How To Keep Your Domain Name Searches Safe From Poachers
domainsherpa.com
domainsherpa.com
GoDaddy is allegedly one of the biggest domain frontrunners, so I don't see much value in instantdomainsearch.com. imo the domainsherpa.com suggestions on domain search are far superior.
That is not exactly correct. Doing a search returns data from instantdomainsearch.com itself. Only once it is returned do you have the option to go to a registrar like godaddy, among others (or just take that name to a registrar of your liking), to actually register the domain.
I have used instantdomainsearch.com many, many times myself to great success.
They are showing suggested alternative domains for sale through BuyDomains.com. It's possible they have a database of available domains, but they may also be using an API which would leak searches.
Why is it not correct ?
When I click the search button, it takes me to the GoDaddy site. Did you really try clicking the Search button on instantdomainsearch.com ?
But you do NOT need to click on the Search button at all to use the site. I used in the past and I did not even notice there was Search button.
Note that you're not guaranteed they're safe because it's trivial for an ISP to sniff all port 43 traffic, but it's a lot better than giving your unregistered name to someone who has a conflict of interest.
We are just using a linux terminal on the back end and this data goes nowhere.
1. That seems to assume that one is using their ISPs DNS service. What if I'm querying the top level .com servers directly? Is that safe?
2. Even if you are using your ISPs DNS servers, if they are getting that data from their logs and selling it I'd expect there would be a fair delay before the data got to some third party that would act on it. That should make it safe if your intent is to buy the domain soon, shouldn't it?
Yes, any ISP would likely have a substantial delay in collecting, filtering and selling this type of data, which is why I think DNFR is most likely happening at registrars. I'm just presenting the facts that there are "middlemen" in the process that people should know about. Thanks for helping me clarify.
First, ask the root servers for the authoritative servers for the TLD you are interested in:
$ dig @f.root-servers.net www.google.com
[...]
;; WARNING: recursion requested but not available
;; QUESTION SECTION:
;www.google.com. IN A
;; AUTHORITY SECTION:
com. 172800 IN NS a.gtld-servers.net.
com. 172800 IN NS b.gtld-servers.net.
[...]
com. 172800 IN NS m.gtld-servers.net.
;; ADDITIONAL SECTION:
a.gtld-servers.net. 172800 IN A 192.5.6.30
b.gtld-servers.net. 172800 IN A 192.33.14.30
[...]
m.gtld-servers.net. 172800 IN A 192.55.83.30
a.gtld-servers.net. 172800 IN AAAA 2001:503:a83e::2:30
[...]
The root servers don't know about google.com, but suggest you ask
[a-m].gtld-servers.net, which are authoritative for .com. (Other TLDs have
other authoritative servers.) So let's ask l.gtld-servers.net: $ dig @l.gtld-servers.net www.google.com
[...]
;; WARNING: recursion requested but not available
;; QUESTION SECTION:
;www.google.com. IN A
;; AUTHORITY SECTION:
google.com. 172800 IN NS ns2.google.com.
google.com. 172800 IN NS ns1.google.com.
google.com. 172800 IN NS ns3.google.com.
google.com. 172800 IN NS ns4.google.com.
;; ADDITIONAL SECTION:
ns2.google.com. 172800 IN A 216.239.34.10
[...]
ns4.google.com. 172800 IN A 216.239.38.10
[...]
The above is an example of a registered domain ("I don't know about
www.google.com, ask ns[1-4].google.com"); if the domain is not registered, it
looks like this: $ dig @l.gtld-servers.net no-such-domain.com
[...]
;; WARNING: recursion requested but not available
;; QUESTION SECTION:
;no-such-domain.com. IN A
;; AUTHORITY SECTION:
com. 900 IN SOA a.gtld-servers.net. nstld.verisign-grs.com. 1301905185 1800 900 604800 86400
[...]
Of course, [a-m].gtld-servers.net are run by Verisign, who could use this information for front-running. I'd be very surprised if they did, though. (DNSSEC may make it possible to query for the existence of a name without revealing it to the answering server, but I'm not sure - I'd have to read up on the protocol.)Note that running through a dictionary and looking for hashes "near" the domain you're interested in works if the DNS server is nice enough to hand out responses of the above form; unfortunately, this can also be used to find which host names are valid for a domain (host names aren't exactly crypto-strength passwords). At least djb advocates giving out answers of the form "there are no domains with hashes between 0xCAFEBABE and 0xCAFEBAC0" (that is, exactly bracketing the query), in which case you'd need to do something more clever.
Unfortunately, I'm not intimately familiar with DNSSEC. I'd be happy to learn the answer, though; if you find it, could you post it as a response, or, if takes a while, e-mail me? (E-mail in profile.)
[EDIT: improved wording, make it clear that actually sending the whole dictionary to the DNS server is not necessary.]
Dear Network Solutions Customer,
Earlier this year, we notified you of the settlement of a class action lawsuit brought against Network Solutions® in connection with our domain name customer protection measure that was discontinued last year.
Today, we are pleased to announce that the court has officially approved the settlement and as result, you are being issued a $6.00 credit applicable to any Network Solutions product or service purchased on the Network Solutions website, valid for one year from the date of the issuance of the credit. Your credit is equal to $6 per qualifying domain name registered through Network Solutions. For example, if you registered two qualifying domains you can expect to receive a credit of $12.00.
A qualifying domain name is one that was (i) searched for through Network Solutions on or between December 14, 2007 and March 15, 2008, (ii) reserved by Network Solutions under our customer protection measure, (iii) registered by you through Network Solutions within the same internet session used for the domain availability search, and (iv) not previously refunded.
