Skip to main content

Topic

DNS Delegation Power

Within the Topic facet, DNS Delegation Power topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

Two domain tokens pass through a registrar switchboard and evidence tray, while separate decision paths reach a protected status-change gate.

ICANN

The Takedown Notice Did Not Become a Verdict: Petroliam Nasional v. GoDaddy

The Ninth Circuit did not call every registrar passive or every takedown request futile. It drew a narrower, more useful line: a service provider's ability to maintain and forward a domain name does not create an unwritten ACPA claim that turns notice into adjudicatory authority.

Aug 26, 2026
An ordered chain of DNS records with an empty interval bounded by two authenticated records.

IETF

How DNSSEC learned to prove a name does not exist

A signed answer can authenticate a record that is present. The harder design problem is authenticating the empty space where an attacker might otherwise hide a name, invent one or replace a truthful “no” with a forged response.

Aug 26, 2026
A tiny blue object with a copper pin and close ring sits within a much broader blue uncertainty disc

History

A Map Pin Was Not a Measurement

DNS LOC could express a coordinate to a thousandth of an arcsecond while declaring a horizontal error circle ten kilometres across. That was not a contradiction. The format distinguished the fineness of an address on a map from the strength of the knowledge behind it. A consumer…

Aug 26, 2026
Anonymous domain records pass through a mechanical difference engine and three permission gates toward phone, mail and email channels.

ICANN

The Public Query Became a Private Lead Machine: Register.com v. Verio

A daily list of newly registered domains looked like public infrastructure until Verio connected it to automated WHOIS queries and rapid sales calls. The resulting case is less a monument to web-contract doctrine than a practical warning about layered permission: public data, a…

Aug 26, 2026
An abstract DNS evidence junction routes verified signals toward different mitigation paths while a larger legitimate network remains active.

ICANN

When a DNS-Abuse Report Becomes Actionable—and What the Contract Still Does Not Order

The decisive step in ICANN's DNS-abuse regime is not the arrival of an allegation. It is the moment when available evidence supports a reasonable finding, after which a registrar or registry must act promptly—but still choose a remedy that fits its role, the harm and the risk to…

Aug 26, 2026
A certificate chain crosses an amber timestamp boundary; certificates before the cutoff remain blue and trusted, while a later certificate is isolated behind a red browser-trust barrier.

CASE FILE

The Certificates Did Not Expire: Chrome's Entrust Cutoff Turned Trust Into an Operating Licence

The decisive field was not the expiry date printed inside a TLS certificate. It was the timestamp proving when that certificate entered the public record—and whether Chrome still accepted the authority behind it at that moment.

Aug 26, 2026
Editorial illustration showing DNS root priming: an aging root-hints card sends one query to the DNS root, whose current authoritative records replace the hint in a resolver cache.

History

The Hint That Had to Be Replaced by an Answer: DNS Root Priming

A recursive resolver begins with an awkward form of knowledge: enough addresses to reach the DNS root, but no current root data in its cache. Priming is the small exchange that turns that inherited hint into an authoritative, expiring answer.

Aug 26, 2026
A public outer network message carrying a luminous encrypted inner message through a shared gateway toward one of several backend servers.

IETF

The secret server name still needs a public front door: ECH’s new privacy boundary

Encrypted ClientHello gives a TLS connection two introductions: one the network may see, and one only the service can open. That is a real privacy gain, but it is not disappearance. The destination’s protection now depends on DNS configuration, a shared front door, key rotation…

Aug 26, 2026
A central request hub routes access tokens to separate registry approval vaults, with only accepted requests producing bounded zone-data copies.

ICANN

One Portal, No Clock: Who Actually Grants Zone-File Access?

CZDS lets a researcher ask many generic top-level-domain registries for zone files from one place. The common doorway is easy to mistake for a common decision. It is neither automatic access nor a single permission desk.

Aug 26, 2026
A forged paper instruction enters a registry console as a domain-control token crosses from a verified blue lane to an amber lane beside a broken confirmation link and a visible restoration path.

