nyc.gov Domain Usage Policy
Overview
OTI oversees the use of the official City of New York domain, nyc.gov, so the public can easily identify official information and maintain security, trust and accountability of government websites. This Policy ensures the City complies with federal regulations and is enforced when an nyc.gov domain is assigned to a website.
Purpose
The purpose of this Policy is to provide requirements for use of the nyc.gov domain in order to maintain security, trust, and accountability for City of New York websites.
Scope
This Policy applies to all uses of the nyc.gov domain.
Authority
Chapter 48 of the NYC Charter promulgates OTI’s authority and oversight with respect to all Citywide information technology, information security, information privacy and telecommunications.
Terms and definitions
Authorized personnel: New York City personnel who are authorized to assign nyc.gov subdomains to websites are responsible for ensuring compliance with this policy prior to assigning a nyc.gov subdomain.
Domain: A domain is the identification name assigned to a website like nyc.gov.
Roles and responsibilities
OTI is responsible for updating this Policy and administering the nyc.gov domain for official information, communication, and services.
New York City government agencies are responsible for the accuracy and maintenance of their content and compliance with this Policy.
Policy
To maintain security, trust and accountability of the official nyc.gov domain, the following are requirements for assignment and operation of nyc.gov internet domains.
- Avoid nyc.gov subdomain names that could mislead or confuse users.
- Do not use the nyc.gov domain for commercial or political campaign purposes.
- Do not use the nyc.gov domain to distribute or promote illegal content.
- Do not use the nyc.gov domain to distribute malware, host open redirects, or engage in malicious cyber activity. New domains are reviewed by OTI security personnel to safeguard city data and information as required by all Cyber Command policies for properly securing websites and SSAP/CCAP processes.
- Each agency which operates a nyc.gov subdomain must provide OTI with a list of authorized individuals who will ensure that any subdomain used by that agency complies with these standards.
- Compliance with the Performance Testing Policy.
- Compliance with the NYC.gov Privacy Policy and Terms of Use.
- Compliance with the Public Digital Experiences Policy.
- Compliance with the content requirements set forth in the City Website Content Policy.
Related policies and procedures
This Policy complies with the DOTGOV Online Trust in Government Act of 2020.
This Policy works in conjunction with the following policies:
- NYC Public Digital Experiences Policy
- Citywide Cyber Command Policies
- Citywide Data Classification Policy
- Citywide Encryption Policy
- Citywide Vulnerability Management
- City Website Content Requirements Policy
- NYC.gov Privacy Policy
- Citywide Privacy Protection Policies and Protocols
Ownership information
This Policy is owned by the OTI Strategic Initiatives Digital Service team. Contact us with questions about this Policy.
Change history
| Version | Change Description | Author(s) | Effective Date |
| 1.0 | First version | Kesone Phimmasone, Chief Digital Strategy Officer | 10/31/25 |