---
id: "name-collision"
kind: "glossary-term"
title: "name collision"
language: "en"
category: "Alternative naming systems"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/name-collision/"
translations:
  es: "https://tldlog.com/es/glosario/colision-nombres/"
  de: "https://tldlog.com/de/glossar/namenskollision/"
  fr: "https://tldlog.com/fr/glossaire/collision-noms/"
  it: "https://tldlog.com/it/glossario/collisione-nomi/"
  pt-BR: "https://tldlog.com/pt/glossario/colisao-nomes/"
  ru: "https://tldlog.com/ru/glossariy/kolliziya-imen/"
  zh-Hans: "https://tldlog.com/zh/cihui/mingcheng-chongtu/"
---

# name collision

A problem that arises when a private network name also exists in the public DNS, sending computers to the wrong place. The 2012 round used controlled interruption, a test period that warned affected networks. For the 2026 Round, ICANN's Name Collision Risk Management Framework covers an initial assessment, temporary delegation and fixes for high-risk names.

A name collision happens when a name meant for one naming system, often a private company network, gets an answer from another, usually the public DNS. Traffic can then fail or go somewhere nobody intended. The risk appears whenever a new name is added to the internet, so ICANN checks every applied-for TLD for it.

## What a name collision is

ICANN's 2026 Applicant Guidebook (AGB) defines it as a name meant to be resolved in one naming system being resolved by mistake in another, which can disrupt or redirect communication. The classic case is a user who means to reach a resource on a private network and unknowingly reaches the same name in the public DNS.

The risk is not limited to top-level names: ICANN says any new gTLD, ccTLD or second-level name can create it. The SSAC's Name Collision Analysis Project (NCAP) says the problem has been known for decades, "possibly as early as the late 1980s".

## Why it happens: private names and new TLDs

Many organisations gave their internal networks an ending that did not exist in the public DNS. Queries for those names leak out to the public root. Once the same string is delegated as a new gTLD, the leaked queries start getting real answers.

Search lists add to the problem: a device appends suffixes from a list to a short name, one by one, until one works. NCAP counts "perhaps a dozen or more" root causes.

In the 2012 round, of about 1,400 applied-for strings, three were judged high-risk: .corp, .home and .mail. ICANN deferred them indefinitely in 2014, and on 7 September 2024 the ICANN Board declined to have them reassessed.

## Reserved and special-use names

Two separate systems keep names out of the root.

- **The IETF** reserves special-use domain names under RFC 6761, in a registry run by IANA. Top-level entries include .test, .example, .invalid, .localhost, .local, .onion for the Tor network and .alt for naming systems outside the DNS. Some names under .arpa are listed too, such as home.arpa for home networks. The .arpa domain itself is an infrastructure TLD run by IANA, not a special-use name as a whole.
- **ICANN** keeps a Blocked Names list in the AGB. It includes every special-use name plus strings such as .internal, which the Board reserved permanently for private use on 29 July 2024, after SSAC advice. Blocked strings cannot be applied for in any round.

RFC 8244 (October 2017) notes that no formal process coordinates the two, and that neither body can stop a third party from simply using a name.

## How ICANN manages collision risk

### Name collisions in the 2012 round

Under the framework approved on 30 July 2014, each new registry ran at least 90 days of continuous controlled interruption. Its zone answered queries with the address 127.0.53.53, which opens no connection, and a text record saying "Your DNS configuration needs immediate attention". NCAP later found few reports, and only one needed action by a registry.

### Name collisions in the 2026 Round

On 7 September 2024 the Board approved the Name Collision Risk Management framework, which replaces the 2014 one.

1. **Initial Assessment.** After String Confirmation Day, an assessment overseen by ICANN's Technical Review Team (TRT) checks each string using root server and resolver logs, among other data. Its report goes to public comment.
2. **Temporary Delegation.** Strings not found high-risk are delegated to name servers run by ICANN to measure real traffic, for at least 90 and at most 365 days (as of October 2026). The root grows by no more than about five percent a month, roughly 75 delegations a month at first (as of October 2026). Contracting waits until this step ends.
3. **High-risk strings.** As of October 2026, they go on a Collision String List. Within 90 days of that designation (or of contention resolution, if the string is in contention), the applicant may withdraw for a full refund of the evaluation fee, or file a Mitigation Plan (up to 180 days on request) whose actions take at most two years. Its review fee is estimated at USD 100,000 to USD 150,000. If the plan fails, the application is terminated, subject to a challenge within 21 days. The refund excludes .corp, .home and .mail.

In March 2026, after public comment, ICANN decided not to use controlled interruption over IPv6, version 6 of the Internet Protocol, in the 2026 Round. ICANN considers it unlikely that collisions will affect significant numbers of networks or users, but the risk remains.

## What network administrators should do

ICANN's guide for IT professionals recommends:

- Treat 127.0.53.53 in a log as a collision warning.
- Use fully qualified domain names (FQDNs) everywhere and stop relying on search lists.
- Move private names under a registered domain, and monitor until the old names are no longer used.
- Without a registered domain, use only reserved options: .internal, home.arpa for home networks, or .test for testing.
- Report a collision to ICANN where there is a reasonable belief of demonstrable, severe harm.

An example: a company's laptops have corp.example.com in their search list, so typing "intranet" reaches intranet.corp.example.com, a name the company controls. Had the company invented its own ending, those queries would leak to the root, and once that string became a gTLD under controlled interruption, users would get 127.0.53.53 instead.

## Sources

- [New gTLD Program: 2026 Round Applicant Guidebook, Module 7](https://newgtldprogram-2026-agb.icann.org/en/11-module-7-string-and-application-evaluation-procedures.html)
- [Name Collision - ICANN](https://www.icann.org/name-collision)
- [Guide to Name Collision Identification and Mitigation for IT Professionals](https://www.icann.org/name-collision/guide-for-it-professionals)
- [Special-Use Domain Names (IANA registry)](https://www.iana.org/assignments/special-use-domain-names)

## related terms

- [New gTLD Program](https://tldlog.com/glossary/new-gtld-program/)
- [alternative root](https://tldlog.com/glossary/alternative-root/)
- [blockchain domain](https://tldlog.com/glossary/blockchain-domain/)
