.dev
also HSTS-preloaded and developer-associated, without the file-extension collision risk that .zip carries
The .zip extension is a generic top-level domain delegated in 2014 and opened for public registration in May 2023. It is run by Charleston Road Registry, Google's registry arm, and is best known as the file-compression format rather than a web address.
Anyone can register a .zip domain on a first-come, first-served basis. The registry requires HTTPS on every .zip site, so factor an SSL certificate into your setup before you commit to a name.
verified against the linked source not verified, not inferred from another extension sources disagree
| Provider | Registration | Renewal | Transfer |
|---|---|---|---|
| OpenproviderNon-member prices | Check providerNo current public quote | Check providerNo current public quote | Check providerNo current public quote |
| AI VikingsPublic price list | $11.251 year totalChecked 2026-09-20 · source 2026-09-19 | $12.97Listed price · confirm termChecked 2026-09-20 · source 2026-09-19 | $11.85Transfer fee · confirm termChecked 2026-09-20 · source 2026-09-19 |
| PorkbunPublic API prices | $10.811 year totalChecked 2026-09-20 | $10.811 year totalChecked 2026-09-20 | $10.81Transfer fee · confirm termChecked 2026-09-20 |
| Name.comPublic retail prices | $16.991 year totalChecked 2026-09-20 | $18.991 year totalChecked 2026-09-20 | $16.99Transfer fee · confirm termChecked 2026-09-20 |
| DynadotRegular account prices | $10.921 year totalChecked 2026-09-20 | $10.921 year totalChecked 2026-09-20 | $10.92Transfer fee · confirm termChecked 2026-09-20 |
| AtomPublic retail prices | $11.001 year totalChecked 2026-09-20 | $11.001 year totalChecked 2026-09-20 | $10.80Transfer fee · confirm termChecked 2026-09-20 |
| CloudflareAt-cost registry prices | Check providerNo current public quote | Check providerNo current public quote | Check providerNo current public quote |
| GoDaddyPublic retail prices | $19.991 year totalChecked 2026-09-20 | $19.991 year totalChecked 2026-09-20 | Check providerNo current public quote |
Advertised prices for standard names, not an availability check. USD as published; taxes and final fees are confirmed at the provider. How we compare All 61 extensions
.zip is run by Charleston Road Registry Inc., the sponsoring organisation named in the IANA delegation record. That's Google's own registry arm: the administrative and technical contacts sit under Google Inc., and the name servers run on Google infrastructure under charlestonroadregistry.com. No separate third-party backend provider gets a mention in the sources we checked.
The contract itself sits with ICANN, which signed a base, non-sponsored Registry Agreement with Charleston Road Registry on 8 May 2014, as recorded on the ICANN registry agreement page. ICANN handles the rules every gTLD operator has to follow. Google Registry, through Charleston Road Registry, writes the .zip-specific policy on top of that, including the mandatory HTTPS notice laid out on its registration policy page.
Three roles matter here if you're buying a .zip domain. The registry, Charleston Road Registry, keeps the master database of .zip names and sets the rules for the whole namespace. The registrar is the separate accredited company, GoDaddy, Namecheap, whichever you pick, that actually sells you the domain and lets you manage it. The registrant is you: the name and contact details on the registration. These are three distinct entities, and swapping registrars changes nothing about who runs the registry underneath.
.zip has no eligibility restriction. Anyone, anywhere, can register one, first come first served, as confirmed by GoDaddy's help documentation. No residency requirement, no trademark, no need to belong to a particular industry or profession.
The registry does put conditions on certain name types, not on registrants themselves. If you register a two-character letter/letter ASCII label, you can't misrepresent an affiliation with a government or country-code manager where none exists, per the .zip Domain Registration Policy. Names on the IOC, Red Cross and IGO reserved names list can only be registered on behalf of the relevant organisation. These are registry rules, binding on every registrar.
Separately, the registry runs a premium pricing policy for certain names, so some strings cost more than the standard rate, as set out in the .zip Pricing Policy. That's a pricing tier, not a barrier to entry, but it changes what a given name actually costs at checkout. Individual registrars might add their own verification steps at the point of sale, but that's registrar practice, not registry rule.
Transferring a .zip domain works the same way as any other EPP-based transfer. You get the authorisation code from your current registrar, unlock the domain, then hand that code over to the new one. Namecheap supports RegistrarLock for .zip, and standard ICANN transfer rules apply on top, including the 60-day lock that kicks in after initial registration or after a change of registrant. ICANN has voted to scrap that lock in a future policy update, but it isn't live for .zip yet, so don't plan around it.
