Pillar guide · DOMAINS · 26 min read

Domain Names: A Complete Guide

How domains work, what gTLD vs ccTLD really means, and how to pick and protect one

Domain Names: A Complete Guide
Illustration · HostDir Editorial

A domain name maps an IP address to a human-readable string. DNS root servers delegate authority to registries for TLDs (like .com, .org). Registrars sell domains to registrants under contract with ICANN. The system uses WHOIS/RDAP for ownership data, auth codes to transfer between registrars, and registry locks to prevent hijacking. Pick a TLD based on brand fit, audience, and renewal price, not just first-year cost.

What a domain name actually is

A domain name is a human-readable label that maps to a numerical IP address. Without it, you would reach websites by typing something like 93.184.216.34. Domain names exist because the people who designed the early internet (notably Paul Mockapetris in 1983, RFC 882 and 883) decided that names were easier to remember than numbers.

Technically, a domain name is a string that conforms to the DNS (Domain Name System) hierarchy. It is composed of labels separated by dots. www.example.com has three labels: www, example, and com. The DNS reads them from right to left. The rightmost label (com) is the top-level domain (TLD). The label to its left (example) is the second-level domain (SLD), which is what you register. The leftmost label (www) is a hostname or subdomain, which the registrant controls.

One common misunderstanding: buying a domain does not buy you a website. It buys you a lease on a DNS entry. The registry (the organization that runs the TLD, e.g., Verisign for .com) delegates authority for that second-level domain to you. You then set NS (nameserver) records to point the domain somewhere. The domain itself is just a pointer. The web content lives on a server at that pointed IP address.

Domain names are not case-sensitive. Example.com and example.com resolve the same way, though the canonical form is lowercase. The maximum length of a full domain name (including dots) is 253 ASCII characters. Each label can be up to 63 characters.

Another key point: a domain name is not a URL. A URL includes the protocol and path, like https://www.example.com/page. The domain is only the www.example.com part. This distinction matters when configuring web servers and SSL certificates.

When you type a domain into a browser, the operating system first checks its local cache and the hosts file, then queries a recursive resolver. The resolver walks the DNS tree: it asks the root server where .com is, then asks the .com nameserver where example.com is, then asks the domain's authoritative nameserver for the A or AAAA record. The whole process takes milliseconds.

TLDs, gTLDs, ccTLDs, sTLDs: the hierarchy explained

The Domain Name System (DNS) is a tree. At the very top sits the root zone, represented as a single dot. Below the root come top-level domains (TLDs). A TLD is everything after the last dot in a domain name: .com, .org, .uk, .gov, and hundreds more. The Internet Assigned Numbers Authority (IANA) maintains the official list of all TLDs. As of 2025, there are more than 1,500 TLDs delegated in the root zone.

TLDs break into three main categories: generic TLDs (gTLDs), country-code TLDs (ccTLDs), and sponsored TLDs (sTLDs). A fourth category, infrastructure TLDs, contains exactly one: .arpa, used for reverse DNS lookups and technical infrastructure. You will never register a domain under .arpa.

Generic TLDs (gTLDs)

Generic TLDs are the most visible group. The original seven gTLDs were defined in RFC 920 (1984): .com, .edu, .gov, .int, .mil, .net, and .org. Of those, .com, .net, and .org were open for anyone to register. The others were restricted to specific types of organizations. In 2012, ICANN launched the New gTLD Program, which opened the door to hundreds of new gTLDs like .app, .blog, .cloud, .io, .ai, and .xyz. As of early 2025, over 1,200 new gTLDs are in the root zone.

New gTLDs operate under registry agreements with ICANN. Each registry runs its own rules for pricing, eligibility, and abuse prevention. Some gTLDs, like .bank and .pharmacy, have strict verification requirements. Others, like .click or .xyz, allow registration by anyone with a credit card.

