As former AD person and dealing with that several companies, the recommendation for internal network DNS has long been subdomain.company.com that is not on public internet.
Even today when setting up greenfield networks, I generally use internal.company.com. It also lets you get public trusted SSL certificates so you don't have to deal with internal PKI.
john_strinlai 12 minutes ago [-]
im not super keen on all of these gTLDs, but anyone choosing to use .lan should have been aware of the risks of using an unofficial/unreserved domain.
at the very least, the .dev stuff should have had people second-guessing their usage of unreserved domains.
gchamonlive 10 minutes ago [-]
Pihole here will still serve .lan internal domains. Anyone that registers .lan globally is the one of reserving a culturally busy domain that was unreserved before.
delecti 5 minutes ago [-]
Eh, maybe someone spinning up a brand new environment using it in 2026 should have known better. But you don't have to go that far back to reach a point where the current list of gTLDs would make .lan feel safe.
john_strinlai 49 seconds ago [-]
>But you don't have to go that far back to reach a point where the current list of gTLDs would make .lan feel safe.
throughout most of my career, there was no unreserved domain that felt safe. but 2014 certainly solidified that feeling with .dev.
alwa 20 minutes ago [-]
This seems like a good time to educate myself about the application (and objection) process.
The bureaucracy seems precision-engineered to stultify, but apparently the public have 104 days after “String Confirmation Day” (17th Nov; capitalization theirs) to lodge objections, assuming the “GAC” doesn’t beat them to it…
…welp, hope somebody more organized (and better-funded) than I can organize an objection. Much as I feel like I’m giving up my right to gripe by assuming somebody else will come along to do the weeding.
mzajc 39 minutes ago [-]
Posting because OpenWRT, possibly others as well, assign .lan names to devices on the LAN by default. People who make use of this might want to follow the application, and, if it goes through, either change the name or make sure queries can't get incorrectly get sent to upstream resolvers.
Regarding that last point, I've had issues with dnsmasq in the past where it was remotely resolving domains even when they were configured to resolve locally. For .lan domains, this could be disastrous because I often send plaintext traffic to them. I did submit a fix/workaround[0], but it's still something to look out for. If anyone knows more about this issue or other ways queries could leak, please share!
Internal. is also an valid option.
I moved everything there about a year ago
16 minutes ago [-]
c0l0 20 minutes ago [-]
That's nice and all, but OpenWrt (and its use of .lan) predates this particular RFC by a rough 14 years.
I hope the gTLD application gets struck down.
pwdisswordfishq 12 minutes ago [-]
God forbid OpenWrt ever receives an update or something.
c0l0 5 minutes ago [-]
If you actually think it's a trivial affair to change a well-established default with more than 20 years of history that is, on top of all other difficulties that such a change typically encompasses, used to identify and name things, I hereby beg you to never design or provide any kind of infrastructure.
deno 12 minutes ago [-]
But what if my LAN is in the garage?
montecarl 14 minutes ago [-]
This reminds me of when I used to do IT work for small businesses in college. One printing company I worked for, had about 100 computers on their network, and was using public ipv4 addresses, that they did not own, on their internal network. I forget what range they were using now. But imagine seeing a DHCP server handing out addresses like 142.250.110.1/16 on a LAN and the public ip being something totally different.
It was funny, because when I brought it up to them, it was hard to articulate why it was a problem and I couldn't convince them it was worth the effort of trying to fix. They never ran into a specific issue due to this while I was there but it felt so gross.
masfuerte 25 seconds ago [-]
The problem is that they wouldn't be able to talk to any internet service that legitimately used those addresses. Whether that was likely to be a problem very much depends on whose addresses they were.
irusensei 3 minutes ago [-]
When I was working with Linux based kiosks and PoS systems I had a good share of issues with the Microsoft MVP signature use of .local on their forests. Back then their training material recommended .local for Active Directory services.
deno 1 minutes ago [-]
There's a good reason to do this if you can't be certain what reserved subnets are used in a given network and you absolutely need a static ip for some reason.
