The .security Domain: An Extension With Published Technical Rules
The .security domain entered the root zone on 3 September 2015 under an ICANN agreement dated 14 May 2015, and its registry operator is XYZ.COM LLC. The extension is governed by the same rule set as its sibling .protection. On 13 August 2026 the zone held 1,026 registrations, 927 of them in the zone file.
Cyber security firms, penetration testing teams, physical security services, authentication products and incident response providers make up the register. No eligibility requirement applies at registration and no sector credential or audit record is asked for. Try candidates in .security domain search, and review the sibling extension on the .protection page.
The registry publishes a dedicated security requirements document for this extension. Sites should be served over HTTPS, TLS 1.1 or later must be used, SSL 2.0 and 3.0 are expressly prohibited, weak cipher suites are excluded, HSTS should be enabled and plain HTTP requests should redirect to HTTPS. Sites handling personal or financial data should carry an extended validation certificate. The registry scans the namespace periodically and reserves the right to suspend a registration immediately where it sees a high likelihood of harm.
.SECURITY Domain at a Glance
- Registry operator XYZ.COM LLC
- Root zone entry 3 September 2015
- Use rule Published TLS and HTTPS requirements, periodic scanning, suspension powers
- Zone size 1,026 registrations, 927 in the zone file (nTLDstats, 13 August 2026)
- Document Requirement No documents are required to register a .security domain
- Character Length 1 - 63 characters
- Registration Period 1 - 10 years
- Name Server Count 2 - 10 servers
.security Domain Prices — No Surprise Fees
Registration, transfer and renewal fees are listed separately. The renewal price can differ from the first-year price, so you see both up front.
-
New Registration
$2,499.99 /year -
Transfer
$2,599.99 /year -
Renewal
$2,799.99 /year -
Restore
$4,099.90 -
Late Renewal
$505.78
Included With Every .security Domain
-
Free DNS management
Change A, MX, TXT and CNAME records yourself from the panel — no waiting on anyone when you move a site or mailbox.
-
Domain lock
While the lock is on, nobody can move your domain to another registrar without your approval.
-
Domain forwarding
Point the domain at your existing site, a campaign page or a social profile — at no extra cost.
-
Free WHOIS privacy
Your name, address and phone stay out of public WHOIS records, which cuts down spam and scam calls.
.security Domain Lifecycle
What happens day by day after it expires
Day 0 is the domain's expiry dateIn short: your .security domain is put on Client Hold on its expiry date, so the site and e-mail stop that same day. You can still renew during the first 20 days, but from this point a late renewal fee is added on top of the renewal price. On day 20 the registration is deleted and until day 50 only a paid restore brings it back. Nothing at all can be done in the 5 days that follow, and on day 55 the name is open to anyone. There is exactly one way never to enter this chain: keep auto-renewal on.
Domain Is Available (Available)
A .security address at this stage has not been taken yet, and it goes to whoever registers first. Check the name you have in mind — if it is free, it can be yours within minutes.
Domain Is Active (Active Period)
Once registration is complete, the domain is registered to you for the term you selected. You can renew at any point before it expires to keep it active, or switch on auto-renewal so you never have to watch the date.
Renewal Window (Client Hold)
On its expiry date your .security domain is put on Client Hold: the site and e-mail go down that day, but the registration is still yours. A single renewal within these first 20 days brings everything back exactly as it was — nothing is lost. The only difference is that a $505.78 late renewal fee is now added to the renewal price; renewing before the expiry date avoids that fee entirely.
Redemption Period (Redemption / RGP)
On day 20 the registration is deleted and the 30-day redemption period that ICANN requires of every gTLD registry begins. The name is not released to anyone during this time; only you can take it back, by paying the restore fee, until day 50. That fee is far higher than a renewal — renewing on time is always the cheaper route.
Pending Delete (Pending Delete)
Once the redemption window closes too, the domain enters its final 5 days and there is no way back. Neither renewal nor restore works here; nobody — your registrar included — can return the name to you. The registry uses this window as the last hold before the name goes back into the pool.
Open to Anyone Again (Released)
On day 55 the name .security returns to the pool and anyone can register it. Sought-after names are often gone within seconds, and there is no guaranteed way to get one back. Yet staying out of this timeline is entirely in your hands: leave auto-renewal on and the expiry date will never catch you off guard.
The timeline above is the schedule Atak Domain applies and publishes. The ICANN chart you will find elsewhere shows a renewal window of up to 45 days after expiry; ICANN's policy on expired registrations (section 2.2.1) lets registrars delete an expired domain at any time, provided they disclose their policy in advance. We apply that window as 20 days and publish it here in plain sight. Full text of the policy: ICANN Expired Registration Recovery Policy
.security Domain Specifications and Registration Rules
Registration conditions, supported features and the registry's own timelines in a single table.
.security Domain Registration
- Document Requirement No documents are required to register a .security domain
- Character Length 1 - 63 characters
- Registration Period 1 - 10 years
- Name Server Count 2 - 10 servers
.security Domain Support
- IDN Support Yes
- Transfer Support Yes
- Late Renewal Support Yes
Frequently Asked Questions About .security Domains
The questions people actually ask before registering — answered plainly.
-
No, there is no eligibility requirement at registration. The agreement carries only the general commitments; no sector credential, audit record or certification is requested. The constraint attaches to use rather than identity: the registry monitors how the name is published against technical criteria. Try candidates on the .security search page.
-
The registry's published document asks for the following: serve the site over HTTPS, use TLS 1.1 or later, never use SSL 2.0 or 3.0, disable weak cipher suites, enable HSTS and redirect plain HTTP requests to HTTPS. Review certificate options on the SSL certificate page and measure your current setup with SSL checker.
-
Yes, the document is not a list of suggestions. The registry scans the namespace periodically, notifies the registrar where it finds non-compliance and expects the registrant to correct it. Where it judges the likelihood of harm to be high, it reserves the right to suspend the registration immediately. That level of enforcement is rare in this category.
-
It does not prove it, yet it is not empty either. The extension establishes a framework of commitments: rules are published, scanning happens and enforcement is defined. Your application's code security, authorisation logic and data retention practice, however, fall outside that scope. Earning visitor trust means describing those areas openly on the page itself.
-
Lift the lock, request the authorisation code and open the request at the gaining registrar. One extra consideration applies here: if DNS and certificate configuration lapse during the move, a namespace scan may record your site as non-compliant. Prepare the certificate in advance. Run the process from the domain transfer page.
Ready to Claim Your .security Domain?
Type a name and see in seconds whether it is free on .security. If it is taken, we list close alternatives right away.
Get Help for .security Domain Registration
Need help registering a .security domain? Our team is ready to assist.