Start With the Picture: The Internet Is an Iceberg

Picture an iceberg. Above the waterline is the part everyone sees: websites, apps, search results, social feeds. It looks huge. It feels like the whole internet. But an iceberg's visible tip is a small fraction of its mass. The real bulk sits underwater, unseen, holding the whole structure up.

The internet works the same way. What you browse every day is the tip. Underneath it sits a control layer most people never think about: the Domain Name System, the root zone, and the small number of organizations that decide which names are allowed to exist at all. That hidden layer is not neutral infrastructure. It is a chokepoint, and right now almost the entire world depends on it.

This lesson walks through three things: what is actually happening at that hidden layer today, why it is becoming a bigger problem as the internet changes, and what happens when Handshake removes that chokepoint by turning top-level domains and second-level names into something ownable, programmable, and monetizable.

Layer One: The Part Everyone Sees

Above the waterline, the modern internet is dominated by a handful of platforms: search engines, social networks, app stores, cloud providers. Most people experience "the internet" as a few logins and a few feeds. This layer is convenient, but it is also rented. You do not own your username, your audience, or your reach on someone else's platform. It can be demonetized, deranked, or deleted by a policy change you never voted on.

Layer Two: The Hidden Root, Where the Real Power Sits

Below that visible layer is DNS, the system that turns names like "example.com" into addresses computers can use. At the very top of DNS sits the root zone: the master list of every top-level domain (.com, .org, .net, and every country code) that is allowed to exist.

Here is the part most people never learn: that root zone is a centrally managed file. A single organization, ICANN, along with the U.S. government's historical role and a small number of root zone operators, controls what goes into it. New TLDs are approved through an expensive, political, gatekept process. Existing TLDs can be suspended at the request of a government. Entire country-code domains have been seized or frozen for political reasons. This is not a conspiracy theory; it is simply how the current system is built, and it has happened repeatedly and publicly.

So the iceberg's hidden mass is this: your entire online identity, from your email to your business's website to your app's backend, ultimately rests on a naming system that a small number of gatekeepers control, and that most users never see or question.

Why This Is Becoming a Bigger Problem Right Now

Three trends are colliding at the same time, and each one puts more pressure on that hidden root layer:

  • AI agents need identity. Software agents are starting to act on behalf of people and companies: browsing, negotiating, signing, transacting. Every AI agent needs a verifiable, cryptographic identity that cannot be impersonated. A centrally gatekept naming system was never designed for millions of autonomous agents that need instant, permissionless names.
  • IoT devices need names too. Billions of connected devices need unique, verifiable identities that cannot be spoofed. Traditional DNS was built for servers registered by humans through a bureaucratic process, not for a refrigerator or a sensor that needs to prove who it is in milliseconds.
  • Governments are tightening control over the visible layer. Proposals like the EU's Chat Control initiative and similar measures elsewhere show a clear direction: more scanning, more verification, more centralized oversight of what happens online. Whatever position you take on those policies, the practical effect is the same: pressure to build identity and communication infrastructure that isn't dependent on a single administrative choke point.

Put together, these trends mean demand for names, identity, and trust is exploding at exactly the moment the current naming system is showing its age and its political fragility.

Layer Three: Where Handshake Sits, Below the Old Root

Handshake replaces the single centrally managed root zone with a decentralized, blockchain-based one. Instead of a committee approving new top-level domains, anyone can bid for and own a TLD directly, recorded on-chain, resistant to seizure, and not dependent on any single company or government's permission.

This is the layer beneath the old hidden layer. It does not just make the visible internet faster or prettier. It changes who controls the naming layer that everything else depends on.

TLDs: Owning the Top of the Namespace

A Handshake TLD is not rented like a traditional domain; it is owned outright, the way you would own a piece of digital land. Owning a TLD means you control every second-level name underneath it. That is a fundamentally different kind of asset than a .com registration, which can be revoked and which you never truly own.

