Posting because OpenWRT, possibly others as well, assign .lan names to devices on the LAN by default. People who make use of this might want to follow the application, and, if it goes through, either change the name or make sure queries can't get incorrectly get sent to upstream resolvers.
Regarding that last point, I've had issues with dnsmasq in the past where it was remotely resolving domains even when they were configured to resolve locally. For .lan domains, this could be disastrous because I often send plaintext traffic to them. I did submit a fix/workaround[0], but it's still something to look out for. If anyone knows more about this issue or other ways queries could leak, please share!
If you actually think it's a trivial affair to change a well-established default with more than 20 years of history that is, on top of all other difficulties that such a change typically encompasses, used to identify and name things, I hereby beg you to never design or provide any kind of infrastructure.
RFCs were originally formalization of what was being used in practice, home.arpa was chosen apparently for reasons of beauracratic convenience rather than what would best serve existing users, who all would prefer .lan and continue to do so since that was published in 2018
> RFCs were originally formalization of what was being used in practice
You may be confusing it with the IETF’s policy.
In early days of the RFCs, most started out as proposals, often but not always with some existing implementation as a jumping-off point to conversation (hence the name). I no longer remember why they started to be numbered and tracked, as the process naturally preceded that.
You can verify what I say by just reading some old ones at the rfc editor site.
But why is it that nowadays, it's enough for a vulture corporation to have enough money to be able to privatize a part of the "web" that is in common usage (in the sense of common good) since so long?
It should be logical even without thinking that the request have to be rejected.
This reminds me of when I used to do IT work for small businesses in college. One printing company I worked for, had about 100 computers on their network, and was using public ipv4 addresses, that they did not own, on their internal network. I forget what range they were using now. But imagine seeing a DHCP server handing out addresses like 142.250.110.1/16 on a LAN and the public ip being something totally different.
It was funny, because when I brought it up to them, it was hard to articulate why it was a problem and I couldn't convince them it was worth the effort of trying to fix. They never ran into a specific issue due to this while I was there but it felt so gross.
When I was working with Linux based kiosks and PoS systems I had a good share of issues with the Microsoft MVP signature use of .local on their forests. Back then their training material recommended .local for Active Directory services.
There's a good reason to do this if you can't be certain what reserved subnets are used in a given network and you absolutely need a static ip for some reason.
At least that's the conclusion I've arrived at at some point, but I don't remember what was the exact use case anymore.
However there are still several global IPv4 ranges that are not local reserved ranges but are effectively reserved and you could use them if you really want to without any issues.
The problem is that they wouldn't be able to talk to any internet service that legitimately used those addresses. Whether that was likely to be a problem very much depends on whose addresses they were.
It's always hard because when you contrive possible examples of how it goes wrong, every single example sounds contrived because of course they are contrived.
Sure one day your printer might start spewing random json code meant for some microservice of the rightful IP owner.
Sure the IP's might be owned by the Air Force and one day they might start getting traffic from your pos ipad that they decide looks like an attempt to attack one of their internal secret networks...
Sure one day traffic meant to go to your printer ends up flooding and dossing a windmill controller, preventing the rightful operators from turning it the right direction during bad weather and causing $25M damage...
And of course the real failures are more like, only people from the Maldives can't send email to your email server, a failure with no impact.
It looks like as part of the process, they delegate the prefix in global DNS and see how much traffic it currently gets; if it gets too much it will be classified as "high-risk" which at least makes things harder. Which is to say, we want as much leakage as possible to hopefully make ICANN think twice about approving this.
Beside the fact that was standard or not it made sense to use .lan domain for local devices, and a lot of router sold were configured with that domain for resolving local network hosts.
To me is a very bad idea to implement this proposal, it should instead be standardized and reserved for internal usage as a fix. There were even RFC like https://www.rfc-editor.org/info/rfc6762/#appendix-G that suggested their usage for local devices in a network.
What is the point of selling the .lan domain, except for making money at the expense of a security risk for millions of networks that already use that domain for internal hosts?
BTW to me there was never any sense to add new TLD domain despite country code. They decided to render internet less secure, by giving scammers infinite TLD to register they scam domain like "apple.lan", with the sole purpose of making for them easy money.
While you're not wrong, I suspect that .lan sees more real world usage than .local
It may not be an official standard, but it does have some weight as a de-facto standard.
I've tried briefly to try and find some numbers to back that up, but can't find much beyond apple's bonjour vs consumer routers - although I've seen companies with AD domains using .lan as well. (Although, I've also seen companies using 1.0.0.0/8 for their internal addressing...)
it definitely gets used, and i hope that the application is denied, but i also hope this is another wake up call for people that pick unreserved domains.
