xxx top-level domain eventually went live in 2011.
An older proposal consisted of seven new gTLDs: arts, firm, .info, nom, rec, .shop, and .web. Later .biz, .info, .museum, and .name covered most of these old proposals.
During the 32nd International Public ICANN Meeting in Paris in 2008, ICANN started a new process of TLD naming policy to take a "significant step forward on the introduction of new generic top-level domains". This program envisioned the availability of many new or already proposed domains, as well as a new application and implementation process. Observers believed that the new rules could result in hundreds of new gTLDs being registered.
On 13 June 2012, ICANN announced nearly 2,000 applications for top-level domains, which began installation throughout 2013. The first seven – bike, clothing, guru, holdings, plumbing, singles, and ventures – were released in 2014. As of 2025, there are approximately 1,200 delegated generic top-level domains (gTLDs) in the global Domain Name System, including legacy gTLDs (such as .com, .org, .net) and gTLDs introduced in the 2012 New gTLD Program.
ICANN has been gearing to roll out the subsequent round of New gTLD expansion but opening the second round of New gTLD Application window in April 2026 for 12 - 15 weeks. The first draft of New gTLD Applicant Guidebook was published on 30 May 2025 followed by the period of public comments has now been approved by the ICANN board and is now expected to be published in ICANN's website by December 2025.
ICANN has also opened up Applicant Support Program to support organizations and communities which are in need of financial support to apply for New gTLD. The application window to apply for financial support has been extended until 19th December 2025 from the original deadline of 19th November 2025. ICANN has also mandated applicants to choose a registry backend service provider from ICANN's accredited Registry Service Provider (RSP) list which is expected to be published in early 2026. ICANN is publishing timely updates on their website.
Rejected domains
ICANN rejected several proposed domains to include .home and .corp due to conflicts regarding gTLDs that are in use in internal networks.
Investigation into the conflicts was conducted at ICANN's request by Interisle Consulting. The resulting report was to become known as the Name Collision issue, which was first reported at ICANN 47.
Dotless domains
Top-level domain
.org[.] is a node in the DNS tree, just like wikipedia.[org.] and en.[wikipedia.org.]. As such, it has its own DNS records.
Due to the structure of DNS, each node in the tree has its own collection of records, and since top-level domains are nodes in DNS, they have records of their own. For example, querying org itself (with a tool such as dig, host, or nslookup) returns information on its nameservers:
Dotless domains are top-level domains that take advantage of that fact, and implement A, AAAA or MX DNS records to serve webpages or allow incoming email directly on a TLD – for example, a webpage hosted on http://example/, or an email address user@example.
ICANN and IAB have spoken out against the practice, classifying it as a security risk among other concerns. ICANN's Security and Stability Advisory Committee (SSAC) additionally claims that SMTP "requires at least two labels in the FQDN of a mail address" and, as such, mail servers would reject emails to addresses with dotless domains.
ICANN has also published a resolution in 2013 that prohibits the creation of dotless domains on gTLDs. ccTLDs, however, fall largely under their respective country's jurisdiction, and not under ICANN's. Because of this, there have been many examples of dotless domains on ccTLDs in spite of ICANN's vocal opposition.
• Uzbekistan's .uz, online at https://uz./ (Deprecated link archived 4 September 2023 at archive.today) It is a mirror of https://cctld.uz/, albeit with an invalid certificate.
• Anguilla's .ai, online at http://ai./ (Deprecated link archived 22 January 2023 at archive.today) It simply displayed a notice that the website was no longer public. The TLD no longer has an A or AAAA record.
Other ccTLDs with A or AAAA records, as of July 2025, include: .cm, .tk and .ws.
A similar query to org's presented above could be made for ai, which showed A and MX records for the TLD:
Historically, many other ccTLDs have had A or AAAA records. On 3 September 2013, as reported by the IETF, they were the following: .ac, .dk, .gg, .io, .je, .kh, .sh, .tm, .to, and .vi.
New TLDs
Following a 2014 resolution by ICANN, newly registered TLDs must implement the following A, MX, TXT, and SRV apex DNS records – where <TLD> stands for the registered TLD – for at least 90 days:
This requirement is meant to avoid domain name collisions when new TLDs are registered. For example, programmers may have used custom local domains such as foo.bar or test.dev, which would both collide with the creation of gTLDs .bar in 2014 and .dev in 2019.
While this does create apex DNS records of type A and MX, they do not qualify as a dotless domain, as the records should not point to real servers. For instance, the A record contains the IP 127.0.53.53, a loopback address (see IPv4 § Addressing), picked as a mnemonic to indicate a DNS-related problem, as DNS uses port 53.
Pseudo-domains
Top-level domain
Several networks, such as BITNET, CSNET, and UUCP, existed that were in widespread use among computer professionals and academic users, but were not interoperable directly with the Internet and exchanged mail with the Internet via special email gateways. For relaying purposes on the gateways, messages associated with these networks were labeled with suffixes such as .bitnet, .oz, .csnet, or .uucp, but these domains did not exist as top-level domains in the public Domain Name System of the Internet.
Most of these networks have long since ceased to exist, and although UUCP still gets significant use in parts of the world where Internet infrastructure has not yet become well established, it subsequently transitioned to using Internet domain names, and pseudo-domains now largely survive as historical relics. One notable exception is the 2007 emergence of SWIFTNet Mail, which uses the swift pseudo-domain.
The anonymity network Tor formerly used the top-level pseudo-domain .onion for onion services, which can only be reached with a Tor client because it uses the Tor onion routing protocol to reach the hidden service to protect the anonymity of users. However, the pseudo-domain became officially reserved in October 2015. i2p provides a similar hidden pseudo-domain, .i2p, and Namecoin uses the .bit pseudo-domain.
Examples
Top-level domain
<table><thead><tr><th>Example domain</th><th>Type</th><th>Sponsoring institution</th></tr></thead><tbody><tr><td>.arpa</td><td>Infrastructure</td><td>Internet Architecture Board; restricted</td></tr><tr><td>.blue</td><td>Generic</td><td>Identity Digital Limited; unrestricted</td></tr><tr><td>.ovh</td><td>Generic</td><td>OVH SAS; run by AFNIC, unrestricted</td></tr><tr><td>.name</td><td>Restricted generic</td><td>VeriSign Information Services, Inc.; unrestricted</td></tr><tr><td>.ac</td><td>Country-code</td><td>Internet Computer Bureau; unrestricted</td></tr><tr><td>.zw</td><td>Country-code</td><td>Postal and Telecommunications Regulatory Authority of Zimbabwe; run by TelOne Zimbabwe; unrestricted</td></tr><tr><td>.aero</td><td>Sponsored</td><td>Société Internationale de Télécommunications Aéronautiques; unrestricted</td></tr><tr><td>.ไทย</td><td>Internationalized country-code</td><td>THNIC</td></tr></tbody></table>