
Are free subdomain registries safe?
Short answer: We operate one of these, so read this with that in mind. A free subdomain registry gives you a name like yourname.runs-on.dev at no cost, and the honest answer to whether that is safe is that it depends on four specific things, only one of which most people check. The name is not yours in the way a registered domain is yours. Its reputation is shared with every other name on the same apex. The operator can take it back. And whether a browser treats your subdomain as its own site, or as a room inside someone else's house, comes down to a single line in a file most people have never heard of. Here is each one, including the one where our own registry currently comes off worse than the alternatives.
## what_you_are_trusting
What you are actually trusting
A free subdomain is not a small version of a domain. It is a different arrangement. When you register example.com, a registrar holds your record and ICANN-accredited rules govern how it can be taken from you, with a dispute process and a transfer window. When you claim yourname.runs-on.dev, one company owns the registered domain and has added a row pointing part of it at you. There is no registrar between you and them, and no dispute process beyond their own.
That is not automatically bad. It is how js.org has run since the 1990s and how is-a.dev runs today, both with large active user bases. But it means the question is not "is this a scam" — for the established registries it plainly is not — it is "what specifically am I exposed to, and does it matter for what I am putting here."
| Risk | Who it hurts | Can you mitigate it? |
|---|---|---|
| Shared apex reputation | Anyone whose traffic depends on not being flagged | Only the operator can, by getting on the Public Suffix List |
| Revocation of your name | Anyone who has printed the URL or built links to it | Partly — pick a registry whose revocations are public and auditable |
| The operator disappearing | Everyone on that apex, all at once | No. This is the irreducible risk of not owning the domain |
| Your claim being public | Anyone who did not expect their GitHub username published | No, and on git-backed registries it is permanent in the history |
## public_suffix_list
The Public Suffix List question, including where we fail it
This is the test that separates a serious free subdomain registry from a hobby one, and it is the one no operator volunteers, because the honest answer is often uncomfortable. Ours is.
Browsers need to know where one site ends and the next begins. Without help, a browser has no way to tell that alice.example.com and bob.example.com belong to strangers rather than to one organisation. The Public Suffix List is how it finds out: a domain listed there is treated as a boundary, so each subdomain under it becomes its own site for cookie scope and for safe-browsing reputation.
The consequence when a registry is NOT on the list is specific and worth stating plainly. If one subdomain on the apex serves a phishing page and a browser vendor flags it, the flag can attach to the apex, and every other name underneath it can inherit an interstitial warning that its owner did nothing to earn. Cookie isolation is similarly weaker.
Checked on 2026-10-02
js.org and is-a.dev both appear in the Public Suffix List. runs-on.dev — the registry we operate — does not. On this specific measure, the two established alternatives are safer than ours today, and anyone choosing between them on safety grounds should weigh that. Submission is tracked as work on our side; until it lands and ships in browser releases, this paragraph stands as written.
Note the second half of that: getting onto the list is not instant even once accepted. The list is compiled into browser releases, so there is a lag of weeks to months between a merged entry and the protection being real in the browsers your visitors use. Treat any registry's claim of being "on the PSL" as a question about when, not just whether.
How to check for yourself, for any registry, in about thirty seconds: open the raw list at publicsuffix.org and search it for the apex domain. If the bare domain appears on its own line, it is listed. This is a fact about a public file, not a claim you have to take from the operator.
## revocation
Can they take the name back? Yes. The question is whether you can see it happen
Every free registry reserves the right to reclaim names, and they have to. A registry that cannot recycle abandoned names fills up with dead claims and stops being useful to anyone. The meaningful difference between registries is not whether they can revoke, it is whether a revocation leaves a record a stranger can audit.
Git-backed registries — where each claim is a file in a public repository and every change arrives as a pull request — make this checkable. Removing a name means deleting a file in a commit with an author and a timestamp. You cannot quietly un-person someone; the history shows what was removed, by whom, and when. A registry run from a private database offers you the operator's word instead.
Our own terms are deliberately blunt about this, and you should read any registry's equivalent before claiming: names are free, dormant names come back into circulation, and impersonation, phishing, malware and illegal content forfeit a name on sight without warning. The reason is in the same document — the company that registered the apex answers for everything served underneath it, so abuse gets removed quickly rather than carefully.
The practical read
Do not put anything on a free subdomain whose URL you cannot afford to change. That rules out print, packaging, anything a client signs, and anything you are building backlinks to as a long-term asset. It does not rule out a portfolio, a demo, a side project, a redirect, or a link in a bio — which is most of what these registries are actually used for.