You can use your credit to register domain names, get reliable Web hosting, create a website, secure your existing site & more.
To take advantage of your credit, follow these simple steps:
Visit www.networksolutions.com and select the product(s) you wish to purchase. In the shopping cart, click ‘Redeem Offer Code’. Enter coupon code XYXYXYXYXYXYXYXYXYX then click ‘Continue’. Your discount will be reflected in the shopping cart. Please note that this settlement does not in any way impact the domain names that you registered, or the terms of domain names you have registered. No action is necessary on your part.
Sincerely,
Network Solutions® Customer Support
/sarcasm
First, I never search for a complete name. I use www.namedroppers.com that allows partial name searches. E.g. if I'm looking for 'coolwidgets', I'd search for "olwidge".
And second, if I see a potentially interesting domain, I grab it right away, without any worries about the cost -- I'll just drop it a year later if I don't need it.
I was positively gutted.
(For those who don't know the domain space 4 letter pronouncable dot-coms are often valued in the five digit range ($xx,xxx) - that one probably just a few thousand but still a good ROI vs. $10 to register. I'd have been happy to build something fun on it.)
There is a lot of anecdotal evidence that Godaddy does steal names from searches. I spend a lot of time working in the domain space and I hear about it from the pros from time to time.
While I'm sure a bit of front running must still go on, it's hard for me to believe it happens to the average joe much if ever. In that light the rules that page lay out sound pretty over the top, and I'm generally a pretty paranoid person. I'd only worry about front running today if I was a known high value target, one who buys or holds a lot of domains. If that was me, I'd just take some mild precautions. Don't use my registrar to search for domains, clear tracking cookies before searching. The implications that you can't trust your ISP DNS system, search engines and certain whois services sounds like '06-'08 logic to me.
we made nametoolkit.com and don't buy domains, ever, not counting nametoolit & name-toolkit.
By the time I closed an paid for the DNS the .net and all other variations had been bought and were directing to those generic filler pages. I can only hope that which ever group poached those wasted some amount of time, effort, or money. I don't run a business from it, and never intend to, but I can see how this kind of shady behavior would warent paranoia from those looking to run a business around a given DNS (/corresponding business name).
Spend a few hours and write your own code to do direct registry searches through the whois telnet query.
I wrote one myself, it's not that hard and you'll learn a bit.
You don't have to resolve them that far to see if they are not-registered (or when they expire) just hit the main registry for the TLD you are interested in.
I plan to update the article on DomainSherpa (http://doms.to/vra) soon with this information.
Set this up to happen on a daily basis through proxy servers for different ips, and you might create an interesting way to bleed them a little bit.
Record the domains entered, and see how many times you get them to nick you. It would make for a fun blog post.
Keep in mind, they have to pay ever time they register a domain.
I do find it rather odd that the owner isn't responding to contact via the whois record - seems an odd sort of extortion where they don't want to take your money.
This sort of stuff happens all the time. As far as I know, it's not usually passed with respect to LLC but rather Trademark.
Regardless, if you really want that name you could have a fighting chance at it.
Look up UDRP to learn more. Better yet UDRP lawyer. There's one who advertises a lot on some of the forums I read. Let me know if you're interested and I can put a bit more legwork into tracking down a name for you.
Entrepreneurs should always register the domain name BEFORE you register for your company.
Since then I've only searched for names I've been willing to buy right away if it was available.
// The .com.au space is much harder to register a domain for than .com
Years ago it was much more difficult, but since then it's been pretty straightforward. None of these names were trademarks or anything like that so there wasn't anything I could contest.
The next day he went to register it and found that it was taken... by godaddy.
Godaddy then set it as a "premium domain" and changed the price to $500.
He was pissed.
He accepted the version of the domain with a '-' between the two words instead. He recently emailed godaddy and let them know that he has 800+ domains with them, explained what happened and said "I would like the domain that you took, unethically, for the regular domain registration price that all available domains go for or I will take my ~$9,000 in annual renewal fees to another registrar.
He has not heard back from godaddy. But he switched his searches aways from them.
I on the otherhand, typically only search for a domain if I am willing to spend the 10 right then to grab it.
function randomWord() { head -n $(numrandom /1..$(wc -l /usr/share/dict/words)/) /usr/share/dict/words | tail -n1; } echo $(randomWord)$(randomWord).com
This has given me an obscure two-word domain name, which I searched in GoDaddy - all subdomains GoDaddy sells weren't registered.
I've repeated this to give a total of twelve domains. The final two of these domains are saucepansgrooming.com and rivaledpopping.com. The other ten domains are written on a folded over piece of paper, and aside from me, the only place they have been disclosed is in a GoDaddy search (which was sent unencrypted over the Internet - so technically someone could have sniffed it). I haven't even attempted a domain name resolution on any of the 12 names.
I plan to come back in a few hours and repeat the search to see whether the names are still available.
This doesn't necessarily mean that GoDaddy doesn't ever take domains - maybe they only do it from high value customers who they think they can extract more money from, rather than people who aren't logged in; maybe I searched for too many domains with too few common substrings so their algorithm classified me as not wanting to seriously buy; maybe I didn't wait long enough because they manually decide which ones to buy; maybe the names I tried are too long to be considered valuable.
Like the article suggests, I always search at the terminal. If the name is available it gets registered then. I look at it as 8 bucks buying me a one year option on the name.
It would be close to $9k at any other registrar though, so I suspect your friend will end up like many before, including me, learning his lesson but leaving the domains there.