You can buy a cheap domain to make sure no one else uses it and just roll it on your lan. Throw some DNS ACME challenges and you have valid certificates too.
I just bought mysefl a '.casa' domain, got wildcard cert for it from lets encrypt and haven't bothered with any of these. Downside, if internet goes down resolver stops, but thats why I have local NS mirror and all DNS queries go through my resolver.
This being on the front page at the same time as the coffee machine sending 1TB of data, and the icann application being submitted by Coffee Danger LLC is just beautiful
This seems like a good time to educate myself about the application (and objection) process.
The bureaucracy seems precision-engineered to stultify, but apparently the public have 104 days after “String Confirmation Day” (17th Nov; capitalization theirs) to lodge objections, assuming the “GAC” doesn’t beat them to it…
…welp, hope somebody more organized (and better-funded) than I can organize an objection. Much as I feel like I’m giving up my right to gripe by assuming somebody else will come along to do the weeding.
There's a short list of grounds they will consider for an objection, and none of them are applicable here. Paraphrasing your second link, they only allow:
- "String Confusion" -- looks or sounds like an existing (approved or being applied for) gTLD. Must be filed by whoever owns (or is applying for) that gTLD.
- "Legal Rights" -- someone else owns a trademark this would violate. Must be filed by whoever's legal rights would be violated.
- "Limited Public Interest" -- the gTLD is immoral under recognized principles of international law. I have no idea when this could be applicable.
- "Community" -- An established community organization believes the group this gTLD is intended to target will object to it. This seems more like a vehicle for e.g. Little People of America to let ICANN know that ".midget" would be offensive.
Unfortunately there doesn't seem to be a way to tell ICANN that .lan has been widely used and will break things in a way they will listen to.
The applicant appears to be an agglomeration of LLCs and legal diversions to hide responsible parties. It does lead me to assumptions about their motivations, whomever they may be.
Source: the application refers to multiple layers of LLC ownership, and the responsible parties listed are general counsels at some IP financialization company, "Identity Digital"
Pihole here will still serve .lan internal domains. Anyone that registers .lan globally are the ones guilty of using a culturally busy domain that was unreserved before.
In time we'll see articles like "Don't register a .lan domain if you want people to visit your site"
Eh, maybe someone spinning up a brand new environment using it in 2026 should have known better. But you don't have to go that far back to reach a point where the current list of gTLDs would make .lan feel safe.
Then why hasn't there been a gTLD reserved for local use? The only ones that are reserved are .local and .home.arpa. .local is out, since it is entirely for use with mDNS / Bonjour.
That leaves .home.arpa, which is very awkward and only a thing since 2018 (my home network's use of .lan definitely predates this). Especially as a non US citizen. It also seemed so far that .lan was the "unofficial" gTLD to be used, since much software like OpenWRT was already using it anyway.
Either way: making .lan internet routable seems entirely unhinged to me. LAN has always been the acronym for Local Area Network. Why would anyone sane think that it is a good idea to make this into a gTLD that can be internet routable? The only way I see forward to do this justice, is to only allow RFC 1918 and IPv6 addresses that are within the assigned prefix for your router.
This seems like a worse version of allowing .zip to be a gTLD. Remember the idea of downloading something from https://github.com/[...]@evil.zip?
(note: i hope .lan does not get approved, but people have to understand that they are rolling dice when using unreserved names)
edit: fucking wild that this is downvoted into negatives. press the wiki link and read the first line if you don't believe me. in fact, i will quote it: "The name internal is reserved by ICANN "
> Then why hasn't there been a gTLD reserved for local use?
.qm to .qz and .xa to .xz have always been implicitly reserved as TLDs that will never be globally-routable [0] [1], but these aren't exactly the most intuitive names so it's unsurprising that nobody uses them.
(".internal" as mentioned by the sibling comment [2] is the best choice these days, but its definition is somewhat recent.)
As former AD person and dealing with that several companies, the recommendation for internal network DNS has long been subdomain.company.com that is not on public internet.
Even today when setting up greenfield networks, I generally use internal.company.com. It also lets you get public trusted SSL certificates so you don't have to deal with internal PKI.
while .local is reserved, it's reserved for mDNS, and should be avoided on things like active directory. using an internal subdomain of a registered public domain is best practice. .internal is also okay.
Why would you even want something like “lan” as a global TLD? Does it mean something else than the obvious?
Fortunately there’s no need to speculate as the application explains this clearly:
AGB Q118: What is the meaning/definition of the applied-for gTLD string?