At least that's the conclusion I've arrived at at some point, but I don't remember what was the exact use case anymore.
However there are still several global IPv4 ranges that are not local reserved ranges but are effectively reserved and you could use them if you really want to without any issues.
vekntksijdhric 30 minutes ago [-]
This is a security issue for many devices. What could possibly go wrong overriding a tld used for internal networking....
jeroenhd 23 minutes ago [-]
You would hope someone would finally learn after .dev and .local started getting used.
irusensei 15 minutes ago [-]
RFC 6762 reserves the .local. TLD for Multicast DNS. There are no reservations for .lan. so something like home.arpa. should be used instead.
procone 8 minutes ago [-]
router.home vs router.home.arpa
.home.arpa is so clunky. Why do I have to put the acronym of a US military project in my domain to access resources on my own local network?
Yes, I know that organization was central to the development of the l Internet, but it's not relevant as a domain 40 years later.
john_strinlai 3 minutes ago [-]
router.internal avoids the military arconym
jstarks 27 minutes ago [-]
What could go wrong using tlds that were not explicitly reserved for internal use?
alerighi 21 minutes ago [-]
Beside the fact that was standard or not it made sense to use .lan domain for local devices, and a lot of router sold were configured with that domain for resolving local network hosts.
To me is a very bad idea to implement this proposal, it should instead be standardized and reserved for internal usage as a fix. There were even RFC like https://www.rfc-editor.org/info/rfc6762/#appendix-G that suggested their usage for local devices in a network.
What is the point of selling the .lan domain, except for making money at the expense of a security risk for millions of networks that already use that domain for internal hosts?
BTW to me there was never any sense to add new TLD domain despite country code. They decided to render internet less secure, by giving scammers infinite TLD to register they scam domain like "apple.lan", with the sole purpose of making for them easy money.
24 minutes ago [-]
davidcollantes 24 minutes ago [-]
Indeed. It akin to an application for a .local TLD.
john_strinlai 22 minutes ago [-]
>It akin to an application for a .local TLD.
it is not, as .local is designated as a special-use domain name and .lan is not.
seanw444 28 minutes ago [-]
This was my first thought as well. Yikes.
0x0 4 minutes ago [-]
I've been using a single letter "fake" tld for my internal LAN DNS zone. Looks like ICANN requires 3+ letters in tld applications, so hopefully should be safe for quite a while.
dijit 7 minutes ago [-]
I'm still seething about `.dev`.
For those not in the know, Google lobbied ICANN to get the name and in their application they stated (repeatedly) that the intent was to buy it so that it could be reserved; as .dev was already used by developers and if someone bought it for commercial purposes it would harm the developer community.
.... they then proceeded to start selling them.
Leading to all kinds of issues, the exact issues that they raised...
When ICANN reserved .internal a couple years ago, I was saying they should just flip and truncate it to .lan(retni) so everyone's happy.
procone 15 minutes ago [-]
gTLDs were a mistake. I say that as an owner of several domains with gTLDs.
There's almost no value.
Large businesses almost never use them. The potential for scams / phish / etc are now limitless.
deno 14 minutes ago [-]
Why would you even want something like “lan” as a global TLD? Does it mean something else than the obvious?
Fortunately there’s no need to speculate as the application explains this clearly:
AGB Q118: What is the meaning/definition of the applied-for gTLD string?
Answer: Lan commonly refers to a broadly recognized term used across a wide range of contexts.
unleaded 18 minutes ago [-]
..Why? Just to annoy people?
vetrom 3 minutes ago [-]
The applicant appears to be an agglomeration of LLCs and legal diversions to hide responsible parties. It does lead me to assumptions about their motivations, whomever they may be.
Group_B 11 minutes ago [-]
so so dumb. Pure greed. This is going to cause so many issues
Rendered at 16:30:49 GMT+0000 (Coordinated Universal Time) with Vercel.
