That time Verisign typo-squatted all of .com and .net
In 2003, Verisign briefly redirected all mistyped .com and .net domains to its own ad-filled “SiteFinder” page, exploiting its control of those registries and triggering legal and technical backlash from ICANN, ISPs, and the operator community. Commenters revisit how this move highlighted structural problems in DNS governance, monopoly power over key TLDs, and practices like DNS hijacking and domain tasting, while also comparing centralized DNS to blockchain-based naming schemes and sharing practical choices for privacy‑respecting DNS, email, and registrars.
Legality and ICANN Response
- Verisign used its registry control over .com/.net to wildcard all non-existent domains to its SiteFinder service.
- People question legality and whether this meant they could “hijack any domain.”
- ICANN sent a strong objection, Verisign withdrew SiteFinder, then sued ICANN for allegedly overstepping its authority and delaying new services (including SiteFinder).
- The dispute led to formalized review processes for registry service changes (RSEP).
- Some commenters frame SiteFinder as “blatant abuse” that was rebranded as a “service.”
Economic Incentives and Security Risks
- Several posts speculate SiteFinder could have produced enormous ad revenue (hundreds of millions to a billion per year), given it briefly became a top-10 website by traffic.
- Others argue manual URL entry is now rare due to search bars and typo-correcting, limiting upside today.
- Typosquatting and malformed-DNS monetization are tied to malware campaigns and phishing, via both domains and search ads.
ISPs and DNS Hijacking
- Many ISPs historically and currently hijack NXDOMAIN responses to show ad/search pages (examples from Germany, Romania, US).
- Some injected ads into unencrypted HTTP traffic.
- This behavior pushed users to third‑party resolvers and contributed to the adoption of HTTPS and encrypted DNS.
- Workarounds include using alternative DNS (Cloudflare, OpenDNS, etc.) and tools like dnsmasq’s bogus-nxdomain setting.
TLDs, Namespaces, and Monopoly Power
- Debate over whether TLDs are still useful:
- One side: TLDs are just informational; a TLD-insensitive or single-namespace system plus search would be simpler.
- Other side: TLDs act as namespaces, reduce conflicts, keep prices accessible, and avoid turning domains into a one-name global trademark system.
- Verisign is criticized as a de facto monopoly on .com/.net, with claims of regulatory capture of ICANN and rent extraction via price increases without added value.
Blockchain-based Naming (Namecoin/ENS) Debate
- Proponents: DNS alternatives like ENS/Namecoin would prevent registry-level hijacks like SiteFinder; domains would be decentralized and censorship-resistant.
- Critics:
- Hard or impossible to correct fraud, theft, or errors; domains can become lost forever.
- No governance to handle trademarks or typosquatting (e.g., phishing on lookalike domains).
- Middleboxes can still intercept unless users run full stacks locally; existing DNS security (DoH/DoT/DNSSEC) already mitigates some threats.
- Broader tension between resistance to governmental/registrar overreach and the need for consumer protection and dispute resolution.
Registrar and Domain Abuse Patterns
- “Domain tasting” and front-running: registrars temporarily register queried domains, display parking/“for sale” pages, and sometimes resell at inflated prices.
- ICANN’s introduction of small non-refundable fees reduced mass tasting but did not eliminate opportunistic behavior around expiring or high-interest domains.