The name on the door¶
Before the move, Purple Lantern’s name was a .dev bought from a US registrar, with a .space beside it that had
been bought for mail once. Everything else was found through that name, logged in through it, and renewed through
it, and nobody had asked who, apart from the registrar, could take it away. The move started here because the name
is the layer everything else hangs off, and it turned out to have more owners than the invoice suggested.
Who owns the street¶
The first scrap of paper says “registrar is only the shop”. Behind the counter sits the registry, the organisation
that runs the namespace, and for a .dev that is
Charleston Road Registry, a Google subsidiary in the US. A European
registrar selling a .dev is a European shop in front of a US road. .space is run by
Radix Technologies from the Cayman Islands. Neither had come up
when the names were bought.
TLD |
Registry |
Jurisdiction |
What happened to it |
|---|---|---|---|
|
Belgium, EU framework |
Registered, and everything moved under it |
|
|
Charleston Road Registry, a Google subsidiary |
US |
Kept for redirects, and no longer |
|
Cayman Islands |
Left to lapse |
So the new name is purplelantern.eu. EURid runs .eu, .ею and .ευ from Belgium under appointment of the
European Commission, which puts the namespace itself inside a European framework. That is the one structural
advantage no US-operated gTLD can offer, and it is why the redirects from .dev run one way. The old name stays on
the map for as long as links elsewhere point at it, and then it goes.
The shop¶
The registrar is the shop, and the shop can change. What Purple Lantern wanted from one, written down before looking:
European ownership, European law, operations inside the EU or EEA
payment by SEPA
DNSSEC, and a registrar or registry lock
a transfer out that does not involve begging, and domain data that exports
an account recovery procedure written down somewhere
no bundling with a hosting platform
Infomaniak in Geneva got the domain. TransIP in the Netherlands would have done as well, with .eu and
automatic DNSSEC. Loyalty to
either is beside the point, since the domain has to be movable without rebuilding the rest of the stack. Two things at
EURid make that true whichever shop is in front.
Registry lock and DNSSEC are switched on through
the registrar, and the registrant portal,
My .eu, hands out transfer codes and shows DNS quality and
registrar details without asking the registrar first.
One record¶
The zone for purplelantern.eu lives in Infomaniak’s DNS, separate from its web hosting and its mail. Three things
were checked before any record went in: the zone can be exported, the nameservers can be changed without a support
ticket, and the domain survives if the DNS service goes. Keeping the zone away from the host is what makes the host
replaceable. If statichost disappears, one record change moves the site. If Infomaniak’s DNS disappears, the zone
moves to other nameservers without the domain moving.
One record took an afternoon. A CNAME cannot sit at the apex beside the SOA and NS records, so purplelantern.eu
itself cannot be a CNAME to the host; docs.purplelantern.eu can. Some DNS providers paper over this with an ALIAS
or flattening record, and statichost’s domain docs recommends using it where
it exists. Infomaniak has none. So the apex domain name got the two addresses from the docs, 95.217.26.94 and
2a01:4f9:c01f:8002::, and the subdomains became CNAMEs to SITENAME.statichost.page. A CNAME follows the host when
it renumbers. An A record does not, and statichost says nothing about whether those addresses are stable or how a
change would be announced. That makes the apex domain name the one record checked against the docs now and then, and
one more line in the zone export.
DNSSEC came switched
on. Infomaniak enables it at purchase
for most extensions, and EURid lists it among
the security features for .eu. What it does is
narrow. Infomaniak signs the zone, EURid publishes a DS record beside the domain, the fingerprint of the signing key,
and a
validating resolver refuses any answer for purplelantern.eu that was not signed by that key. It encrypts nothing and
hides nothing. The catch is in moving. A zone that moves to other nameservers gets new signing keys, and a DS record
at EURid that still points at the old key makes every validating resolver treat the domain as forged, and the sites
vanish. RFC 6781 gives the order for the case where the
old operator will not help: the DS record removed at EURid through the registrar, the nameservers changed, and a new
DS record inserted once the new zone is signed, with the domain unsigned in between.
