Sign in
P-4ProposedGlobal, Registry Council

TLDs

Version
v1
In force since
Not yet
Next review
At adoption
Snapshot
None yet
Adopted by
Proposed for founding adoption
Signature
At adoption
Log entry
Not appended yet
Binding text
English

Proposed, not in force

Open for comment until 28 October 2026, 00:00 UTC. Nothing here binds anyone until it is adopted.

1

Scope

1.1
Bindingp4-c1

This policy sets what every TLD must meet to enter the root and to stay in it, and the floors every TLD policy builds on.

2

Delegation

2.1
Bindingp4-c2

A TLD string is proposed, checked under P-1, open for public comment for 14 days, and decided by the Community Council. Until councils vote in GOpenCDR, Tier 0 decides through the approval P-13 describes.

2.2
Enforced rulep4-c3Not enforced yet

A TLD is delegated only when it is signed with DNSSEC and has a DS record in the root, publishes no wildcards and no synthesised answers, answers over IPv4 and IPv6, over TCP and with EDNS, runs no open recursion, and has the same serial on every server. The root is not touched until every server answers.

Rule tld.predelegation.

2.3
Enforced settingp4-c4Enforced in part

A domain enters its TLD's zone only with at least 2 nameserversfloor; in a test TLD, one is enough. A TLD may ask for more, up to 13.

3

Operating a TLD

3.1
Bindingp4-c5

Hosted is the default: Gelhaus Solutions runs the TLD's registry, signs with the TLD's own keys and serves it. The operator decides the TLD's policy, looks after its registrants and gives the first response to abuse.

3.2
Bindingp4-c6

Self-hosting is permitted after technical checks. A self-hosted TLD meets 2.2 at all times, keeps its keys under controls no weaker than P-2, accepts continuous conformance probing, and may be suspended from the root while it falls below 2.2.

3.3
Enforced settingp4-c7Not enforced yet

A self-hosted TLD deposits a complete, encrypted export of its registry data with Gelhaus Solutions at least every 7 daysfloor, used only if its delegation ends without a successor.

3.4
Enforced settingp4-c8Not enforced yet

When a delegation ends, the TLD passes to a successor the Operators Council approves. Without one it is wound down in a sunset that gives registrants at least 6 monthsfixed to move their names.

4

TLD policies

4.1
Bindingp4-c9

Every TLD publishes its policy in this library. It may be stricter than any global floor and never looser. Global policy imposes no prices, removal terms or content rules on a TLD; a TLD may opt in to more.

4.2
Enforced settingp4-c10

Each TLD chooses who may register in it: anyone, invitation holders only, or for now nobody. Until it has chosen, registration is closeddefault.

4.3
Enforced settingp4-c11Not enforced yet

The root zone is public to anyone. A TLD zone goes to enrolled mirrorsdefault unless the TLD's policy opens it to anyone or restricts it to certified mirrors.

4.4
Bindingp4-c12

A TLD policy names any registrant data it collects beyond the floor of P-5, with its purpose and how long it is kept. For that data, the TLD policy is its privacy information.

4.5
Bindingp4-c13

A TLD may limit who may register, may charge for names and may register by invitation only. The root takes no share of anything registrants pay.

4.6
Bindingp4-c14

Tier 0 reviews every change to a TLD policy before it is published, and checks it against the floors when it is saved. The Operators Council may amend a TLD policy by two thirds, only on the topics the charter allows, with the operator recused, after 30 days of comment.

5

Fees

5.1
Bindingp4-c15

Community TLDs pay nothing to apply or to be hosted. Brand and private TLDs pay a cost-recovery application fee, and a hosting fee where they are hosted. Contention between applications for one string is settled by the council's review of their merits, not by price.