Answer: Lan commonly refers to a broadly recognized term used across a wide range of contexts.
Man, my whole life I’ve identified with, related to, and wished to finally just be associated with “the concept represented by the applied-for string”!
For those not in the know, Google lobbied ICANN to get the name and in their application they stated (repeatedly) that the intent was to buy it so that it could be reserved; as .dev was already used by developers and if someone bought it for commercial purposes it would harm the developer community.[0]
.... they then proceeded to start selling them.
Leading to all kinds of issues, the exact issues that they raised...
I've been using a single letter "fake" tld for my internal LAN DNS zone. Looks like ICANN requires 3+ letters in tld applications, so hopefully should be safe for quite a while.
Debian should apply for this so they can take advantage of case insensitivity and sans-serif fonts so to let people go to DEB.lAN to view their website
.lan is widely used (by OpenWRT and Ubiquity and likely others) by home / SMB routers, where all connected devices will automatically be assigned hostname.lan. Technically, .home.arpa and/or .internal are designated for this, but .home.arpa is pretty clunky and they're very new (.home.arpa is from 2018 and .internal from 2024). Usage of .lan for this predates either.
The .lan domain has been on an rpz blocklist along with several other commonly used names in my networks for quite some time. I have no plans for that domain to ever successfully resolve regardless of whether or not it goes live.
> RFC 8375 defines the intranet domain as .home.arpa, but ICANN in 2024 says it should use .internal instead. Is ICANN not choosing .lan or .home because these two domains might still fetch a good price?
Every year around $4B is spent on websites. Where is the money going, who's getting rich?
It's monopolies like Verisign (of the .com tld) that have luxurious profits. No competition, plus they are allowed to raise their prices above inflation while their infrastructure costs go down every year.
This being on the front page at the same time as the coffee machine sending 1TB of data, and the icann application being submitted by Coffee Danger LLC is just beautiful
[OP] mzajc | 6 hours ago
Regarding that last point, I've had issues with dnsmasq in the past where it was remotely resolving domains even when they were configured to resolve locally. For .lan domains, this could be disastrous because I often send plaintext traffic to them. I did submit a fix/workaround[0], but it's still something to look out for. If anyone knows more about this issue or other ways queries could leak, please share!
[0]: https://github.com/openwrt/openwrt/pull/18610
gclawes | 6 hours ago
https://www.rfc-editor.org/info/rfc8375/
c0l0 | 6 hours ago
I hope the gTLD application gets struck down.
pwdisswordfishq | 6 hours ago
c0l0 | 6 hours ago
free_bip | 5 hours ago
jamesnorden | 3 hours ago
stop50 | 6 hours ago
throw0101a | 5 hours ago
* https://en.wikipedia.org/wiki/.internal
Other special use domains:
* https://en.wikipedia.org/wiki/Special-use_domain_name
* https://en.wikipedia.org/wiki/Top-level_domain#Reserved_doma...
* https://datatracker.ietf.org/doc/html/rfc6761
pqb | 6 hours ago
[0]: https://amplifi.com/
deno | 6 hours ago
bandie91 | 22 minutes ago
esskay | 6 hours ago
lokoj | 2 hours ago
penskymaterial | 41 minutes ago
Palomides | 5 hours ago
gumby | 4 hours ago
You may be confusing it with the IETF’s policy.
In early days of the RFCs, most started out as proposals, often but not always with some existing implementation as a jumping-off point to conversation (hence the name). I no longer remember why they started to be numbered and tracked, as the process naturally preceded that.
You can verify what I say by just reading some old ones at the rfc editor site.
fridder | an hour ago
greatgib | 13 minutes ago
It should be logical even without thinking that the request have to be rejected.
brookst | 10 minutes ago
montecarl | 6 hours ago
It was funny, because when I brought it up to them, it was hard to articulate why it was a problem and I couldn't convince them it was worth the effort of trying to fix. They never ran into a specific issue due to this while I was there but it felt so gross.
irusensei | 6 hours ago
penskymaterial | 42 minutes ago
deno | 6 hours ago
At least that's the conclusion I've arrived at at some point, but I don't remember what was the exact use case anymore.
However there are still several global IPv4 ranges that are not local reserved ranges but are effectively reserved and you could use them if you really want to without any issues.
masfuerte | 6 hours ago
Brian_K_White | 5 hours ago
Sure one day your printer might start spewing random json code meant for some microservice of the rightful IP owner.
Sure the IP's might be owned by the Air Force and one day they might start getting traffic from your pos ipad that they decide looks like an attempt to attack one of their internal secret networks...