Country-Code TLDs (ccTLDs)

Country-code TLDs are two-letter codes based on ISO 3166-1 alpha-2. Each corresponds to a country or territory. Examples include .us (United States), .de (Germany), .jp (Japan), and .io (British Indian Ocean Territory). ccTLDs are managed by each country's designated manager, often called a ccTLD registry. Policies vary widely. .de requires a German administrative contact. .tv (Tuvalu) and .io have no geographic restrictions and are marketed globally. ccTLDs are not subject to ICANN's contractual framework in the same way gTLDs are, though they must follow technical standards (RFC 1591).

Sponsored TLDs (sTLDs)

Sponsored TLDs are a subset of gTLDs that serve a specific community. A sponsoring organization represents that community and sets eligibility rules. Examples include .aero (air transport industry, sponsored by SITA), .cat (Catalan language and culture, sponsored by Fundació puntCAT), .coop (cooperatives, sponsored by DotCooperation LLC), .museum (museums, sponsored by the Museum Domain Management Association), and .travel (travel industry, sponsored by Tralliance Registry Management Company). To register a domain under an sTLD, you typically must prove membership in the relevant community. The sponsoring organization enforces these rules.

The hierarchy in practice

When you type example.com into a browser, the resolver walks the tree. It queries the root servers for .com, then the .com registry's name servers for example.com. The TLD determines which registry holds the authoritative data for that domain. The registry publishes the zone file that lists the domain's name servers. The registrar (the company you pay) communicates with the registry via the Extensible Provisioning Protocol (EPP) on port 700. This is why you cannot register a domain directly with the registry: you must go through an ICANN-accredited registrar or a reseller.

Understanding the TLD hierarchy helps you choose where to register. A .com domain costs roughly $10 to $15 per year at most registrars. A .io domain often costs $40 to $60 per year because the ccTLD registry (Internet Computer Bureau, now part of Identity Digital) sets higher wholesale prices. A .gov domain is free but requires a government entity to apply. The TLD is not just a suffix. It determines the registry, the rules, the price, and sometimes the legal jurisdiction for dispute resolution.

Registries vs registrars vs registrants

The domain name system depends on three distinct roles that often get confused: the registry, the registrar, and the registrant. Each has a separate function in the lifecycle of a domain name. Understanding the difference helps you know who to contact when something goes wrong and where your money actually goes.

Registry: the authoritative database owner

The registry is the organization that manages a specific top-level domain (TLD). For .com and .net, that is Verisign. For .org, the Public Interest Registry (PIR) runs it. For country-code TLDs like .uk (Nominet) or .de (DENIC), the local registry manages it. The registry operates the central database of all domain names registered under that TLD. They define the rules for that TLD, set the wholesale price that registrars pay, and run the authoritative name servers that answer DNS queries for that TLD. A registry does not sell domains to end users. They only deal with accredited registrars.

Registrar: the retail interface

A registrar is a company that has been accredited by ICANN (for gTLDs) or by the country-code registry (for ccTLDs) to sell domain registrations to the public. Registrars act as the middleman. They handle billing, customer support, DNS management panels, WHOIS data collection, and domain transfers. Examples include GoDaddy, Namecheap, Cloudflare, Google Domains (now sold to Squarespace), and dozens of smaller resellers. Many registrars also offer web hosting, email, and SSL certificates, but their core function is to push registration requests to the registry on your behalf. When you pay for a domain, part of that fee goes to the registrar, and part of it (often the majority) is passed to the registry as a yearly fee.

Registrant: you, the domain owner

The registrant is the individual or organization that holds the legal right to use a domain name for a fixed period. You are the registrant when you buy a domain. Your name, address, email, and phone number are submitted to the registrar and, unless you use WHOIS privacy, become visible in the public WHOIS database. The registrant has the right to renew the domain, transfer it to another registrar, update DNS records, or let it expire. The registrant does not own the domain permanently. They lease it, one year at a time, from the registry via the registrar.

