The Art of the Domain Hack
How the Internet's Best URLs Are a Game of Words — and how one Nigerian TLD became the smartest address on the internet.
And how one Nigerian TLD became the smartest address on the internet
There is a certain kind of person on the internet who has a three-letter Instagram handle, a Gmail address that is just their first name, and a personal website with a domain that makes you stop and read it twice. These people did not stumble into those assets. They hunted them. And nowhere is that hunt more creative — or more cutthroat — than in the world of domain hacks.
What Even Is a Domain Hack?
A domain hack is when the top-level domain (TLD) — the bit after the dot — becomes part of the word itself. The result is a URL that reads as a single coherent word or phrase, split invisibly across the domain structure.
The most famous early example is del.icio.us, the social bookmarking site that launched in 2003 and blew people's minds simply by existing. The domain used .us (United States) as the final syllable of "delicious." It was stupid clever. Everyone wanted one.
Since then, the domain hack has evolved from a novelty into an art form. Some of the best ones in the wild:
- t.co — Twitter's URL shortener, using Cocos Islands' TLD
- bit.ly — Libya's TLD completing the word "bitly"
- over.gg — Guernsey's TLD for an esports analytics platform
- drip.is — Iceland's TLD, reading as "drip is"
- youtu.be — Belgium's TLD completing "YouTube"
- instagr.am — Armenia's TLD, before Instagram bought instagram.com
Notice the pattern: country-code TLDs (ccTLDs) assigned to tiny nations with currencies nobody thinks about become gold mines for creative domain hunters, because their registry fees are priced for local economies, not Silicon Valley startups.
The Geography of Cheap Genius
Every country on earth gets a two-letter TLD. Most of them are boring — .uk, .de, .fr — used almost exclusively by locals. But some of them accidentally became valuable because of where those two letters fall in the English language.
.ly (Libya) exploded after bit.ly. Now a .ly domain costs a premium because everyone knows the trick.
.io (British Indian Ocean Territory) became the default for tech startups. Now it costs $40-60/year and climbing.
.ai (Anguilla) used to be cheap. Then the AI boom happened. Now Anguilla's government is reportedly making millions annually off domain registrations alone. An island with 18,000 people is accidentally funding itself off the artificial intelligence hype cycle.
The economics are fascinating: when a ccTLD becomes culturally desirable, the registry raises prices. When it stays obscure, it stays cheap. The game is finding the obscure ones before everyone else does.
Which brings us to Nigeria.
.ng and the Naira Discount
Nigeria's TLD is .ng. Two letters that end a staggering number of English words: bleeding, burning, aching, haunting, gatekeeping, belonging, unraveling. The suffix "-ing" is one of the most common in the English language, and .ng completes every single one of them.
For years, .ng stayed under the radar. Nigeria is the largest economy in Africa, but its currency — the naira — has faced significant devaluation. Registry fees priced in local economic context meant that .ng domains were registering at the equivalent of roughly $8-10 USD per year. For that price, you could own bleedi.ng. You could own hauntii.ng. You could own words that, as a .com, would cost thousands on the aftermarket.
The domain hack community has started to notice. But for a brief window, .ng was — and in many cases still is — one of the best-value TLDs on the internet for English wordplay.
The Hunt for gatekeepi.ng
This is the part of the story that starts with frustration and ends with accidental genius.
The goal was simple: find a domain hack on .ng that had the same gut-punch quality as bleedi.ng — a site that already existed, minimalist and ominous, just an image and an audio file dropped on a dark page like a message from someone who doesn't owe you an explanation.
The hunt went through dozens of candidates. ra.ge — taken. ooz.ing — taken. seethi.ng — taken. yearn.ing — taken. mourn.ing — taken. The good ones, predictably, were gone.
Then came gatekeepi.ng.
The first reaction was dismissal. "Gatekeeping" had become one of those internet words — overused, discourse-coded, the kind of thing you see in Reddit arguments and TikTok callout videos. It felt too zeitgeisty, too tied to a moment.
But then something clicked. Gatekeeping doesn't just mean hoarding information petulantly. It means controlling access. And what is a platform where people buy and sell exclusive information? What is a personal website where the gate is always closed?
It's gatekeeping. Literally.
The domain was available. The annual fee: ₦13,250 — roughly nine dollars and sixty cents. The registration took four minutes on a Nigerian registrar. The concept clicked into place like a key in a lock.
gatekeepi.ng was acquired for less than the price of a coffee.
Why the Domain Name Matters More Than You Think
In an era of social media profiles and link-in-bios, you might wonder whether the domain even matters anymore. It does. Maybe more than ever.
