Tenancy and the Public Suffix List
home.network sells personal DNS namespaces. Each customer is delegated one label and controls every name beneath it.
home.network is not currently in the Public
Suffix List. Inclusion requires a scale the service has yet to reach,
so the boundary below is enforced by home.network and is not yet applied by
browsers. Treat cookie isolation between labels as absent until this notice
says otherwise.
The boundary
- A label belongs to exactly one customer, under a paid contract.
- Labels are sold to unrelated parties. alice.home.network and bob.home.network are two different people.
- Credentials are scoped to a single label. No customer can create, read or delete a record outside their own label.
- Certificate challenges are writable only at the label apex, so issuance is limited to that label and the wildcard beneath it.
Expected behaviour
| Input | Public suffix | Registrable domain |
|---|---|---|
| home.network | network | home.network |
| alice.home.network | home.network | alice.home.network |
| nas.alice.home.network | home.network | alice.home.network |
Why an entry would matter
Browsers derive cookie scope, document.domain, storage partitioning and same-site treatment from the registrable domain. Without a list entry, a page under one label can set a cookie scoped to home.network that every other customer's browser then sends. Customers run private services under these names, so the result is a leak between parties with no relationship to each other.
Verification
- Zone: ns1.home.network, ns2.home.network, DNSSEC-signed (ECDSA P-256, NSEC3 narrow).
- Validation record: _psl.home.network TXT, to be published with the pull request URL at submission time and left in place afterwards.
- Operator and postal address: Impressum.
- Policy this page restates, with a 90-day notice requirement attached: commitments.
- Contact: security@home.network.