.risk
Is .risk a real TLD? Who’s applying to run it?
Nobody has applied for .risk in its own right, as of 7 October 2026. Hyperion Ltd named .risk as the replacement string of its .audit application.
A narrow professional-vertical name for risk and compliance firms; usable, but the word itself warns rather than reassures.
risk-management, insurance, compliance and GRC software firms, plus cyber-risk and financial-risk consultancies wanting a descriptive hackable name (e.g. cyber.risk)
No applications recorded for this TLD yet.
The 2012 applications making the most similar bet. Chosen by AI from every string in that round, without being told what happened to any of them.
Same bet: an abstract professional-discipline noun with no product behind it, sold to consultancies, compliance functions and standards bodies, and leaning on the natural left-of-dot qualifier construction (food.safety / cyber.risk) rather than on any single owner class.
Same kind of wager on the industry that exists to price and transfer risk, with brokers and carriers as the primary-identity buyers, but it is a hard commercial category with established consumer demand and ad budgets, where risk is a soft abstract that no one searches for.
Another abstract discipline noun bought by the same enterprise-assurance buyer and used the same qualifier-prefix way, but it had already hardened into a concrete vendor product category that gives it a defined registrant base risk never had.
What a .risk domain is
.risk is not a TLD yet. It is a string on our record of the ICANN 2026 new gTLD round, filed under Commerce. Nobody has applied for .risk in its own right. It is named on ICANN’s list as part of an application for another string.
Is the .risk domain extension real yet?
.risk is not yet a domain extension you can register: nothing resolves under it, and no registrar sells names in it. Nobody has applied for it on the public record; the ICANN 2026 new gTLD round is the process that would decide whether it becomes one.
When can you buy a .risk domain?
You can’t yet. ICANN publishes every applied-for string on Reveal Day, 7 October 2026 at 18:00 UTC. A .risk name can only be registered after that, once the string is delegated and its registry opens. Last round's closest parallel to .risk was .safety, delegated on 24 December 2015.
Is .risk a real TLD?
Not yet. .risk is not in the DNS root, so nothing resolves under it. It’s here because ICANN’s list names .risk as part of an application for another string. Every entry on this page links to its source.
- Hyperion Ltd · first recordedICANN
“HL2584-T22214 · Hyperion Ltd · replacement string of .audit”ICANN
- Band chosen: usable but limited (30-49), at its low edge. Risk management is a real, large professional field (enterprise risk, insurance underwriting, cyber risk, financial risk, GRC tooling), so there is a genuine population of buyers for whom a descriptive hackable name on .risk (cyber.risk, credit.risk, climate.risk) is coherent and could serve as a primary identity for a boutique or a product line. That keeps it above the vanity band: demand would be ongoing rather than event-driven. It is not in the strong-niche band because the word carries a cautionary connotation — brands in this sector sell reassurance, and a name ending in 'risk' can read as a warning rather than a credential — so most serious firms would keep a .com and treat .risk as a redirect or campaign name at best, which implies a thin aftermarket. By analogy (flagged as analogy), single-word professional-vertical TLDs such as .insure, .security, .finance and .consulting have found sustained but modest registration bases and little premium resale; .risk sits toward the weaker end of that group because the term is a hazard noun, not a service noun. The verified record shows a single application from Hyperion Ltd, filed as a replacement string for .audit under the Applicant Support Program, with no contention recorded; that profile suggests a small, specialist-operator launch, which I take neutrally as pointing to modest marketing reach and therefore slower adoption. Main market uncertainty: whether the GRC and cyber-risk software segment, which is comfortable using 'risk' in product names, treats the TLD as a descriptive asset rather than a liability — if it does, the string could climb into the 40s; if not, demand collapses to defensive and hobby registrations. Volume figures for comparable TLDs are unknown to me under the rules here.