6 ms·
I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real. It's a strange edgecase that the owner of John.
by dpoloncsak 13d ago
I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real.
It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com
In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com
edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule
- dbt00 13d agoThat is definitely not true. There are literally thousands if not tens of thousands of well known domains that do this. .co.uk is a very common example.
- desas 13d agoI think the problem is that .co.uk, .gov.uk and so on are very well known in the UK. The .name subdomain rules are not very well known anywhere.
- necovek 13d agoHow familiar are you with Serbian co.rs, org.rs, in.rs (individuals) and top-level .rs too? Will you confuse it with iz.rs giving free subdomains to individuals too ("iz" means from in Serbian)? How about all the other 200+ country TLDs and rules for non-country TLDs?
- davkan 13d agoI can’t think of any prominent ones outside of country code domains.
- bombcar 13d agoYou can almost guess someone's age from that alone - they're more rare, but long domain names still appear that encode a city and a state, and you could just "grab" the first part when signing up.
- davkan 13d agoOutside of the context of ccTLDs and city.state.gov etc, I struggle to think of examples 3LD+ domains where they are owned and operated by completely different concerns than the parent. If at some point you could just register your own mysite.state.gov domains willy nilly that's probably before my initial time online around 2000. Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.
- saimiam 13d agoAll Indian banks use bankname.bank.in as their domain. I’m not sure who owns bank.in but this is a common suffix which is different from the .co.uk pattern.
- marysol5 12d agoIDRBT Institute for Development and Research in Banking Technology
- bombcar 13d agoMany services today support vanity domains - Google even has special support for it: https://publicsuffix.org/list/public_suffix_list.dat https://publicsuffix.org/list/public_suffix_list.dat
- notpushkin 12d agoTangential, but why call out Google specifically? PSL is widely used: https://publicsuffix.org/learn/ https://publicsuffix.org/learn/
- ketzu 13d agoGithub Pages is probably the most well known one (on here). I think geocities had this as well? A lot of hosting services offer this in general. (eg render) Tumblr? (Might not count as the control over the page is more limited. The subdomains "are" still tumblr.) For reddits subdomains are redirects to subreddits of the same name, so I guess that doesn't count.
- davkan 13d agoNone of these examples are of actual separate registration/ownership of a 3LD from the parent 2LD. Cloudflare owns the domain for myproject.pages.dev and hosts all the relevant infra. Not to say that there isn't a different entity represented by the 3LD than the 2LD but it's not exactly the same. Also I would not consider the examples of tumblr and reddit to be relevant. A person's blog on myprofile.tumblr.org is still the tumblr organization. This would be true for reddit even if they didn't redirect. Reddit admins moderate content on all subreddits.
- megagpt1 13d agoYou can buy example.it.com on many registrars. Someone bought it.com and operates it like a TLD.
- davkan 13d agoInteresting. I do wonder how many people outside scammers and squatters buy them. I'd rather have an .xyz or .biz address personally.
- dotancohen 12d agoWhen someone defames at SEO-optimized large-company.it.com, then Large Company gets interested. Or, more succinctly, when money gets involved.
- ketzu 13d agoI see, that's a valid way to think of domain ownership. When I read > I have been taught and tell my users to check the domain to verify a website is real. I was thinking more of control of the content as "ownership" of the domain.
- strenholme 13d agoI remember I had beach.santa-cruz.ca.us at one point registered to me. I owned beach.santa-cruz.ca.us, someone else owned santa-cruz.ca.us, yet someone else owned ca.us, and I believe Network Solutions took care of .us at the time.
- fc417fc802 13d agoYou say "registered" to you as though this was via an official registrar but surely you mean that someone rented ca.us and decided on their own to lease out subdomains to people? (Aside, I always see "owned" and "bought" but you can only ever "lease" under the ICANN system as the present situation so clearly demonstrates.)
- brirec 13d agoHistorically, xx.us (where xx is a two letter state code) domains have been owned* by the named US state, which then would issue subdomains on top. I believe this was originally planned and set up by ICANN themselves. *: I realize that “owned” is a loaded word here, but (1) I’m referring to a registrar/issuer, which makes it yet more complicated as to how much “ownership” (de facto or otherwise) a given entity may have, and (2) I really don’t give a fuck about pedantic word choice if the meaning is unambiguous.
- fc417fc802 13d agoMy aside wasn't intended to be pedantic, rather observing the apparent inconsistency in how it appears people think about these matters versus what the present situation illustrates the reality to be. > but (1) I’m referring to a registrar/issuer, which makes it yet more complicated We're also talking about a ccTLD which makes it even more complicated. AFAIK those fall entirely under the jurisdiction of the respective UN recognized government although I don't know how strong that agreement is in practice (treaty versus something else). So at that point I guess we've roughly got ICANN -> US federal government -> CA state government -> registrar -> private party -> sublet.
- 13d ago
- ndiddy 13d ago.name is still a weird edge case because of the naming rules. Whether or not all subdomains under doe.name belong to the same person depends solely on whether the first person registered "doe.name" (in which case they do) or "john.doe.name" (in which case they don't, and "doe.name" is excluded from purchase as a standalone domain).
