
.dev Was HTTPS-Locked Two Years Before You Could Register It — HSTS, Localhost Collisions, and the Engineer URL
~642k active names, Charleston Road Registry on Nomulus, Chromium HSTS preload since September 2017 (before GA February 2019), the local-*.dev breakage story, verified roofs from web.dev to github.dev—and why the old guide's AIO boilerplate and "created for developers" tagline failed audit.
NewName Editorial
Editorial Team
Open web.dev. You get Google's live web-platform documentation—guides, Baseline, real engineering content. Open tech.dev. In mid-2026 you are more likely to hit a parked page or a registrar upsell than a shipped developer product. Same suffix, opposite evidence quality. The stub this guide replaces never made that distinction. It also claimed "Stack Overflow, MDN, npm and many other developer brands" use .dev as secondary domains without naming a single verified hostname—and recycled daily-TLD AIO boilerplate claiming AI engines cite .dev documentation "prolifically" because dev docs are "well-structured by convention." Unaudited, delete-on-sight.
The story worth telling is not "Google made .dev for developers." It is HSTS preload applied to the entire public suffix years before general registration opened—and the collateral damage when thousands of engineers had already pointed myapp.dev at 127.0.0.1 in /etc/hosts. That sequence—not marketing copy—is what separates .dev from .com, and from sibling .app in ways buyers actually feel at launch.
Security first, registration second: the 2017–2019 gap
Most domains earn HSTS gradually: serve Strict-Transport-Security, ramp max-age, submit to hstspreload.org, wait for a Chrome release. hstspreload.org's current guidance explicitly discourages routine preloading for ordinary sites—the subdomain operational burden is too high.
.dev skipped opt-in and skipped waiting for registrants. On 16 September 2017, Chromium commit 7ad1c6b added public suffix dev to transport_security_state_static.json with mode: force-https and include_subdomains: true (Chromium source). Firefox, Safari, and Edge inherit variants of the same baked-in list. The rule ships in browser binaries—not fetched at runtime.
Public registration did not open until 28 February 2019—more than 17 months later (Google Registry launch details). During that gap, Google owned the delegated gTLD internally; Chrome already refused cleartext on any hostname ending in .dev, including ad-hoc local entries developers had used for years instead of .localhost.
What that means in practice:
- The first navigation to
http://anything.devupgrades to HTTPS or hard-fails. No cleartext window for downgrade attacks. - Every subdomain inherits the rule—including
staging.api.product.dev, forgotten DNS typos, and your old/etc/hostsentry fordashboard.dev. - HSTS does not issue certificates. You still need TLS termination (Let's Encrypt, Cloudflare, your host's auto-cert). No cert = browser error, not a polite redirect.
- Removal at the TLD layer is effectively impossible. Individual domains can petition hstspreload.org removal; a preloaded public suffix does not roll back because one team misconfigured staging.
Google Registry's hello.dev launch post framed this as moving "the web to an HTTPS-everywhere future." Sibling TLDs .app, .page, .new, and others share the same preload family in Chromium's static file—but .dev was preloaded first, and its pre-existing use as a local dev hostname made the policy uniquely disruptive.
The localhost collision nobody planned for
Before ICANN's new gTLD round finished, .dev was not a public namespace—it was a convenient fake TLD in hosts files and internal DNS. When Chrome 63+ enforced preload, local setups without valid HTTPS certs stopped loading entirely (The Register, November 2017). Google will not remove TLD-level preload (Stack Overflow consensus).
Fix (one-time): migrate local environments to .localhost, .test, .invalid, or .example—all reserved and not HSTS-preloaded per RFC 6761. Do not register a public .dev name and point it at loopback; you will fight both DNS and browser policy.
Who runs it—and how .dev differs from .app
Registry operator (2026): Charleston Road Registry Inc. (CRR), d/b/a Google Registry—a wholly owned Google LLC subsidiary, separate from registrar retail per ICANN's registry/registrar split (Google Registry FAQs). Technical stack: Nomulus on Google Cloud—the same open-source registry software behind .app, .google, and dozens of other Google TLDs.
