TLDs
- Version
- v1
- In force since
- Not yet
- Next review
- At adoption
- Snapshot
- None yet
- Adopted by
- Proposed for founding adoption
- Signature
- At adoption
- Log entry
- Not appended yet
- Binding text
- English
Proposed, not in force
Open for comment until 28 October 2026, 00:00 UTC. Nothing here binds anyone until it is adopted.
Scope
This policy sets what every TLD must meet to enter the root and to stay in it, and the floors every TLD policy builds on.
Delegation
A TLD string is proposed, checked under P-1, open for public comment for 14 days, and decided by the Community Council. Until councils vote in GOpenCDR, Tier 0 decides through the approval P-13 describes.
A TLD is delegated only when it is signed with DNSSEC and has a DS record in the root, publishes no wildcards and no synthesised answers, answers over IPv4 and IPv6, over TCP and with EDNS, runs no open recursion, and has the same serial on every server. The root is not touched until every server answers.
Rule tld.predelegation.
A domain enters its TLD's zone only with at least 2 nameserversfloor; in a test TLD, one is enough. A TLD may ask for more, up to 13.
Operating a TLD
Hosted is the default: Gelhaus Solutions runs the TLD's registry, signs with the TLD's own keys and serves it. The operator decides the TLD's policy, looks after its registrants and gives the first response to abuse.
Self-hosting is permitted after technical checks. A self-hosted TLD meets 2.2 at all times, keeps its keys under controls no weaker than P-2, accepts continuous conformance probing, and may be suspended from the root while it falls below 2.2.
A self-hosted TLD deposits a complete, encrypted export of its registry data with Gelhaus Solutions at least every 7 daysfloor, used only if its delegation ends without a successor.
When a delegation ends, the TLD passes to a successor the Operators Council approves. Without one it is wound down in a sunset that gives registrants at least 6 monthsfixed to move their names.
TLD policies
Every TLD publishes its policy in this library. It may be stricter than any global floor and never looser. Global policy imposes no prices, removal terms or content rules on a TLD; a TLD may opt in to more.
Each TLD chooses who may register in it: anyone, invitation holders only, or for now nobody. Until it has chosen, registration is closeddefault.
The root zone is public to anyone. A TLD zone goes to enrolled mirrorsdefault unless the TLD's policy opens it to anyone or restricts it to certified mirrors.
A TLD policy names any registrant data it collects beyond the floor of P-5, with its purpose and how long it is kept. For that data, the TLD policy is its privacy information.
A TLD may limit who may register, may charge for names and may register by invitation only. The root takes no share of anything registrants pay.
Tier 0 reviews every change to a TLD policy before it is published, and checks it against the floors when it is saved. The Operators Council may amend a TLD policy by two thirds, only on the topics the charter allows, with the operator recused, after 30 days of comment.
Fees
Community TLDs pay nothing to apply or to be hosted. Brand and private TLDs pay a cost-recovery application fee, and a hosting fee where they are hosted. Contention between applications for one string is settled by the council's review of their merits, not by price.