Neil Fraser registered neil.fraser.name nearly twenty-five years ago. It predates YouTube. It carries his website, his email, and the API endpoints his IoT devices phone home to, and it is paid up through 2040. In February it stops resolving. Not lapsed, not lost in a dispute. On April 15 Verisign asked ICANN to delete the entire third level of the .name hierarchy to simplify its own administration, ICANN approved it on July 28, and Fraser found out from his registrar last week.
The story is not 22,000 orphaned domains under a TLD most people forgot existed. The story is that the one identifier most of us have keyed our digital lives to was always a lease, the landlord can amend the lease unilaterally, and the body whose job is to say no said yes.
.name was not a reseller trick like the *.uk.co outfits that buy a Colombian second-level and sublet it. It was chartered as a third-level registry from day one: you registered first.last.name through any registrar, with a full WHOIS record, on the same footing as co.uk. Fraser picked it in part because Global Name Registry ran it and Verisign did not. Verisign bought Global Name Registry a few years later. That is the whole arc of the piece in one sentence, and it is why the proposal reads less like housekeeping than like a landlord who inherited tenants he never wanted.
The damage is not the website. It is the chain behind it. The domain is the email address. The email address is the recovery address. The recovery address is the account, for every service opened against it since 2002. And once the third level is gone, the vacant second level, fraser.name, is presumed to return to the pool.
Should someone (other than me) scoop up fraser.name they would be able to recreate and control neil.fraser.name. They'd be able to hijack hundreds of accounts that are linked to that address. They could commit code with my authentication. They could seize control of IoT devices. There is no way to enumerate all accounts (online and offline) which have been opened using this email address over the past quarter century.Neil Fraser
Read that as a security engineer, not as a sympathetic reader. Every password-reset flow on the internet assumes that whoever controls a mailbox today is the person who opened the account. A registry deleting a namespace and releasing its parent converts that assumption into an attack surface for 22,000 people at once, with a scheduled date, published in a PDF.
What ICANN approved is a principle, not a cleanup.
Verisign's defense is not stupid. The third level of .name was a small, aging product; 22,000 registrants is a rounding error next to .com; registries retire products; registrars were notified. All true. But none of it touches the precedent. The registrar-registry-ICANN stack exists so that a paid registration is a commitment the registry cannot walk away from for convenience. ICANN's letter says it can. Every 2040 expiry date in every WHOIS record now carries an unwritten clause: unless the registry would rather not.
The practical read is short. Keep your root-of-trust email on a second-level domain under a TLD with decades of boring behind it, not on a product a registry can decide to discontinue. Keep an inventory of what recovers to that address, because the day you need the list is the day nobody can produce it. And hold the fact steady that even .com is a lease. Fraser's is the cleanest demonstration we are likely to get.
The registration runs to 2040. The registry runs to February. Only one of those numbers was ever real.