Methodology
Where each badge comes from
- Taken / free — name.com Core API v1
domains:checkAvailability, production, read-only. - Registrar, nameservers, created, abuse contact — RDAP via the IANA bootstrap. A 404 means not registered and overrides a stale availability answer.
- Already yours / where it lands — DNS-over-HTTPS A/MX/NS lookups plus an HTTP redirect-chain probe (max 5 hops).
- Appears in Google — SerpApi, capped at 25 queries per scan, cached 24h.
- One-line reason — a model call from the fact tuple only. It cannot change band or score.
Rule weights (documented as judgment)
- Keyword class (combosquat): +3
- Mail configured (MX): +3
- Appears in Google: +2
- Homoglyph or omission: +2
- Created within 12 months: +1
- Parked: −1
- Established, likely unrelated: −3, sorts after every other stranger-held card
- Forwards home → band "yours", regardless of score.
- Purchasable → band "free", score from class priors only.
These weights rank attacker economics as a judgment call, not a sourced formula. No source ranks permutation classes by attacker preference (dossier gap).
"Established, likely unrelated"
A stranger-held candidate gets this treatment only if it is a live site with its own page title and its registration predates the brand by more than 10 years. Both conditions are judgment, not sourced facts: a 10-year cutoff and "has a title" are a proxy for "this is probably a dictionary-word or acronym collision that existed long before this scan, not someone squatting this brand" — not proof of unrelatedness. Mail-only, parked, dark, and undetermined candidates are never given this treatment, since none of those show independent, ongoing use of the name the way a titled live site does.
Registrar budget
0 name.com calls used this hour (account cap: 3,000/hour, D-23).
Not covered
Not covered: look-alikes on someone else's subdomain (brand.example.net), free-hosting pages, non-Latin homographs beyond our table, social handles. A determined attacker uses these too.