4 ms·
I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real. It's a strange edgecase that the owner of John.
by dpoloncsak 29d ago
I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real.
It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com
In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com
edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule
- marysol5 28d agoPeople still fall for paypal.com.4385ht43987th34098rh34279h3.legitorg.ru
- dbt00 29d agoThat is definitely not true. There are literally thousands if not tens of thousands of well known domains that do this. .co.uk is a very common example.
- desas 29d agoI think the problem is that .co.uk, .gov.uk and so on are very well known in the UK. The .name subdomain rules are not very well known anywhere.
- necovek 29d agoHow familiar are you with Serbian co.rs, org.rs, in.rs (individuals) and top-level .rs too? Will you confuse it with iz.rs giving free subdomains to individuals too ("iz" means from in Serbian)? How about all the other 200+ country TLDs and rules for non-country TLDs?
- davkan 29d agoI can’t think of any prominent ones outside of country code domains.
- bombcar 29d agoYou can almost guess someone's age from that alone - they're more rare, but long domain names still appear that encode a city and a state, and you could just "grab" the first part when signing up.
- davkan 29d agoOutside of the context of ccTLDs and city.state.gov etc, I struggle to think of examples 3LD+ domains where they are owned and operated by completely different concerns than the parent. If at some point you could just register your own mysite.state.gov domains willy nilly that's probably before my initial time online around 2000. Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.
- saimiam 29d agoAll Indian banks use bankname.bank.in as their domain. I’m not sure who owns bank.in but this is a common suffix which is different from the .co.uk pattern.
- marysol5 28d agoIDRBT Institute for Development and Research in Banking Technology
- bombcar 29d agoMany services today support vanity domains - Google even has special support for it: https://publicsuffix.org/list/public_suffix_list.dat https://publicsuffix.org/list/public_suffix_list.dat
- notpushkin 28d agoTangential, but why call out Google specifically? PSL is widely used: https://publicsuffix.org/learn/ https://publicsuffix.org/learn/
- ndiddy 29d ago.name is still a weird edge case because of the naming rules. Whether or not all subdomains under doe.name belong to the same person depends solely on whether the first person registered "doe.name" (in which case they do) or "john.doe.name" (in which case they don't, and "doe.name" is excluded from purchase as a standalone domain).
- deleted 29d ago[deleted]
- dpoloncsak 29d agoThe fact that multiple organizations need to keep a public list of known 3LDs proves it's the edge case, does it not? "Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.
- deleted 29d ago[deleted]
- esseph 29d agoThis seems largely country dependent with some exceptions. In the US, once upon a time, elementary/middle/highschools might be attached to something like schoolname.district.state.gov. But now, even my local area school now has a .com. It seems that older hierarchy style is falling out of fashion for smaller/shorter domains across public services, schools, government agencies, etc. Now here it seems to be either a .com, .gov, .org, or a totally different and newer tld. Even .net has fallen out of fashion.
- CoffeeOnWrite 29d agoThe writing was on the wall when Pennsylvania switched their license plates from www.state.pa.us to visitpa.com
- pests 29d agoGood article on this by a fellow hner https://computer.rip/2025-11-11-dot-us.html https://computer.rip/2025-11-11-dot-us.html
- gapan 29d agoThere are still exceptions to this like .co.uk and many others.
- veltas 29d agoYet that is a problem the owner of such a domain has freely entered into by buying that domain, it's their right to keep it despite this apparent problem, if they wish.
- dpoloncsak 29d agoUnderstood, and .name isn't being used enough in business to worry about 'the effect it will have on my users'. Just pointing out that it doesn't work like the 'norm' (although I guess it's not quite as unique as I thought, either)
- veltas 26d agoThat's actually the point of the .name TLD is that it's not for businesses, it's for individuals. This whole situation demonstrates ICANN is more for businesses than individuals. It should just be there for everyone and every organisation that's trying to use URI's, shame that it's not worked out that way. This is exactly what the big tech companies want, they might as well hand ICANN over to Facebook or Google, they wouldn't do much worse.
- amiga386 29d agoHello sysadmin. Good luck navigating the internet. What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List https://en.wikipedia.org/wiki/Public_Suffix_List It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.
- dpoloncsak 29d agoI appreciate this, and yeah the government/education ones slipped my mind, but I stand by the fact that the reason a list needs to be kept in the first place is because this is the edge case and not the norm.
- iminatx 28d agoSupposing it were not an edge case and were typical, how exactly would you implement the same thing without keeping a list?
- strenholme 29d agoThe .name mess is not in the public suffix list. https://github.com/publicsuffix/list/issues/2306 https://github.com/publicsuffix/list/issues/2306 for more discussion.
- fc417fc802 29d agoThe public suffix list is a half assed bandaid over a fundamentally broken system.
- Glide 29d agoLooking at the threads below, very few people are discussing technical things in dns terms like zone or nameserver. Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with. Then when you consider DNS is fundamental infrastructure and people build secure things on top of it, (ahem DNS challenges for certs), it's remarkable that anyone would want or desire edge cases.
- strken 29d agoThis doesn't seem like a problem if you exclusively support 3LDs and don't let anyone register 2LDs.
- marysol5 28d agoProblem is, all these systems we still use were never designed to be like this. Hell DNS used to be one woman in an office who updated the zone if you e-mailed her.
- vidarh 28d agoThis wasn't really a consideration for anyone back when we applied for .name, and it already wasn't true back then (.us, and .uk were both prominent examples where it didn't hold)
- gwillen 28d agoThere is a list called the Public Suffix List, which is used for most purposes to make determinations about which 2lds do not own/manage the corresponding 3lds. It's maintained by Mozilla as a public service, which isn't exactly where you'd expect to find it. But it's mostly important for web security / "same origin" stuff, so it makes sense. In addition to all the country codes TLDs that do 3rd-level registration, the PSL does also include stuff like github.io. (Maintenance of the list involves manual volunteer labor, so scaling is a real problem...) (And of course the PSL wouldn't work well for the .name situation, where it's sometimes 2 and sometimes 3, and it can change over time. But that's no excuse for this clusterfuck of just suddenly dropping a bunch of domains that are paid up years in advance.)
- xp84 24d ago>It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com I think you meant to say "the owner of John.Doe.name does not need to own Doe.name" since .com just works under the 'normal' rules you're used to. But it's worth pointing out that under the current system (that Verisign is destroying), no registrant owns (e.g.) fraser.name just as no one (but the registry itself) owns co.uk. So, if someone checks who owns fraser.name they wouldn't have found a scenario, for instance, that fraser.name belongs to, say, Simon Fraser University, with admissions.fraser.name belonging to some phishing site. > I have been taught and tell my users to check the domain to verify a website is real. Anyway, having seen enough eyes glaze over at the most basic tutorials of this sort, I'm afraid you're wasting your time. Given that this edge case is on nobody's radar, I don't think it's what's preventing 80% of Internet users from being able to get a passing score on a basic quiz on the hierarchial DNS. As evidenced by all the government entities that gave up and registered literal ".coms"