How the money flows

Registry sets a wholesale price ($7.85 for .com as of 2024). Registrar marks it up to whatever they want (often $10 to $15). Registrant pays the retail price. If a registrar goes out of business, ICANN has a process to transfer domains to another accredited registrar so the registrant does not lose their domain. But if the registrar fails to pay the registry, the domain can be suspended regardless of whether the registrant has already paid the registrar.

How a domain registration actually flows (EPP, WHOIS, DNS)

When you register a domain, you aren't just picking a name and paying a fee. A specific sequence happens behind the scenes, involving your registrar, a registry operator, and the global DNS infrastructure. Understanding this flow helps you troubleshoot delays, avoid registration failures, and appreciate why you must keep your WHOIS data accurate.

Step 1: Checking availability

Your registrar queries the registry's EPP server with a domain:check command. The registry responds with an avail flag. EPP is the standard protocol defined in RFC 5731 (and related RFCs 5732-5734) that governs communication between registrars and registries. If the domain name is available, the registrar moves to the next step.

Step 2: Submitting the registration request

You fill out contact details: registrant, administrative, technical, and billing contacts (though many modern systems use only registrant and admin). Your registrar constructs an ep:domain:create EPP XML payload. This includes:

  • The domain name (e.g., example.com)
  • Registration period (usually 1-10 years)
  • Contact IDs or raw contact data
  • Nameserver hostnames (or host objects)
  • Optional authInfo (a registrar-generated code for future transfers)

The registrar sends this over a TLS-encrypted EPP connection to the registry's production endpoint (typically port 700). The registry validates the request: checks that the domain is still available, verifies the registrar's credentials, and ensures the contact data passes syntax checks. If everything passes, the registry creates the domain record and returns an EPP response with a creDate (creation timestamp).

Step 3: WHOIS population

Once the domain is created, the registry populates its WHOIS database. This data is exposed through port 43 (the WHOIS protocol per RFC 3912) and often through a web-based WHOIS lookup. The registry also pushes the data to thin WHOIS services if the TLD uses a thin model (like .com and .net, where only registrar and nameserver info is stored; thick TLDs like .org store full contacts). Your registrar may also run its own WHOIS server that mirrors the registry's data. Your email address and phone number become publicly visible here unless you purchase WHOIS privacy or live in a GDPR-compliant region where the registry masks them by default.

Step 4: DNS delegation

A domain name is useless until its NS records point to working DNS servers. In the EPP domain:create request, your registrar specified nameserver hostnames. The registry adds these NS records to the TLD zone file. For example, if you registered example.com, the .com zone now includes a delegation from example.com to ns1.yourhost.com and ns2.yourhost.com. This propagation to the root and TLD nameservers usually happens within minutes, but it can take up to 48 hours globally due to DNS caching. To speed things up, set lower TTLs on your own nameservers after delegation.

Step 5: Finalizing the registration

The registry sends a confirmation to the registrar, who then marks the domain as active in their billing system. Some registries also send an email verification request to the registrant's email address (as required by ICANN for gTLDs). You must click the validation link within 15 days or the registration may be suspended. After that, your domain is live and ready to host a website or email service.

Picking a TLD: brand, intent, perception, and price

The TLD you choose is the first thing people see after your domain name. It signals what you do, where you are, and how serious you are. But the choice is no longer limited to .com, .org, and .net. Since ICANN’s new gTLD program launched in 2013, there are over 1,500 TLDs. Picking one requires weighing four factors: brand alignment, user intent, public perception, and renewal cost.

Brand alignment and meaning

A TLD can reinforce your brand or confuse it. A tech consultancy might register as name.io to imply input/output or “I/O”. A pizzeria could use name.pizza. These specific TLDs tell visitors instantly what the site offers. But they carry risk: if you pick .pizza and later want to sell the business, the TLD might limit buyers. Generic TLDs like .com or .net are neutral and resellable. If your company name is ambiguous, a descriptive TLD like .tech, .design, or .law helps disambiguate.

