New gTLD Application for .lan

mzajc 116 points 140 comments October 08, 2026
newgtldprogram-aps.icann.org · View on Hacker News

Discussion Highlights (19 comments)

mzajc

Posting because OpenWRT, possibly others as well, assign .lan names to devices on the LAN by default. People who make use of this might want to follow the application, and, if it goes through, either change the name or make sure queries can't get incorrectly get sent to upstream resolvers. Regarding that last point, I've had issues with dnsmasq in the past where it was remotely resolving domains even when they were configured to resolve locally. For .lan domains, this could be disastrous because I often send plaintext traffic to them. I did submit a fix/workaround[0], but it's still something to look out for. If anyone knows more about this issue or other ways queries could leak, please share! [0]: https://github.com/openwrt/openwrt/pull/18610

vekntksijdhric

This is a security issue for many devices. What could possibly go wrong overriding a tld used for internal networking....

sybercecurity

Full collection of proposed new gTLDs: https://newgtldprogram-aps.icann.org/statistics Also see a .bldg application, which also might conflict with some legacy naming schemes.

alwa

This seems like a good time to educate myself about the application (and objection) process. The bureaucracy seems precision-engineered to stultify, but apparently the public have 104 days after “String Confirmation Day” (17th Nov; capitalization theirs) to lodge objections, assuming the “GAC” doesn’t beat them to it… https://newgtldprogram.icann.org/en/application-rounds/round... …of course there’s a “filing fee,” priced in “hours of a panel of lawyers’ time,” to lodge such an objection… https://newgtldprogram-2026-agb.icann.org/en/8-module-4-comm... …welp, hope somebody more organized (and better-funded) than I can organize an objection. Much as I feel like I’m giving up my right to gripe by assuming somebody else will come along to do the weeding.

unleaded

..Why? Just to annoy people?

p1mrx

When ICANN reserved .internal a couple years ago, I was saying they should just flip and truncate it to .lan(retni) so everyone's happy.

Faelian2

It's a shame that ICANN did get so greedy and put everyone at risk. Having internal domain names owned by some guy on the internet has already compromised multiple corporate networks. See the talk from this guy: https://www.romhack.io/wp-content/uploads/2025/10/Internal-D...

procone

gTLDs were a mistake. I say that as an owner of several domains with gTLDs. There's almost no value. Large businesses almost never use them. The potential for scams / phish / etc are now limitless.

deno

Why would you even want something like “lan” as a global TLD? Does it mean something else than the obvious? Fortunately there’s no need to speculate as the application explains this clearly: AGB Q118: What is the meaning/definition of the applied-for gTLD string? Answer: Lan commonly refers to a broadly recognized term used across a wide range of contexts.

Group_B

so so dumb. Pure greed. This is going to cause so many issues

dijit

I'm still seething about `.dev`. For those not in the know, Google lobbied ICANN to get the name and in their application they stated (repeatedly) that the intent was to buy it so that it could be reserved; as .dev was already used by developers and if someone bought it for commercial purposes it would harm the developer community.[0] .... they then proceeded to start selling them. Leading to all kinds of issues, the exact issues that they raised... https://github.com/basecamp/pow/issues/397 https://github.com/laravel/valet/issues/433 https://danielbachhuber.com/switch-laravel-valet-from-dev-to... https://community.localwp.com/t/dev-domain-doesnt-work/4277 https://forums.theregister.com/forum/all/2017/11/29/google_d... [0]: https://gtldresult.icann.org/applicationstatus/applicationde...

bombcar

Can I get a group of Ians and register .Ian?

0x0

I've been using a single letter "fake" tld for my internal LAN DNS zone. Looks like ICANN requires 3+ letters in tld applications, so hopefully should be safe for quite a while.

ChrisArchitect

Related: ICANN Reveals 2026 Round Applications for New Generic Top-Level Domains https://news.ycombinator.com/item?id=49997301

saghm

Debian should apply for this so they can take advantage of case insensitivity and sans-serif fonts so to let people go to DEB.lAN to view their website

moecables

I'm out of the loop on this, can someone explain who this is and why this is bad?

gertrunde

21 separate applications for some variation on .agent/.agentic I'm guessing that'll end up being expensive for someone...

ectospheno

The .lan domain has been on an rpz blocklist along with several other commonly used names in my networks for quite some time. I have no plans for that domain to ever successfully resolve regardless of whether or not it goes live.

yegle

> RFC 8375 defines the intranet domain as .home.arpa, but ICANN in 2024 says it should use .internal instead. Is ICANN not choosing .lan or .home because these two domains might still fetch a good price? My tweet on Sep 26, 2026

Semantic search powered by Rivestack pgvector
8,906 stories · 83,542 chunks indexed