Lesson: What Does It Actually Mean to "Own" a Top-Level Domain?

Let's start with a simple question, the kind I'd open a class with: when a company wins the rights to a gTLD like .audi or .bmw through ICANN, what have they actually acquired?

The honest answer is: a contract. A registry agreement. A legal document that says, for as long as you keep paying fees and meet ICANN's operational requirements, you may run the backend infrastructure for that string. It is a lease, renewable at the pleasure of a central authority, governed by rules you did not write and cannot change unilaterally.

Now let's ask the same question about a Handshake TLD. What do you actually acquire when you win one at auction?

You acquire a root record on a blockchain. Not a lease. Not a contract subject to renewal terms. An entry you control with a private key, that you can update, transfer, or build on top of, without asking anyone's permission first.

That difference — contract versus asset — is the whole lesson today. Let's break down what it means in practice.

Step 1: Understand the Legacy Model

Under ICANN's structure, a gTLD sits inside a hierarchy: ICANN at the root, a registry operator running the TLD, registrars selling names underneath it, and resellers underneath them. Every layer takes a cut, every layer depends on the layer above honoring its agreements, and the whole structure can be modified by ICANN policy changes that no single registry operator controls.

This isn't a criticism of intent — it's simply what a multi-party, legally-mediated hierarchy looks like. It was built for a world where domain infrastructure needed institutional oversight. But it also means a TLD, however valuable, is not something you can plug directly into a piece of software. It's an administrative arrangement, not a building block.

Step 2: See What Changes When the TLD Is On-Chain

A Handshake TLD is a UTXO-style name record secured by a decentralized blockchain. There is no registry agreement to renew, because there is no registry authority granting you temporary use of the string. You hold it the way you'd hold any other on-chain asset.

Because it's on-chain, it's also composable — meaning other smart contracts and applications can read it, verify it, and build logic around it, the same way DeFi protocols compose with each other. This is the part that a legal contract can never do: a PDF registry agreement can't be called by a smart contract. A blockchain record can.

Step 3: See Composability in Action

This is where the lesson gets concrete. I've built two projects specifically to demonstrate this:

  • DNMT (Domain-Bound NFT Music Token): a music token where ownership and royalty logic are literally bound to a Handshake name. The name isn't just an address — it's a functional component of the asset's identity and rights structure.
  • ROSSOBAY: a real estate NFT protocol that uses HNS TLD infrastructure as the naming and identity layer for property records. Here, the TLD isn't decoration on top of a deed — it's part of how the deed's identity is anchored and verified.

Neither of these would be possible with an ICANN gTLD, because you cannot write a smart contract that reads a registry agreement. You can write one that reads a Handshake name. The same principle extends to AI agents that need self-issued, verifiable identity — another category of "user" that a legal registry agreement was never designed to serve.

Step 4: Draw the Distinction Clearly

Here's the summary I'd want a student to walk away with:

  • An ICANN gTLD is legal infrastructure — it depends on contracts, jurisdictions, and a central operator's ongoing compliance.
  • A Handshake TLD is programmable infrastructure — it depends on cryptographic ownership and can be directly integrated into software.

That's not a marketing distinction. It's a structural one, and it's why builders working on tokenized assets, identity systems, or decentralized applications increasingly look at HNS names as a base layer rather than just an address. It's the same layer I mapped out in the Iceberg of the Internet series — most people never see it, but it's where the real structural decisions get made.

How to See This Yourself

If you want to explore Handshake names as programmable infrastructure firsthand, the easiest entry point is the SkyInclude Browser, which resolves HNS names natively without extra configuration.


NIHON — Handshake Infrastructure & Web3 Identity.