.sec
Is .sec a real TLD? Who’s applying to run it?
.sec is not contested. One application for it is on ICANN’s Reveal Day list, as of 7 October 2026. It is SecM Tech Solutions. XYZ named .sec as a backup string for its .creative application. ICANN deactivated it, because another applicant applied for the same string. Namecheap named .sec as a backup string for its .sys application. ICANN deactivated it, because another applicant applied for the same string. Namecheap named .sec as a backup string for its .intel application. ICANN deactivated it, because another applicant applied for the same string.
A short, readable security shorthand that security tools and startups may use, but most will still default to .com or .io.
cybersecurity vendors, infosec tools and researchers, and pentest or bug-bounty projects wanting a short "sec" identity
Named on the ICANN gTLD application list, 7 October 2026 as a replacement (backup) string of the applicant's .intel application, shown as deactivated: another applicant applied for the same string
Named on the ICANN gTLD application list, 7 October 2026 as a replacement (backup) string of the applicant's .sys application, shown as deactivated: another applicant applied for the same string
Named on the ICANN gTLD application list, 7 October 2026 as a replacement (backup) string of the applicant's .creative application, shown as deactivated: another applicant applied for the same string
The 2012 applications making the most similar bet. Chosen by AI from every string in that round, without being told what happened to any of them.
Same bet exactly — a generic category namespace sold to every vendor, team and practitioner in one industry, with .sec simply the clipped form of the same word (the .auto/.automobile relationship, not the .car/.bmw one).
Stakes the identical buyer pool and the identical promise, but as a claim-word rather than a category label, so it has to work as a phrase-ender (login.secure) instead of as the plain name of the field.
The same structural wager as .sec in a different field: a three-letter clipping of a professional category betting that the field's own shorthand is legible enough to carry primary identity for an entire industry rather than one firm.
What a .sec domain is
.sec is not a TLD yet. It is a string on our record of the ICANN 2026 new gTLD round, filed under AI & tech. One application for it is on ICANN’s Reveal Day list.
Is the .sec domain extension real yet?
.sec is not yet a domain extension you can register: nothing resolves under it, and no registrar sells names in it. It is a string applicants have put forward in the ICANN 2026 new gTLD round, the process that decides whether it becomes one.
When can you buy a .sec domain?
You can’t yet. ICANN publishes every applied-for string on Reveal Day, 7 October 2026 at 18:00 UTC. A .sec name can only be registered after that, once the string is delegated and its registry opens. Last round's closest parallel to .sec was .security, delegated on 17 September 2015.
Is .sec a real TLD?
Not yet. .sec is not in the DNS root, so nothing resolves under it. It’s here because .sec is on ICANN’s Reveal Day list of applied-for strings. Every entry on this page links to its source.
“FEI2676T-T21331 · Fomalhaut Exploration, Inc. · replacement string of .intel · Deactivated REI2616T-T86820 · Rigel Exploration, Inc. · replacement string of .sys · Deactivated STS2562-T71111 · SecM Tech Solutions · primary XL2625T-T12904 · XYZ.COM LLC · replacement string of .creative · Deactivated”ICANN
- Band chosen: 30-49 (usable but limited), at its upper edge. The string works in its favor: "sec" is the everyday shorthand inside the security industry (infosec, appsec, devsec), it is three characters, and the category it maps to is large, well funded and brand-conscious, so some security products and research projects would plausibly use name.sec as a primary identity. Against it: the industry already has a long-form security TLD in market (.security), and by analogy with that and other category-word TLDs, uptake has read as niche rather than default, with serious security companies continuing to choose .com, .io or .ai; by analogy, a short abbreviation TLD run outside the large registry groups tends to see registrar-driven volume and defensive registrations more than primary-identity use. The string is also ambiguous outside security (the US securities regulator, "seconds"), which dilutes the brand signal for a general audience. Not in the 50-69 band because there is no evidence yet of sustained demand for a security-specific namespace that outlasts launch promotion, and the aftermarket for any security-word TLD is thin by analogy; not in the 10-29 band because the word is a genuine, widely used category term with a serious buyer group, not a joke or event string. The record shows one confirmed applicant (SecM Tech Solutions, under the Applicant Support Program) and three deactivated replacement-string applications from Namecheap entities and XYZ, which suggests several registrars and registries saw value in the string, though those three are no longer live; the applicant facts inform adoption likelihood only, in that a smaller operator typically has a narrower registrar channel, which is a distribution uncertainty rather than a demand one. Main market uncertainty: whether security companies treat .sec as a credible primary identity at all, or whether the regulator association and existing .io/.com habits keep it to redirects and vanity use.