A domain on a country-code extension is a lease from a government, not a purchase. That is true, widely under-appreciated, and usually explained badly. The scary version of this argument says.io could vanish in five years. The evidence says otherwise, and the real risks are duller and more expensive than a shutdown.
Do you actually own your.io or.ai domain?
No, and you do not own a.com either. Every domain is a renewable registration, not property. What makes country-code extensions different is who ultimately controls the registry: a national government or its delegate, whose authority derives from the territory existing on the ISO 3166-1 country list.
RFC 1591, written in 1994, set the tone by describing domain managers as trustees with a duty to serve the community, and calling concerns about ownership inappropriate. That framing still governs how the system is administered.
What actually happens when a country stops existing
This is where most coverage of the topic goes wrong. There is a formal policy, it is recent, and it is slower than the headlines suggest.
When a code leaves ISO 3166-1, the corresponding extension becomes ineligible and ICANN's IANA function issues a Notice of Removal. The default period after that notice is five years. Managers can request an extension of up to five more, taking the outside case to ten years, and the criteria for granting it include material problems that cannot be mitigated inside the default window.
Two facts change how you should read that. First, this policy was only approved in 2022. The retirements people cite as precedent,.yu for Yugoslavia and.an for the Netherlands Antilles, happened under ad hoc practice rather than under this framework. Second, and more importantly, the clock starts when ICANN chooses to issue the notice, not when the country disappears.
The case that undercuts the panic
.SU was assigned to the Soviet Union in 1990. The code left ISO 3166-1 in 1992. The extension is still resolving in 2026, still has roughly 112,000 registrations, and its retirement is now scheduled for 2030.
That is 38 years between the country ceasing to exist and the extension being switched off, and the last stretch of it under a policy specifically written to end exactly this situation. Attempts to retire it earlier were deferred under pressure from registrants and Russian interests.
The lesson is not that ccTLDs are safe. It is that retirement is a political negotiation with a very long fuse, and that a registry with a large, vocal, commercially significant user base has considerable use to extend it..io has GitHub Pages, Docker, crates.io and Kubernetes registry endpoints hardcoded across millions of systems. If the extension criteria mean anything at all, that is the strongest possible case for the maximum extension.
The risk that is actually likely: price
Sovereign shutdown is the dramatic risk and the improbable one. Pricing use is the boring risk and the near-certain one.
.ai illustrates it. Anguilla's registry income went from single-digit millions in 2018 to a scale the IMF has described as a substantial share of total government revenue, on the back of the AI naming rush. Wholesale pricing has risen and minimum registration terms have lengthened. None of that requires bad faith. It is what any registry does once a cohort of well-funded companies has made its extension part of their brand and their infrastructure.
You are not exposed to a 38-year retirement timeline. You are exposed to renewal pricing set by an operator who knows migration would cost you more than the increase.
What the usual advice gets wrong
"Register the.com defensively" is sensible and insufficient. Holding the.com does nothing about the hardcoded references, the API endpoints, the OAuth callbacks, the email history and the accumulated links that make a migration expensive. The defensive registration protects the brand. It does not reduce the switching cost, which is the thing the registry is pricing against.
A few things that help more:
Separate the brand from the infrastructure. Marketing on a ccTLD is a small, reversible bet. API endpoints and package registries on a ccTLD are the expensive kind of dependency. Keep the second on an extension you consider boring.
Do not hardcode a domain where a variable will do. Most of the cost in a domain migration is not DNS. It is the references you cannot find.
Price the renewal, not the shutdown. When you model a ccTLD dependency, model the operator doubling the price at renewal, because that is the scenario with real probability behind it.
Frequently asked questions
Could.io really be retired?
Only if the code leaves ISO 3166-1, and then only after a Notice of Removal starting a five-year clock that can be extended to ten. Given the infrastructure dependency, a maximum extension is the likely outcome. The UK and Mauritius Chagos arrangement that raised the question has not resolved the underlying status either way.
Is a gTLD like.com actually safer?
Safer from sovereign risk, yes, because no country's existence is load-bearing. Not risk-free: gTLD registries operate under ICANN contracts that get renegotiated, and price caps on several extensions have been loosened in recent years. The risk changes shape rather than disappearing.
What happens to my site if an extension is retired?
You would have years of notice and would need to migrate, which for a content site is a redirect exercise with measurable SEO cost, and for infrastructure is considerably harder. The WooCommerce move to woo.com and back is the usual cautionary example of migration costing more than expected.
Should I avoid ccTLDs entirely?
No. Country extensions are often the right answer, particularly for a business genuinely operating in that country, where a local extension carries trust a generic one does not. The mistake is treating a novelty extension as neutral infrastructure because the name was available.
If you are weighing provider attributes you cannot verify yourself,what green verification actually provescovers the same problem from the other side.
Follow HostList for new rankings, original research, and changes across the hosting industry.