Registration terms run from 1 to 10 years, though renewals are usually capped lower than that. Namecheap, for instance, caps renewals at 9 years. Grace and redemption periods differ by registrar too: Hosterion quotes up to 45 days grace after expiry plus a 30-day redemption quarantine, while Gandi publishes a 45-day late-renewal window followed by a restore period that carries a noticeably steeper first-year fee. None of this comes from a single registry-wide policy, it's registrar-reported, so treat the exact day counts and restore fees as a guide rather than gospel.
One gap worth flagging: Google Registry doesn't publish one clear page laying out grace, redemption and restore periods for .zip directly. Check the actual numbers with whichever registrar you're using before you rely on them.
.zip is a good fit for a narrow slice of buyers and a bad fit for almost everyone else. The registry markets it at developers and people chasing a short, technical-sounding name, and Google's own showcase leans the same way, hadi.zip, a personal site belonging to an Android developer, being the example they lead with. That's the context where the string reads naturally rather than as a mismatch: developer tools, personal tech projects, code-adjacent side projects.
Scenario one: a developer wants a personal site for notes and open-source work. A short .zip name works fine here, the audience already knows the string is a domain rather than a file, and the HTTPS requirement is a minor extra step rather than anything that stops people at the door.
Scenario two: a SaaS product built around file compression or storage, the kind of use case registrar marketing copy from providers like 101domain likes to push. Looks appealing on paper. In practice it sits uncomfortably close to the riskiest pattern security researchers have documented: names like microsoft-office.zip and similar brand-mimicking strings have already turned up in phishing campaigns. A legitimate compression tool trying to earn trust in that exact namespace has to work harder than it should have to.
Scenario three: a consumer brand, an e-commerce shop, anything sent out by email or chat to a general audience. This is where .zip fits worst. One comparison source we checked flags file-extension collision risk for .zip that .com, .app and .dev simply don't carry, and consumer contexts are precisely where that confusion gets exploited. For that audience, a boring, unambiguous extension is the safer editorial call, not just a matter of taste.
Google Registry's own showcase list isn't long. Hadi.zip, an Android developer's personal site, is one of the few genuine examples it points to. Download.zip used to be on that list too, a curated-download newsletter run by creator David Imel, but a third-party review couldn't reach the site at the time of checking, so file that one under "used to exist" rather than a working example today. Outside the registry's own picks, researchers at DNS Research Federation and Gen Digital have both written up .zip domains turning up in phishing runs that mimic file names such as invoices or software updates, and that's coloured how a lot of the wider internet now reads the string.
Get HTTPS sorted before you go live. The registry mandates it, and .zip sits on the HSTS preload list, so without a valid SSL certificate the domain simply won't load in a modern browser, no insecure warning page, nothing at all. That's a stricter bar than most gTLDs set. On email: .zip text inside messages or chat apps can turn itself into a clickable link automatically, which is worth remembering before you type one out casually in a message.
It suits a primary domain for developer tools and personal sites, where the audience already reads technical branding without blinking, and it's a shakier pick as a redirect target for a consumer brand. One naming rule worth following: stay away from anything that echoes a common filename or software title, invoice, update, that sort of thing, because that's the exact pattern already linked to abuse.
also HSTS-preloaded and developer-associated, without the file-extension collision risk that .zip carries
same Google Registry HTTPS enforcement model, aimed at app and product launches rather than a compression-format association
well-established developer and tech-startup convention with wide name recognition, at a different cost structure
the default for consumer-facing brands and e-commerce where avoiding any file-extension confusion matters most
a plainer alternative for storage, backup or file-sharing services without evoking a specific compressed-file format
Google Registry put .zip on the HSTS preload list, and that list is baked directly into the browser code. Practically speaking, that means Chrome, Firefox and the rest will flat-out refuse to load a .zip site over plain HTTP. No warning page, no click-through, it just won't render. So unlike an older extension where HTTPS is a nice-to-have, here a certificate isn't optional at all. Registrars are required to tell you this before you hand over your money.
Sources: registry.google
Anyone, anywhere, can register on a first-come, first-served basis. There's no nationality restriction and no industry restriction stated. The one catch: two-letter labels, or names that appear on the IOC, Red Cross or IGO reserved list, come with specific representations attached under the registry's policy.
Sources: godaddy.com, registry.google
Yes, this genuinely happened. Independent research from the DNS Research Federation and Gen Digital documented .zip domains being used shortly after public launch to mimic file names such as invoices or software updates, exploiting the confusion between a file extension and a domain extension. The registry's own HTTPS requirement covers transport security. It does nothing for this naming-confusion problem, because that was never what it was designed to fix.
Sources: dnsrf.org, gendigital.com
Facts on this page were checked against the sources below on 2026-09-17. Prices come from the public sources described in the methodology and carry their own check dates. Registry facts and retail prices are refreshed on different schedules.
HostList does not sell domains and earns nothing from the provider links on this page. Report a correction.