## what_happens_if
What happens if the operator disappears
This is the risk with no mitigation, and any operator who tells you otherwise is selling something. If the company holding the registered domain stops paying for it, every name underneath goes dark together. There is no escrow, no transfer, and no registrar to appeal to, because you were never the registrant.
What you can do is size the risk honestly before you depend on it. Three questions, in order of how much they tell you:
01Is the registry's data portable?
If every claim is a public file in a public repository, the data survives the operator even if the domain does not. Someone can stand up a replacement and rebuild the records. If the claims live only in a private database, nothing survives.
02How long has the apex been renewed, and by whom?
WHOIS creation and expiry dates are public. A domain registered last month by an individual is a different proposition from one a company has renewed for a decade. This is thirty seconds of checking and it is the most predictive signal available.
03Is there a named legal entity behind it?
An incorporated company with a published address is accountable in a way an anonymous maintainer is not — not because incorporation guarantees longevity, but because it gives you somebody to reach and a public record of whether they still exist.
For the registry we operate, those answers are: every claim is a JSON file in a public repository under an open licence; the apex is held by Advance Labs Inc., federally incorporated in Canada; and the project is young, which is the honest weak point of the three. A registry launched in 2026 has no renewal track record, and js.org's decades of it is a genuine advantage we cannot manufacture.
## seo
Does a free subdomain hurt your SEO?
Less than people fear, and differently than they expect. Search engines treat a subdomain on a shared apex as its own site for ranking purposes in most cases, which means you neither inherit the apex's authority nor are dragged down by it. You start from nothing, the same as a new domain would.
The real costs are two, and neither is a ranking penalty. First, links you earn accrue to a name you do not own, so if you later move to your own domain you are rebuilding from zero unless the operator will serve a redirect for you. Second, and increasingly the bigger one, an AI answer engine deciding whether to cite you is making an entity-trust judgement, and a free subdomain is weaker evidence of a real organisation than a registered domain with matching business records.
If the thing you are putting on the subdomain needs to be cited by name — a company, a product, anything commercial — that second cost is the one that matters, and it is worth the price of a domain. If it is a personal project, a demo, or a developer portfolio, it is not.
Check how an AI engine reads your site## verdict
The short version
- Safe for: portfolios, demos, side projects, redirects, link-in-bio: The downside if the name goes away is that you change a link. That is a cost you can absorb, and in exchange you get a short memorable name for nothing.
- Not safe for: anything commercial, anything printed, anything signed: A client-facing business on a name someone else can reclaim is a risk with no upside, and a domain costs about ten dollars a year. Buy the domain.
- Check the Public Suffix List before you choose between registries: It is the one safety difference that is a matter of public record rather than operator assurance, and today it favours js.org and is-a.dev over the registry we run.
- Prefer a registry whose claims are public files: It makes revocation auditable and the data portable if the operator vanishes. Those are the two risks you can actually do something about.
## faq
Is runs-on.dev safe?
It is operated by Advance Labs Inc., a federally incorporated Canadian company, and every claim is a public file in an open-source repository, which makes revocations auditable and the registry data portable. Two honest caveats: it launched in 2026, so it has no long renewal track record, and as of 2026-10-02 it is not yet on the Public Suffix List, while js.org and is-a.dev are. Suitable for portfolios, demos and side projects; not suitable for anything commercial, printed or contractual.
What is the safest free subdomain registry?
On the one measure that is a matter of public record rather than operator assurance — presence on the Public Suffix List, which keeps one subdomain's bad behaviour from damaging the others — js.org and is-a.dev are both listed and most newer registries are not. Beyond that, prefer any registry whose claims are public files in a public repository, because that makes revocation auditable and the data portable if the operator disappears.
Can a free subdomain be taken away from me?
Yes. Every free registry reserves the right to reclaim names, both for abuse and for dormancy, and you have no registrar or dispute process to appeal to because you are not the registrant. The practical rule is to never put anything on a free subdomain whose URL you cannot afford to change.
Does using a free subdomain hurt my SEO?
There is no ranking penalty — search engines generally treat a subdomain on a shared apex as its own site, so you start from zero rather than being dragged down. The real costs are that any links you earn accrue to a name you do not own, and that AI answer engines weigh a free subdomain as weaker evidence of a real organisation when deciding whether to cite you by name.