Having internal domain names owned by some guy on the internet has already compromised multiple corporate networks. See the talk from this guy:
https://www.romhack.io/wp-content/uploads/2025/10/Internal-D...
Even today when setting up greenfield networks, I generally use internal.company.com. It also lets you get public trusted SSL certificates so you don't have to deal with internal PKI.
at the very least, the .dev stuff should have had people second-guessing their usage of unreserved domains.
throughout most of my career, there was no unreserved domain that felt safe. but 2014 certainly solidified that feeling with .dev.
The bureaucracy seems precision-engineered to stultify, but apparently the public have 104 days after “String Confirmation Day” (17th Nov; capitalization theirs) to lodge objections, assuming the “GAC” doesn’t beat them to it…
https://newgtldprogram.icann.org/en/application-rounds/round...
…of course there’s a “filing fee,” priced in “hours of a panel of lawyers’ time,” to lodge such an objection…
https://newgtldprogram-2026-agb.icann.org/en/8-module-4-comm...
…welp, hope somebody more organized (and better-funded) than I can organize an objection. Much as I feel like I’m giving up my right to gripe by assuming somebody else will come along to do the weeding.
Regarding that last point, I've had issues with dnsmasq in the past where it was remotely resolving domains even when they were configured to resolve locally. For .lan domains, this could be disastrous because I often send plaintext traffic to them. I did submit a fix/workaround[0], but it's still something to look out for. If anyone knows more about this issue or other ways queries could leak, please share!
[0]: https://github.com/openwrt/openwrt/pull/18610
https://www.rfc-editor.org/info/rfc8375/
[0]: https://amplifi.com/
I hope the gTLD application gets struck down.
It was funny, because when I brought it up to them, it was hard to articulate why it was a problem and I couldn't convince them it was worth the effort of trying to fix. They never ran into a specific issue due to this while I was there but it felt so gross.
At least that's the conclusion I've arrived at at some point, but I don't remember what was the exact use case anymore.
However there are still several global IPv4 ranges that are not local reserved ranges but are effectively reserved and you could use them if you really want to without any issues.
.home.arpa is so clunky. Why do I have to put the acronym of a US military project in my domain to access resources on my own local network?
Yes, I know that organization was central to the development of the l Internet, but it's not relevant as a domain 40 years later.
To me is a very bad idea to implement this proposal, it should instead be standardized and reserved for internal usage as a fix. There were even RFC like https://www.rfc-editor.org/info/rfc6762/#appendix-G that suggested their usage for local devices in a network.
What is the point of selling the .lan domain, except for making money at the expense of a security risk for millions of networks that already use that domain for internal hosts?
BTW to me there was never any sense to add new TLD domain despite country code. They decided to render internet less secure, by giving scammers infinite TLD to register they scam domain like "apple.lan", with the sole purpose of making for them easy money.
it is not, as .local is designated as a special-use domain name and .lan is not.
For those not in the know, Google lobbied ICANN to get the name and in their application they stated (repeatedly) that the intent was to buy it so that it could be reserved; as .dev was already used by developers and if someone bought it for commercial purposes it would harm the developer community.
.... they then proceeded to start selling them.
Leading to all kinds of issues, the exact issues that they raised...
https://github.com/basecamp/pow/issues/397
https://github.com/laravel/valet/issues/433
https://danielbachhuber.com/switch-laravel-valet-from-dev-to...
https://community.localwp.com/t/dev-domain-doesnt-work/4277
https://forums.theregister.com/forum/all/2017/11/29/google_d...
Also see a .bldg application, which also might conflict with some legacy naming schemes.
ICANN Reveals 2026 Round Applications for New Generic Top-Level Domains
https://news.ycombinator.com/item?id=49997301
There's almost no value.
Large businesses almost never use them. The potential for scams / phish / etc are now limitless.
Fortunately there’s no need to speculate as the application explains this clearly: