Scope
This policy sets the technical conditions for managed domain labels, DNS configuration, and registrar transactions. It supports reliable operation alongside the AUP.
The enabled registry interface and namespace rules determine which operations are available. Mention of a protocol or feature here does not promise it is enabled for every registrar or namespace.
Label syntax
| Rule | Requirement |
|---|---|
| Characters | Standard ASCII letters, digits, and interior hyphens for ordinary hostname labels. |
| Length | A label must fit DNS limits; eligibility and reservation may impose further restrictions. |
| Position | A hostname label cannot begin or end with a hyphen. |
| Case | Domain names are compared without case sensitivity. |
| Separators | Dots separate labels and cannot appear inside an individual registration label. |
| Other input | Spaces, control characters, URLs, and email addresses are not registration labels. |
A DNS label is limited to 63 octets; the complete wire-format name is limited to 255 octets, including separators and the root. A maximum-length string is not automatically registrable. See the IETF hostname and DNS requirements.
Internationalised and reserved labels
Internationalised names require explicit registry support and validation of the relevant encoded form. Do not assume that a Unicode display string or an xn-- prefix will be accepted.
Labels that resemble operational services, breach reservation rules, or create a material confusion risk may be rejected. The Reserved Name List describes the applicable categories.
Nameservers and delegation
Use valid nameserver hostnames that are authoritative for the domain and reachable through the required network paths. Verify that the zone is served consistently and that any necessary glue records match the relevant hosts.
Keep old and new DNS service available during a migration where practical. Cached records and time-to-live values mean changes are not immediately visible everywhere. Registration alone does not configure hosting, mail, or a working DNS zone.
DNSSEC changes
Where DNSSEC delegation is supported, submit DS information that matches the keys actually used by the authoritative zone. Validate algorithm, digest, and key-tag data before changing the parent record.
Coordinate key rotation and provider migration carefully. An incorrect DS record can make a domain fail validation even though its nameservers respond. Remove or replace stale delegation material through the registrar using an authenticated request.
Registry states and lifecycle
| State or restriction | Operational implication |
|---|---|
| Active registration | A registry record exists; actual resolution still depends on DNS configuration. |
| Hold | DNS delegation may be suppressed while the record is retained. |
| Transfer restriction | A registrar or registry transfer operation is blocked. |
| Pending operation | A requested change has not completed. |
| Expired or recovery state | Services and available recovery operations depend on the applicable lifecycle rules. |
Read the actual status returned by the registry and ask your registrar when its effect is unclear. Public lookup data can lag a recent change and is not a transaction receipt.
Interface security and transaction handling
Use only authorised credentials and published endpoints. Validate input, protect secrets, observe rate limits, and retain transaction identifiers. Retry a failed request only after checking whether the original operation completed; duplicate requests can create conflicting changes.
Do not scan for credentials, probe other registrars’ data, or bypass access restrictions. Scheduled maintenance and interface changes follow the relevant partner communications.
Faults and incident reports
For DNS or transaction failures, contact your registrar with the domain, UTC timestamps, observed status or error, and relevant transaction identifiers. Remove secrets and unrelated personal data from diagnostic material.
Report active compromise or harmful use through Report Abuse. Emergency restrictions may be applied under the AUP while the responsible parties restore a valid and secure configuration.