Researchers find North Korea has only 28 TLDs on .kp domain after misconfigured nameservers allowed TL;DR project to obtain all the top-level DNS data
North Korea is the most repressive, secretive state in the world. There's no free press, no independent media, and scarce few people have access to the Internet.
Context & Ripple Effects
This 2016 finding came from an accident of configuration, not espionage: North Korea's own nameservers were left open, letting the TL;DR project enumerate the entire .kp zone. The result — just 28 TLDs — gave outsiders their first complete census of a domain space the state had otherwise kept opaque, sitting alongside other leaked windows into its controls like Red Star OS's USB-stick watermarking exposed the year before.
First-order effects
- Researchers and the TL;DR project gain a complete map of North Korea's public-facing web — 28 TLDs is the entire footprint — while Pyongyang's nameserver operators face an immediate operational failure to fix.
Second-order effects
- The zone dump becomes a baseline for later measurement: subsequent research tracked .kp activity growing roughly 300% after 2017 as traffic shifted toward a new Russian connection (the ~300% surge study), making the 28-TLD snapshot the reference point for gauging expansion under sanctions.
Third-order effects
- If the pattern holds, closed states' infrastructure itself becomes the intelligence surface — DNS, routing, and traffic analysis substituting for press access where domestic visibility stays near zero, as Pscore's surveys of monitored, approval-gated access later confirmed on the user side.
The trend: Researchers are increasingly mapping repressive states' digital footprints through infrastructure leaks and traffic analysis rather than on-the-ground reporting.