ActorStack.dev

Why .io, .ai and .co are missing from every zone-file tool

Country-code TLDs are run outside ICANN's contracts, so their zone files are not available through the zone data service at any price. The gap matters most in exactly the namespaces a startup cares about.

By Oswaldo Carabano6 min read

Short answer

Country-code top-level domains such as `.io`, `.ai`, `.co`, `.me`, `.tv` and `.cc` are operated under agreements with their own national authorities rather than under ICANN's generic TLD contracts, so their zone files are not distributed through ICANN's zone data service at any price. No level of approval brings them into coverage, because the service they would come from does not cover them. That gap lands precisely where it hurts: those are the TLDs a startup expects to check, and a squatter looking for an unwatched namespace has the same information. Any report built on gTLD zone data should state the boundary rather than let an empty result imply a clean namespace.

Key points

  • Country-code top-level domains are operated under agreements with national authorities rather than ICANN's generic TLD contracts, which is why their zone files are not distributed through the zone data service.
  • No level of approval brings `.io`, `.ai` or `.co` into coverage, because the service those files would come from does not cover country-code TLDs at all.
  • The gap falls on exactly the namespaces a startup checks first, which is why stating it up front beats letting an empty result imply availability.
  • For brand protection the gap is adversarial rather than incidental: a squatter looking for an unwatched namespace has the same map of what is monitored.
  • Coverage of 1,075 gTLDs and 255,631,856 delegated domains is real and large, and it is still a defined subset rather than the whole DNS.
  • A report built on gTLD zone data should name the boundary in its own text, because a reader cannot infer a missing namespace from rows that are not there.
On this page5 sections

The gap in this data is not random. It falls almost exactly on the namespaces a technology company cares about most.

Two kinds of top-level domain

Generic top-level domains — .com, .net, .org, .app, .dev, .shop and roughly a thousand others — run under contracts with ICANN. Country-code top-level domains run under arrangements with national authorities: .io, .ai, .co, .me, .tv, .cc, .uk, .de, and every other two-letter suffix.

Why the country-code files are not available

ICANN's zone data service distributes zone files under the generic TLD contracts. A country code operator is not party to those contracts, so there is nothing for the service to distribute — this is not a pricing tier or an approval level, and no amount of requesting changes it.

Which TLDs this actually removes

CoveredNot covered
.com, .net, .org, .info, .biz.io, .ai, .co, .me
.app, .dev, .cloud, .shop, .store.tv, .cc, .uk, .de
.xyz, .top, .online, .site — 1,075 in allEvery other country-code TLD, without exception

Coverage is 255,631,856 delegated domains, and it is not evenly spread even inside the covered set: .com alone is 166 million of that total, and 481 of the 1,075 TLDs hold fewer than a thousand domains each. Breadth catches the obscure case; it does not double the volume.

Why the gap is worst for brand protection

For a typosquat sweep the missing namespaces are not incidental — they are adversarial. A squatter choosing where to register has the same public information about which zones are watched, and a homograph domain in a country-code TLD is a well-known choice. A clean sweep across 1,075 gTLDs is real news and it is not the whole news.

Stating the boundary in a report

A reader cannot infer a missing namespace from rows that are not there. If a report says “no lookalike domains found”, it should say across what — and pair the gTLD sweep with a tool that can test country-code candidates, such as a permutation engine.

Frequently asked questions

Why can't I check .io domains with a zone-file tool?
Because `.io` is a country-code top-level domain, operated under an agreement with its own national authority rather than under ICANN's generic TLD contracts. Its zone file is not distributed through ICANN's zone data service, so no approval level makes it available.
Which popular TLDs are missing?
`.io`, `.ai`, `.co`, `.me`, `.tv` and `.cc` are the ones that come up most, along with every other country-code TLD. The covered set is 1,075 generic TLDs including `.com`, `.net`, `.org`, `.app`, `.dev`, `.shop` and `.xyz`.
Does an empty result mean my brand is safe?
Only within the covered namespaces. An empty result says nothing was found across 1,075 gTLDs, and it says nothing at all about country-code TLDs, which is why the boundary belongs in the report rather than in a footnote.

Sources

Every URL below was requested and returned a page on the date shown.

  1. Law or regulatorchecked 18 Sept 2026
    Root Zone Database — the delegation record for every TLDIANA
  2. Platform docschecked 18 Sept 2026
    Centralized Zone Data ServiceICANN
  3. Law or regulatorchecked 18 Sept 2026
    Registry Reports — monthly per-TLD transaction and domain countsICANN
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsExplainer

What a zone file contains

A zone file is a delegation record: which domains exist in a TLD and where each one points its nameservers. It holds no registrant, no registrar, no dates and none of the domain's own records — and knowing that is what makes the six zone-file Actors readable.

7 min
A white shuttered window on a peach-coloured building with a for-sale notice beside it.
DomainsGuide

Bulk availability without WHOIS

Screening a naming shortlist against zone files instead of querying WHOIS per name: what it costs, what the verdicts mean, and where the method stops being enough.

7 min
A row of residential mailboxes on posts in front of a wooden fence and trees.
DomainsGuide

Detecting domain hijacking

Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.

7 min