# Research Brief: .bank.in — Security Sanctuary or Shutdown Whitelist?

**Source article:** https://bankin-report.cashlessconsumer.in/shutdown-critique
**CashlessConsumer investigation hub:** https://bankin-report.cashlessconsumer.in/
**Compiled:** July 1, 2026

---

## TL;DR

The Reserve Bank of India (RBI) was awarded Central Banking's "Initiative of the Year" (March 2026) for `.bank.in`, a **mandatory** domain namespace for all regulated Indian banks, operated by IDRBT (a wholly RBI-owned body). The award framed it purely as an anti-phishing / anti-cybercrime tool.

The critique: **`.bank.in` is not only a security initiative — it is a whitelist infrastructure purpose-built for surgically precise internet shutdowns.** The same namespace that protects citizens from phishing can keep banking running while the rest of the internet goes dark. Shield, choke-point, or both.

---

## 1. What is `.bank.in`?

- A **restricted top-level domain** under the `.in` country code, reserved exclusively for India-regulated banks.
- **Mandatory, not optional** — after the migration deadline there is no legitimate non-`.bank.in` banking website.
- **Sole registrar: IDRBT** (Institute for Development and Research in Banking Technology), wholly owned by RBI. No bank joins the namespace without RBI approval.
- Confirmed by government/public statements: the zones "will be maintained by RBI-nominated agency, IDRBT, to ensure that no unauthorized person or organization is able to acquire a domain in these domain zones." [^1]
- Justified publicly by a real problem — CERT-In data cited that ~65–67% of fraud-related domains impersonated financial institutions. [^1]

## 2. The Shutdown Mechanics (the core critique)

India already has the technical capacity to block internet access at multiple layers (submarine cable gateways, ISP-level BGP, DNS filtering, app-layer blocks). The state's problem has always been **granularity**: how to shut down social media *without* shutting down banking?

`.bank.in` solves that with a single firewall rule:

| Approach | Before `.bank.in` | After `.bank.in` |
| --- | --- | --- |
| Total shutdown | Everything goes dark (ATMs, UPI, NEFT, RTGS, markets) | Rarely used — too destructive |
| DNS-level filter | ISPs maintain ad-hoc whitelists that leak/break | One rule: allow `*.bank.in`, block `*` |
| DPI-based block | Expensive, error-prone, VPN-bypassable | Rarely needed — namespace is self-enforcing |
| Selective social block | Leaky targeted orders to ISPs | `.bank.in` unaffected — banking stays online by default |

**Key insight:** `.bank.in` shifts compliance from every individual ISP to a single centrally controllable namespace. Any authority that controls the `.in` zone (NIXI) or the `.bank.in` zone (IDRBT/RBI) can define what "banking" means at the DNS level.

## 3. India's Shutdown Track Record (gives the critique its weight)

- **World leader in shutdowns** — India accounts for roughly 60% of all government-ordered internet shutdowns globally (Access Now, various years). [^2]
- Globally, deliberate shutdowns have skyrocketed: Access Now/#KeepItOn tracked **296 deliberate shutdowns in 54 countries in 2024**. [^3]
- **Common triggers:** farmer protests (2020–21), Jammu & Kashmir (2019, ~533-day shutdown), CAA/NRC protests (2019), communal violence (2023 Manipur, 2026 Sambhal), exam-cheating prevention.
- **State vs Centre tension:** most shutdowns are ordered by *state* governments, not the Centre. RBI is a *central* institution — a namespace it controls can operate independently of state-level shutdowns *if RBI chooses* to keep it open.
- **J&K precedent:** when Article 370 was revoked (Aug 2019), J&K had a ~533-day shutdown. Banking services were among the most affected, with no mechanism to keep essential financial services online while blocking everything else.

