Protected: For it.com New gTLD 2026 Applicants…

This content is password-protected. To view it, please enter the password below.

Posted in Uncategorized | Enter your password to view comments.

I Almost Helped a Scammer Take Over My Google Account

I had a close call today, and I want to explain what happened because the scheme was much more convincing than the usual phishing attempt. Nothing was ultimately hacked, and I did not lose control of my email. I did not click the link, approve the request, or give anyone a verification code. Still, the sequence of events was believable enough that I could understand how someone could fall for it.

A real email from Google does not mean the person calling you works for Google.

It started when I received an email security alert that came from Google. The subject line was, “Security alert for [email protected].” The message stated that my email address had been set as the recovery email for that Gmail account. I do not know Brian McCabe, and I did not recognize the email address, so I ignored it.

The message said that the recovery email for Brian’s account had been changed and that the account holder should review the activity if the change was not authorized. It included a link to Google’s account notification page. I did not click it, but at that point, I viewed the message as strange rather than immediately dangerous.

Shortly afterward, I received an automated telephone call asking whether I had attempted to change my recovery email. That caught my attention because it seemed connected to the Google message I had just received. I acknowledged that I did not try to change my recovery email by pressing 1.

Then I received another call, this time from a live person who said he was calling from Google. The person was very articulate, intelligent-sounding, and convincing.

He told me that the recovery email on my own Google account had been changed. He claimed that the Brian McCabe Gmail address had been added as the recovery address for my account and that once he verified my account, they could correct it. The problem was that this was not what the email said. The very slight nuance was a bit confusing.

The email said that my address had been added as the recovery email for Brian’s account. The caller was saying that Brian’s address had been added to mine. Those are two different events, and the contradiction immediately bothered me.

The caller then asked me to open the Google app on my phone and approve something. I told him that I was not comfortable approving a request based on an incoming telephone call. Anyone can call you and claim to represent Google, your bank, or another company.

Then, when I turned down that request, he sent me a text message containing a six-digit code from Google. The caller asked me to read the code back to him. I refused. At this point, I became fairly certain that he was trying to access my account and needed me to complete a security step he could not complete himself.

Any time you feel rushed, pressured, or even a hint of discomfort that something doesn’t feel right, TRUST YOUR INSTINCT!

The caller then tried to increase the pressure. He claimed that the person attempting the change had provided my Social Security number. He said that if I did not verify my identity, the change to my recovery email would likely go through. That statement made even less sense. Google does not normally resolve account security issues via unsolicited phone calls that involve Social Security numbers.

I did not click anything in the email. I did not approve the request in the Google app. I did not provide the six-digit code, nor did I give the caller any personal information. I told him that his explanation did not match the email I had received and that I was not going to take action based on an unsolicited call.

The email, app message, and text messages ALL actually came from Google! But they were prompted by actions from a scammer.

After looking more closely at the email header, it appears that the original email was actually sent by Google. The sending servers and authentication records looked legitimate. That is what made the scheme more sophisticated.

My best understanding is that the attacker may have added my email address as the recovery address for a Gmail account he controlled. That action could have caused Google to send me a genuine security notification. He then called me and cited a real Google message to make his story sound credible.

While he had me on the phone, he may have initiated a login attempt, an account recovery process, or a security change involving my account. That could have caused Google to send the prompt and the six-digit code. In other words, he may not have been impersonating Google through email at all. He may have been manipulating Google’s real systems to generate messages and codes, then trying to convince me to complete the process for him.

That is the part people need to understand. The attacker did not necessarily need to break Google’s security. He needed to convince me to bypass it and allow him to change my recovery email to one that he controlled. By doing that, he would be able to access my email account, change the password, and lock me out.

I changed my Google password afterward and reviewed my recent security activity. I checked the devices signed into my account, my recovery email and phone number, my passkeys, and my two-step verification settings. I also reviewed Gmail forwarding, filters, and delegation settings to make sure nothing unfamiliar had been added. Because my account has Google Workspace administrative access, I reviewed those settings as well.

I found no evidence that the attacker succeeded.

My advice is to trust your discomfort when something does not add up. The caller sounded calm and professional until I refused his requests. The timing of the calls made him appear connected to the email. The email itself may have been genuine. But the story the caller told me did not exactly match the message I received, and then he asked me to approve a request and read him a security code.

Never approve a login request just because someone on the phone tells you to. Never read a verification code to an unsolicited caller. It does not matter what the caller ID says or how professional the person sounds. Google does not solve these problems by calling clients. Neither do banks and financial institutions.

A verification code is meant to protect you. Anyone who calls and asks you to provide it may be trying to take control of your account. By the way, after the incident, I verified on Google that this is going on…

https://support.google.com/faqs/answer/17170932

Be careful.

Posted in Domain Name News, Personal, Plain Interesting, Security, Tech News and Views | Leave a comment

ChatGPT Will Take Away Your Agency and Independence if You Are Not Careful

AI is supposed to be a tool that enhances human efforts and increases productivity… And it is that.

But be careful. If you don’t watch what it is doing, it will take away your agency and independence. I love AI and ChatGPT, and I use them. Mostly, however, I would be embarrassed to say and to think that it is doing my thinking for me. So I instruct it carefully to use my voice and my style in all of my actions and requests. I do not ask it to think for me, and I don’t want it to. Look at this…

Last week, I spent a full airplane ride researching distribution for a client. I reviewed each website in our distribution channel to assess how they handled our product. I compiled a list with links and comments. It was my work.

Then today, I asked ChatGPT to reorder, alphabetize, and format my research for presentation. It did so, but somehow added a marker for ChatGPT to each of the URLs I pasted there. That was not my doing nor my request. It pissed me off, honestly.

