Back in June, the Human-Centred Computing Foundation (HCCF) announced an ambitious yet somewhat ambiguous application for the .self domain1 which is exclusively for self-hosted projects and will be assigned to people free-of-charge. Then in August, they confirmed they had submitted their application to ICANN2 (which qualified for the Applicant Support Program to significantly reduce the standard $227k fee). It might seem like a positive counter to the current obsession of companies scrambling to jump on the genAi bandwagon with vibe-coded slop websites on .ai domains but exactly how it will actually work is not detailed in their single-page overview of the project3.
If one second-level domain (2LD) is available for free to every individual with no re-selling or cybersquatting allowed, how is it going to cover the ongoing registry costs and how will it actually enforce its restrictions? Its other unique feature is its exclusivity for self-hosted sites, but how do you define self-hosted and how do you verify such a status? If someone builds a website or service from scratch but installs it on a virtual private server (VPS) provided by huge companies like Hetzner or Digital Ocean, does this qualify as self-hosted and how do you police it?
The other obvious problem with advertising your site as self-hosted is the attraction to bad actors who recognise an increased chance of poor security - and this would still be true even if VPSs are included, since people are perfectly capable of misconfiguring them. But bad actors might also be attracted to using .self domains to misuse them, as evidenced by Freenom when it gave away the likes of .tk and .ml domains which were so popular with spammers that it caused some anti-spam systems to filter out their entire TLDs.
In the comments for a post on Hacker News, HCCF responded to some of these queries4:
We plan on operating the domain as a public good and are actively seeking sponsors to help fund us. Think of it as a similar model to ISRG and LetsEncrypt.
Our rule of one person per subdomain will hopefully prevent this at scale, though it will admittedly be more difficult to examine any particular domain so closely. We may have to implement some type of heartbeat where the owner of said domain has to respond within a certain amount of time.
Another bullet point on their PDF simply lists a "trusted mail relay" and again the only detail on this was provided in a Hacker News comment:
One of the biggest problems people have when self-hosting their own mail servers is delivery issues because the big email providers don't trust your server. The goal with the shared mail server is to create a server that is trusted by those providers and then making it accessible to users of the .self TLD so they can forward their mail to it and have confidence it will be delivered. It would act only as a relay, users would still self-host their own mailboxes. And nothing would force you to use it.
They also mentioned they are likely to reserve obvious 2LDs for "specific purposes" such as "my.self automatically pointing to a homepage on your local network" although how this would work is unclear since the domain can only point to a single address in public DNS with no knowledge of a registrant's local DNS configuration.