Applications / .firm / NA2631T-T79393 · published by ICANN 7 October 2026 · snapshot 2026-10-08
.firm
StandardActiveRegistry Services, LLC, US Q1·Q25
Ultimately controlled by GoDaddy Inc. Q108 · ICANN record ↗
1. Existing Registry Operator and Affiliate of Registrars
2. Affiliated Registrars:
GoDaddy.com, LLC (IANA 146)
Bombora Technologies Pty Ltd (IANA 353)
Wild West Domains, LLC (IANA 440)
Blue Razor Domains, LLC (IANA 612)
Go China Domains, LLC (IANA 1149)
Go Canada Domains, LLC (IANA 1150)
Go Australia Domains, LLC (IANA 1151)
Go Montenegro Domains, LLC (IANA 1152)
Go France Domains, LLC (IANA 1153)
Mesh Digital Limited (IANA 1390)
123-Reg Limited (IANA 1515)
GoDaddy Online Services Cayman Islands Ltd (IANA 1659)
GoDaddy Corporate Domains, LLC (IANA 3786)
§ 1 — Meaning of the string Q118·Q120
"Firm" refers to a business organization, especially one formed by a partnership of two or more people, that offers professional services or engages in commercial trade.
/fɜːrm/
§ 2 — Mission and purpose Q133
1. Mission and Purpose of the Applied-for gTLD
.firm gives professional partnerships a web address that states plainly what they are. Many practices operate as a firm in the truest sense: a group of experts who pool their reputations under one name and stand behind their collective work. The namespace is built for practices that trade on judgment, expertise, and trust rather than mass-market products. For a law, accounting, consulting, design, or advisory partnership, the name is often the first thing a client encounters. A clear, category-defining address helps that practice create a recognizable presence, distinguish itself from a crowded field of generic addresses, and signal that it operates as an established professional entity.
.firm also gives partnerships naming room that has grown scarce elsewhere. A distinctive practice name paired with .firm can produce a short, memorable, on-point address even when the equivalent option in older namespaces is long since taken. This helps a firm turn its name into something clients remember, refer, and return to, while keeping the branding aligned across signage, correspondence, proposals, and the web.
The purpose is not to serve every business, but to serve the specific slice of the market that identifies as a firm and wants that identity reflected online.
Intended Registrants: Professional partnerships and practices, including law firms, accounting and audit practices, consulting groups, architecture and engineering studios, financial advisory partnerships, and boutique agencies operating under a formal firm structure.
Related Activities Supporting the Purpose:
• Registrar distribution aimed at professional services providers and their web and branding partners.
• Awareness-building among partnerships that want a web address matching how they already describe themselves.
• Registrant education explaining how a category-defining suffix can clarify the nature of a practice at a glance.
• Community outreach to professional associations and the studios, marketers, and developers who build sites for firms.
• Responsible registry operations supporting stable, predictable availability of the namespace.
2. Sustainability of the Purpose Over Time
The partnership of professionals is one of the oldest continuously operating business structures in commerce. .firm bundles individual reputations into a shared name, distributes liability and standards across partners, and outlasts any single practitioner. Partners retire and join, but the firm endures, and its name carries forward the trust it has accumulated.
.firm occupies the space between broad business extensions and profession-specific labels. Where a generic address says nothing about structure and a single-profession suffix can box a practice in, .firm communicates standing and collective accountability while staying open to any discipline. It is positioned as the identity choice for practices that want their name to carry the weight of an established partnership.
Bar associations, accountancy and audit bodies, engineering and architecture boards, and financial regulators license, insure, and discipline at the level of the practice as well as the individual. Referral networks, professional indemnity arrangements, and client procurement processes are all organized around the firm as the contracting party. New advisory disciplines keep emerging (cybersecurity, sustainability assurance, data governance, regulatory strategy), and each tends to organize into practices once the work demands specialization and collective standing.
The label adapts to whatever expertise is being offered while the underlying arrangement, experts joined under one accountable name, stays constant. This is why the word has survived shifts in industry, geography, and generation: it names a way of organizing professional trust, not a passing category of service.
§ 3 — Commitments and safeguards Q164–Q188
| More trustworthy, consumer risk, regulated sector, government reporting, harm, government function Q164–Q169 | Yes to: more trustworthy (Q164) |
|---|---|
| Voluntary Safeguard PICs Q170·Q171 | |
| Registry Voluntary Commitments Q172·Q173 | None · 5 do |
| Code of Conduct exemption requested Q185·Q188 | No |
§ 4 — All other published answers
Every other answer ICANN published for this application, in the order of the form. Contact details (Q17–Q24) are left to the ICANN record.
Q199Q2.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO, and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE) of the applying entity, the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC2.2-1.1 - As of the submission date of the application, the applying entity is a current registry operator or an affiliated entity of a current registry operator with one or more active Registry Agreements (RA). SC2.2-1.2 - The applying entity and/or a QPE will fund the startup and long-term operation of all of the applying entity’s current gTLDs and applied-for gTLD strings. SC2.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.
Q2.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO, and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE) of the applying entity, the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC2.2-1.1 - As of the submission date of the application, the applying entity is a current registry operator or an affiliated entity of a current registry operator with one or more active Registry Agreements (RA). SC2.2-1.2 - The applying entity and/or a QPE will fund the startup and long-term operation of all of the applying entity’s current gTLDs and applied-for gTLD strings. SC2.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.
Answered with a document. Attachments are not published by ICANN.
Q200Q2.3-1 - Provide a document with a list of all of the applying entity’s current gTLDs and a list of all gTLDs for entities affiliated with the applying entity (if applicable).
Q2.3-1 - Provide a document with a list of all of the applying entity’s current gTLDs and a list of all gTLDs for entities affiliated with the applying entity (if applicable).
Answered with a document. Attachments are not published by ICANN.
Q220Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.
Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.
Answered with a document. Attachments are not published by ICANN.
Q221Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.
Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.
Answered with a document. Attachments are not published by ICANN.
Q121As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.
As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.
true
Q223By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
true
Q224By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
true