The sad part is that I had to rebuke the system. I hated that. I told ChatGPT that I will cancel my subscription if it keeps doing that, especially without telling me.

What are we to do?

There is something to the idea of labeling “AI-written content,” and I suppose it can make sense to label “AI-assisted content,” but I don’t like it sneaking things into my work without telling me. I also fear that this is just the beginning.

What is going to happen to the next generation?

Either the next generation will master AI, or AI will master them. I know that when I see a very long, perfectly written communique, I get suspicious. I wonder, did that person really write this? Or was it an AI prompt result, cut and pasted? To be honest, I lose some respect for people doing that. I think the balance is somewhere in the middle. Certainly, I have used AI for years to improve my writing, grammar, and composition (Grammarly has been a go-to). I am distracted when I read content with grammatical errors in English, whether it is a book, an email, or a blog post. So there is a very good case for people for whom English (or any language, for that matter) is not their first language. It improves communication.

But we have to be very careful, 1. not to get lazy, and 2. not to give over our thoughts to AI. Monitor the output of your AI and make sure it does what you ask. If it doesn’t cancel your subscription, choose another one.

P.S. This article was written by me but was AI-Assisted (for grammar and spelling). Sheesh!

Posted in Uncategorized | Tagged | Comments Off on ChatGPT Will Take Away Your Agency and Independence if You Are Not Careful

How Much Can it Cost to Run a New TLD at 100k Domains Under Management?

Now that ICANN has met again and we are getting closer to the 2026 application window for new Top-Level Domain Names, I thought I would share some rough figures on the cost of running a Registry with 100,000 Domains Under Management (DUM). The base ICANN cost to establish a TLD is about $232,000 (includes a $5k Rights Protection Mechanism Access Fee), and to maintain it at 100,000 domain-years is $51,500 per year, based on fees from the draft agreement and 2026-round materials. This includes:

  • Initial ICANN setup cost: $232,000 (extras not included).
  • Ongoing annual ICANN fees once the TLD is live
  • Draft RA: annual registry fee ($25,750) plus $0.2575 per transaction. At 100,000 transactions, the annual ICANN cost is about $51,500.

This assumes one transaction per domain per year at 100,000 domains, reflecting the typical steady-state registry size for ICANN fees. The per-transaction fee generally applies if over 50,000 transactions per year, which a 100,000-DUM registry will typically exceed.

Two key caveats should be kept in mind when budgeting using these figures. The draft agreement allows ICANN to raise fees in line with inflation, so $51,500 is only a current estimate based on draft figures. Other possible costs not included: conditional evaluation fees, auction or contention costs, objections, RSTEP fees for technical evaluations, RPM fees for Sunrise/Claims periods, or the Variable Registry-Level Fee if registrars disapprove variable accreditation fees. These are situational and should only be included for comprehensive modeling.

In summary: ICANN-only planning number Setup: $232,000 Annual run rate at 100k DUM: $51,500/year

That is the simplest version.

You’ll still need to consider the following variable costs:

  • Registrar and marketing needs – Registrars may require registry support for marketing and integration.
  • Fraud monitoring – as the registry grows, maintaining security and handling abuse incurs costs.
  • RSP and DNS fees – Estimate predictable technology management costs.
  • Data escrow, legal, and policy – Plan for these necessary, if modest, expenses.
  • Staff – Some registries run on minimal staff, but if you want to scale, you’ll likely need some help.

What Can a Registry Be Worth? Is it Worth it?

Below are the biggest examples. Very little data exists on what new gTLD registries have been sold for since 2012. But certainly, there is a market for them. A registry can be worth the risk if the TLD has real demand, strong renewals, and a solid distribution plan. These are some of the top industry players.

  • Verisign (.com / .net): about $1.56B in annual revenue and roughly $26B market value
  • Public Interest Registry (.org): about 11M domains and roughly $106M in annual revenue
  • Proposed .org / PIR sale: $1.135B (not completed, but a strong valuation signal)
  • Nominet (.uk): about 10.2M domains and £55.9M in revenue
  • .ai (Anguilla): became a major economic asset, generating tens of millions in revenue

Examples for some of the 2012 players:

  • Rightside sold to Donuts (2017): about $213M
  • Neustar registry business sold to GoDaddy (2020): $218M
  • MMX assets sold to GoDaddy (2021): about $120M

What makes a registry valuable:

  • Recurring renewal revenue
  • Pricing power
  • Premium domain inventory
  • Strong brand or category relevance
  • Good registrar/channel distribution
  • Low operating overhead once established

Bottom line:
A registry is not valuable just because it exists. It becomes valuable when it turns into a durable, recurring digital asset. A strong string can be worth millions or more. With a good team and a strong idea, a registry business can be very valuable.

Acronyms:

DUM – Domains Under Management
RPM – Rights Protection Mechanism
RSTEP – Registry Services Technical Evaluation Panel
RSP – Registry Service Provider
DNS – Domain Name System
RA – Registry Agreement

Sources:
Much of what I gleaned above comes from ICANN’s draft registry agreement. In many ways, this document is more important than the Applicant Guidebook.

Disclaimer: Nothing I state in this article or on my blog is meant to be investment or legal advice. Applicants must do their own due diligence and consult with an attorney or their own investment advisors.

Posted in ccTLDs, Country Code People, Domain Name News, Domain Names, New gTld Auctions, New Top Level Domains, Plain Interesting, Registrars, Registries | Comments Off on How Much Can it Cost to Run a New TLD at 100k Domains Under Management?