A top-level domain (TLD) is the final segment of a domain name — the letters that follow the last dot, for example the ".com" in example.com. TLDs are the highest level in the hierarchical Domain Name System (DNS) and appear in the root zone, which is the authoritative list of all TLDs maintained by the Internet Assigned Numbers Authority (IANA).

Types and categories

  • Generic TLDs (gTLDs): originally intended for general purposes (e.g., .com, .org, .net) and more recently expanded to many specialized or brand-oriented names.
  • Country-code TLDs (ccTLDs): two-letter codes assigned to countries or territories (for example .uk, .de) based on international standards.
  • Sponsored and restricted TLDs: operated under specific eligibility rules for a community or purpose (for example education, finance, or brands).
  • Infrastructure and special-use names: certain entries serve operational roles (for example .arpa) or are reserved/special-use by standards bodies.
  • Internationalized TLDs (IDN): TLDs using non‑ASCII characters encoded into the DNS with punycode so that native scripts can appear in addresses.

Historically, the first set of TLDs was introduced in the 1980s to organize an expanding Internet. Management of the root zone and the TLD allocation process evolved into a multistakeholder model overseen by bodies such as IANA and ICANN. A major expansion of available gTLDs in the 2010s allowed a large number of new, specialized and brand TLDs.

Operation and registration involve two main roles: the registry, which runs the technical and policy systems for a TLD, and registrars, which sell domain names to the public. Different TLDs impose different rules — some are open to anyone, others restrict registrations to local residents, companies, or verified communities.

TLDs have practical importance for technical routing, branding and user expectations. They can signal commercial intent (.com), organizational type (.org), geographic connection (.fr), or trust and regulation (.gov). Security features such as DNSSEC can be applied at the TLD level to improve authenticity of DNS responses.

Notable distinctions include reserved or special-use names, country-code assignments tied to international codes, and the distinction between the root zone (the registry of TLDs) and lower-level domain registration. The TLD landscape continues to change as new identifiers, policies and governance practices evolve to meet the needs of a global Internet.