Acquisition economics differ from .app. CRR won .dev through ICANN's new gTLD application process for the standard $185,000 evaluation fee—not a last-resort auction. (.app cost $25,001,000 at auction in 2015; see .app guide.) Delegation to Google dates to 2014; the zone stayed internal until the 2019 launch window.
Launch calendar:
| Phase | Dates | |-------|-------| | Sunrise (TMCH) | 16 January – 19 February 2019 | | Early Access (declining daily fee) | 19 – 28 February 2019 | | General Availability | 28 February 2019 onward |
.dev vs .app in one table—not interchangeable branding:
| Dimension | .dev | .app |
|-----------|--------|--------|
| HSTS preload | Sept 2017 | Oct 2017 |
| Public GA | Feb 2019 | May 2018 |
| Semantic pitch | Engineer, docs, tooling, infra | Consumer/mobile product identity |
| Unique scar tissue | Broke local *.dev hostnames | Less localhost history |
| Active zone (mid-2026) | ~642k | ~1.2M |
| Typical buyer | Dev portals, API docs, PaaS subdomains | App download pages, consumer SaaS canonical URLs |
Same security contract; different URL story. Choose .dev when your audience is engineers reading docs at 2 a.m., not consumers tapping an App Store link.
Zone size: surging, still half of .app
| Metric | Source / date | Figure |
|--------|---------------|--------|
| Active domains | whois.lws.fr / ICANN MRR, April 2026 | ~641,857 |
| YoY growth (active) | Same | +34.5% |
| Zone registrations (DNS snapshot) | DNS.coffee / NamePros analysis, March 2026 | ~603,110 |
| vs .app | .app guide | ~728k .dev cumulative vs ~1.2M active .app |
| vs .io | .io guide | Smaller base, faster recent YoY on .dev |
The 2025–2026 surge added roughly 145k names in twelve months per DNS.coffee tracking—after years of ~40–60k annual growth. Treat that as AI/dev-tool branding fashion plus Google's portfolio marketing, not proof every registered string hosts documentation.
Pricing: standard shelf, premium tiers that persist
Google Registry sets wholesale via rate card; registrars add markup (.dev pricing policy). Premium names carry elevated registration and renewal identified before purchase—not a one-time launch surcharge.
| Tier | Typical range (USD, mid-2026) |
|------|------------------------------|
| Standard new registration (1 yr) | $13–$20 |
| Standard renewal (1 yr) | $15–$22 |
| Transfer | $13–$20 |
| Registry premium (tiered dictionary words) | $280–$1,000+/yr renewal on short names (HN registrar thread on Google premium tiers) |
| Secondary end-user sales (examples) | cat.dev $30,000 (Sedo, July 2026, Domain Name Wire); six-figure .dev pairs rare but real in DNJournal YTD charts |
Model renewal at the tier you bought. Names like build.dev and chat.dev often sit on premium landers—not live products—at premium renewal classes. agent.dev may resolve to a parked or experimental surface; verify before treating any dictionary word as a "notable site."
Verified roofs—and the brochure names to delete
Skip Mad Libs (startup.dev, api.dev, docs.dev as "notable sites" without live products). These mid-2026 checks return mission-aligned surfaces on .dev itself:
web.dev — Google's web platform documentation hub; canonical engineering education on the registry's own TLD.
github.dev — Browser-based editor: swap .com → .dev in any GitHub URL or press . on a repo (github/dev repo). Infrastructure, not marketing redirect.
*.fly.dev — Fly.io's default public hostname for every deployed app; fly.dev is the platform's own apex, not a sidecar to fly.io.
stripe.dev — Stripe's developer documentation surface with live API catalog headers (Link: rel="api-catalog").
thirdweb.dev — Web3 SDK/developer portal with a live product surface (distinct from thirdweb.com marketing home).
daily.dev — Developer news/community platform at scale on .dev as primary domain.
chromestatus.dev / opensource.dev — Google-owned developer-facing properties on the TLD they operate.
vercel.com — Counterexample: Vercel's canonical brand remains .com; vercel.dev may resolve but is not the primary corporate URL teams cite in procurement.
stackoverflow.com / developer.mozilla.org — Counterexamples: majors lead with .com / .org; do not infer .dev adoption from industry association.