Your domain is the one piece of internet real estate that is completely, unambiguously yours. Social platforms can ban you, deplatform you, change their algorithms, shut down entirely (ask anyone with a Vine archive). Your domain is yours as long as you renew it.
More practically: a great domain is the first impression. Before anyone sees your site, they read the URL. A domain that makes someone pause — that makes them go wait, how did he get that — is doing marketing work before a single pixel loads.
gatekeepi.ng does that. The wordplay is clean. The concept is loaded. The price was nine dollars.
The Dark Side: Domain Hijacking
Here's where the story gets less fun.
Domain names are property. Valuable property. And like any valuable property, people try to steal them. Domain hijacking — the unauthorized takeover of a domain from its rightful owner — is more common than most people realize, and recovery is rarely guaranteed.
How It Happens
Phishing attacks are the most common vector. You receive an email that looks exactly like it's from your registrar — urgent, official, warning you about account suspension or an expiring domain. You click the link, enter your credentials on a convincing fake login page, and the attacker has full access to your account. From there, they change the email address, transfer the domain, and disappear.
Social engineering is even more insidious because it requires no technical skill at all. An attacker calls your registrar's customer support, claims to be you, says they've lost access to their account, and convinces a support agent to hand over control. It sounds absurdly simple. It works more often than it should.
Registrar breaches happen when the registrar itself gets compromised. In 2018, a group of hackers exploited a vulnerability in GoDaddy's system and gained access to domains belonging to Mozilla, Yelp, and Mastercard, sending ransom demands to institutions across the US.
Expired domains are the simplest method of all: do nothing. If you forget to renew your domain, it goes back into the pool. Squatters actively monitor expiring domains and register them the moment they lapse, sometimes within minutes.
Famous Victims
Sex.com (1995) — One of the earliest and most legendary cases. A con artist named Stephen Cohen sent a forged letter to the registrar, fraudulently transferring the domain from its owner. He ran the site profitably for years before courts ordered it returned, with a $65 million judgment. Cohen fled rather than pay. He was eventually arrested in 2005.
Perl.com (2021) — The domain for the Perl programming language community was hijacked by attackers who exploited vulnerabilities in the registration process and redirected it to a parked page, blindsiding the entire developer community.
The New York Times (2013) — The Syrian Electronic Army compromised the NYT's domain registrar through a spear-phishing campaign, redirecting millions of readers to a political message page for hours.
Google Vietnam & Lenovo (2015) — Hacker group Lizard Squad hijacked Google's Vietnam regional domain and Lenovo's website, redirecting visitors to defaced pages. Even Google, with all its security resources, was not immune.
SubdoMailing (2024) — A large-scale campaign in which attackers took over more than 8,000 subdomains belonging to brands including eBay, Marvel, McAfee, MSN, and The Economist, using them to distribute spam and phishing emails at massive scale.
How to Protect Yourself
If you own a domain — even a personal one, even a $9 .ng domain hack — these steps are non-negotiable:
- Enable two-factor authentication on your registrar account. Every registrar offers it. Use it.
- Lock your domain. Most registrars offer a "transfer lock" that prevents the domain from being moved without extra verification. Turn it on.
- Enable WHOIS privacy. Without it, your name, email, and phone number are publicly visible, making you a target for phishing and social engineering.
- Never click registrar emails. If you get an email about your domain, go directly to your registrar's website and log in there. Do not follow links in emails.
- Set up auto-renew. The most embarrassing way to lose a domain is to simply forget to pay for it.
- Use a strong, unique password for your registrar account. Not the same one you use anywhere else.
ICANN, the body that oversees internet domains, does offer dispute resolution processes — but recovering a hijacked domain is slow, expensive, often international, and frequently unsuccessful. Prevention is the only reliable strategy.
The Future of Domain Hacks
The golden age of domain hacking is not over — it's just moved to less obvious TLDs. The .com gold rush happened decades ago. .io is expensive now. .ai is getting there.
But .ng is still early. .st (São Tomé & Príncipe) is underexplored. .ga (Gabon) has wordplay potential. New gTLDs like .art, .design, and .studio are still reasonably priced and increasingly legitimate.
The game remains the same as it was in 2003 when del.icio.us launched: find the TLD that hasn't been discovered yet, find the word that splits perfectly across the dot, and register it before someone else has the idea.
gatekeepi.ng is proof the game is still very much alive.
And the gate is still closed.
This domain is privately held and reserved for personal, non-commercial use by its owner. It is not indexed, not monetized, and not available. If you are reading this, you were not supposed to find it.