Skip to main content

Topic

DNS Delegation Power

Within the Topic facet, DNS Delegation Power topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

Conceptual DELEG record tiles move as one bounded group while a separate nameserver lattice remains intact

IETF

An EPP Draft Adds a Remove-All Command for DELEG Records

An individual Internet-Draft now gives a registrar-side client a way to request removal of every DELEG record for one domain in a single EPP update. The proposed shortcut makes the authority for a bulk change, and the evidence of what it changed, more important than the brevity…

Sep 30, 2026
A wordless registry machine forks one accepted change into a continuous copper NS path and a modular blue DELEG path with an intentional removable gap, producing two different parent-zone answer patterns.

IETF

The Registry Accepted the New Delegation. The Parent Still Had Two Answers

An EPP success response can close a registry transaction while leaving the DNS change open. Revision 03 of the proposed EPP mapping for DELEG records makes that distinction operationally urgent: one command can remove every DELEG record, even as traditional NS data continues to…

Sep 29, 2026
Martin J. Dürst

Leaders

Martin J. Dürst and the Boundary Inside a Unicode URL

A link can look like one string to its reader and become several different things to software. Martin J. Dürst’s work on Internationalized Resource Identifiers helped make that handoff explicit: a Unicode host name, a DNS label, a URI path and a server-side resource key do not…

Sep 29, 2026
A resolver cache still exchanges amber DNS pulses with an old child server after the parent has severed that branch and illuminated a new cyan delegation, while a cyan revalidation pulse dissolves stale descendants.

CASE FILE

The Child Still Answered. The Parent Had Already Moved the Delegation

A DNS server can answer authoritatively from the old home of a zone after the parent has assigned that zone elsewhere. Revision 14 of the delegation-revalidation draft turns that paradox into an operating rule: child-side credibility must never be allowed to renew parent-side…

Sep 29, 2026
An old ACME key disconnects while a new key, a DNS observation, retained public-key hashes and four separate authorization clocks continue toward an account-wide cutoff.

IETF

The ACME Key Rotated. Yesterday's DNS Authorization Still Works

The newest ACME DNS persistence draft turns routine key rotation into an accounting problem. A retired signing key may be unable to place another order while its public thumbprint still keeps an earlier DNS authorization usable.

Sep 29, 2026
One service identity splits into a current cyan DNS view for an IoT device and an older amber view for a controller; a firewall blocks the current path while permitting the stale projection.

CASE FILE

The Name Was Allowed. Yesterday’s Address Blocked the Device: RFC 9726

A manufacturer can put the right service name in a MUD policy while a firewall enforces the wrong moment of that name. RFC 9726 exposes the hidden translation between DNS intent and packet rules—and why a clean policy file is not proof of a working or safe IoT device.

Sep 28, 2026
Abstract editorial illustration with layered horizontal planes suggesting a document and hierarchy, a single red circular accent on a muted navy and off-white palette, with no text or symbols.

ICANN

The Second Face of JPRS: The Contract Track That Sits Beside Japan's .jp Mandate

Japan Registry Services Co., Ltd. is usually described in one sentence: it runs .jp. That sentence covers only half of the company's authority. The other half is not delegated by anyone — it is bought, signed and renewed, and it is policed by a different institution with a…

Sep 28, 2026
Still life on a dark wooden desk: a stack of string-tied manila folders, a typed letter bearing a round red 'au' seal, a stamped airmail envelope and reading glasses resting on a dot-matrix printout, with an early computer terminal glowing faintly in the background; through a window, a stylized outline of Australia under a constellation of network nodes above Melbourne, and a thin ribbon marked 1986 and 2001 along the desk edge.

History

From Personal Delegation to Public Registry: The Instrument Trail That Moved .au, 1986–2001

In March 1986, the .au country-code top-level domain was delegated to one person: Robert Elz, then a network programmer at the University of Melbourne. By the end of 2001, the public record showed the domain's authority in the hands of .au Domain Administration Ltd (auDA), a…

Sep 28, 2026
Stylized editorial illustration of the layered governance control surface over the .jp domain registry, with JPRS at the centre beneath Japanese government oversight and JPNIC accountability channels and the IANA root above

ICANN

Who Controls the .jp Registry? The Instrument Chain Above JPRS

Japan Registry Services Co., Ltd. (JPRS) sits at the center of a layered control surface for the .jp country-code top-level domain: IANA and ICANN grant its international authority, JPNIC and Japan's government can challenge it, and a 2025–2026 evaluation cycle plus a second…

Sep 28, 2026
Stylized .jp domain node beneath a document-and-scales motif in a muted indigo and slate editorial illustration

ICANN

Challenging a .jp Registration Just Got Easier: What the 2026 JP-DRP Rules Revision Actually Changed

Japan's procedure for disputing ownership of a .jp domain name was quietly modernised this spring — but its most consequential limits were left exactly where they were.