User intent and trust

Users type .com out of habit. Data from Verisign’s Domain Name Industry Brief shows .com accounts for about 46% of all registered domains (as of Q4 2024). People assume a business has a .com. If you pick a less common TLD, expect some email typos and direct navigation loss. However, new TLDs can signal intent. A site like example.blog tells the user it is a blog, not a store. For startups, .app hints at a downloadable application. Google treats all TLDs equally in search ranking, but user trust varies. A 2023 survey by McAfee found that 72% of users distrust .zip and .mov TLDs because they mimic file extensions. Avoid TLDs that look like file names or system extensions unless you have a specific security reason.

Country TLDs and local perception

ccTLDs like .de (Germany), .co.uk, .jp, or .ca imply local presence. Many ccTLDs require a local address or registration. Google uses ccTLDs as a strong geotargeting signal. If you operate in one country only, a ccTLD can improve local click-through rates. But if you expand internationally, a ccTLD may pigeonhole your brand. Some ccTLDs are repurposed globally: .io (British Indian Ocean Territory) is popular with tech startups, .tv (Tuvalu) for streaming sites, .ly (Libya) for link shorteners. These carry no geographic requirement but registration costs vary widely. .io renewals have jumped from $30 to over $70 per year in 2024 for some registrars.

Price tiers

TLD prices diverge wildly. .com renews around $10 to $15. .tech renews around $20 to $30. Specialty TLDs like .luxury, .beer, or .realty can cost $50 to $100+ per year. Some registries use introductory teaser pricing (e.g., $2 first year, $80 renewal). Always check the renewal price before registering. The most expensive domains are not names but TLDs: .inc can cost $2,000 per year. For a small business or personal site, a premium TLD might not justify the yearly cost.

Three practical rules

  • If your domain is a brand name, buy the .com even if you use another TLD for your main site. Redirect it.
  • If your site serves one country, consider that country’s ccTLD over a generic new gTLD.
  • Check the renewal price, transfer-out policies, and whether the registry allows private WHOIS. Some restrictive TLDs (like .bank) require strict verification.

In short, your TLD is a signal. Pick one that reinforces your message, fits your audience’s expectations, and stays within your budget for the long term.

WHOIS, privacy, and GDPR

Every domain registration has a public record called WHOIS. Since the early days of the internet (RFC 812, 1982), WHOIS was a simple directory: anyone could look up a domain and see the registrant's name, address, phone number, and email. The system worked fine when the internet was a research network. By the late 1990s, spammers, telemarketers, and identity thieves were scraping WHOIS databases daily.

The original WHOIS model forced registrants to publish their personal contact details as a condition of owning a domain. ICANN required it. If you wanted example.com, your home address went into a public database. The consequences were predictable: spam, harassment, doxxing. The domain industry responded with a tiered solution called WHOIS Privacy, also called Private Registration.

WHOIS Privacy is a service offered by registrars. The registrar replaces the registrant's personal contact information in the public WHOIS output with generic proxy data. Typically the registrar lists itself or a forwarding service as the registrant org, and provides a contact email that forwards to the real owner. The underlying registration at the registry still points to the true registrant; the public query only sees the privacy shield. Services like Namecheap's WhoisGuard and GoDaddy's Domains by Proxy have been offering this for over a decade.

Then came the GDPR (General Data Protection Regulation) in May 2018. European law treats a person's name, home address, phone number, and email as personal data. Publishing them without explicit consent violates Article 6 of GDPR. ICANN could not force registrars and registries to expose personal data of EU residents. The result was a messy compromise: registrars began redacting personal fields in WHOIS output, showing only the state, country, and masked contact email. Non-EU registrants also got redacted output because it was easier for registrars to apply one policy globally.

