How Domain Registration Actually Works: TLDs, Registrars and What You’re Really Buying

Written by TK WebHosts Last updated

You don’t buy a domain name. You lease it, one registration period at a time, from a system with three distinct layers—and most of what looks confusing about domains, from surprise renewal prices to transfer delays, comes from not knowing which of those three layers is actually responsible for the thing you’re looking at.

This is a practical explainer of the mechanics: what a registration actually is, who runs what, what decides the price, and where the genuine traps sit. It applies to any domain, in any country.

What you’re actually buying

A domain registration is a time-limited right to have a name point somewhere on the internet—typically one to ten years, renewable. Nobody “owns” a domain the way they own a car. The registrant holds a registration; the underlying name remains part of a shared, centrally coordinated namespace that the registrant leases access to.

That distinction matters because it explains almost every domain-related problem people run into: a domain can lapse if a renewal payment fails, a dispute can result in a registration being suspended or transferred, and the terms of the lease are set by policy the registrant did not negotiate and usually never reads.

The three-tier system: registry, registrar, registrant

Every domain sits inside the same three-layer structure.

  1. The registry operates a specific top-level domain (TLD)—the part after the final dot, such as `.com` or `.uk`. The registry runs the authoritative database for that TLD and sets its technical and policy rules. IANA’s Root Zone Database is the master list of every TLD and which registry operates it.
  2. The registrar is the accredited business that sells registrations to the public and communicates with the registry on the registrant’s behalf. ICANN’s registrar accreditation programme is what makes a registrar authorised to sell generic TLDs (gTLDs) such as `.com`, `.org` or `.shop`—an accredited registrar has direct access to the gTLD registries it sells.
  3. The registrant is the person or organisation that holds the registration—the buyer.

A registrant almost never deals with a registry directly. Registrars exist specifically so that ordinary buyers don’t have to negotiate access to a registry’s systems themselves.

Two different kinds of TLD, with two different rulebooks

Not every TLD works the same way, and the difference matters more than most buyers realise.

Generic TLDs (gTLDs)—`.com`, `.org`, `.net`, and the newer wave like `.shop`, `.app` or `.io`—are contracted directly with ICANN under a standard registry agreement. Registrar accreditation, transfer policy and dispute procedures are uniform across every gTLD, because ICANN sets them.

Country-code TLDs (ccTLDs)—`.uk`, `.de`, `.ng`, `.co`—are delegated by IANA to a national registry, which then sets its own eligibility rules, pricing and policies independently of ICANN. Some ccTLD registries require a genuine connection to the country; others sell openly worldwide. Some allow instant registrar transfers; others impose their own lock periods that have nothing to do with ICANN’s rules. There is no single ccTLD rulebook—each one is its own jurisdiction. IANA’s Root Zone Database records which registry operates each one and is the starting point for checking a specific ccTLD’s actual policy rather than assuming it matches `.com`.

This is the single most common source of confusion when someone’s experience with a `.com` doesn’t match what happens on a ccTLD: they’re not the same system with a different suffix. They’re two different sets of rules that happen to share the same registrar storefront.

Restricted TLDs: when you need a local presence or proxy

Not every TLD is open to anyone with a credit card. Some registries restrict eligibility outright, and the restriction takes one of two different forms.

Geographic eligibility. Many ccTLD registries require the registrant to demonstrate an actual connection to that country or region before they’ll issue a domain. Canada’s registry, CIRA, is explicit about it: CIRA describes a Canadian Presence Requirement that every `.ca` registrant must satisfy, choosing from defined categories—Canadian citizen, permanent resident, a corporation, or a trademark registered in Canada, among others. There is no blanket “pay a fee and skip it” category in that list; the registrant genuinely has to fit one of the defined categories.

Australia and Ireland run comparable systems. auDA states plainly that a `.com.au` domain represents a person or organisation with a genuine connection to Australia, satisfied by holding a valid ABN or Australian Company Number, or being an Australian citizen or permanent resident. Ireland’s registry likewise requires supporting documentation proving a connection to Ireland as part of the `.ie` application itself, not as an optional extra step.

Credential eligibility. A smaller number of gTLDs restrict registration by verified industry credential rather than geography. fTLD Registry Services operates `.bank` and `.insurance` on exactly this basis—register.bank states plainly that only verified banks can register a `.bank` domain, with eligibility checked before the domain is issued, not after.

Where a registry does permit it, the common workaround for a buyer who doesn’t personally meet a geographic eligibility requirement is a registrar-provided local presence or trustee service: the registrar, or a local partner, supplies the local contact and address the registry’s rules require, while the buyer remains the actual beneficial user of the domain. This is a real, established part of the industry—but it is entirely at the discretion of the specific registry, not a universal right. Some registries’ eligibility categories, like CIRA’s for `.ca`, don’t include a generic proxy option at all. The only reliable way to know whether a proxy route exists for a specific TLD is to check that registry’s own eligibility rules directly, rather than assuming it works the same way it did for a different ccTLD.