- deleted 13d ago[deleted]
- dpoloncsak 13d agoThe fact that multiple organizations need to keep a public list of known 3LDs proves it's the edge case, does it not? "Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.
- deleted 13d ago[deleted]
- esseph 13d agoThis seems largely country dependent with some exceptions. In the US, once upon a time, elementary/middle/highschools might be attached to something like schoolname.district.state.gov. But now, even my local area school now has a .com. It seems that older hierarchy style is falling out of fashion for smaller/shorter domains across public services, schools, government agencies, etc. Now here it seems to be either a .com, .gov, .org, or a totally different and newer tld. Even .net has fallen out of fashion.
- CoffeeOnWrite 13d agoThe writing was on the wall when Pennsylvania switched their license plates from www.state.pa.us to visitpa.com
- pests 13d agoGood article on this by a fellow hner https://computer.rip/2025-11-11-dot-us.html https://computer.rip/2025-11-11-dot-us.html
- gapan 13d agoThere are still exceptions to this like .co.uk and many others.
- veltas 13d agoYet that is a problem the owner of such a domain has freely entered into by buying that domain, it's their right to keep it despite this apparent problem, if they wish.
- dpoloncsak 13d agoUnderstood, and .name isn't being used enough in business to worry about 'the effect it will have on my users'. Just pointing out that it doesn't work like the 'norm' (although I guess it's not quite as unique as I thought, either)
- veltas 10d agoThat's actually the point of the .name TLD is that it's not for businesses, it's for individuals. This whole situation demonstrates ICANN is more for businesses than individuals. It should just be there for everyone and every organisation that's trying to use URI's, shame that it's not worked out that way. This is exactly what the big tech companies want, they might as well hand ICANN over to Facebook or Google, they wouldn't do much worse.
- amiga386 13d agoHello sysadmin. Good luck navigating the internet. What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List https://en.wikipedia.org/wiki/Public_Suffix_List It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.
- strenholme 13d agoThe .name mess is not in the public suffix list. https://github.com/publicsuffix/list/issues/2306 https://github.com/publicsuffix/list/issues/2306 for more discussion.
- dpoloncsak 13d agoI appreciate this, and yeah the government/education ones slipped my mind, but I stand by the fact that the reason a list needs to be kept in the first place is because this is the edge case and not the norm.
- iminatx 12d agoSupposing it were not an edge case and were typical, how exactly would you implement the same thing without keeping a list?
- fc417fc802 13d agoThe public suffix list is a half assed bandaid over a fundamentally broken system.
- Glide 13d agoLooking at the threads below, very few people are discussing technical things in dns terms like zone or nameserver. Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with. Then when you consider DNS is fundamental infrastructure and people build secure things on top of it, (ahem DNS challenges for certs), it's remarkable that anyone would want or desire edge cases.
- strken 13d agoThis doesn't seem like a problem if you exclusively support 3LDs and don't let anyone register 2LDs.
- marysol5 12d agoProblem is, all these systems we still use were never designed to be like this. Hell DNS used to be one woman in an office who updated the zone if you e-mailed her.
- vidarh 12d agoThis wasn't really a consideration for anyone back when we applied for .name, and it already wasn't true back then (.us, and .uk were both prominent examples where it didn't hold)
- gwillen 12d agoThere is a list called the Public Suffix List, which is used for most purposes to make determinations about which 2lds do not own/manage the corresponding 3lds. It's maintained by Mozilla as a public service, which isn't exactly where you'd expect to find it. But it's mostly important for web security / "same origin" stuff, so it makes sense. In addition to all the country codes TLDs that do 3rd-level registration, the PSL does also include stuff like github.io. (Maintenance of the list involves manual volunteer labor, so scaling is a real problem...) (And of course the PSL wouldn't work well for the .name situation, where it's sometimes 2 and sometimes 3, and it can change over time. But that's no excuse for this clusterfuck of just suddenly dropping a bunch of domains that are paid up years in advance.)
- marysol5 12d agoPeople still fall for paypal.com.4385ht43987th34098rh34279h3.legitorg.ru
- xp84 8d ago>It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com I think you meant to say "the owner of John.Doe.name does not need to own Doe.name" since .com just works under the 'normal' rules you're used to. But it's worth pointing out that under the current system (that Verisign is destroying), no registrant owns (e.g.) fraser.name just as no one (but the registry itself) owns co.uk. So, if someone checks who owns fraser.name they wouldn't have found a scenario, for instance, that fraser.name belongs to, say, Simon Fraser University, with admissions.fraser.name belonging to some phishing site. > I have been taught and tell my users to check the domain to verify a website is real. Anyway, having seen enough eyes glaze over at the most basic tutorials of this sort, I'm afraid you're wasting your time. Given that this edge case is on nobody's radar, I don't think it's what's preventing 80% of Internet users from being able to get a passing score on a basic quiz on the hierarchial DNS. As evidenced by all the government entities that gave up and registered literal ".coms"