Today, the public WHOIS record for most domains shows something like this:

Registrant Name: REDACTED FOR PRIVACY
Registrant Organization:
Registrant Street: REDACTED FOR PRIVACY
Registrant City: REDACTED FOR PRIVACY
Registrant State/Province: California
Registrant Postal Code: REDACTED FOR PRIVACY
Registrant Country: US
Registrant Email: [REDACTED]@example.com

The reduction in public WHOIS data changed how domain ownership disputes, abuse reporting, and law enforcement operate. ICANN introduced the Registration Data Access Protocol (RDAP), specified in RFC 9082 and RFC 9083, as a replacement for the WHOIS port-43 protocol. RDAP provides tiered access: redacted data for the public, full data for authorized requesters. The system is still being adopted; not all TLDs and registrars support RDAP fully as of 2025.

If you run a business and need your real contact info visible for customer trust, you can opt out of WHOIS privacy at many registrars. But the default is now almost always redacted, regardless of TLD. The only major exceptions are a few ccTLDs like .DE (Germany) and .NL (Netherlands) that require accurate public WHOIS by their registry rules, and some profession-specific sTLDs like .BAR or .LAWYER that publish your name for verification.

Regardless of privacy settings, your registrar still has your accurate data. You are required by ICANN's Registrar Accreditation Agreement (RAA) to keep your contact information current. If you move, update it. Stale WHOIS data is a common cause of domain loss when renewal notices go to a dead email and the domain drops.

Domain transfers, auth codes, and the 60-day rule

A domain transfer moves the registration of a domain from one registrar to another. It does not move DNS hosting or website content. Those are separate services, even if your current registrar bundles them. The transfer process is governed by the Extensible Provisioning Protocol (EPP), which all ICANN-accredited registrars use. The registry does not care who you pay; it only cares which registrar is the sponsor of the domain in its database.

Auth codes (EPP codes)

Every domain registered under a gTLD (like .com, .org, .net) has an auth code, also called an EPP code. It is a case-sensitive string assigned by your current registrar. You must provide this code to the gaining registrar to initiate the transfer. The code proves you have authority over the domain. Without it, the gaining registrar cannot request the transfer from the registry. Some ccTLDs like .uk use a different system called IPS tags, but the principle is the same. You can usually generate a new auth code from your registrar's control panel. If the code fails to work, it may have expired or been regenerated. Generate a fresh one and try again within 24 hours.

The 60-day transfer lock

ICANN rule 2013R-13 states that when you register a new domain or change the registrant contact (the actual owner), the registry will impose a 60-day transfer lock. During this period, the domain cannot be transferred to a different registrar. This rule exists to prevent domain theft: if someone hijacks your account and changes the registrant email, they cannot immediately transfer the domain away. The lock is non-negotiable for most gTLDs. Some registrars let you waive it, but that is a violation of ICANN policy if done at registration. The safe approach is to plan ahead. If you know you will move a domain, change the registrant contact after the transfer, not before.

Transfer steps in order

The standard flow looks like this:

  1. Unlock the domain. Disable the registrar lock in your current registrar's control panel.
  2. Get your auth code. Copy the EPP code from your current registrar.
  3. Initiate at the gaining registrar. Enter the domain name and auth code. The gaining registrar sends an EPP transfer request to the registry.
  4. Approve or wait out the auto-approve. The current registrar emails the registrant address (the one on file in WHOIS) asking for approval. If you do nothing, the transfer auto-approves after five days. You can approve immediately via a link in that email.
  5. ICANN fees and extension. Transferring adds one year to the domain's expiration date (capped at 10 years total). The gaining registrar charges the ICANN fee, usually included in the transfer price.

Be careful with domains less than 60 days old or with recent registrant changes. The registry will reject the transfer request, and you may waste the fee. Always check WHOIS for the Transfer Prohibited status. If you see clientTransferProhibited or pendingTransfer, proceed with caution.

Domain locks, registry locks, and stopping domain hijacks

A domain hijack happens when an attacker gains control of your domain without your permission. They change the DNS records, redirect your traffic, or transfer the domain to a different registrar. The worst part: many hijacks start with a social engineering attack against your registrar's support team. The attacker convinces the help desk to reset the account password or approve an unauthorized transfer. Two technical controls stop this cold: the registrar lock and the registry lock.