What actually decides the price

A registrar’s price for a domain is built from three components, only one of which the registrar fully controls:

  • The wholesale registry fee. Every registry sets its own per-year wholesale price for its TLD, charged to every accredited registrar equally. This is the floor beneath which no registrar can profitably sell that TLD long-term.
  • The ICANN fee. A small per-domain fee applies to gTLD registrations, funding ICANN’s own operations. It’s usually a few cents to under a dollar and is the same regardless of registrar.
  • The registrar’s own markup, which is where actual price competition happens—and where the promotional-pricing trap lives.

That third component explains why a `.com` can be advertised at a fraction of its real cost for the first year: registrars can choose to sell a first registration below their own cost as a customer-acquisition expense, then charge closer to (or above) the real market rate at renewal. Nothing about that is against any rule. It just means the number on the landing page and the number on the renewal invoice are frequently not the same number, and the gap is a business decision by the registrar, not a registry price change.

WHOIS, RDAP and what’s actually public

Every registered domain has a public registration record, historically queried through a protocol called WHOIS. ICANN describes RDAP—the Registration Data Access Protocol—as WHOIS’s designated replacement, developed by the IETF to deliver the same kind of registration data through a standardised, more secure query and response format, with better support for internationalised text and access control than the older protocol offered.

What’s actually visible in that record depends on the registrant’s own privacy settings and the applicable registry’s rules. Many registrars offer (or, at some registries, are required to provide) a WHOIS/RDAP privacy or proxy service, which substitutes the registrar’s own contact details for the registrant’s in the public record while keeping the real details on file for legal and abuse purposes. Privacy protection is not automatically part of every registration and is not universal across every registry—whether it’s included, optional, or unavailable at all depends on both the registrar and the specific TLD.

Transfers: why some domains move instantly and others don’t

Moving a domain from one registrar to another is meant to be a routine, registrant-controlled action, not a favour the losing registrar grants. The mechanism is an authorisation code (often called an EPP code or auth code)—a value the current registrar must provide on request, which the new registrar then uses to complete the transfer.

For gTLDs, ICANN’s Transfer Policy sets rules that apply industry-wide regardless of which registrar is on either end. Two of those rules catch people out most often:

  • A registrar may impose a 60-day inter-registrar transfer lock following a change of registrant contact details, unless the registrant opts out of it. Updating the name or organisation on a registration can therefore accidentally block a transfer for two months.
  • A new registration is generally locked against transfer for 60 days from its creation date. A domain bought yesterday typically cannot be moved to another registrar today, even with a valid auth code.

ccTLDs are not bound by ICANN’s transfer policy at all, because ICANN doesn’t set ccTLD rules—each ccTLD registry decides its own transfer mechanics. Some mirror the gTLD approach closely; others run instant, auth-code-based transfers with no equivalent lock period. That’s a genuine, registry-specific difference, not a technicality—worth checking directly against the registry in question rather than assuming gTLD rules apply.

The lifecycle of a domain that isn’t renewed

A domain that expires doesn’t disappear the moment the renewal date passes. ICANN’s own lifecycle documentation for a typical gTLD sets out a staged process: after expiration, a domain generally passes through one or more grace periods during which the original registrant can usually still renew it—often at a steadily increasing cost the further past expiration it gets—before it’s finally released back into general availability for anyone to register. The exact lengths and costs of those stages vary by registry and registrar, so a registrant relying on “I’ll just re-register it later if I forget” is relying on a window that isn’t guaranteed to be free, fast, or even available depending on the TLD.

How to choose a registrar

Price is the least reliable signal, for the reasons above. More useful questions:

  1. Is the first-year price representative of the renewal price? Check the registrar’s own renewal pricing page, not just the offer you’re being shown.
  2. Is WHOIS/RDAP privacy included, optional, or unavailable for this specific TLD? Don’t assume it carries over from a `.com` habit to a ccTLD.
  3. Does the registrar support auth-code transfers cleanly, without added retention friction? A registrar that makes leaving difficult is telling you something about how it competes.
  4. For a ccTLD, does the registrar actually hold accreditation with that specific registry, or is it reselling through an intermediary? That affects both support quality and how quickly issues get resolved.
  5. What is genuinely included—DNS management, email forwarding, support—versus what’s an upsell at checkout?

The conclusion: know which layer you’re actually dealing with

Most domain confusion collapses once the three-tier structure is clear. A slow transfer, a locked registration, a renewal price that doesn’t match the first-year offer, a WHOIS record that shows a proxy instead of a real name—none of these are arbitrary. Each one is a specific policy, set at a specific layer, by a specific party: sometimes ICANN, sometimes a ccTLD’s own registry, sometimes the registrar’s own commercial decision.

Knowing which layer set the rule is what turns “domains are annoying” into “this specific thing is happening because of this specific policy, and here’s what I can actually do about it.”

Ready to register?

Check availability and compare live pricing before you commit to a registrar.

About the author

TK WebHosts

TK WebHosts turns practical experience with websites, hosting and digital systems into clear guidance.