Skip to content

Add: MyOnlinePortal.net subdomains#2759

Open
geraldhansen wants to merge 1 commit intopublicsuffix:mainfrom
geraldhansen:main
Open

Add: MyOnlinePortal.net subdomains#2759
geraldhansen wants to merge 1 commit intopublicsuffix:mainfrom
geraldhansen:main

Conversation

@geraldhansen
Copy link

@geraldhansen geraldhansen commented Jan 31, 2026

Public Suffix List (PSL) Submission

Checklist of required steps

  • Description of Organization

  • Robust Reason for PSL Inclusion

  • DNS verification via dig

  • Each domain listed in the PRIVATE section has and shall maintain at least two years remaining on registration, and we shall keep the _psl TXT record in place in the respective zone(s).

Submitter affirms the following:

  • This request was not submitted with the objective of working around other third-party limits.
  • The submitter acknowledges that it is their responsibility to maintain the domains within their section. This includes removing names which are no longer used, retaining the _psl DNS entry, and responding to e-mails to the supplied address. Failure to maintain entries may result in removal of individual entries or the entire section.
  • The Guidelines were carefully read and understood, and this request conforms to them.
  • The submission follows the guidelines on formatting and sorting.
  • A role-based email address has been used and this inbox is actively monitored with a response time of no more than 30 days.

Abuse Contact: service@myonlineportal.net

  • Abuse contact information (email or web form) is available and easily accessible.

    URL where abuse contact or abuse reporting form can be found:
    https://myonlineportal.net/impressum


For PRIVATE section requests that are submitting entries for domains that match their organization website's primary domain, please understand that this can have impacts that may not match the desired outcome and take a long time to rollback, if at all.

To ensure that requested changes are entirely intentional, make sure that you read the affectation and propagation expectations, that you understand them, and confirm this understanding.

PR Rollbacks have lower priority, and the volunteers are unable to control when or if browsers or other parties using the PSL will refresh or update.

(Link: about propagation/expectations)

  • Yes, I understand. I could break my organization's website cookies and cause other issues, and the rollback timing is acceptable. Proceed anyways.

Description of Organization

We are a free DynDNS provider and have been active since 2010. We offer various subdomains and additional services in this area.

I am the owner of these domain and technical responsible.

Organization Website:
https://myonlineportal.net

Reason for PSL Inclusion

Our customers have brought to our attention that not being included in the Public Suffix List (PSL) may pose a potential security risk. As every customer is using their registered subdomains for own private purposes we need to give them the most available security (including cross-subdomain cookie injection, unintended credential autofill, and potential abuse of email authentication mechanisms).

For the moment we haven't reported limitations from third parties but to avoid this for the future (like Let's Encrypt issuances) it will be good to be present in the PSL.

We confirm that we hold the registration for mentioned domains already over 10 years and will maintain them also for the future.

Previous PRs:
None - this is our first PSL submission.

Number of users this request is being made to serve:
10000

DNS Verification

dig +short TXT _psl.my-homeip.com
"https://github.com/publicsuffix/list/pull/2759"
dig +short TXT _psl.my-homeip.de
"https://github.com/publicsuffix/list/pull/2759"
dig +short TXT _psl.my-homeip.net
"https://github.com/publicsuffix/list/pull/2759"
dig +short TXT _psl.myonlineportal.at
"https://github.com/publicsuffix/list/pull/2759"
dig +short TXT _psl.myonlineportal.ch
"https://github.com/publicsuffix/list/pull/2759"
dig +short TXT _psl.myonlineportal.eu
"https://github.com/publicsuffix/list/pull/2759"
dig +short TXT _psl.myonlineportal.net
"https://github.com/publicsuffix/list/pull/2759"
dig +short TXT _psl.myonlineportal.org
"https://github.com/publicsuffix/list/pull/2759"

@pencilnav
Copy link

pencilnav commented Jan 31, 2026

Similar to #2750 (comment) (also a free DynDNS provider)

All submitted domains have multiple security vendors listing it as malicious/phishing/suspicious on virustotal.
e.g. https://www.virustotal.com/gui/domain/my-homeip.com has 8 security vendors listing it as malicious/phishing.

Can be a blocker. (see #2750 (comment))

@geraldhansen
Copy link
Author

Exactly - but all these malicious domains are probably reasoned by subdomains from fraud users where we like to protect all other users.

@geraldhansen
Copy link
Author

I checked all mentioned subdomain which are mentioned by virustotal they all doesn't exists anymore - because we take fraud quite serious - the checks looks quite old for me and incredible intransparent. It's quite not clear why pages like alphamountain.ai BitDefender or CyRadar are doing and how they check or what kind of databases they maintain.
But all of them are behind a paywall - which looks like another step away from the free internet.

@hiifeng
Copy link
Contributor

hiifeng commented Feb 1, 2026

For DynDNS-style platforms, aggregated security signals (e.g. VirusTotal) are commonly used as a high-level indicator of recurring abuse patterns.
The current page shows that multiple security vendors (such as alphamountain.ai, BitDefender, and CyRadar) have flagged the relevant domains.
In this situation, those reputation and abuse-related flags typically need to be actively remediated and cleared (for example, by working with the affected security vendors) before this PSL PR can move forward.

@pencilnav
Copy link

pencilnav commented Feb 2, 2026

@geraldhansen Based on previous PRs with similar situations (multiple of them), it is likely that you'll need to conduct these security vendors (which is not behind a paywall) to reduce your virustotal counts to zero for all domains before this can go any further. (#2515 (comment))

the checks looks quite old for me

It was analayzed 6 hrs ago.

@simon-friedberger
Copy link
Contributor

simon-friedberger commented Feb 2, 2026

Hi @geraldhansen!

  • Could you provide a little more info on your 10k users, please? Are those registered users? Active users? For what kind of period? Can you split those by domain?
  • Do you need all the domains to be added?
  • Can you please switch to a role-based IP address such that we can reach somebody even if you leave the project?
  • Can you please add landing pages to all the domains with instructions on how to report abuse?

@pencilnav
Copy link

pencilnav commented Feb 3, 2026

@simon-friedberger

role-based IP address

*role based email address (e.g. psl-contact@example.com)

Signed-off-by: Gerald Hansen <gerald.hansen@posteo.de>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants