Snapshot of 8 October 2026 · ICANN APS, public fields

Applications / .tap / TPL2697T-T31121 · published by ICANN 7 October 2026 · snapshot 2026-10-08

.tap

Brand TLD · Spec 13Active

TAPTAP PTE. LTD., SG Q1·Q25

Ultimately controlled by XD Inc., YIMENG HUANG Q108 · ICANN record ↗

§ 1 — Meaning of the string Q118·Q120

"Tap" is an English word meaning: (1) a light strike or touch; (2) a device for controlling liquid flow (faucet); (3) to intercept or draw from a resource.

/tæp/

§ 2 — Mission and purpose Q133

I. Mission and Objectives As the applying entity and potential Registry Operator of ".tap", our mission is to build a unified digital identity system for our Group, serving both internal management and external brand interaction. Through centralized management, we will drive standardized development of business units, establish trusted digital connections with global customers and partners, and provide solid digital support for our globalization strategy.

Our objective is to make ".tap" our exclusive, authoritative digital identity and a digital bridge for brand interaction and value delivery with global customers and partners. Registration rights are limited to headquarters, wholly-owned subsidiaries, majority-controlled subsidiaries, VIE-controlled entities, and other affiliates, ensuring unified, compliant use of global brand domains. By holding our domains, we will build a secure, trustworthy digital network supporting internal collaboration and customer marketing, service, and brand community building, ultimately preserving brand equity and improving digital efficiency and brand influence.

II. Intended Registrants Intended registrants are limited to our Group and our various subordinate entities, including the headquarters, wholly-owned subsidiaries, majority-controlled subsidiaries, VIE-controlled subsidiaries, and other affiliated entities.

III. Intended Users Intended users include Group employees, authorized external partners, global customers, and end consumers. Through dedicated domains, they will access internal systems and external platforms. The goal is to ensure secure, efficient, and trustworthy information flow both internally and externally, building a controlled yet open brand digital ecosystem.

IV. Relevant Activities We will use ".tap" as our global brand TLD to integrate the digital identities of all core operating entities and consolidate internal domain systems, centralizing brand assets. It will also serve as our unified external brand domain window, where all official marketing, customer service, and brand interaction platforms use ".tap" to create a consistent digital brand identity.

Relying on ".tap", we will establish a unified digital operations and brand governance system, using standardized domain structures and naming conventions to regulate IT resource access and create a traceable, auditable domain management mechanism. We will define application processes, naming rules, and usage restrictions for different registrants to ensure all domain usage complies with our brand security and compliance requirements.

To support our globalization vision, we will use our unified domain architecture to connect global branches, partners, and customers, leveraging ".tap" for consistent brand marketing, customer engagement, and community building worldwide to boost brand recognition and user loyalty. We will deploy ".tap" uniformly across regions, with internal technical support ensuring consistent global resolution and management, providing marketing teams with unified digital tools.

V. Statement of Long-Term Sustainability We have built a broad business network and large user base. Our market position and physical footprint provide stable, long-term demand for the domain. As a core brand asset, ".tap" is aligned with our brand strategy, and sustained brand value growth drives our domain operations.

As the Group's internal dedicated registry, we operate with a professional team, adequate funding, and a comprehensive system, covering all costs from our own funds without relying on external revenue, ensuring long-term financial sustainability and alignment with business needs.

We will comply with ICANN and global rules, enforce brand security standards, maintain operational and technical compliance to mitigate risks and preserve domain credibility, thereby providing a secure, long-term digital platform for our Group's global strategy and brand building.

§ 3 — Commitments and safeguards Q164–Q188

More trustworthy, consumer risk, regulated sector, government reporting, harm, government function Q164–Q169Yes to: more trustworthy (Q164), consumer risk if abused (Q165)
Voluntary Safeguard PICs Q170·Q171

• Registry Operators will include a provision in their Registry-Registrar Agreements that requires Registrars to include in their Registration Agreements a provision requiring registrants to comply with all applicable laws, including those that relate to privacy, data collection, consumer protection (including in relation to misleading and deceptive conduct), fair lending, debt collection, organic farming, disclosure of data, and financial disclosures. • Registry Operators will include a provision in their Registry-Registrar Agreements that requires registrars at the time of registration to notify registrants of the requirement to comply with all applicable laws. • Registry Operators will include a provision in their Registry-Registrar Agreements that requires Registrars to include in their Registration Agreements a provision requiring that registrants who collect and maintain sensitive health and financial data implement reasonable and appropriate security measures commensurate with the offering of those services, as defined by applicable law.

Registry Voluntary Commitments Q172·Q173None · 5 do
Brand TLD criteria confirmed, trademark certificate attached Q180·Q181Yes · certificate not published
Confirms the string is not a “generic string” Q183Yes
Spec 11 §3(d) statement Q184

The applying entity confirms that the planned operation of the ".tap" TLD fully complies with the requirements of Section 3(d) of Specification 11 of the Registry Agreement and there would not exist any such conflict. The reasons are as follows:

I. ".tap" is a brand string and is not subject to Specification 11, Section 3(d) According to the explicit definition in Section 3(d) of Specification 11, the restrictive provisions therein apply only to generic strings, i.e., strings consisting of a word or term that denotes or describes a general category of goods, services, groups, organizations, or things. ".tap" is a clear brand string based on the following grounds: 1.”tap” is a registered trademark that refers to specific products and services provided by TAPTAP PTE. LTD. and its affiliates, and is not a generic term for a particular class of goods or industry. 2. This application is submitted under the application category established by ICANN for brands, which is specifically designed to allow brand owners to operate an exclusive domain name space consistent with their trademarks. Therefore, the provision in Section 3(d) of Specification 11 regarding the prohibition of restricting registration eligibility to a single entity or its affiliates does not apply in this application.

II. The operational model is consistent with the purpose of brand TLD and ICANN policies As a brand TLD, ".tap" will be operated as follows: 1.The TLD will serve as a dedicated digital asset for internal use by TAPTAP PTE. LTD. Registration eligibility will be limited to the Group and its various subordinate entities, including the headquarters, wholly-owned subsidiaries, majority-controlled subsidiaries, VIE-controlled entities, and other affiliated entities. 2.Within the above scope of use, clear and transparent registration and management policies will be established, ensuring that all eligible affiliated entities can register and use domains fairly and in accordance with a unified internal governance process. 3.This registration model restricts domain name users to known and trustworthy legal entities, effectively reducing the risk of DNS abuse and meeting the security and stability requirements of the domain name system.

In summary, as a brand string, the operation of ".tap" is a normal use of a brand TLD and is not subject to the restrictions of Specification 11, Section 3(d). We will operate the TLD as described above and ensure its continued compliance with the relevant provisions of the Registry Agreement.

§ 4 — All other published answers

Every other answer ICANN published for this application, in the order of the form. Contact details (Q17–Q24) are left to the ICANN record.

Q212Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.

Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.

Answered with a document. Attachments are not published by ICANN.

Q220Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.

Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.

Answered with a document. Attachments are not published by ICANN.

Q221Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.

Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.

Answered with a document. Attachments are not published by ICANN.

Q121As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.

As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.

true

Q223By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

true

Q224By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

true