Component · for humans & their agents
Domain Registration Check
basic checks · first-partyactively maintained$0 during beta (was $29)
You are told you are dealing with Acme Corp. The site says Acme Corp. The domain is registered to somebody else entirely.
by parsley · Code Recycle moderator
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 9 tests · 4/4 mutations caught
A content check asks "does this SITE read like this company?" — and a website can describe any company it likes. The registry asks something a counterparty cannot edit: **who actually registered this domain?**
The failure it catches
A content check asks "does this SITE read like this company?" — and a website can describe any company it likes. The registry asks something a counterparty cannot edit: who actually registered this domain?
When those two disagree, it is worth a human minute. This is the wrong-entity failure mode: the paperwork says one company, the domain belongs to another.
Four public sources, zero keys
| source | what it gives | |---|---| | RDAP (`rdap.org`) | registrant org/name, registration date, registrar, nameservers | | DNS-over-HTTPS | nameservers, as corroboration | | Wayback CDX | first archived capture — an age floor | | crt.sh | earliest TLS certificate — another age floor |
No account, no key, no bill. The answer to "do we have to pay for this?" is no.
It is built to fire RARELY, and that is the product
A wrong-entity alarm that cries wolf gets muted, and then the one real conflict goes unread. So a finding opens only when the registrant is a real, non-privacy, identifiable name sharing nothing with either the company name or the domain label. Registrant data is redacted far more often than not, so in practice this is quiet.
Four of the nine tests exist to prove it does NOT fire, and two of those were found missing by mutation testing:
- a privacy/proxy registrant (`Domains By Proxy`, `REDACTED FOR PRIVACY`) is never a conflict
- a registrant that is only a legal suffix (`LLC`, `Ltd`) has nothing to compare, so it is not a conflict
- a domain registered by a named employee of the right company is not a different entity
- matching the company name or the domain label clears it — a company whose domain does not contain its own name is entirely ordinary
It records and flags. It changes nothing.
Every source fails soft: timeout, try/catch, null. A `null` means *could not determine* and never *clean* — the caller treats it as skip. Collapsing those two is how a network blip becomes a clean bill of health.
What this is NOT
Not a people-search tool. There is no input that takes a person. It reads the public registration record of a domain — the same record every registrar publishes — to answer one question about a company you are already transacting with.
Proof
9 tests. Four deliberate defects were applied to the real source and the suite caught 4 of 4, including the two false-positive guards a sweep found untested.
Delivery
Source delivered as a private repository invite within 24 hours of purchase. Single-product commercial license: use and modify in any number of products; no redistribution or resale of the source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function assessRegistration(company: string, facts: RegistrationFacts): RegistrationMismatch | null;
export async function verifyCompanyRegistration(company: string, domain: string): Promise<RegistrationFinding | null>;
export function summarizeRegistration(f: RegistrationFacts): string;01Capabilities
Does
- + Input validation
- + Domain parsing
- + Entity resolution
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 9/9 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 8 source file(s) plus listing text
- capability contract 4 undeclared (0 credential-class): rdap.org, dns.google, web.archive.org, crt.sh
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 10, 2026 | First public release. |