Trash the old guide's lazy equivalence between "developer company" and ".dev mandatory." The suffix signals engineering identity when you canonicalize docs, APIs, or infra hostnames there—not when you defensively register and park.
HSTS preload ops checklist (before you point DNS)
- TLS on every hostname you create—including
www,api,staging, preview deploys, and legacy CNAMEs. - Staging cannot serve HTTP on a public
.devsubdomain; use.localhost,.test, or a non-preloaded TLD for internal cleartext if you truly need it. - Certificate automation before bulk subdomain creation—one expired cert on
old-api.product.devis a hard outage. - PaaS default subdomains (
*.fly.dev, custom*.yourproduct.dev) inherit preload; customers' misconfigured certs become your support ticket. - Deep links and CLI output must use
https://; document the scheme for SDK examples.
This is the trade Google Registry made: namespace-wide downgrade protection in exchange for zero tolerance for TLS misconfiguration.
SEO and AI search: gTLD, not a documentation cheat code
.dev is a standard generic TLD in Google's systems—no geographic targeting, no special ccTLD handling. John Mueller's standing guidance applies: keywords in the TLD are not a ranking signal. Forced HTTPS removes one misconfiguration vector; it does not substitute for content, links, or Core Web Vitals.
For AI surfaces (ChatGPT Search, Perplexity, Google AI Overviews): models cite pages with authority and freshness, not suffix semantics. web.dev appears because it is Google's official web documentation, not because .dev whispers "developer" to model weights. No audited AIO preference layer exists—do not bolt on schema templates expecting citation dividends.
One routing question—not a who-should matrix
Skip symmetric columns. Ask:
Are you building an engineer-facing surface—docs, SDK portal, API explorer, infra hostname—where HTTPS-from-byte-zero and "this person writes code" URL semantics justify staging rigidity—or buying a trendy redirect you could host on .com?
Choose .dev when you ship developer tools, open-source projects, technical blogs, or PaaS default hostnames where the suffix shortens explanation to an engineering audience, you will canonicalize documentation or API references on .dev (not just defensively register), and your team accepts TLS automation as a launch gate. Pair with defensive .com before enterprise procurement—see Domain Hacks.
Skip .dev when you sell to non-technical consumers (→ .app), when mainland China is core (ICP filing complexity on exotic gTLDs—keep .cn/.com.cn operational), when I/O infra vanity without Google preload rigidity matters more (→ .io), when AI product signaling beats engineer semantics (→ .ai), or when you only want a cheap defensive redirect you will never promote.
Alternatives worth comparing:
.app— Same HSTS preload family; consumer-app semantics, larger zone..page— Google sibling for landing pages; also HTTPS-preloaded..io— No TLD-level HSTS; Chagos ccTLD sovereignty stack..tech— Descriptive gTLD without forced preload..com— Institutional default; HTTP still allowed (please don't).
FAQ
Why can't I load my new .dev domain over HTTP?
The entire .dev public suffix has been in Chromium's HSTS preload list since September 2017, with includeSubDomains. Browsers refuse cleartext before your site sends any headers.
Do I still need an SSL certificate?
Yes. HSTS forces HTTPS connections; TLS certificates complete them. No cert = connection failure.
Can I use .dev for local development?
Not on the public namespace. Use .localhost, .test, or .invalid. Public .dev names require valid HTTPS.
Who operates .dev in 2026?
Charleston Road Registry (Google Registry) on Nomulus. Retail registrars (GoDaddy, Porkbun, etc.) sell names—they do not operate the registry.
How is .dev different from .app?
Same HSTS family, different launch timing, zone size, and URL semantics: .dev = engineer/docs/infra; .app = consumer product identity.
Is .dev good for SEO?
Neutral as a gTLD. HTTPS is a baseline signal .dev makes hard to violate. Rankings follow normal quality signals—see SEO-friendly domain names.
Premium renewal shocked me—who sets that?
Google Registry tiering at registration time. Registrars pass through the same renewal class; shop tiers before checkout.
Stress-testing developer brand architecture across suffixes? Our domain search checks .dev, .app, .io, and 1,000+ extensions in one pass—or read Subdomain vs Subdirectory before you structure a docs portal on docs.product.dev.


