ActorStack.dev

14 guides

The registry's own record of delegation, not a sample of it

Six Actors over one source: the registry zone files for 1,075 gTLDs, obtained through ICANN's Centralized Zone Data Service. Availability screening, typosquat sweeps, reverse nameserver lookups, new delegations, zone exits and hijack alerts — and, throughout, what a zone file cannot tell you.

Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsExplainer

What a zone file contains

A zone file is a delegation record: which domains exist in a TLD and where each one points its nameservers. It holds no registrant, no registrar, no dates and none of the domain's own records — and knowing that is what makes the six zone-file Actors readable.

7 min
A desk with stacked legal reference books, loose documents and a newspaper.
DomainsExplainer

ICANN CZDS access

Access to gTLD zone files is granted one TLD at a time, by each registry operator, under an agreement that shapes what a product built on the data is allowed to look like.

7 min
Printed notices and leaflets stapled to a wooden hoarding on a street.
DomainsReference

gTLDs and ccTLDs

Country-code TLDs are run outside ICANN's contracts, so their zone files are not available through the zone data service at any price. The gap matters most in exactly the namespaces a startup cares about.

6 min
A white shuttered window on a peach-coloured building with a for-sale notice beside it.
DomainsGuide

Bulk availability without WHOIS

Screening a naming shortlist against zone files instead of querying WHOIS per name: what it costs, what the verdicts mean, and where the method stops being enough.

7 min
A white measuring tape curving across a dark background, showing the numbers 15 to 45.
DomainsMeasured

Probably free, not available

Absence from a zone file usually means unregistered, and sometimes does not. The gap was measured against ICANN's own monthly registry reports rather than estimated, and it differs by TLD.

6 min
A row of residential mailboxes on posts in front of a wooden fence and trees.
DomainsGuide

Typosquat detection

How to run a brand sweep across 1,075 gTLDs, how to read `exact`, `typo` and `contains` differently, and why an empty result is the outcome worth paying for.

7 min
A laptop screen showing a plain text-mode terminal with a command prompt.
DomainsComparison

dnstwist versus zone search

Permutation engines find the squats their rules predicted. Searching the registry zone finds what is actually registered, including the spellings no generator would produce — and each approach misses something the other catches.

6 min
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsGuide

Reverse nameserver lookup

Pivoting from a nameserver to the domains delegated to it is useful on infrastructure that belongs to one organisation and useless on a large provider's. The difference is the whole technique.

6 min
A shelf of office binders with dated labels along their spines.
DomainsComparison

Passive DNS versus zone files

Two sources that look interchangeable for infrastructure questions and answer differently shaped questions. Which one to reach for depends on whether you need history, resolution or completeness.

6 min
Printed notices and leaflets stapled to a wooden hoarding on a street.
DomainsExplainer

Zone entry is not registration

Zone entry is the earliest public signal that a domain went live, and roughly 20–30% of those events are re-appearances rather than new registrations. The number is an outside estimate and is labelled as one.

5 min
A white shuttered window on a peach-coloured building with a for-sale notice beside it.
DomainsExplainer

Zone exit is not expiry

Leaving the zone runs roughly 35 days ahead of a domain being released, and most exits are never releases at all. The `minDaysAbsent` filter is what turns the signal into something usable.

6 min
A row of residential mailboxes on posts in front of a wooden fence and trees.
DomainsGuide

Detecting domain hijacking

Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.

7 min
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsMeasured

What dns_provider can tell you

The nameserver identifies who runs the DNS for 69.1% of domains. It does not identify what a site is built with, and the measurement that settled that question is worth seeing.

5 min
A white measuring tape curving across a dark background, showing the numbers 15 to 45.
DomainsMeasured

DNSSEC adoption by TLD

Measured across the whole zone, 5.0% of domains publish a DS record. Per registry the rate runs from 0% to 100%, which is what makes the global figure unusable on its own.

5 min