The gap in this data is not random. It falls almost exactly on the namespaces a technology company cares about most.
Two kinds of top-level domain
Generic top-level domains — .com, .net, .org, .app, .dev, .shop and roughly a thousand others — run under contracts with ICANN. Country-code top-level domains run under arrangements with national authorities: .io, .ai, .co, .me, .tv, .cc, .uk, .de, and every other two-letter suffix.
Why the country-code files are not available
ICANN's zone data service distributes zone files under the generic TLD contracts. A country code operator is not party to those contracts, so there is nothing for the service to distribute — this is not a pricing tier or an approval level, and no amount of requesting changes it.
Which TLDs this actually removes
| Covered | Not covered |
|---|---|
.com, .net, .org, .info, .biz | .io, .ai, .co, .me |
.app, .dev, .cloud, .shop, .store | .tv, .cc, .uk, .de |
.xyz, .top, .online, .site — 1,075 in all | Every other country-code TLD, without exception |
Coverage is 255,631,856 delegated domains, and it is not evenly spread even inside the covered set: .com alone is 166 million of that total, and 481 of the 1,075 TLDs hold fewer than a thousand domains each. Breadth catches the obscure case; it does not double the volume.
Why the gap is worst for brand protection
For a typosquat sweep the missing namespaces are not incidental — they are adversarial. A squatter choosing where to register has the same public information about which zones are watched, and a homograph domain in a country-code TLD is a well-known choice. A clean sweep across 1,075 gTLDs is real news and it is not the whole news.
Stating the boundary in a report
A reader cannot infer a missing namespace from rows that are not there. If a report says “no lookalike domains found”, it should say across what — and pair the gTLD sweep with a tool that can test country-code candidates, such as a permutation engine.



