For registries and DNS operators
Last updated 2 October 2026
TLDscout helps people pick a domain name by checking one name across many extensions. We want to be a well-behaved, easily identified client of your systems. This page says exactly what we query, how often, and how to reach us if you'd like us to change anything.
Contact: [email protected] (operations, permissions, opt-outs) · [email protected] (anything that looks like abuse). We act on requests to slow down or stop quickly, and we'll confirm when it's done.
What a search does
A visitor's search sends DNS queries only. For each extension in the visitor's scope (60 to about 540 extensions), the server asks:
- a public recursive resolver (Cloudflare 1.1.1.1 or Google 8.8.8.8) for the name's NS records, and
- the extension's own authoritative nameservers whether the name is delegated (one query; if a server doesn't answer, the next one of that extension's servers is asked).
Answers are cached: "delegated" for up to 24 hours and "not delegated" for up to 15 minutes, so popular names cost nothing on repeat. Searches are rate-limited per visitor and protected by a bot check, so automated bulk use is blocked.
A search never sends an RDAP or WHOIS query. No registry database is consulted automatically.
What Verify does
On a single row, a visitor may click Verify with the registry. That sends one RDAP query for one name, and only to registries whose published terms permit lookups reasonably necessary to register a domain name. Each such registry also has a daily budget of Verify lookups on our side, and we honour every rate limit, Retry-After and block we receive: we stop asking until it ends, and we never switch addresses to get around one.
- We show the visitor only the verdict (registered, not registered, reserved), never any part of the record.
- Where your terms allow keeping it, the verdict may be cached for up to one hour, under a one-way coded key; otherwise it isn't kept.
- Where your terms don't permit this use, or we haven't confirmed that they do, we don't query you at all: the visitor is sent to a registrar instead. That currently includes, among others, GoDaddy Registry, CentralNic, Nominet, Google Registry, GMO Registry, DENIC, EURid and SIDN.
- We never query WHOIS for .gg or .je.
If you'd prefer that TLDscout didn't query your RDAP service at all, or would like it to use a different limit, tell us and we'll change it. If you'd be willing to allow more (for example, automatic checks within a limit you set), we'd like to hear from you too.
How to recognise TLDscout
- User-Agent on every HTTP request (RDAP, IANA data):
TLDscout/<version> (+https://tldscout.xyz/registries.html; [email protected]) - One fixed IPv4 address for all lookups, whose reverse DNS (PTR) name is under tldscout.xyz. We don't rotate addresses or use proxies.
- security.txt at /.well-known/security.txt.
Other data we use
- IANA's root zone list, RDAP bootstrap and IDN tables: fetched at most daily (IDN tables weekly).
- Porkbun's public price list: fetched daily. Cloudflare prices via cfdomainpricing.com (MIT licence): fetched daily.
Opting out or slowing down
Email [email protected] with the extensions or the service (DNS or RDAP) concerned. We can stop Verify lookups to you entirely, lower the daily budget, or space DNS queries to your nameservers more widely. We'll confirm the change.
TLDscout is run by C.S. Assets LLC, a Florida limited liability company (Alachua County, Florida, USA).