Glossary
Registrar
RDAP
The structured, authenticated successor to WHOIS for registration data. Responses are JSON and access to contact detail is tiered, so what you can see depends on who you are.
Defined in RFC 9083.
Where this appears
The lessons that use this term, and what each is for.
Domain Security FundamentalsLocks, contacts and expiryAudit a domain’s registrar-level controls and name what is missing.DNS Security PractitionerReading lock stateDetermine from RDAP which locks a domain actually has, and which it only appears to.Domain Abuse & ImpersonationAge and timingUse registration date as a signal without over-weighting it.Domain Abuse & ImpersonationPrivacy is not guiltInterpret a privacy proxy correctly, and say what registration data can still tell you.Domain Abuse & ImpersonationReuse across a setLink separate registrations into one campaign from shared infrastructure.Domain Abuse & ImpersonationThe cost of being wrongState what each misclassification costs, and which direction to err in.Brand ProtectionWhat to capture, and in what orderAssemble a complete evidence package for a live finding before anything changes.Brand ProtectionProvenanceCapture evidence in a form that survives someone disputing it.Brand ProtectionThe first messageWrite an abuse report an overloaded desk can act on without asking you anything.Brand ProtectionWhat automates wellIdentify the stages of the programme that should be fully automated.Domain Trust ArchitectureA method you can run by handAssess any estate against every surface using public data and a fixed sequence.Domain Trust ArchitectureEvidence per findingRecord each finding so somebody else can verify it without repeating your work.Domain Security PractitionerWhat the evidence supportsSeparate what you have established from what you have inferred, in writing.Domain Security PractitionerThe agency nobody can contactRecover control of a domain administered by a party that no longer answers.