Blog Detail

Buyer reviewing evidence to verify control of a domain before making an offer

Before You Bid on a Domain, Verify Who Controls It

Sep 12, 2026 By DomainsNoBroker Editorial Team

A convincing listing is not proof that the person behind it controls the domain. Before discussing price in detail or sending money, establish a reasonable chain of evidence connecting the prospective seller to the domain’s registrar account, website, or transfer process.

This does not require asking for sensitive credentials. It means checking independent signals, requesting a low-risk demonstration of control, and preserving enough documentation to explain why you believed the seller was authorized to transact.


Start with public registration data

For many generic top-level domains, begin with ICANN’s Registration Data Lookup service. RDAP is now the primary public registration-data system for gTLDs, although the information available may be limited or redacted. The record can help you confirm the domain, registrar, status codes, creation details, expiration information, and any published contact route.

Do not treat a matching name or email address as conclusive proof. Privacy and proxy services can legitimately conceal the registrant’s details, and registration data may be outdated or inaccurate. Instead, use the record as one part of a broader verification process. ICANN explains that its lookup tools provide publicly available registration data and may offer a way to report inaccurate information. Review ICANN’s lookup guidance before drawing conclusions.


Compare the listing with the domain itself

Open the domain in a browser and compare what you see with the seller’s claims. A parked page, developed website, redirect, or blank DNS response can all be legitimate, but discrepancies deserve questions. For example, a seller who says the name is used by a business should be able to explain why the website points elsewhere, why the branding differs, or why the domain has recently changed nameservers.

Review the domain’s visible contact page, company information, copyright notice, and social profiles where relevant. These signals do not prove ownership, but they can reveal whether the person communicating with you appears connected to the business represented on the site. Also check the domain’s nameservers, mail records, and certificate details using reputable lookup tools. DNS signals are supporting evidence, not a substitute for registrar-level control.


Request proof that is reasonable and reversible

A legitimate seller should understand why a buyer wants confirmation. Ask for a demonstration that does not expose passwords, authentication codes, recovery emails, or account screenshots containing private information. Useful options include:

  • Publishing a short, buyer-provided verification phrase on the domain’s website.
  • Adding a temporary DNS TXT record containing a unique code.
  • Sending an email from an address hosted on the domain, when that mailbox is genuinely controlled by the seller.
  • Sharing a redacted registrar screenshot that shows the domain inside the account without revealing credentials or security settings.
  • Initiating an agreed transfer or ownership-confirmation step through the registrar, without releasing the domain before payment protections are in place.

The best method depends on the domain’s current use. A parked domain may support a DNS record more easily than a website edit. A business domain may not have an available mailbox. Agree on the exact proof, its wording, and when it will be removed before the seller performs it.


Understand what an Auth-Code can and cannot prove

An Auth-Code, sometimes called an EPP or transfer code, is used to help authorize a registrar-to-registrar transfer for many gTLDs. ICANN describes it as a code created by the registrar to help identify the registered name holder and prevent unauthorized transfers. That makes it relevant to the transfer stage, but it is not a reason to request or circulate the code casually.

Never ask a seller to send an Auth-Code before the transaction terms and payment protections are settled. A code alone also does not prove that the person contacting you is the rightful owner; it may have been obtained improperly or forwarded by someone with temporary access. Use ICANN’s Auth-Code explanation to understand the terminology and keep the code private until the appropriate registrar step.


Watch for communication warning signs

Seller behavior often matters as much as technical evidence. Slow responses are not automatically suspicious, but pressure tactics are. Be cautious when someone insists on immediate payment, refuses a simple control check, changes the beneficiary or payment instructions at the last minute, or claims that escrow is unnecessary because the deal is “urgent.”

Other warning signs include a seller who cannot explain the registrar, gives inconsistent ownership stories, uses several unrelated identities, refuses written terms, or asks you to pay a third party whose relationship to the domain is unclear. Be especially careful with requests for gift cards, cryptocurrency, wire transfers, or payment to an unrelated personal account. The Federal Trade Commission advises online shoppers to avoid payment methods that are difficult to reverse and to keep records of communications. Its marketplace safety guidance is a useful general reference.


Keep a verification record

Create a simple transaction file before making an offer. Save the original listing URL, screenshots with dates, RDAP results, the seller’s stated identity, the domain’s visible website details, and copies of important messages. Record exactly how control was demonstrated, when the proof was added or removed, and which registrar is expected to process the transfer.

Documentation helps you notice contradictions before money changes hands. It also gives you a clear checklist for closing: agreed price, included assets, transfer destination, payment method, timing, renewal status, and who is responsible for unlocking the domain or approving the transfer.


Separate ownership checks from payment security

Verification answers one question: can this person reasonably demonstrate control of the domain? It does not guarantee that the transaction will be completed, that the domain is free of disputes, or that a transfer cannot be delayed. Use a reputable escrow or secure transaction process appropriate to the deal, and confirm the payment instructions through an independently verified channel.

Do not release funds merely because the seller passed a website or DNS challenge. The final payment and transfer sequence should be agreed in writing, with each party knowing what event triggers release. For a higher-value purchase, consider professional legal or tax advice about the agreement, business identity, intellectual-property issues, and applicable reporting obligations.


Use direct listings, but apply your own checks

Direct communication can make it easier to ask precise questions and negotiate with the person presenting the domain. If you want to browse domain listings, treat each listing as a starting point for diligence rather than proof of ownership. Buyers can also create a DomainsNoBroker account to participate in the marketplace, while sellers and buyers should independently confirm who controls a domain before finalizing terms.

When you contact domain owner directly, keep the conversation focused: ask who controls the registrar account, which verification method they can complete, and how they propose to transfer the name. Buyers who find domains listed by owners still need to verify the person behind the listing. A careful process protects both sides without requiring disclosure of unnecessary account information.


A practical pre-offer checklist
  1. Record the exact domain, listing source, seller identity, and asking price.
  2. Check ICANN RDAP or the applicable registry lookup and note the registrar and status.
  3. Compare the listing with the live website, redirects, nameservers, and public business signals.
  4. Request one reasonable proof-of-control action using a unique, temporary code.
  5. Check for inconsistent stories, pressure, unusual payment requests, or last-minute changes.
  6. Write down the agreed price, transfer sequence, payment protection, and included assets.
  7. Use secure payment procedures and preserve the complete transaction record.

The goal is not absolute certainty; it is disciplined risk reduction. A seller who can provide consistent evidence, answer specific questions, and follow a documented transfer process is easier to evaluate than one who relies only on urgency or an attractive price.


Frequently Asked Questions

Does public WHOIS or RDAP data prove who owns a domain?

No. Public registration data may be redacted, privacy-protected, outdated, or inaccurate. Use it to identify the registrar and compare available details, then request a reasonable proof-of-control action from the seller.


What is the safest proof that a seller controls a domain?

A temporary website verification phrase or DNS TXT record is often practical because it demonstrates control without requiring passwords. The exact method should fit the domain’s current setup and should be removed after verification.


Should I ask for the domain’s Auth-Code before paying?

Generally, no. An Auth-Code is part of the transfer process and should be handled privately through the agreed registrar or transaction workflow. Do not circulate it casually or treat it as complete proof of rightful ownership.


Can a domain marketplace guarantee that a seller owns a domain?

A marketplace listing should not be treated as a substitute for buyer diligence unless the marketplace explicitly explains a verification program and its scope. Confirm control independently and use secure payment and transfer procedures.


What should I do if a seller refuses verification?

Pause the negotiation and do not send payment. Ask whether a different low-risk method, such as a temporary DNS record or redacted account view, would work. If the seller refuses every reasonable option or applies pressure, move on.

We may use cookies or any other tracking technologies when you visit our website, including any other media form, mobile website, or mobile application related or connected to help customize the Site and improve your experience. Learn More

Allow