Restricted TLD
In short: A TLD with restricted registration — only certain people, organisations, or industries are allowed to use it, e.g. .gov (only US government agencies) or .bank.
In more detail: For restricted TLDs, the registry checks eligibility (proof, affiliation, industry) before registration is possible. This is meant to build trust and make abuse harder, since the TLD itself already makes a statement about the domain holder.
In Depth
Examples of restricted TLDs and their access restrictions:
.gov— exclusively US government agencies, verified by the responsible US federal authority..mil— exclusively the US military..bank— only verified financial institutions, including mandatory additional security measures (among other things, two-factor authentication for domain management)..edu— largely restricted to accredited US educational institutions.
The point behind this: a restricted TLD makes phishing harder, because attackers can’t register a .bank or .gov domain for a fake page without going through the same strict verification as the real institution. This creates a certain built-in trust — if a user sees a .gov domain, they can be relatively confident they’re actually communicating with a US authority, quite unlike an arbitrary .com domain.