ActorStack.dev

How ICANN's zone data service works, and what the agreement forbids

Access to gTLD zone files is granted one TLD at a time, by each registry operator, under an agreement that shapes what a product built on the data is allowed to look like.

By Oswaldo Carabano7 min read

Short answer

ICANN's Centralized Zone Data Service is the single request point through which a researcher asks each generic top-level domain's registry operator for access to its zone file. Approval is per TLD and per registry rather than blanket, which is why coverage of 1,075 gTLDs is an accumulation of individual approvals rather than a subscription tier. The agreement behind that access constrains the product as much as it enables it: handing over a substantial portion of a zone is forbidden, and querying registries at scale is prohibited, which is why every one of these Actors is anchored on an input the operator supplies and why none of them makes a WHOIS or RDAP lookup to resolve an ambiguity.

Key points

  • ICANN's Centralized Zone Data Service is a request point, not a data source: each generic top-level domain's registry operator approves or refuses access to its own zone.
  • Approval is granted one TLD at a time, so coverage of 1,075 gTLDs is an accumulation of individual approvals rather than a subscription level.
  • The agreement forbids handing over a substantial portion of a zone, which is why every Actor built on this data requires an anchoring input and has no whole-namespace mode.
  • Querying registries at scale is prohibited under the same agreement, which is why none of these Actors resolves an ambiguity with a WHOIS or RDAP lookup.
  • ICANN does not endorse, sponsor or review a tool built on zone data, and a product that implies otherwise is misrepresenting the arrangement.
  • Country-code top-level domains are outside ICANN's contracts entirely, so no amount of approval brings `.io`, `.ai` or `.co` into coverage.
On this page5 sections

The constraints on this data are more interesting than the data, because they decide what a product built on it is even allowed to look like.

A request point rather than a data source

ICANN's Centralized Zone Data Service is where a researcher asks for access. It does not hold the zones. Each request is routed to the registry operator that runs that top-level domain, and that operator decides. ICANN provides the counter, not the goods.

Approval comes one TLD at a time

There is no plan that unlocks everything. Access to .com is one decision by one operator; access to .shop is another decision by another. Coverage of 1,075 generic top-level domains is therefore an accumulation of individual approvals rather than a subscription level — which is also why it grows unevenly and why some namespaces will never be in it at all.

What the agreement forbids

Two restrictions shape everything downstream:

  • No substantial portion of a zone may be handed on. Access is for research and analysis, not for redistribution.
  • Registries may not be queried at scale. Which rules out resolving a zone-file ambiguity with a WHOIS or RDAP lookup, however convenient that would be.

How a constraint becomes a product shape

A policy note saying “do not request too much” would put the restriction on the operator. Instead every one of the six Actors is built with no input that could express such a request. A brand sweep needs a brand. An availability screen needs a candidate list. A monitor needs a domain list or a filter, and the look-back window is capped at 90 days with no “since forever” option to reach for.

Attribution, and what ICANN does not do

The data is sourced from the Registry Operators' own zone files, obtained through ICANN's Centralized Zone Data Service under agreement with those operators. ICANN does not endorse, sponsor or review any Actor built on it. Access under an agreement is not approval of the product, and a tool implying otherwise is misrepresenting the arrangement.

Frequently asked questions

What is ICANN's Centralized Zone Data Service?
It is the single point through which a researcher requests access to a generic top-level domain's zone file. The request goes to that TLD's registry operator, which decides on it, so the service routes requests rather than holding the data itself.
Why is coverage 1,075 TLDs and not all of them?
Because approval is granted one TLD at a time by each registry operator. Coverage is an accumulation of individual approvals over time, which is also why it grows unevenly rather than in tiers.
Why can't an Actor return a whole zone?
Because the agreement behind the data forbids handing over a substantial portion of a zone. Rather than rely on a policy note, the Actors are built with no input that could express such a request: every run is anchored on a brand, a candidate list, a nameserver or a filter the operator supplies.
Does ICANN endorse tools built on zone data?
No. ICANN does not endorse, sponsor or review a product built on zone file access, and the attribution is published on every Actor for that reason. Access under an agreement is not an endorsement of what is built with it.

Sources

Every URL below was requested and returned a page on the date shown.

  1. Platform docschecked 18 Sept 2026
    Centralized Zone Data ServiceICANN
  2. Law or regulatorchecked 18 Sept 2026
    Root Zone Database — the delegation record for every TLDIANA
  3. Law or regulatorchecked 18 Sept 2026
    Registry Reports — monthly per-TLD transaction and domain countsICANN
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsExplainer

What a zone file contains

A zone file is a delegation record: which domains exist in a TLD and where each one points its nameservers. It holds no registrant, no registrar, no dates and none of the domain's own records — and knowing that is what makes the six zone-file Actors readable.

7 min
A white shuttered window on a peach-coloured building with a for-sale notice beside it.
DomainsGuide

Bulk availability without WHOIS

Screening a naming shortlist against zone files instead of querying WHOIS per name: what it costs, what the verdicts mean, and where the method stops being enough.

7 min
A row of residential mailboxes on posts in front of a wooden fence and trees.
DomainsGuide

Detecting domain hijacking

Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.

7 min