Tenancy and the Public Suffix List

home.network sells personal DNS namespaces. Each customer is delegated one label and controls every name beneath it.

home.network is not currently in the Public Suffix List. Inclusion requires a scale the service has yet to reach, so the boundary below is enforced by home.network and is not yet applied by browsers. Treat cookie isolation between labels as absent until this notice says otherwise.

The boundary

  • A label belongs to exactly one customer, under a paid contract.
  • Labels are sold to unrelated parties. alice.home.network and bob.home.network are two different people.
  • Credentials are scoped to a single label. No customer can create, read or delete a record outside their own label.
  • Certificate challenges are writable only at the label apex, so issuance is limited to that label and the wildcard beneath it.

Expected behaviour

InputPublic suffixRegistrable domain
home.networknetworkhome.network
alice.home.networkhome.networkalice.home.network
nas.alice.home.networkhome.networkalice.home.network

Why an entry would matter

Browsers derive cookie scope, document.domain, storage partitioning and same-site treatment from the registrable domain. Without a list entry, a page under one label can set a cookie scoped to home.network that every other customer's browser then sends. Customers run private services under these names, so the result is a leak between parties with no relationship to each other.

Verification

  • Zone: ns1.home.network, ns2.home.network, DNSSEC-signed (ECDSA P-256, NSEC3 narrow).
  • Validation record: _psl.home.network TXT, to be published with the pull request URL at submission time and left in place afterwards.
  • Operator and postal address: Impressum.
  • Policy this page restates, with a 90-day notice requirement attached: commitments.
  • Contact: security@home.network.

home.network