Skip to main content

Topic

DNS Delegation Power

Within the Topic facet, DNS Delegation Power topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

A forged paper instruction enters a registry console as a domain-control token crosses from a verified blue lane to an amber lane beside a broken confirmation link and a visible restoration path.

ICANN

The Forged Letter That Moved Sex.com: Kremen v. Cohen and Network Solutions

A forged instruction did not move a physical entity. It changed the authoritative registration record for a domain name—and forced a federal appellate court to ask what, exactly, the registrant controlled.

Aug 26, 2026
A sealed court order and a receiver’s custody case sit before domain-record files linked to registrar and registry systems.

ICANN

A Domain Name in a Receiver’s Hands: Office Depot v Zuccarini

The judgment was entered in Florida, the debtor lived elsewhere, the registrars were scattered across three countries, and the `.com` registry sat in Northern California. To collect the debt, the Ninth Circuit had to decide where an intangible domain name could be found.

Aug 26, 2026
A shared oval entrance leads to cobalt and ochre bays whose response cards carry matching integral identifying tabs

History

Two Queries, Two Servers: Why DNS Needed NSID

A service address can stay the same while the machine answering changes. DNS needed a way to identify the instance behind a particular reply, not merely whichever instance answered the next question. The resulting standard made the association precise while leaving the identity…

Aug 26, 2026
A glowing cell in a dense DNS port bitmap ends before a dark socket and detached plug

History

The Bit That Could Not Keep a Service Running: Why DNS WKS Never Became a Live Directory

Before opening a connection, an early Internet mailer could inspect one bit in DNS and decide whether a server existed. The bit was exact. The world behind it was not.

Aug 25, 2026
Conceptual editorial scene separating two registrar response desks, a protected evidence review area and a distinct registry control mechanism.

ICANN

The Four-Hour Transfer Contact That Cannot Reverse the Transfer

The Four-Hour Transfer Contact That Cannot Reverse the Transfer intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The…

Aug 25, 2026
A sealed court writ reaches a root-zone junction and three relays while the registry-record cabinet remains separate.

ICANN

The Writ Reached ICANN; the Registry Data Stayed Abroad

The creditors proposed to sell or license operation of `.ir`. A court could reach ICANN in the United States, but an order changing the root-zone pointer would not deliver the foreign registry’s database, secure a competent successor or oblige the world’s networks to follow the…

Aug 24, 2026
Experts assemble unlabeled network evidence before a narrow illuminated review gate, a separate operator voting chamber and independent server nodes.

ICANN

The drafting room behind root advice: who controls the RSSAC Caucus pipeline?

Most RSSAC reports are built in a body far larger than the committee that formally approves them. The current rules make that division visible: experts may propose, research and draft; root server operator representatives keep the gates for admission, scope, amendment and…

Aug 24, 2026
Security experts examine abstract network evidence before three translucent appointment gates, a separate Board room and independent network nodes.

ICANN

The security advisers the Board appoints: where SSAC authority stops

Three dates describe the gate. On 25 November 2025, an internal membership committee recommended three candidates. On 10 December, SSAC approved them by consensus. On 25 January 2026, the ICANN Board appointed them. Expertise entered through a committee of incumbents and acquired…

Aug 24, 2026
Seven copper service tokens and three blue public-fund tokens split beside a blank ledger; a judicial light boundary precedes an empty retroactive route.

CASE FILE

The 30 Percent Congress Legalised After It Was Collected

For two and a half years, every covered domain registration carried a public-purpose assessment that Congress had not specifically authorised. One month after a judge exposed the defect, Congress made the past lawful “as if” it had acted first.

Aug 24, 2026
A cyan DNS selection plane sends a service request toward two preferred server sockets with unequal amber paths and one recessed backup target

History

The Name That Chose a Service: How DNS SRV Found Servers

A domain once led clients toward one address and a remembered port. DNS SRV made service location an explicit, bounded choice among hosts.

