Public Comment: TSG on gTLD Integrations with Alternative Naming Systems

Unregistry's submission to the ICANN Technical Study Group, filed 21 September 2026. We wrote it from the perspective of end users and merchants, the people who actually use names every day.

Where we stand

We support the framework, and we focused our comments on where it is thinnest: the user side. Integration state should be public, sync failures bounded, lifecycle communication mandatory, and rights enforcement should reuse the DNS accountability stack rather than duplicate it. Our main proposal: a registrant-directed, multi-network model that connects the DNS to every Web3 naming system through records in the registrant's own DNSSEC-signed zone.

Six positions from the submission

String+Controller, Supported

The framework's threshold principle is right: the same string must be controlled by the same party in every system, at all times, or set aside for that party's exclusive use. Without that guarantee you have two names trading on the appearance of one. We support same-string integration under it.

Make Integration State Public

Which systems a name is integrated into, and its state in each, should be exposed through RDAP so users, resolvers, and researchers can verify on their own that DNS and alt-system states agree. Verifiability is the cheapest protection for user confidence available.

Bound the Failure, Protect the User

When integrated systems fall out of sync, divergence must be detected within a defined window and a fail-safe default must exist. A name whose states cannot be reconciled should stop resolving everywhere rather than resolve differently in different places.

Enforcement Follows the Anchor

An integrated name with a live DNS name behind it already sits inside the full DNS accountability stack, registrant data, UDRP/URS, court orders. Acting on the DNS name propagates the effect instead of building a parallel rights system inside every network.

The Registrant-Directed Model

Our main proposal: let any registrant publish association records in their own DNSSEC-signed zone linking their domain to matching names on ANY Web3 network, one or several, held or trusted, changed at will, no registry involvement. DNSSEC is the trust anchor; proven and declared associations stay visibly distinct.

Standardize at the IETF

Record formats, any new RRType, and a w3n: URI scheme belong in the IETF. One common standard matters: if every Web3 network invents its own ad-hoc convention, the fragmentation lands on users and the verifiability never materializes.

Why this is the integration model we build on

No ICANN application is required for Web3-native namespaces. Backwards compatibility with the traditional DNS comes from exactly this mechanism: association records in a DNSSEC-signed zone, proven by control-proofs, verifiable by anyone. The submission is the technical position behind what this site sells.

Submitted by Unregistry: Ageesen Sri, Strategy/R&D · 21 September 2026