The opportunities here fall into a few clear categories:

  • Brand and community TLDs. A company, a project, or a community can own its own TLD outright and issue names beneath it the way a landlord issues leases, or the way a country issues addresses.
  • Vertical infrastructure TLDs. A TLD built specifically for IoT device identity, for AI agent naming, or for a business registry can become the default naming layer for that entire vertical, the way .com became the default for commercial websites.
  • Cultural and linguistic TLDs. Multilingual and Punycode-based names let communities register identity in their own script and language, something the legacy gTLD system handles poorly.

SLDs: Where Everyday People and Businesses Live

Beneath every TLD are second-level domains, the names people and businesses actually register and use day to day. This is where most of the near-term opportunity sits, because it requires far less capital than owning a whole TLD.

  • Personal and business identity. A name under a decentralized TLD becomes a censorship-resistant identity anchor: an email, a website, a wallet address, and a verifiable public record, all tied to one name that cannot be taken down by a platform decision.
  • Portable identity for nomads and remote workers. A name is not tied to a country, a bank, or a government ID. It travels with the person, which matters increasingly for digital nomads and anyone operating across borders.
  • Digital inheritance. Because ownership of a name is a cryptographic key rather than an account with a company's customer support desk, names can be planned for and passed on the same way any other property is, something the current domain system handles very poorly.
  • Domain-bound creative assets. Concepts like binding an NFT music token or a piece of real estate metadata to a specific name turn the SLD into more than an address; it becomes a container for ownership and provenance.

Programs and Real Uses Emerging Now

This is not only theoretical. Concrete use cases are already forming around Handshake infrastructure:

  • DNSSEC and DANE-based security for sectors like banking, where a cryptographically owned domain and TLSA records reduce the risk of certificate-based fraud and phishing.
  • Business registry transparency, where a government or chamber of commerce could anchor verified business identity to a name that cannot be silently altered.
  • Anti-phishing infrastructure, since a domain that cannot be duplicated or spoofed at the root level closes off a whole category of attack that plagues today's web.
  • Resolution through independent browsers, so that people can reach these names directly without depending on legacy DNS providers to decide whether to support them.
  • Mining pool infrastructure, where merged mining and pool accountability metrics are shaping how secure and how decentralized the underlying chain remains, which matters because the security of the naming layer is only as good as the security of the network beneath it.

The Money Layer: How Value Is Created and Captured

It helps to think about value at three levels:

  • TLD ownership as digital land. Early, well-chosen TLDs function like early real estate: scarce, ownable outright, and valuable in proportion to what gets built underneath them.
  • SLD issuance and rent. A TLD owner can issue, lease, or sell names beneath it, creating a recurring or one-time revenue stream, similar to how a landlord earns from tenants.
  • Application-layer value. The real long-term money is rarely in the name itself; it is in what gets built on top: identity verification services, secure email, decentralized business registries, IoT device fleets, and creative assets bound to names. The name is the address; the business is what happens at that address.

Scarcity is also a growing factor on its own. As AI agents and DAOs increasingly need their own machine-readable names, demand for short, meaningful, ownable names is rising from a source that barely existed a few years ago: software, not just people.

What Changes in Everyday Life

Zoom back out to the iceberg. As this hidden layer shifts from centralized to decentralized, the visible layer above it changes too, even for people who never think about DNS:

  • A personal or business identity that cannot be deplatformed by a single company's decision.
  • Devices and AI agents that can prove who they are without relying on a certificate authority that can be pressured or compromised.
  • Cross-border digital life that does not depend on any one country's registrar rules.
  • A new category of ownable digital property, with the same estate-planning, investment, and business logic that applies to physical land and real assets.

The Lesson to Take Away

Most people only ever see the tip of the internet iceberg: the apps and the sites. The part that actually determines who gets to exist online, and under whose permission, sits below the waterline in the root zone. Handshake's bet is that this hidden layer should not be owned by a handful of gatekeepers. It should be ownable, auditable, and permissionless, the same way the early internet promised to be before it consolidated.

TLDs are the land. SLDs are the addresses built on that land. And what gets built at those addresses, identity, security, commerce, creative ownership, is where the next wave of opportunity, and the next wave of money, is forming.

NIHON — Handshake Infrastructure & Web3 Identity