## 4. The Design Pattern — RBI as Gatekeeper (5 architectural facts)

1. **All banking domains end in `.bank.in`** — mandatory.
2. **Registration is centralised** — IDRBT (RBI-owned) is the sole registrar.
3. **The zone is monitored daily** — CashlessConsumer's own audit feed at `github.com/CCAgentOrg/bank-in-domains` publishes DNS/HTTPS status for every registered domain. RBI can know exactly which domains are live.
4. **Delegation can be revoked** — IDRBT can remove a bank's delegation from the parent zone at any time.
5. **One rule, one block** — allow `.bank.in`, deny `*`. A single submarine-cable-level ACL.

**Bottom line:** the infrastructure for a "banking stays on while the rest goes dark" shutdown model already exists. The only missing ingredient is a government order.

## 5. The Award Controversy

Central Banking gave RBI its "Initiative of the Year" (March 2026), citing `.bank.in` as "a key tool in the battle against cyber crime." The citation made **no mention of shutdown risk**. Either:

- **Naive** — a London-based committee unaware of India's shutdown record and the dual-use nature of restricted namespaces, or
- **Deliberately narrow** — cybersecurity is the only *defensible* framing; the shutdown use case is the kind of feature never put in a press release.

The award is not wrong — `.bank.in` *does* fight phishing. But fighting phishing is the **best-case** use. The worst case — enabling state control over access to financial services — is equally well-served by the same architecture.

## 6. The Tension: RBI as Shield vs State as Sword

RBI is **not** "the government" — it is a statutory body with a degree of independence. But that independence is limited and can be overridden. The `.bank.in` architecture does not distinguish between RBI using it for security and the state using it for control.

| Scenario | Who Orders | RBI Position | Outcome |
| --- | --- | --- | --- |
| J&K-style shutdown | State/Centre | RBI may resist state shutdown, keep bank.in live | Banking works even if state blocks rest |
| Centre orders RBI to cooperate | Centre (FSB etc.) | RBI cannot refuse a government directive | `.bank.in` whitelisted, rest blocked |
| State blocks `.bank.in` DNS | State govt | RBI zone sits above state | Depends on ISP compliance |
| Emergency financial freeze | RBI itself | RBI could de-register individual bank domains | A bank removed from bank.in is effectively invisible online |

## 7. What This Means for Citizens (4 risks)

1. **State-level shutdowns become cheaper** — "block all but `.bank.in`" is trivially enforceable and auditable.
2. **Financial exclusion becomes a weapon** — during 2023 Manipur violence, financial services were disrupted for weeks; `.bank.in` could make exclusion *surgical*.
3. **Bank-specific censorship** — a bank out of political favour could have its `.bank.in` delegation revoked = de facto kill switch.
4. **Surveillance choke-point** — all `.bank.in` DNS queries flow through resolvers that know exactly which bank you're visiting. Mandatory logging at NIXI level = complete picture of who banks where and when.

## 8. The Honest Caveat (from CashlessConsumer)

The infrastructure described **already exists**. The `.bank.in` zone is live, the registry is complete, the enforcement mechanism (exclusion from the namespace) is codified. What is **not** known:
- Whether this use was intended.
- Whether RBI has internal safeguards against it.
- Whether those safeguards would survive a real crisis.

This is a **design-level risk**, not a proven abuse. The point is to name the dual-use architecture *before* a crisis forces the question.

---

## Sources

[^1]: https://www.lightreading.com/regulatory-politics/india-ramps-up-security-pushes-multilingual-internet
[^2]: https://www.accessnow.org (Access Now / #KeepItOn shutdown tracking, various years)
[^3]: https://gizmodo.com/how-governments-turn-the-internet-into-a-weapon-2000699263
- Primary critique: https://bankin-report.cashlessconsumer.in/shutdown-critique
- Investigation hub: https://bankin-report.cashlessconsumer.in/
- Cookie tracking analysis: https://bankin-report.cashlessconsumer.in/cookie-tracking
- Daily audit feed: https://github.com/CCAgentOrg/bank-in-domains
- Source code: https://github.com/CCAgentOrg/idrbt-bankin-investigation
