14 guides
The registry's own record of delegation, not a sample of it
Six Actors over one source: the registry zone files for 1,075 gTLDs, obtained through ICANN's Centralized Zone Data Service. Availability screening, typosquat sweeps, reverse nameserver lookups, new delegations, zone exits and hijack alerts — and, throughout, what a zone file cannot tell you.

What a zone file contains
A zone file is a delegation record: which domains exist in a TLD and where each one points its nameservers. It holds no registrant, no registrar, no dates and none of the domain's own records — and knowing that is what makes the six zone-file Actors readable.

ICANN CZDS access
Access to gTLD zone files is granted one TLD at a time, by each registry operator, under an agreement that shapes what a product built on the data is allowed to look like.

gTLDs and ccTLDs
Country-code TLDs are run outside ICANN's contracts, so their zone files are not available through the zone data service at any price. The gap matters most in exactly the namespaces a startup cares about.

Bulk availability without WHOIS
Screening a naming shortlist against zone files instead of querying WHOIS per name: what it costs, what the verdicts mean, and where the method stops being enough.

Probably free, not available
Absence from a zone file usually means unregistered, and sometimes does not. The gap was measured against ICANN's own monthly registry reports rather than estimated, and it differs by TLD.

Typosquat detection
How to run a brand sweep across 1,075 gTLDs, how to read `exact`, `typo` and `contains` differently, and why an empty result is the outcome worth paying for.

dnstwist versus zone search
Permutation engines find the squats their rules predicted. Searching the registry zone finds what is actually registered, including the spellings no generator would produce — and each approach misses something the other catches.

Reverse nameserver lookup
Pivoting from a nameserver to the domains delegated to it is useful on infrastructure that belongs to one organisation and useless on a large provider's. The difference is the whole technique.

Passive DNS versus zone files
Two sources that look interchangeable for infrastructure questions and answer differently shaped questions. Which one to reach for depends on whether you need history, resolution or completeness.

Zone entry is not registration
Zone entry is the earliest public signal that a domain went live, and roughly 20–30% of those events are re-appearances rather than new registrations. The number is an outside estimate and is labelled as one.

Zone exit is not expiry
Leaving the zone runs roughly 35 days ahead of a domain being released, and most exits are never releases at all. The `minDaysAbsent` filter is what turns the signal into something usable.

Detecting domain hijacking
Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.

What dns_provider can tell you
The nameserver identifies who runs the DNS for 69.1% of domains. It does not identify what a site is built with, and the measurement that settled that question is worth seeing.

DNSSEC adoption by TLD
Measured across the whole zone, 5.0% of domains publish a DS record. Per registry the rate runs from 0% to 100%, which is what makes the global figure unusable on its own.