Sure one day traffic meant to go to your printer ends up flooding and dossing a windmill controller, preventing the rightful operators from turning it the right direction during bad weather and causing $25M damage...
And of course the real failures are more like, only people from the Maldives can't send email to your email server, a failure with no impact.
antonkochubey | an hour ago
boredatoms | 5 hours ago
gavinsyancey | 57 minutes ago
https://icannwiki.org/Name_Collision_Risk_Management_Framewo...
vekntksijdhric | 6 hours ago
seanw444 | 6 hours ago
jstarks | 6 hours ago
alerighi | 6 hours ago
To me is a very bad idea to implement this proposal, it should instead be standardized and reserved for internal usage as a fix. There were even RFC like https://www.rfc-editor.org/info/rfc6762/#appendix-G that suggested their usage for local devices in a network.
What is the point of selling the .lan domain, except for making money at the expense of a security risk for millions of networks that already use that domain for internal hosts?
BTW to me there was never any sense to add new TLD domain despite country code. They decided to render internet less secure, by giving scammers infinite TLD to register they scam domain like "apple.lan", with the sole purpose of making for them easy money.
denkmoon | 18 minutes ago
davidcollantes | 6 hours ago
john_strinlai | 6 hours ago
it is not, as .local is designated as a special-use domain name and .lan is not.
gertrunde | 5 hours ago
It may not be an official standard, but it does have some weight as a de-facto standard.
I've tried briefly to try and find some numbers to back that up, but can't find much beyond apple's bonjour vs consumer routers - although I've seen companies with AD domains using .lan as well. (Although, I've also seen companies using 1.0.0.0/8 for their internal addressing...)
john_strinlai | 5 hours ago
jeroenhd | 6 hours ago
irusensei | 6 hours ago
procone | 6 hours ago
.home.arpa is so clunky. Why do I have to put the acronym of a US military project in my domain to access resources on my own local network?
Yes, I know that organization was central to the development of the l Internet, but it's not relevant as a domain 40 years later.
john_strinlai | 6 hours ago
irusensei | 6 hours ago
procone | 5 hours ago
This is not how anything should work.
john_strinlai | 2 hours ago
0x457 | 5 hours ago
dwedge | an hour ago
sybercecurity | 6 hours ago
Also see a .bldg application, which also might conflict with some legacy naming schemes.
alwa | 6 hours ago
The bureaucracy seems precision-engineered to stultify, but apparently the public have 104 days after “String Confirmation Day” (17th Nov; capitalization theirs) to lodge objections, assuming the “GAC” doesn’t beat them to it…
https://newgtldprogram.icann.org/en/application-rounds/round...
…of course there’s a “filing fee,” priced in “hours of a panel of lawyers’ time,” to lodge such an objection…
https://newgtldprogram-2026-agb.icann.org/en/8-module-4-comm...
…welp, hope somebody more organized (and better-funded) than I can organize an objection. Much as I feel like I’m giving up my right to gripe by assuming somebody else will come along to do the weeding.
ZeroWidthJoiner | 5 hours ago
This may very well end up to be determined too risky to be delegated, like .corp, .home and .mail in 2018.
gavinsyancey | an hour ago
- "String Confusion" -- looks or sounds like an existing (approved or being applied for) gTLD. Must be filed by whoever owns (or is applying for) that gTLD.
- "Legal Rights" -- someone else owns a trademark this would violate. Must be filed by whoever's legal rights would be violated.
- "Limited Public Interest" -- the gTLD is immoral under recognized principles of international law. I have no idea when this could be applicable.
- "Community" -- An established community organization believes the group this gTLD is intended to target will object to it. This seems more like a vehicle for e.g. Little People of America to let ICANN know that ".midget" would be offensive.
Unfortunately there doesn't seem to be a way to tell ICANN that .lan has been widely used and will break things in a way they will listen to.
unleaded | 6 hours ago
vetrom | 6 hours ago
Source: the application refers to multiple layers of LLC ownership, and the responsible parties listed are general counsels at some IP financialization company, "Identity Digital"
hdgvhicv | 6 hours ago
p1mrx | 6 hours ago
Faelian2 | 6 hours ago
Having internal domain names owned by some guy on the internet has already compromised multiple corporate networks. See the talk from this guy:
https://www.romhack.io/wp-content/uploads/2025/10/Internal-D...
john_strinlai | 6 hours ago
at the very least, the .dev stuff should have had people second-guessing their usage of unreserved domains.
gchamonlive | 6 hours ago
In time we'll see articles like "Don't register a .lan domain if you want people to visit your site"
delecti | 6 hours ago
john_strinlai | 6 hours ago
throughout most of my career, there was no unreserved domain that felt safe. but especially after .dev.
kokx | an hour ago
That leaves .home.arpa, which is very awkward and only a thing since 2018 (my home network's use of .lan definitely predates this). Especially as a non US citizen. It also seemed so far that .lan was the "unofficial" gTLD to be used, since much software like OpenWRT was already using it anyway.
Either way: making .lan internet routable seems entirely unhinged to me. LAN has always been the acronym for Local Area Network. Why would anyone sane think that it is a good idea to make this into a gTLD that can be internet routable? The only way I see forward to do this justice, is to only allow RFC 1918 and IPv6 addresses that are within the assigned prefix for your router.
This seems like a worse version of allowing .zip to be a gTLD. Remember the idea of downloading something from https://github.com/[...]@evil.zip?
john_strinlai | an hour ago
there is. it's .internal.
https://en.wikipedia.org/wiki/.internal
(note: i hope .lan does not get approved, but people have to understand that they are rolling dice when using unreserved names)
edit: fucking wild that this is downvoted into negatives. press the wiki link and read the first line if you don't believe me. in fact, i will quote it: "The name internal is reserved by ICANN "
kokx | an hour ago
That explains why I hadn't heard of this yet. My current incarnation of my internal network dates from ~april 2024.
gucci-on-fleek | an hour ago
.qm to .qz and .xa to .xz have always been implicitly reserved as TLDs that will never be globally-routable [0] [1], but these aren't exactly the most intuitive names so it's unsurprising that nobody uses them.
(".internal" as mentioned by the sibling comment [2] is the best choice these days, but its definition is somewhat recent.)
[0]: https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2#User-assign...
[1]: https://en.wikipedia.org/wiki/Country_code_top-level_domain#...
[2]: https://news.ycombinator.com/item?id=50012163
steventhedev | 36 minutes ago
stackskipton | 6 hours ago
Even today when setting up greenfield networks, I generally use internal.company.com. It also lets you get public trusted SSL certificates so you don't have to deal with internal PKI.
Faelian2 | 5 hours ago
john_strinlai | 5 hours ago
procone | 6 hours ago
There's almost no value.
Large businesses almost never use them. The potential for scams / phish / etc are now limitless.
deno | 6 hours ago
Fortunately there’s no need to speculate as the application explains this clearly:
notpushkin | 5 hours ago
Group_B | 6 hours ago
dijit | 6 hours ago
For those not in the know, Google lobbied ICANN to get the name and in their application they stated (repeatedly) that the intent was to buy it so that it could be reserved; as .dev was already used by developers and if someone bought it for commercial purposes it would harm the developer community.[0]
.... they then proceeded to start selling them.
Leading to all kinds of issues, the exact issues that they raised...
https://github.com/basecamp/pow/issues/397
https://github.com/laravel/valet/issues/433
https://danielbachhuber.com/switch-laravel-valet-from-dev-to...
https://community.localwp.com/t/dev-domain-doesnt-work/4277
https://forums.theregister.com/forum/all/2017/11/29/google_d...
[0]: https://gtldresult.icann.org/applicationstatus/applicationde...
xd1936 | an hour ago
denkmoon | 17 minutes ago
bombcar | 6 hours ago
eugenekay | 32 minutes ago
0x0 | 6 hours ago
veyh | 3 hours ago
montjoy | 6 hours ago
ChrisArchitect | 6 hours ago
ICANN Reveals 2026 Round Applications for New Generic Top-Level Domains
https://news.ycombinator.com/item?id=49997301
saghm | 6 hours ago
moecables | 5 hours ago
gavinsyancey | 40 minutes ago
gertrunde | 5 hours ago
I'm guessing that'll end up being expensive for someone...
ectospheno | 5 hours ago
yegle | 5 hours ago
My tweet on Sep 26, 2026
gertrunde | 5 hours ago
There are questions that literally say as part of the question "Choose Yes or No", so they've answered "true"...
And Q165 is fun: "Is it likely that consumers will face significant risks if domain names in the TLD(s) in the application are abused?" Answer: "No"
OutOfHere | 4 hours ago
childintime | 4 hours ago
It's monopolies like Verisign (of the .com tld) that have luxurious profits. No competition, plus they are allowed to raise their prices above inflation while their infrastructure costs go down every year.
"America" has our best interests at heart /s
phs318u | 2 hours ago
https://www.icann.org/en/board-activities-and-meetings/mater...
gavinsyancey | an hour ago
tvbusy | an hour ago
sidneythekidney | an hour ago
dwedge | an hour ago