Sep 28, 2026
An edge device presents an amber key to a registration gateway while a blue publication path reaches authoritative nodes but breaks before a dark service endpoint.

CASE FILE

The Printer Kept Its Name After the Reset. The Key That Owned It Did Not

RFC 9665 makes automatic service registration workable by letting the first accepted device key defend a DNS-SD name. That useful continuity is narrower than identity: a valid signature can preserve a name while the owner, registrar, published answer or service behind it has…

Sep 27, 2026
Three configuration channels reach a home gateway while a downstream authoritative DNS chain breaks before external observation.

IETF

The configuration arrived. The public zone did not: RFC 9527

RFC 9527 can deliver the domain and manager coordinates an automated Homenet Naming Authority needs. The harder claim begins after that success: whether the delegated name is authoritative, signed, current and reachable from outside the home.

Sep 27, 2026
A client signal passes through a transparent proxy prism and three fading glass alias nodes toward a server that remains behind a separate authentication aperture.

IETF

The proxy exposed the alias chain. It did not authenticate the host: RFC 9532

RFC 9532 gives an HTTP intermediary a precise way to disclose the DNS aliases it encountered on the way to its next hop. That visibility can reveal cloaking and explain routing, but it remains the proxy’s account of one resolver view—not a credential for the resource behind the…

Sep 27, 2026
Abstract textless illustration of three interlocking glass panels connected by golden link lines above a faint silhouette of the Japanese archipelago, representing the instrument chain behind .jp registry authority.

ICANN

Who Holds the Keys to .jp: An Instrument-by-Instrument Audit of JPRS's Registry Authority

Japan Registry Services Co., Ltd. (JPRS) operates the .jp country-code top-level domain, but the company's public profile as a registry says little about where its authority actually comes from, who can challenge it, and what has changed on that control surface recently. This…

Sep 27, 2026
Minimal square editorial illustration of one abstract registry-document seal connected by a single network line to a glowing circular root-server node carrying a stylized letter F, over a subtle world map in navy, slate and amber.

Global Institutional Trends

AS210764: who can change the ISC-AGP1 record, and what the maintainer chain says about ISC stewardship

AS210764: who can change the ISC-AGP1 record, and what the maintainer chain says about ISC stewardship intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the…

Sep 27, 2026
A dimly lit server room at night seen from a low three-quarter angle: a 42U rack of name-server hardware with neatly bundled cabling, small amber and green status LEDs and blank unlettered metal panels occupies the right portion of the frame, while a sheet of plain white paper clipped to the grey steel side panel carries a hand-drawn chart of five horizontal ink bars along a faint ruled line — one long bar cut short by a single heavy diagonal stroke, two others running much further right, with small tick and check strokes above; a black binder clip holds the sheet and a plain pen rests on a narrow ledge below.

Global Institutional

BIND 9 repair ends where ISC's support boundary begins

Internet Systems Consortium draws three lines that decide whether a BIND 9 defect becomes a repair: which release branches stay in support, which severity earns a public advisory, and which single monthly release carries the patch. Dated records from ISC, from Debian's packaging…

Sep 25, 2026
A wide horizontal photograph of a long, empty grey concrete and dark stone institutional corridor seen straight on; it leads to a closed dark-wood double door at the far end, with a single narrow blade of cold daylight escaping as one thin sharp line across the dark floor beneath the door.

ICANN

ICANN Can Declare Its Own Breach. The Remedy Still Needs Someone Else to Act.

A finding of breach is binding. The repair is only a recommendation. The .WEB record and one terminated community petition show where ICANN's accountability stops being automatic.

Sep 25, 2026
An amber signal crosses a gap toward a separate brass aperture, with a small point of light beyond it.

Story

ARIN Closed the DS Automation Suggestion. The Parent-Side Handoff Is Still a Question

A DNS operator can publish a signal that a key should change, but it cannot by that act alone alter the parent zone. In January, ARIN agreed that automatically updating DNSSEC delegation-signer records would be useful and closed the request into its planning process. The…

Sep 24, 2026
Many paths enter a glass resolver chamber beside a separate signing enclosure, connected by a narrow verification line.

ICANN

Ghana’s DNSSEC Rate and Nigeria’s Signed Zone Are Different Kinds of Progress

ICANN’s latest account of African DNS security puts mobile-network resolvers beside a country-code registry. The gains are real but belong to different operators and measure different parts of a secure lookup.

Sep 24, 2026
يرسل سجل قانوني كهرماني بطاقات شركات فارغة نحو شجرة تفويض DNS زرقاء عبر بوابتي تحقق منفصلتين.

History

The Company Register Was Supposed to Settle the Domain Name. It Only Moved the Boundary: RFC 2352

In 1998, an independent RFC proposed giving each legally registered organisation a domain path derived from its formal name, legal form and jurisdiction. The promise was clean: let company and trademark authorities decide entitlement, then let DNS carry the result. The attached…

Sep 24, 2026