The registrar lock (clientTransferProhibited)

The registrar lock is your first line of defense. It is an EPP status code sent to the registry that tells the registry: reject any transfer request for this domain. The code is clientTransferProhibited. Every major registrar applies this lock by default to your domain the moment you register it. You can see it yourself. On a Linux box, run:

whois example.com | grep -i status

If the output includes clientTransferProhibited, your registrar lock is on. To transfer a domain to another registrar, you must log into your registrar dashboard, explicitly unlock the domain, and generate an auth code. The lock is a simple on/off toggle in the registrar control panel. A registrant can turn it off at will. That is its weakness. If an attacker steals your registrar login credentials, they can unlock the domain and start a transfer.

The registry lock (serverStatus codes)

The registry lock is stronger. It lives at the registry operator level, not at the registrar level. The registry lock uses one of two EPP codes: serverTransferProhibited or serverStatusProhibited. The registrant cannot remove this lock through the registrar control panel. Removing it requires a process that usually involves verifying identity out of band, often through a phone call, a notarized letter, or an in-person meeting with the registrar. For Verisign-operated TLDs like .com and .net, the optional Registry Lock service requires the registrar to request the unlock on behalf of the registrant, and Verisign flags the request for manual review.

Registry locks protect against credential theft. Even if an attacker has full access to your registrar account, they cannot change the domain's authorization or transfer it because the server-side status block sits above the registrar. No registrar can override it unilaterally.

How to get a registry lock

Not every registrar offers the registry lock service. Among those that do: Cloudflare, MarkMonitor, CSC, and OpenSRS (through select resellers). The service costs extra, usually $50 to $200 per year on top of the renewal fee. Some registrars require a contract and a verified point of contact. For a high-value domain, say a .com that runs your ecommerce store or your email infrastructure, the cost is trivial compared to the risk of a hijack.

Other protective steps

The registrar lock and registry lock only block transfers and DNS changes at the registry level. They do not prevent an attacker from logging into your registrar account and changing the nameservers if the lock is off. Pair the locks with two-factor authentication on your registrar account. Use a hardware key (YubiKey, Google Titan) if the registrar supports FIDO2. Disable domain contact email as a password reset mechanism if you can. And check your domain's WHOIS status codes periodically. Any code you did not set yourself is a red flag. A quick weekly check with a cron job running whois yourdomain.com | grep -E '^ Domain Status:' is a simple safety net.

IDNs and Punycode for non-ASCII domains

The Domain Name System was originally designed to handle only ASCII characters: the 26 letters A through Z, the digits 0 through 9, and the hyphen. That worked fine for English, but it excluded billions of people who write in Arabic, Chinese, Cyrillic, Devanagari, Greek, Hebrew, Japanese, Korean, Thai, and dozens of other scripts. In 2003, the IETF published RFC 3490, RFC 3491, and RFC 3492, collectively defining Internationalized Domain Names (IDNs). These standards let you register and use domain names containing non-ASCII characters.

ICANN opened IDN registrations for gTLDs starting in 2009. Today, most major registries support them. Verisign, for example, began accepting IDN .com and .net registrations in 2011. As of 2024, over 10 million IDN domains are registered globally.

How Punycode works

Under the hood, DNS still only understands ASCII. So IDNs are converted to a special ASCII representation called Punycode. The algorithm defined in RFC 3492 takes a Unicode string and encodes it into a string that starts with xn--. For example, the Chinese domain 例子.测试 becomes xn--fsqu00a.xn--0zwm56d. The browser does this conversion transparently. If you type münchen.de into your address bar, the browser sends xn--mnchen-3ya.de to the DNS resolver.

You can see the Punycode form of any IDN by using the idn command on Linux or macOS:

$ idn --punycode münchen.de
xn--mnchen-3ya.de

Or by using online tools like the one at punycode.org.

