.pki
Is .pki a real TLD? Who’s applying to run it?
.pki is not contested. One application for it is on ICANN’s Reveal Day list, as of 7 October 2026. It is VeriSign Sàrl.
A technical acronym for digital-certificate systems; useful to a few security vendors, rarely a company's main web address.
certificate authorities, enterprise security teams and identity/trust vendors who run public-key infrastructure and want a namespace that says so
The 2012 applications making the most similar bet. Chosen by AI from every string in that round, without being told what happened to any of them.
Same bet: an insider security-discipline abbreviation only practitioners decode, wagering that jargon carries more authority with security buyers than a plain word, with vendors and specialist units as the identity holders.
Same bet one level more consumer-facing: an unowned technical security-product category any vendor in the field could credibly stand on, so its value rests on category recognition rather than a brand.
Same bet structurally: a short standards acronym for a piece of internet plumbing owned by no company, wagering that an infrastructure spec's own abbreviation can anchor the identity of those who implement it.
What a .pki domain is
.pki is not a TLD yet. It is a string on our record of the ICANN 2026 new gTLD round, filed under Infrastructure. One application for it is on ICANN’s Reveal Day list.
Is the .pki domain extension real yet?
.pki is not yet a domain extension you can register: nothing resolves under it, and no registrar sells names in it. It is a string applicants have put forward in the ICANN 2026 new gTLD round, the process that decides whether it becomes one.
When can you buy a .pki domain?
You can’t yet. ICANN publishes every applied-for string on Reveal Day, 7 October 2026 at 18:00 UTC. A .pki name can only be registered after that, once the string is delegated and its registry opens. Last round's closest parallel to .pki was .comsec, delegated on 16 November 2015.
Is .pki a real TLD?
Not yet. .pki is not in the DNS root, so nothing resolves under it. It’s here because .pki is on ICANN’s Reveal Day list of applied-for strings. Every entry on this page links to its source.
- VeriSign Sàrl · first recordedICANN
- Band chosen: 10-29 (vanity/joke/narrow). The string is a well-understood acronym inside the security profession (public key infrastructure) but means little to the general public, so its natural buyers are a small set of certificate authorities, trust-service providers, and enterprise PKI programs. Those buyers already hold strong .com identities and treat PKI as a function, not a brand; the likelier end use is as a technical or service namespace (certificate endpoints, trust directories) rather than a primary identity, and such use produces little aftermarket. By analogy (flagged as analogy), narrow security-flavoured strings such as .security and .trust have shown thin registration bases and little resale demand relative to broad tech strings, and .pki is narrower than either. It is not in the 30-49 band because there is no plausible volume-registration or price-driven market: the vocabulary is too specialist to draw small businesses or speculators, and the brand signal reads as a protocol, not a destination. It is not in the 1-9 band because a real professional community exists, the term has durable relevance as certificate and identity systems keep growing, and the record shows a confirmed standard application from VeriSign Sàrl, an operator whose existing business is in registry and (historically) certificate-adjacent infrastructure, which raises the odds the string is put to coherent infrastructure use rather than left idle. Main market uncertainty: whether the TLD is run as an open registry (where demand would be very thin) or as a controlled technical namespace tied to trust services (where utility could be real but resale value near zero either way); contention count on the record is 1, applicant status confirmed, application type standard.