A domain listing, email address, or social media profile does not by itself prove that someone controls a domain. Before you negotiate seriously or send money, perform a structured domain ownership verification process that checks public registration data, control of the domain, and the identity of the person offering it.
This matters especially when buyers and sellers communicate directly. MarketDomainNames can help people connect through direct listings, but each party should independently confirm ownership and use secure transaction practices before completing a sale. You can browse domain listings while treating every listing as an introduction—not as ownership evidence.
Start with the domain’s public registration data
For generic top-level domains such as .com, .net, and .org, begin with an RDAP lookup. ICANN describes RDAP as the standardized successor to WHOIS for accessing current registration data. The result may show the registrar, creation date, expiration information, status codes, nameservers, and sometimes a registrant organization or contact route.
Public records are useful, but they have limits. Privacy services and data-protection rules can hide a person’s name, email address, or street address. ICANN’s registration-data policy identifies fields that may be published while allowing personal information to be redacted in appropriate circumstances. Therefore, a missing personal name does not automatically mean the listing is fraudulent—and a visible name does not prove that the person contacting you is that registrant.
Record the lookup date and save the result as a PDF or screenshot. Compare the registrar, domain status, nameservers, creation date, and expiration date with the seller’s explanation. Major inconsistencies should pause the transaction until they are resolved.
Ask the seller to prove control, not disclose sensitive credentials
The strongest practical test is a temporary action that only the controller can normally perform. Ask the seller to place a unique verification phrase in the domain’s DNS as a TXT record, create a temporary page at a specified URL, or send an email from an address hosted on the domain. The exact method should be agreed in writing and removed after verification.
Do not ask for—and do not accept—an account password, two-factor authentication code, registrar security answer, or full payment-card details. A legitimate seller should be able to demonstrate control without exposing credentials. If the seller claims an agency, employer, or client owns the domain, ask for written authority identifying who may negotiate and transfer it.
For a business transaction, request reasonable identity and authority information: the seller’s legal or trading name, a working contact method, the name of the current registrar, and confirmation that the seller can authorize a transfer. You are not trying to collect unnecessary personal data. You are creating enough evidence to connect the offer, the domain, and the person responsible for completing the sale.
Use registrar details as a consistency check
Ask the seller to identify the registrar shown in the domain record and, when appropriate, provide a live screen share of the domain inside the registrar account. The screen should show the domain name and relevant management area without revealing passwords, payment information, recovery codes, or unrelated domains.
A seller may also demonstrate control by changing a low-risk DNS record or confirming a registrar-generated notice. Avoid relying on a forwarded email alone: email headers, addresses, and screenshots can be manipulated or impersonated. When possible, independently type the registrar’s official website into your browser rather than following a payment or transfer link sent in an unsolicited message.
An Auth-Code, sometimes called a transfer code, is used to authorize an inter-registrar transfer for many generic top-level domains. It is not a preliminary ownership certificate. The seller should provide it only through a secure, agreed process after the commercial terms are settled. ICANN explains that the code helps identify the domain holder and supports the transfer process, but buyers should never post it publicly or send it to an unknown intermediary.
Know what public records cannot confirm
RDAP or WHOIS data can confirm registration-related details, but it may not establish beneficial ownership, authority to sell, trademark rights, or whether a company employee is acting with permission. A domain can also be held by a privacy service, corporate subsidiary, trust, or acquisition vehicle.
Likewise, a domain’s website content is not proof of ownership. A person can copy a site, control hosting without controlling the domain, or redirect traffic temporarily. Treat social profiles, marketplace badges, logos, and urgent claims of exclusivity as supporting context only.
If the domain is valuable, business-critical, or connected to a brand dispute, consider obtaining professional legal or transactional advice before signing an agreement. Ownership verification reduces risk, but it does not replace title review, trademark analysis, or a properly documented purchase.
Warning signs that deserve a pause
- The seller refuses every reasonable control test but demands immediate payment.
- The contact email is unrelated to the listed owner, company, or domain history without a credible explanation.
- The seller asks you to use an unfamiliar payment page, cryptocurrency wallet, gift card, or personal account.
- The price, deadline, or story changes sharply after you request verification.
- The seller sends a look-alike registrar link, forged screenshot, or edited ownership document.
- The domain is locked, involved in a dispute, near expiration, or subject to an unexplained change in registrar or account access.
None of these signs proves fraud by itself. Together, they justify slowing down, independently verifying contact information, and refusing to proceed until the inconsistencies are explained.
Document verification before payment or transfer
Create a transaction folder containing the listing URL, domain name, seller communications, RDAP result, verification method and date, agreed price, transfer responsibilities, and identity or authority details that were reasonably provided. Note exactly what was verified and what remains unknown.
Put the commercial terms in writing: the domain being sold, included assets, price and currency, payment conditions, who pays transaction costs, transfer method, timing, representations about authority, and the remedy if the transfer cannot be completed. For higher-value transactions, use an established escrow arrangement or another secure process that clearly defines when funds are released. Do not treat an escrow logo in an email as proof that the service is genuine.
Before releasing funds, confirm that the transaction instructions have not changed through a suspicious email or messaging account. Verify payment instructions using a previously known contact method. After transfer, confirm that the domain appears in the buyer’s registrar account, update recovery information, enable available security controls, and preserve the completion records.
A practical verification checklist
- Run an independent RDAP lookup and save the result.
- Compare registrar, status, dates, nameservers, and ownership claims.
- Request a temporary DNS, website, or domain-email control test.
- Confirm the seller’s identity and authority without collecting unnecessary data.
- Write down price, transfer terms, payment instructions, and deadlines.
- Use a secure transaction method and verify instructions independently.
- Confirm the domain is under the buyer’s control after transfer.
Direct communication can make a domain transaction faster and more transparent, but it also makes disciplined verification essential. If you are preparing a portfolio for sale, you can create a DomainsNoBroker account and review the available seller subscription plans. For more practical guidance, visit the DomainsNoBroker blog.
Frequently Asked Questions
Does WHOIS or RDAP prove who legally owns a domain?
No. RDAP can show registration-related details, but privacy redaction, corporate ownership, agency relationships, and incomplete public data can prevent it from identifying the ultimate owner or proving authority to sell.
What is the safest way to verify a domain seller?
Compare independent RDAP data with the seller’s claims, request a temporary DNS or website control test, confirm the seller’s authority, document the terms, and use a secure transaction process. Never request or share passwords or two-factor codes.
Should a seller send the domain’s Auth-Code before payment?
An Auth-Code is part of the transfer process, not a general ownership certificate. It should be handled privately and only when the transaction terms and secure payment process are ready. Never publish it or send it to an unknown party.
What should I save before buying a domain?
Save the listing, communications, RDAP result, control-test evidence, agreed price, transfer obligations, payment instructions, and any written confirmation of the seller’s authority. Keep records until the transfer and payment process are fully complete.
Related topic: verified domain owner.
Related topic: avoid domain sale scams.