Registration rules and risks

Not every Unicode character is allowed in a domain name. ICANN maintains a set of IDN Tables that specify which characters each registry accepts. The tables are designed to prevent homograph attacks, where a character from one script looks identical to a character from another. For instance, the Cyrillic small letter a (U+0430) looks exactly like the Latin a (U+0061). A malicious actor could register xn--pple-43d.com (which displays as аррle.com using Cyrillic characters) to phish Apple users.

To mitigate this, registries enforce rules like: a domain label can contain characters from only one script (with exceptions for certain special characters). The Greek, Latin, and Cyrillic scripts cannot be mixed in a single label. Browsers also help. Since Chrome 66 (2018), the address bar displays the Punycode form of any domain that mixes scripts from different Unicode blocks. Firefox and Safari have similar protections.

When you register an IDN, you typically register the Punycode form. The registrar handles the conversion. You pay the same price as for an ASCII domain. The WHOIS record stores both the Punycode and the Unicode representation. DNS resolution works exactly the same way: the Punycode form is what gets stored in the zone file.

One practical gotcha: email addresses using IDNs can be problematic. Not all mail servers handle SMTPUTF8 (RFC 6531) correctly. If you run a mail server, test IDN email delivery before relying on it.

What to do when a domain you want is already taken

So you typed your dream domain into a registrar’s search box and got the dreaded red “unavailable” badge. It happens constantly. There were roughly 358 million registered domains as of Q1 2024 (Verisign Domain Name Industry Brief), and most short combinations in popular TLDs like .com were gone years ago. But a taken domain isn’t a dead end. You have several real options, ranging from free workarounds to moderately expensive purchases.

Try a different TLD or alternate name

The simplest fix: pick a different extension. If example.com is taken, try example.net, example.co, example.io, or a newer gTLD like example.xyz, example.online, or example.dev. This doesn’t require any negotiation or extra cost. You can also add a hyphen, a short prefix, or a descriptive word to distinguish your name. For instance, getexample.com, examplehq.com, or tryexample.io may still be free. Use whois or any registrar’s search tool to check availability.

Check if the domain is really in use (or parked)

Many registered domains never host a website. They are parked by speculators who hope to sell them later. You can verify by visiting the domain, doing a DNS lookup via dig example.com ANY, and checking if it resolves to an active web server or just a generic parking page. If the domain returns NXDOMAIN or only shows registrar holding pages, the owner might be willing to sell. You can look up the registrant info via WHOIS (if not redacted) or use a domain marketplace to contact the owner.

Use a domain marketplace or broker

If you want the exact domain, you can buy it on the aftermarket. Services like Afternic, Sedo, GoDaddy Auctions, and DAN.com list thousands of domains for sale. Some are priced outright (buy now), others go to auction. You can place an offer the seller may accept. For high demand names, consider a professional domain broker who negotiates for you. Brokers typically charge a success fee between 10% and 20% of the purchase price. Actual sales happen via a transfer process using EPP auth codes (see our section on domain transfers).

Check for expiration and backorder

Domains expire if the owner doesn’t renew. Each TLD has a grace period after expiration (typically 30 to 45 days), followed by a redemption period of 30 days where the domain can be restored for a fee. After that, the domain drops and becomes available for registration again. You can use a backorder service from companies like SnapNames, DropCatch, or your registrar. These services attempt to register the domain the exact second it drops. Backorders are not guaranteed; if multiple parties backorder the same name, it goes to auction. Expect to pay $10 to $60 for the backorder attempt plus the winning auction price.

One warning: do not engage with squatters who send unsolicited emails demanding money to “release” a domain you inquired about. Legitimate aftermarket transactions go through a registrar or marketplace, not side deals.

Use a different name entirely

Sometimes the wisest move is to rebrand. Persisting on a taken domain can cost thousands of dollars and create confusion with an existing site. A unique name that passes a quick trademark search can save you legal headaches later. For example, many startups today use invented words or phrase combinations that are inherently available, rather than fighting for a taken .com. Your registrar search combined with a WHOIS lookup will quickly tell you which routes are open.

