Industry stats Updated Jun 2026 All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026 .com + .net total 176.1M names in zone Verisign · Q1 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026 Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026 Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026 Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026 No CMS detected 30% of all sites W3Techs · 17 Jun 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025 Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025 Industry stats Updated Jun 2026 All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026 .com + .net total 176.1M names in zone Verisign · Q1 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026 Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026 Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026 Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026 No CMS detected 30% of all sites W3Techs · 17 Jun 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025 Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Domains DNS ICANN

DNS root server naming test yields unexpected results

RSSAC 028 study finds DNSSEC signing of root server names may not break legacy systems.

DNS root server naming test yields unexpected results
panumas nikhomkhai · Pexels

The global DNS root server naming scheme, unchanged since 1995, is undergoing its first major technical review in nearly a decade. A recent study commissioned by ICANN’s Root Server System Advisory Committee (RSSAC) has tested six alternative naming schemes for the 13 root servers, with results that challenge long-held assumptions about backward compatibility and security trade-offs.

Root servers, identified by letters A through M under the root-servers.net domain, form the foundation of the DNS hierarchy. While only 13 distinct names exist, each represents a globally distributed anycast cluster operated independently. The current naming structure creates a circular dependency: resolvers must locate root servers to bootstrap DNS, yet the root server names reside within a domain that itself requires root server resolution. This paradox is resolved through an unsigned "priming" response containing glue records, a method that has remained static since its 1995 implementation.

What the study measured

The RSSAC 028 study, initiated in 2017, focused on two primary objectives: evaluating the feasibility of DNSSEC-signing the root server naming domain and assessing the impact of alternative naming schemes on the priming response size. Researchers from NLnet Labs and SIDN Labs tested six candidate naming structures, measuring their effect on the 512-byte UDP packet limit that has governed DNS priming since the protocol’s early days.

Contrary to expectations, the study found that DNSSEC-signed priming responses could remain within the 512-byte limit across all tested naming schemes. This discovery addresses a key concern that had stalled progress for nearly a decade—the fear that cryptographic signatures would push packet sizes beyond legacy system compatibility. The findings suggest that the technical barrier to securing root server naming may be lower than previously assumed.

Why the results matter

The current unsigned priming response presents a security vulnerability that has persisted for nearly 30 years. While the response is carefully curated to minimize risk, its lack of cryptographic validation leaves it susceptible to manipulation. The study’s results indicate that DNSSEC signing could be implemented without breaking compatibility with older resolvers, a critical consideration for the internet’s foundational infrastructure.

Background

Background: The DNS root zone contains delegations for all top-level domains (TLDs) and is served by 13 logical root servers (A-M). These servers are not single machines but globally distributed anycast clusters. The root-servers.net domain, created in 1995, has never been DNSSEC-signed, leaving its priming responses vulnerable to tampering.

Willem Toorop, a researcher at NLnet Labs, discussed the implications in a recent APNIC podcast. He noted that while the technical path forward appears clearer, the DNS community’s cautious approach means any changes would still require years of further testing and consensus-building. The study also revealed that some naming schemes performed better than others in terms of packet size efficiency, though all remained within acceptable limits.

What comes next

The study’s findings have reignited discussions within ICANN and the broader DNS operations community. While no immediate changes to root server naming are expected, the results provide a data-driven foundation for future policy decisions. The next steps will likely involve additional testing of the most promising naming schemes, particularly those that balance security improvements with minimal disruption to existing infrastructure.

For operators, the study serves as a reminder that foundational DNS components are not static. While the root server system has remained largely unchanged for decades, the technical and security landscape continues to evolve. The possibility of DNSSEC-signed root server names—once considered a distant prospect—now appears more achievable than previously thought.

Companies mentioned

ICANN NLnet Labs SIDN Labs

Discussion · coming soon

Be the first to join the thread when community discussion launches.