Aug 23, 2026
Three distinct glass name chains keep their leading blocks while one shared blue suffix is replaced by an amber suffix at a fixed gate between two separate authority rings

History

The Alias That Could Not Move Authority: DNS DNAME

DNAME redirects descendant lookups by replacing one suffix. The owner, zone apex and NS delegation stay put even when many queries follow the new subtree.

Aug 23, 2026
A glass DNS name tree leads from a soft root to one amber synthesis source that creates a translucent cyan leaf while a separate violet delegated branch remains bounded.

History

The Name Created by a Question: How DNS Wildcards Stay Bounded

A DNS wildcard can synthesize a name never stored in the zone. Exact nodes, empty non-terminals and delegation still decide when that default may answer.

Aug 23, 2026
Amber forged DNS responses and a pale-cyan legitimate response race through separate transaction-ID and source-port mechanisms while a middlebox narrows port lanes and a signed-proof chain remains distinct.

CASE FILE

The Answer That Won the Race: Kaminsky's DNS Poisoning and the Entropy Behind Trust

The dangerous answer did not need a signature or a privileged route; it only had to resemble one outstanding question closely enough and arrive first. The 2008 DNS crisis turned that narrow acceptance rule into a renewable race—and showed why a patch can buy safety without…

Aug 22, 2026
A compact signed packet expands into many brass keys and glass signatures before a local limiter stops the overloaded validation branch while blue request paths continue.

CASE FILE

The Signature That Demanded Every Key: What KeyTrap Revealed About the Cost of Trust

KeyTrap turned a valid-looking DNSSEC workload into a claim on somebody else’s processor, exposing the point at which faithful verification must yield to a locally governed budget.

Aug 22, 2026
Legacy amber certificate infrastructure remains behind while business assets cross to a blue issuance chamber and three client gates independently reject, delay or accept trust.

CASE FILE

The Root That Wasn't Sold: What Symantec's Exit Revealed About Transferable Trust

Symantec could sell its certificate-authority business, but it could not sell a command to keep trusting the old roots. That decision remained inside independently operated clients.

Aug 22, 2026
A narrow amber route diverts from a blue DNS cluster through a recursive lens and a cracked certificate barrier toward a violet wallet chamber.

CASE FILE

The Route That Borrowed a Name: What the MyEtherWallet Hijack Revealed About Layered Authority

A route accepted elsewhere let false DNS answers arrive locally, but the 2018 MyEtherWallet attack still had to cross a chain of independent technical vetoes.

Aug 22, 2026
A shared controller key synchronizes a hierarchical DNS delegation tree with an alternative naming mesh while a contained turn-down path remains available.

ICANN

ICANN’s Alternative-Name Test Stops at Technical Feasibility

ICANN has opened public comment on a model for linking a gTLD to the same string in alternative naming systems. The initial report says the arrangement can be technically safe if one controller and one coherent source of truth govern every copy of the name. That is a demanding…

Aug 22, 2026
A circular electromechanical sequence counter crosses from amber to blue at one seam while a dark segment sits opposite and two blank 1990s terminals observe from separate desks

History

The Number That Became Newer After Zero: How DNS Ordered Versions Without a Clock

At the edge of a 32-bit counter, DNS asks operators to accept an apparent impossibility: zero may be newer than 4,294,967,295. That rule let independent name servers agree on version order without sharing a clock, but only inside a deliberately bounded window.

Aug 22, 2026
A mid-1990s DNS operations room where an amber notification pulse leaves a primary server, compact cyan change bundles reach several secondary consoles, and one console stages them before a green atomic activation

History

The Zone That Knocked: How DNS NOTIFY and IXFR Cut Staleness

DNS once made every secondary wait before learning its authority was stale. In 1996, NOTIFY delivered the knock and IXFR carried only the edit.

Aug 22, 2026
A blank late-1980s resolver console faces two separate network equipment areas joined by one narrow amber jumper, with cool-blue activity continuing on the child side and an unused cable loop beside it

History

The Address You Needed DNS to Find: How Glue Broke the Delegation Loop

A DNS referral can name the server that knows the answer and still leave a resolver unable to reach it. Glue was the small, deliberately non-authoritative exception that let the resolver cross that gap without giving the parent zone control over the child's facts.

Aug 22, 2026