If none of these options work, revisit your TLD choice or name structure. The perfect domain for your brand might be waiting in a different extension or with a small tweak.

Frequently asked questions
Who actually owns a domain name? Read

No one owns a domain name. When you register one, you get an exclusive right to use it for a paid term (typically 1-10 years) under ICANN rules. The registry (e.g., Verisign for .com) holds the authoritative database. Your name appears as the registrant in WHOIS, but you lose the domain if you let the term expire and someone else registers it.

What is the difference between a gTLD and a ccTLD? Read

A generic top-level domain (gTLD) like .com or .xyz is open for anyone to register without geographic restriction. A country-code top-level domain (ccTLD) like .de (Germany) or .us (United States) is tied to a specific territory. Some ccTLDs require local presence or citizenship. A sponsored TLD (sTLD) like .gov or .edu requires proof of eligibility from the sponsoring organization.

How do I transfer my domain to a different registrar? Read

First, unlock the domain at your current registrar and obtain the auth code (EPP code). Provide that code to the gaining registrar and start the transfer. ICANN rules require the losing registrar to approve within five days unless you refuse. The transfer adds one year to the domain's expiration. Be aware of the 60-day lock after a change of registrant, which blocks transfers for 60 days.

What is a registry lock and how does it prevent hijacking? Read

A registry lock is an extra security layer applied at the registry level, above your registrar. Any change (DNS delegation update, transfer, deletion) requires out-of-band verification, often by phone or token. This stops attackers from using a support ticket at your registrar to remove a registrar lock. The Verisign Registry Lock service charges a fee. Enterprise domain holders often use it to prevent takeover.

Does WHOIS show my personal address? How is GDPR handled? Read

Since GDPR went into effect in May 2018, most registrars redact personal data in public WHOIS and RDAP output. They replace registrant name, email, and street with something like "Redacted for Privacy" and show a proxy email. Your registrar must still hold your real contact info. Some registrars offer paid WHOIS privacy as an add-on; others include it for free. Law enforcement and IP lawyers can request access through the registrar.

What is Punycode and why does it matter for non-English domains? Read

Punycode is an encoding scheme that converts Unicode characters into ASCII using the prefix xn--. For example, the Chinese string 例子 becomes xn--fsq.xn--fsq. This allows DNS (which handles only ASCII) to support internationalized domain names (IDNs). Attackers exploit this with homograph attacks: they register a Punycode domain that looks visually identical to a known ASCII domain (e.g., using Cyrillic 'а' instead of Latin 'a'). Always verify the actual Punycode.

What can I do if someone already registered the domain I want? Read

First, check the WHOIS record for the domain's expiration date. You can set up a backorder with a drop-catching service like Namecheap Backorder or SnapNames to attempt registration the moment it expires. Alternatively, contact the registrant through the registrar's privacy form. In some cases, you can buy the domain on a marketplace (Afternic, Sedo). For trademark-infringing domains, file a UDRP (Uniform Domain-Name Dispute-Resolution Policy) complaint at WIPO.

Glossary terms used in this guide
DNS Root zone ICANN WHOIS RDAP EPP code Registry lock UDRP Punycode IDN
Put this guide to work Where the practical stuff lives
Continue reading
NETWORKING · Updated Jun 2026

BGP: A Complete Guide to Border Gateway Protocol

How the internet's routing protocol works, why it matters, and what every network operator should know

RFC grounded
INFRASTRUCTURE · Updated Jun 2026

Installing Hermes Agent on a Linux VPS

Self-host Nous Research's open-source AI agent on Ubuntu or Debian with persistent memory, a messaging gateway and a systemd service.

RFC grounded
INFRASTRUCTURE · Updated Jun 2026

Object storage explained: S3, R2, B2 and self-hosted MinIO

A reference for picking an object storage provider, understanding the egress trap, and knowing the parts of the S3 API that actually matter.

RFC grounded

Who Is Online

In total there are 53 users online: 0 registered, 47 guests and 6 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: Applebot Baiduspider Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 369