So the scraps hold, outside the registrar account because the day they are needed may be the day that account does not open, that DNSSEC is on, the DS record EURid publishes, and that sequence for changing nameservers with DNSSEC on.
The American bit¶
The certificates come from Let’s Encrypt, as they did before. Excellent, automated through ACME, supported everywhere, and run by the Internet Security Research Group, a non-profit with its legal address in San Francisco. Neither unsafe nor unsuitable. It does mean that a European registrar, European DNS and a European host ending in Let’s Encrypt is not an all-European trust chain. What was checked instead is whether the CA could be swapped without touching the architecture. With standard ACME at the host, yes. The certificate is not the strategic dependency. The ability to get and renew one is.
Certificate Transparency turned up on the list and was moved straight off it. Every certificate a public CA issues is
written into public, append-only logs, and Chrome and Safari refuse a certificate that is not in the logs, so there is
nothing to opt into and nothing to move. The logs are run by a handful of CAs and browser makers, and which of them
holds the entry makes no difference to a domain owner. What the logs give a domain owner is a lookup. A search of them
for purplelantern.eu lists every certificate ever issued for the name, so a certificate that a hijacked DNS
validation or a misbehaving CA produced without being asked shows up there, which is the only way a domain owner would
ever hear of it. The logs themselves move on their own; Let’s
Encrypt retired its RFC 6962 logs for static CT logs between
November 2025 and February 2026, and nobody with a certificate had to do anything.
None of it needs making European.
WHOIS and RDAP went the same way. For .eu, EURid runs its own lookup under its own data policy, one more reason to
keep registry and registrar apart in the head. What went into the notes for the domain is the registry, the
registrar, both lookups, the registrant and technical contacts, and how a transfer works.
Paying for it¶
A domain can be perfectly sovereign right up until the card expires. The old name renewed on a card, which is a US card network’s policy sitting between the name and its renewal. Infomaniak’s checkout offers “Bank” and PayPal, nothing labelled SEPA, and the bank option is a transfer to Infomaniak’s euro IBAN, which from a European account is a SEPA credit transfer in everything but the label. So the domain is paid by transfer from a bank account the registrant controls, independent of the host, and not hanging off the same mailbox everything else recovers through. A European bank paying a European registrar.
Getting back in¶
The hidden dependency that gets missed most often, and it was missed here too until the recovery chain was drawn out: domain, registrar, recovery email, and then whatever the recovery email recovers through. If that mailbox recovers through a Google account, a US phone number and a US service, the European registrar has not bought much. So the chain now ends in something that is none of those: the recovery codes, kept in the vault and in no account. A hardware key is on the list, a European-made one, when there is time to find it. A phone number is convenient, and a poor thing to build a company on.
The password manager sits near the root of the same chain, because it holds the way into every other dependency. Two ways to go. A cloud manager is convenient, synchronised and everywhere, and then it is a critical service in its own right; a European name on the tin says nothing about where the vault lives, and Bitwarden states that its vault data lives in Microsoft Azure, in the US or the EU.
Purple Lantern went the other way. With KeePassXC the vault is an encrypted file under its owner’s control, stored locally and backed up with everything else. It takes a key file or a hardware key as part of the lock, and version 2.7.9 holds a CSPN certification from ANSSI, granted on 17 November 2025. What that buys: a password-manager outage is an inconvenience, not a lock-out from everything. For a one-woman company that difference is the whole argument.
On the door¶
European legal identity
│
.eu domain
│
┌──────────┴──────────┐
EURid registry European registrar
│
DNSSEC
│
European DNS service
│
┌───────────┴───────────┐
static host email
beside it, not beneath it:
offline recovery
│
registrar, email, forge, hosting accounts
The name in a European namespace, its administration with a replaceable European registrar, the DNS independent, the authentication portable, and no single account the recovery route for everything else. Let’s Encrypt still hangs off it. Not a real problem, as long as nothing American sits in the one position from which the rest can be revoked, renamed, locked or made inaccessible.
Granny Weatherwax holds that most of witchcraft is the hat. People see the pointy hat and behave accordingly, and the woman under it still has to do the actual work.