ICANN proposes .INTERNAL, a new TLD available for internal use but never plumbed into the global DNS, taking on the same role as 192.168.x.x IPv4 bloc
The plan is to keep the world at bay by never recording it in the DNS root - like may already do with a subdomain for an intranet
Context & Ripple Effects
ICANN’s earlier recognition of .onion showed the DNS governance system can formalize a namespace with uses distinct from ordinary public domains. Its stewardship role was also reinforced by the transition of DNS oversight to ICANN.
The proposed label addresses a long-running boundary between private network naming and the globally delegated namespace: internal systems need names that resolvers will not treat as public destinations.
First-order effects
- If adopted, organizations would gain a standardized suffix for private naming rather than relying on locally chosen domains or subdomains.
- The global DNS root would not delegate the suffix, preserving its separation from publicly resolvable TLDs while giving DNS operators a common convention.
Second-order effects
- Enterprise DNS, resolver, and network-management vendors would need to account for the reserved suffix in defaults, documentation, and validation rules.
- A shared private-use label could reduce future naming collisions between internal deployments and domains later introduced into the public namespace, though migration from existing naming schemes would remain optional.
Third-order effects
- The move extends the use of formally governed namespaces for functions outside the public DNS, alongside precedents such as the recognized .onion namespace.
- If widely implemented, DNS policy will increasingly distinguish between globally delegated names and reserved operational namespaces, making compatibility decisions by browsers, resolvers, and enterprise tooling more consequential.
The trend: DNS governance is evolving from managing only public delegation toward explicitly reserving namespaces for distinct operational and security contexts.