.login
Is .login a real TLD? Who’s applying to run it?
.login is not contested. One application for it is on ICANN’s Reveal Day list, as of 8 October 2026. It is EchoStar. Identity Digital named .login as a backup string for its .boost application. ICANN deactivated it, because another applicant applied for the same string or named it as a backup. Identity Digital named .login as a backup string for its .road application. ICANN deactivated it, because another applicant applied for the same string or named it as a backup. Identity Digital named .login as a backup string for its .podcast application. ICANN deactivated it, because another applicant applied for the same string or named it as a backup. Identity Digital named .login as a backup string for its .lounge application. ICANN deactivated it, because another applicant applied for the same string or named it as a backup. Squarespace named .login as a backup string for its .hub application. ICANN deactivated it, because another applicant applied for the same string or named it as a backup. Codyssey SL named .login as a backup string for its .auth application. ICANN deactivated it, because another applicant applied for the same string or named it as a backup.
A functional string for sign-in pages, not an identity; demand is mostly defensive, and phishing worries limit serious use.
brands and software companies wanting a dedicated sign-in address (acme.login), plus defensive registrants guarding against look-alike phishing of their customers
Named on the ICANN gTLD application list, 7 October 2026 as a replacement (backup) string of the applicant's .auth application, shown as deactivated: another applicant applied for the same string or named it as a backup
Named on the ICANN gTLD application list, 7 October 2026 as a replacement (backup) string of the applicant's .hub application, shown as deactivated: another applicant applied for the same string or named it as a backup
Named on the ICANN gTLD application list, 7 October 2026 as a replacement (backup) string of the applicant's .lounge application, shown as deactivated: another applicant applied for the same string or named it as a backup
Named on the ICANN gTLD application list, 7 October 2026 as a replacement (backup) string of the applicant's .podcast application, shown as deactivated: another applicant applied for the same string or named it as a backup
Named on the ICANN gTLD application list, 7 October 2026 as a replacement (backup) string of the applicant's .road application, shown as deactivated: another applicant applied for the same string or named it as a backup
Named on the ICANN gTLD application list, 7 October 2026 as a replacement (backup) string of the applicant's .boost application, shown as deactivated: another applicant applied for the same string or named it as a backup
The 2012 applications making the most similar bet. Chosen by AI from every string in that round, without being told what happened to any of them.
Same bet as .login: a single functional security-infrastructure word with no category of businesses behind it, whose value rests on a trust-and-access vendor (or a platform) owning the gesture rather than on registrants self-identifying with the word.
Also a bare web-interaction verb rather than an industry or a brand, betting that the gesture users perform on a page can carry a namespace — nobody's primary identity is 'click' or 'login', so both live or die on utility and redirect use.
Another universal site-action verb sold as an open namespace, but it names something a site gives you rather than a credentialed identity step, so the buyer is a file or content host, not an identity provider.
What a .login domain is
.login is not a TLD yet. It is a string on our record of the ICANN 2026 new gTLD round, filed under Infrastructure. One application for it is on ICANN’s Reveal Day list.
Is the .login domain extension real yet?
.login is not yet a domain extension you can register: nothing resolves under it, and no registrar sells names in it. It is a string applicants have put forward in the ICANN 2026 new gTLD round, the process that decides whether it becomes one.
When can you buy a .login domain?
You can’t yet. ICANN publishes every applied-for string on Reveal Day, 7 October 2026 at 18:00 UTC. A .login name can only be registered after that, once the string is delegated and its registry opens. Last round's closest parallel to .login was .secure, delegated on 10 August 2016.
Is .login a real TLD?
Not yet. .login is not in the DNS root, so nothing resolves under it. It’s here because .login is on ICANN’s Reveal Day list of applied-for strings. Every entry on this page links to its source.
“CS2676T-T34770 · Codyssey SL · replacement string of .auth · Deactivated EDCL2689T-T27113 · ECHO Domain Co L.L.C. · primary SRL2616T-T36153 · Squarespace Registry LLC · replacement string of .hub · Deactivated VTL2632T-T22581 · Velvet Taupe, LLC · replacement string of .lounge · Deactivated VTL2632T-T30500 · Velvet Taupe, LLC · replacement string of .podcast · Deactivated VTL2632T-T38419 · Velvet Taupe, LLC · replacement string of .road · Deactivated VTL2632T-T80905 · Velvet Taupe, LLC · replacement string of .boost · Deactivated”ICANN
- Band chosen: 10-29 (vanity/joke/narrow), at its upper edge. The word 'login' describes an action on someone else's site, so a .login address is almost always a secondary surface pointing at a brand that lives elsewhere; serious projects are unlikely to adopt it as primary identity over the next 5 years. The plausible uses are (a) a company running its sign-in portal at brand.login and (b) defensive registrations by brands and security teams who do not want a third party controlling a 'their-brand.login' phishing page. Use (b) is real but shallow: it produces registrations without end-use, and it does not build an aftermarket. Use (a) is possible but cuts against the grain of how authentication is deployed, where sign-in lives on the primary domain or a subdomain of it, and where security training tells users to distrust unfamiliar domains. By analogy (flagged as analogy), action-word and security-themed strings from the 2012 round such as .secure-style, .support-style and .support/.help-style strings became low-signal namespaces with thin resale and a meaningful share of abuse-related registrations rather than category standards; I expect .login to behave similarly or worse because its meaning actively invites credential-harvesting pages, which can lead browsers, registrars and corporate filters to treat the whole TLD with suspicion. Not in the band above (30-49): the volume case is defensive rather than usage-driven and the brand signal is weak or negative, so it does not reach 'registrations at volume with a usable brand signal'. Not in the band below (1-9): there is a realistic defensive market and a narrow functional one, so it is not 'no market'. Record facts, stated neutrally: there is one application still in contention on the record, from EchoStar (ECHO Domain Co L.L.C.), filed as a standard application; three further applications (Codyssey SL, Squarespace Registry LLC, Identity Digital via Velvet Taupe, LLC) are recorded as deactivated and were replacement strings for .auth, .hub and .lounge respectively; a .quantum application by EchoStar naming this one as primary is also recorded as deactivated. A single standard applicant implies a general-purpose registry policy rather than a verified-brand one, which keeps my adoption expectation on the defensive/low-trust path. Main market uncertainty: whether any meaningful set of brands would choose to run canonical sign-in at brand.login (which would raise end-use utility toward the 30s), versus security teams and browsers classifying .login as inherently risky, which would push it toward the low 20s. Figures on registration counts, pricing and abuse rates are unknown to me under the rules here.