ICANN

The Forged Letter That Moved Sex.com: Kremen v. Cohen and Network Solutions

A forged instruction did not move a physical entity. It changed the authoritative registration record for a domain name—and forced a federal appellate court to ask what, exactly, the registrant controlled.

Aug 26, 2026
A sealed court order and a receiver’s custody case sit before domain-record files linked to registrar and registry systems.

ICANN

A Domain Name in a Receiver’s Hands: Office Depot v Zuccarini

The judgment was entered in Florida, the debtor lived elsewhere, the registrars were scattered across three countries, and the `.com` registry sat in Northern California. To collect the debt, the Ninth Circuit had to decide where an intangible domain name could be found.

Aug 26, 2026
A shared oval entrance leads to cobalt and ochre bays whose response cards carry matching integral identifying tabs

History

Two Queries, Two Servers: Why DNS Needed NSID

A service address can stay the same while the machine answering changes. DNS needed a way to identify the instance behind a particular reply, not merely whichever instance answered the next question. The resulting standard made the association precise while leaving the identity…

Aug 26, 2026
A glowing cell in a dense DNS port bitmap ends before a dark socket and detached plug

History

The Bit That Could Not Keep a Service Running: Why DNS WKS Never Became a Live Directory

Before opening a connection, an early Internet mailer could inspect one bit in DNS and decide whether a server existed. The bit was exact. The world behind it was not.

Aug 25, 2026
Conceptual editorial scene separating two registrar response desks, a protected evidence review area and a distinct registry control mechanism.

ICANN

The Four-Hour Transfer Contact That Cannot Reverse the Transfer

The Four-Hour Transfer Contact That Cannot Reverse the Transfer intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The…

Aug 25, 2026
A sealed court writ reaches a root-zone junction and three relays while the registry-record cabinet remains separate.

ICANN

The Writ Reached ICANN; the Registry Data Stayed Abroad

The creditors proposed to sell or license operation of `.ir`. A court could reach ICANN in the United States, but an order changing the root-zone pointer would not deliver the foreign registry’s database, secure a competent successor or oblige the world’s networks to follow the…

Aug 24, 2026
Experts assemble unlabeled network evidence before a narrow illuminated review gate, a separate operator voting chamber and independent server nodes.

ICANN

The drafting room behind root advice: who controls the RSSAC Caucus pipeline?

Most RSSAC reports are built in a body far larger than the committee that formally approves them. The current rules make that division visible: experts may propose, research and draft; root server operator representatives keep the gates for admission, scope, amendment and…

Aug 24, 2026
Security experts examine abstract network evidence before three translucent appointment gates, a separate Board room and independent network nodes.

ICANN

The security advisers the Board appoints: where SSAC authority stops

Three dates describe the gate. On 25 November 2025, an internal membership committee recommended three candidates. On 10 December, SSAC approved them by consensus. On 25 January 2026, the ICANN Board appointed them. Expertise entered through a committee of incumbents and acquired…

Aug 24, 2026
Seven copper service tokens and three blue public-fund tokens split beside a blank ledger; a judicial light boundary precedes an empty retroactive route.

CASE FILE

The 30 Percent Congress Legalised After It Was Collected

For two and a half years, every covered domain registration carried a public-purpose assessment that Congress had not specifically authorised. One month after a judge exposed the defect, Congress made the past lawful “as if” it had acted first.

Aug 24, 2026
A cyan DNS selection plane sends a service request toward two preferred server sockets with unequal amber paths and one recessed backup target

History

The Name That Chose a Service: How DNS SRV Found Servers

A domain once led clients toward one address and a remembered port. DNS SRV made service location an explicit, bounded choice among hosts.

Aug 23, 2026
Three distinct glass name chains keep their leading blocks while one shared blue suffix is replaced by an amber suffix at a fixed gate between two separate authority rings

History

The Alias That Could Not Move Authority: DNS DNAME

DNAME redirects descendant lookups by replacing one suffix. The owner, zone apex and NS delegation stay put even when many queries follow the new subtree.

Aug 23, 2026