Check a Domain

Country Extension

.it domain names

Run by Italy's National Research Council: flat pricing, one-year terms, and one-day transfers.

What .it is

.it is the country-code top-level domain (ccTLD) for Italy, delegated on 23 December 1987 and among the earliest European ccTLDs. The registry is Registro .it, the registry function inside the Istituto di Informatica e Telematica of Italy's national research council, the Consiglio Nazionale delle Ricerche, in Pisa. It has never been privatised or outsourced: the delegation has moved only between CNR institutes, from CNUCE in 1987 to IAT in 1997 and to IIT in 2001. The governing document is Regulation version 8.0 of 30 May 2022, stable since.

On the most recent verifiable figure there were 3,537,551 .it domains at 31 December 2025, up 1.22 per cent over the year. The registrant mix contradicts the usual assumption about European ccTLDs: 52 per cent are held by natural persons, 29 per cent by companies and 10 per cent by freelancers. This is a mainstream consumer namespace, not a corporate register.

Who can register .it

.it is restricted, but the restriction is broad and has nothing to do with Italy specifically. Regulation v8.0 permits registration only to adults with citizenship, residence or a registered office in the European Economic Area, the Vatican City State, San Marino, Switzerland or the United Kingdom — the EEA limb covering all 27 EU member states plus Iceland, Liechtenstein and Norway. Eligibility is satisfied by any one of the three connections, so an EU citizen resident in Argentina qualifies on citizenship alone and a US company with a registered branch in Ireland qualifies on registered office. No connection to Italy is required.

The UK position is the useful contrast. Where EURid suspended, withdrew and ultimately revoked .eu domains held by UK-established registrants after Brexit, Registro .it added the United Kingdom to its eligibility list by name on 30 May 2022 — though its own annexed country list still files the United Kingdom under the heading for EU member states, so the annex is not a reliable reference.

Eligibility is enforced rather than merely declared: losing the required qualifications, or failing to supply requested documentation, is an express ground for revocation. There is no sanctioned trustee route, since the Regulation makes no provision for trustees and states that the registrant has sole responsibility for the domain; trustee products place the trustee as registrant of record, so the trustee becomes the legal holder and the client has no registry-recognised claim. One further detail catches applicants out: an Italian natural person must supply a codice fiscale, a non-Italian natural person an identity document number instead, and any legal entity a VAT number, mandatory for foreign entities.

What .it costs to own

Registro .it operates a flat-rate, prepaid, per-transaction wholesale model and sells only to accredited registrars, who must hold a VAT number, pass a competency test on live EPP operations, and maintain a positive prepaid balance. The annual renewal fee sits below the registration fee — but the change-of-registrar fee is priced at the same level as a registration, so .it transfers are not free at wholesale and do not bundle a year of renewal the way a gTLD transfer does. Restoring from redemption is likewise charged at registration level.

There is no premium tier, and this is confirmed rather than inferred: the registrar contract sets flat rates irrespective of domain characteristics, so a short dictionary word costs the same at registry as any other name and high prices occur purely on the aftermarket. Reserved is not premium — geographic names for Italian regions and municipalities are held for the corresponding territorial bodies on eligibility grounds.

Registration terms, renewals, and transfers

One year is both the minimum and the maximum — the registry supports no other term. Domains are registered for one year and automatically renewed at each expiry, so where a registrar advertises two, five or ten years it is selling a prepaid commitment on its own books rather than a registry term. A cancellation request must reach the registry within fifteen days of expiry, or the domain renews.

Transfers work through an AuthInfo code of eight to thirty-two characters, assigned by the registrant to the domain and notified to the registrant by the registrar at registration. Contrary to a claim in wide circulation, the .it AuthInfo has no validity period: it behaves as a persistent password on the domain object, and the thirty days often quoted is the redemption period, which is a different thing.

The transfer itself is the fastest mainstream mechanism in Europe. The gaining registrar submits the request with the AuthInfo, the domain enters a pending-transfer state, and that state lasts a maximum of one day: unless the new registrar cancels it or the old one rejects it, the registry approves it automatically. The losing registrar may block only where the relevant authorities have served formal notice, and no post-registration or post-transfer locks exist.

Selling a .it is a separate operation: the current holder passes the AuthInfo to the new holder, whose registrar performs the change, and a combined transfer-and-trade command exists where both change at once. After deletion there is a thirty-day redemption period recoverable only through the same registrar, after which the registry publishes daily cancellation lists with exact drop times.

WHOIS, RDAP, and privacy

.it did not blanket-redact after GDPR. It runs a consent model that is asymmetric by registrant category: natural persons, sole proprietorships and freelancers are treated as data subjects and may withhold consent to publication, in which case their data is suppressed. Legal persons, bodies and associations cannot withhold consent, on the reasoning that they are no longer considered interested parties, and the technical rules require the consent flag to be true for every entity type except natural persons and freelancers.

The net effect is the inverse of the ICANN gTLD default. With consent, a query returns the domain, status, DNSSEC flag, dates, registrant organisation and address, admin and technical contacts, registrar and nameservers, with the web WHOIS adding nationality, telephone and email. Without consent, the registrant, admin and technical names and organisations are hidden while the dates, registrar and nameservers remain. Suppression is per contact, so partial disclosure is normal, and consent can be changed at any time through the registrar, who has no discretion and must promptly grant the request.

There is no legitimate-interest disclosure gateway of the kind ICANN contemplates, and for trademark enforcement the practical route is the opposition and reassignment procedure. Privacy and proxy services are neither provided for nor needed: the consent flag is free and registry-native, while third-party proxies collide with the rule that the registrant has sole responsibility for the domain.

RDAP does not exist for .it — the IANA record lists a WHOIS server and no RDAP server, and the bootstrap file contains no entry — so tooling that expects RDAP will fail. DNSSEC is deployed on algorithm 13, though registrars are split into DNSSEC-accredited and non-accredited categories. Internationalised names have been supported since 11 July 2012 across six Unicode blocks including Greek and Cyrillic, though scripts cannot be mixed in one name.

Who .it suits, and who should avoid it

It suits:

  • Any business trading into Italy, one of Europe's larger ccTLDs and, with most registrations held by individuals, an ordinary address rather than a corporate one.
  • UK businesses in particular, since .it wrote the UK into its eligibility rules by name where .eu did the opposite.
  • Anyone with EEA, Swiss, San Marinese, Vatican or UK citizenship, residence or registered office — the citizenship limb covers expatriates worldwide.
  • Registrants who value transfer freedom, given one-day auto-approval and almost no losing-registrar veto.
  • Price-sensitive portfolio holders, given flat wholesale pricing and no premium tier.

It is a poor choice for:

  • Companies and organisations that require WHOIS privacy. This is the sharpest disqualifier: legal entities have no opt-out, so a corporate registrant's name and address are published and cannot be suppressed.
  • Genuinely ineligible parties, since there is no sanctioned trustee route and losing eligibility is a ground for revocation.
  • Anyone wanting multi-year registry-level registration, because one year is the only term.
  • Automation stacks that require RDAP, or registrants who need DNSSEC from a registrar that is not DNSSEC-accredited.
  • Opportunistic drop-catchers, because the drop is published in advance and professionally contested.

Common mistakes with .it

Getting the entity type and tax identifier wrong. Italian natural persons need a codice fiscale, foreign natural persons an identity document number instead, and foreign legal entities a VAT number. For natural persons the name and organisation fields must be identical, which trips up order forms that leave the organisation blank, and failure to supply required documentation is a ground for revocation.

Assuming corporate WHOIS privacy exists. A company, association or public body will have its organisation name and address published with no mechanism to suppress them, so firms that register in a company name for tidiness end up publishing their registered address.

Confusing a data change with a trade. Selling a .it requires a change of registrant using the AuthInfo passed from the old holder to the new one; editing the registrant fields is a data change, which the registry forbids as a route to changing the holder.

Conflating the fifteen-day and thirty-day windows. The auto-renew window after expiry is fifteen days; the redemption period after deletion is a separate thirty days, recoverable only through the same registrar — so a registrant already moving providers can find the right to recover sits with the registrar they were leaving.

A national namespace inside a research institute

Almost every major ccTLD has at some point been handed to a foundation, a government agency or a commercial operator. .it never has. The delegation was made in December 1987 to the Consiglio Nazionale delle Ricerche on the basis of the technical and scientific expertise of its researchers, who were among the first in Europe to adopt IP protocol technology, and it has stayed inside CNR ever since, passing only between CNR institutes in Pisa. IANA's administrative contact for the Italian namespace is the Director of IIT-CNR by role rather than by name.

The origin story is unusually precise. The request for the first .it domain went in from CNR's CNUCE institute in Pisa on 23 December 1987 — the same date IANA still records as the delegation date — and the domain became active on 1 January 1988. Wikipedia gives the name as cnuce.cnr.it, which could not be corroborated from a registry source, though the date is confirmed by IANA.

What difference does public research ownership make to a registrant? It shows up in three places: no premium tier of any kind, so the registry has neither the mechanism nor the incentive to reprice a short name; radical transparency about the drop, with cancellation lists published daily with exact times; and open WHOIS for organisations, a choice that treats the register as a public record first and a product second. The liberalisation history reads the same way, traceable through document versions: holding limits went in 1999 for organisations and 2004 for individuals, and eligibility widened beyond the European Union on 11 July 2012, when version 6.2 added the EEA, the Vatican, San Marino and Switzerland.

Common questions

Who is allowed to register a .it domain?

Adults with citizenship, residence or a registered office in the European Economic Area, Switzerland, San Marino, the Vatican City State or the United Kingdom. Any one of the three connections is enough, and no connection to Italy itself is required.

Can a UK company still register a .it domain after Brexit?

Yes. The United Kingdom was explicitly added to the .it eligibility list by Regulation version 8.0 on 30 May 2022 — the opposite of what happened to UK registrants on .eu.

Can I register a .it domain for more than one year?

Not at the registry. One year is both the minimum and the maximum term, with automatic renewal each year. Multi-year offers are prepaid commitments on the registrar's books, not a registry-level term.

Is WHOIS privacy available for .it domains?

Only for natural persons, sole proprietorships and freelancers, who may withhold consent to publication free of charge through their registrar. Companies, associations and public bodies have no opt-out, and their name and address are published.

How long does a .it transfer take?

Usually one day. The gaining registrar submits the AuthInfo code, and unless the transfer is cancelled or formally rejected within that period the registry approves it automatically.

Related extensions

.us

CountryNexus required

The only major extension where you must formally declare your connection to the country and cannot hide your details afterwards.

Registry Services, LLC (GoDaddy Registry)

.uk

Country

The shorter British option, with a transfer mechanism that works nothing like the auth codes used by generic extensions.

Nominet

.co.uk

Country

Far more widely held than direct .uk, and the extension British customers actually expect to see.

Nominet