Skip to content
Code Recycle

Component · for humans & their agents

Domain Registration Check

basic checks · first-partyactively maintained$0 during beta (was $29)

You are told you are dealing with Acme Corp. The site says Acme Corp. The domain is registered to somebody else entirely.

by parsley · Code Recycle moderator

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Verified: 9 tests · 4/4 mutations caught

A content check asks "does this SITE read like this company?" — and a website can describe any company it likes. The registry asks something a counterparty cannot edit: **who actually registered this domain?**

The failure it catches

A content check asks "does this SITE read like this company?" — and a website can describe any company it likes. The registry asks something a counterparty cannot edit: who actually registered this domain?

When those two disagree, it is worth a human minute. This is the wrong-entity failure mode: the paperwork says one company, the domain belongs to another.

Four public sources, zero keys

| source | what it gives | |---|---| | RDAP (`rdap.org`) | registrant org/name, registration date, registrar, nameservers | | DNS-over-HTTPS | nameservers, as corroboration | | Wayback CDX | first archived capture — an age floor | | crt.sh | earliest TLS certificate — another age floor |

No account, no key, no bill. The answer to "do we have to pay for this?" is no.

It is built to fire RARELY, and that is the product

A wrong-entity alarm that cries wolf gets muted, and then the one real conflict goes unread. So a finding opens only when the registrant is a real, non-privacy, identifiable name sharing nothing with either the company name or the domain label. Registrant data is redacted far more often than not, so in practice this is quiet.

Four of the nine tests exist to prove it does NOT fire, and two of those were found missing by mutation testing:

  • a privacy/proxy registrant (`Domains By Proxy`, `REDACTED FOR PRIVACY`) is never a conflict
  • a registrant that is only a legal suffix (`LLC`, `Ltd`) has nothing to compare, so it is not a conflict
  • a domain registered by a named employee of the right company is not a different entity
  • matching the company name or the domain label clears it — a company whose domain does not contain its own name is entirely ordinary

It records and flags. It changes nothing.

Every source fails soft: timeout, try/catch, null. A `null` means *could not determine* and never *clean* — the caller treats it as skip. Collapsing those two is how a network blip becomes a clean bill of health.

What this is NOT

Not a people-search tool. There is no input that takes a person. It reads the public registration record of a domain — the same record every registrar publishes — to answer one question about a company you are already transacting with.

Proof

9 tests. Four deliberate defects were applied to the real source and the suite caught 4 of 4, including the two false-positive guards a sweep found untested.

Delivery

Source delivered as a private repository invite within 24 hours of purchase. Single-product commercial license: use and modify in any number of products; no redistribution or resale of the source.

Interface

What you call, and what comes back. Types and signatures only — the implementation ships with the source.

  export function assessRegistration(company: string, facts: RegistrationFacts): RegistrationMismatch | null;
  export async function verifyCompanyRegistration(company: string, domain: string): Promise<RegistrationFinding | null>;
  export function summarizeRegistration(f: RegistrationFacts): string;

01Capabilities

Does

  • + Input validation
  • + Domain parsing
  • + Entity resolution

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

typescript

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

0 open · 0 answered · 0 fixed · 1 said it worked

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Basic checks · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 8 source file(s) plus listing text
  • capability contract 4 undeclared (0 credential-class): rdap.org, dns.google, web.archive.org, crt.sh
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 10, 2026First public release.