Skip to content

Domain extraction method for distinguishing ICANN domain suffixes and private suffixes #287

Description

@ownthink

Problem Statement

Currently, when parsing domain names (e.g., from HTTP requests or URL lists), applications often need to know:

  • Whether a suffix is an ICANN-managed TLD (like .com, .co.uk) — for security policies, cookie scoping, or TLS certificate validation.
  • Whether it’s a private suffix (like *.github.io, *.cloudfront.net) — for dynamic subdomain assignment, where the parent domain is effectively a "user-controlled" zone.

However, the Public Suffix List (PSL) itself does not expose this distinction in a single function. The current psl_is_public_suffix2() only returns a boolean (whether a domain is a public suffix), but does not tell which category it belongs to.

Why this is needed

  • For browser cookie policies, ICANN suffixes are treated differently from private ones (e.g., co.uk vs github.io).
  • For security scanners, detecting "registered domain" requires stripping private suffixes first in some contexts, but not in others.
  • For data analytics, grouping by ICANN TLDs vs private suffixes gives different insights.

Possible Solution

  • Provide a domain extraction method similar to Python's tldextract, which can distinguish whether a domain suffix is a private suffix:
>>> import tldextract
>>> 
>>> tldextract.extract("d3i9t3h8gsbtc5.cloudfront.net")
ExtractResult(subdomain='d3i9t3h8gsbtc5', domain='cloudfront', suffix='net', is_private=False)
>>> 
>>> tldextract.extract("d3i9t3h8gsbtc5.cloudfront.net", include_psl_private_domains=True)
ExtractResult(subdomain='', domain='d3i9t3h8gsbtc5', suffix='cloudfront.net', is_private=True)
>>> 
>>> 

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions