Before you negotiate a domain price, confirm that the person offering it can actually control and transfer the name. A polished listing, professional email address, or convincing story is not proof of ownership. The goal is to establish control through independent checks without asking the seller to reveal unnecessary private information.
If you are wondering, how do I verify that a domain seller is legitimate? use several small checks together: inspect available registration data, identify the registrar, request a safe control demonstration, compare the seller’s information across conversations, and document the results before you make an offer.
Start with public registration and registrar information
Use the ICANN Lookup tool to review the domain’s available registration data. Depending on the extension, privacy rules, and applicable law, you may see the registrar, registration dates, status codes, nameservers, or limited registrant information. You may not see the owner’s name or email address, so an incomplete result is not automatically suspicious. ICANN explains that not all registration data must be returned in a lookup request.
Record the domain’s registrar, status, expiration date if shown, nameservers, and any publicly displayed organization or contact details. Then compare those details with the seller’s explanation. For example, a seller who says the domain is at Registrar A should be able to explain why a current lookup identifies Registrar B, or provide a reasonable account of a recent transfer.
Look for transfer-related restrictions as well. A status such as “client transfer prohibited” may mean the name is locked at the registrar. That does not prove fraud, but it affects timing and should be discussed before money changes hands. ICANN’s Transfer Policy describes registrar-transfer requirements and circumstances that can create transfer delays or locks.
Ask for a safe proof-of-control step
The strongest practical part of domain ownership verification is a demonstration that requires access to the domain account or its DNS, but does not require the seller to surrender credentials. Ask the seller to add a temporary DNS TXT record containing a random phrase you provide. You can then verify that the record appears through a reputable DNS lookup service. Afterward, the seller should remove it.
Another option is a temporary change to a harmless page or a unique verification file placed on the domain’s website. This method is less useful if the seller does not control the hosting account, so DNS verification is often clearer. Do not ask the seller to send a password, authentication code, registrar authorization code, or screenshot containing sensitive account information.
Control of DNS is strong evidence of operational control, but it is not identical to a completed transfer. Before closing, the seller still needs to confirm the registrar account can release the domain and that the name is not subject to an undisclosed dispute, court order, renewal problem, or transfer restriction. Ask direct questions and keep the answers in writing.
Match the seller’s identity across the conversation
Compare the name or business identity used in the listing, email address, payment instructions, agreement, and registrar-related communications. Small differences can have innocent explanations, such as an employee selling for a company or a privacy service masking registration data. The important point is that the seller should explain the relationship clearly and consistently.
For a company-owned domain, ask for the legal business name and a company email address. Independently visit the company’s official website rather than relying only on a link supplied in an email. If the seller claims to represent another owner, request written authorization or arrange for the registered business owner to participate in the transaction.
Be cautious when a seller refuses every reasonable verification step, pressures you to pay immediately, changes payment details late in the process, or insists that you communicate only through an untraceable channel. A mismatch is a reason to pause and investigate, not an automatic conclusion that the seller is dishonest.
Watch for transaction and payment red flags
- Urgency without explanation: pressure to pay within minutes or lose the domain.
- Unusual payment demands: gift cards, cryptocurrency, wire transfers to an unrelated person, or payment apps with no meaningful buyer protection.
- Fake confirmation messages: an email claiming funds are held or released without confirmation from the actual payment provider.
- Third-party identity gaps: the person negotiating, the purported owner, and the payment recipient are different without documentation.
- Unverifiable escrow instructions: a seller sends a lookalike escrow website or asks you to use a service reached through a suspicious link.
The Federal Trade Commission advises online buyers to review marketplace rules, understand who helps if something goes wrong, and use a safer payment method. Its consumer guidance also warns against sellers who insist on payment methods that are difficult to reverse. Treat those warnings as practical risk controls, not as a substitute for checking the domain itself.
Document the checks before making an offer
Create a simple verification record with the domain name, lookup date, registrar, visible status, nameservers, seller’s stated identity, verification method, and any unresolved questions. Save relevant emails and screenshots, but redact passwords, authentication codes, and unnecessary personal data. A dated record helps you notice changes between negotiation and closing.
Use the record to classify the opportunity as ready for negotiation, needs more information, or do not proceed. If the seller passes control checks but cannot explain a corporate ownership mismatch, pause. If the seller’s identity appears consistent but the domain is locked or recently changed registrants, ask the registrar about the expected transfer process before agreeing to a deadline.
Use safeguards when you move from verification to payment
Verification should come before payment, but it does not eliminate transaction risk. For a meaningful purchase, consider a reputable escrow provider or another payment process with clearly documented release conditions. The written terms should identify the exact domain, purchase price, currency, included assets, transfer obligations, inspection period if any, and what happens if the transfer fails.
Do not assume that a marketplace listing or direct introduction guarantees the seller’s identity, title, payment outcome, or transfer. DomainsNoBroker helps buyers and sellers connect directly, which can make verification questions and negotiation more direct; the parties remain responsible for checking the seller, agreeing to terms, and completing the transaction safely. You can browse domain listings while applying the same checks to every seller.
Before sending funds, confirm the escrow or payment provider through its official website, verify payment instructions using a separate communication channel, and make sure the release condition requires the domain to reach the buyer’s registrar account. After transfer, update account security, enable multifactor authentication where available, and retain the final transaction records.
A practical pre-offer checklist
- Run the domain through ICANN Lookup or the relevant registry or registrar lookup.
- Record the registrar, status, dates, nameservers, and visible organization details.
- Ask the seller to complete a temporary DNS TXT verification.
- Compare the seller’s identity, email domain, company details, and payment recipient.
- Ask about transfer locks, recent registrant changes, renewal status, and known disputes.
- Write down unresolved questions and do not let urgency replace answers.
- Agree on written terms and a safer payment or escrow process before paying.
A seller who can explain the domain’s history, demonstrate control safely, and accept reasonable written safeguards is easier to evaluate than one who relies on pressure or vague assurances. Verification will not make every transaction risk-free, but it can prevent a basic mistake: negotiating with someone who cannot deliver the domain.
Related resources
For more buyer guidance, learn from the DomainsNoBroker blog or contact DomainsNoBroker about the marketplace experience. Sellers can also review the seller subscription plans before creating a listing.
Frequently Asked Questions
Can public WHOIS or ICANN Lookup prove who owns a domain?
Not always. Privacy services, data-protection rules, and registry practices may limit the information shown. Public lookup is useful for identifying the registrar, status, dates, nameservers, and any visible organization details, but buyers should also request a safe proof-of-control step.
What is the safest way to verify domain control?
Ask the seller to add a temporary DNS TXT record containing a random phrase you provide, then verify that it appears publicly. Never request passwords, authentication codes, or registrar account screenshots containing sensitive information.
Should I pay before the domain is transferred?
For a valuable domain, consider using a reputable escrow or payment process with written release conditions. The terms should identify the exact domain and require successful delivery to the buyer’s registrar account before funds are released.
Is a transfer lock proof that a domain seller is fraudulent?
No. A transfer lock can be a normal registrar setting or may result from a recent registrant change. It should be explained and factored into the timeline before you agree to payment or a closing deadline.
Related topic: verified domain owner.