Why not use a registrar’s availability API?
Registrar APIs are fast and convenient, and they are one hop further from the record. Some also cache. The answer Webault wants is the one from the source.
Every name Webault shows has been looked up at the registry for its extension. This post is about what that means in practice: why the lookup isn’t DNS, what counts as a clear answer, what happens when there isn’t one, and why a round takes seconds instead of milliseconds.
Because DNS answers a different question. A DNS query tells you whether a name has nameservers. It doesn’t tell you whether it’s registered. Millions of registered domains have no DNS records: parked without a page, held by investors, reserved by companies for later. To a DNS check they all look free.
Tools that show hundreds of results as you type are usually doing DNS, reading a zone-file snapshot, or reading a cache. Those are cheap and fast, and they are wrong often enough that we didn’t want to ship them. It is the single most common reason a name shows as available and can’t be bought.
The registry. Every extension is operated by one registry that holds the authoritative record of what is registered under it, and that record is the only thing that can settle the question.
For generic extensions the protocol is RDAP, the Registration Data Access Protocol. It is the designated successor to WHOIS: ICANN’s global amendment to the base registry agreement sunset the obligation to provide gTLD registration data over WHOIS on 28 January 2025, leaving RDAP as the definitive source. RDAP returns structured JSON rather than the free text WHOIS produced, which matters when you are parsing thousands of answers rather than reading one.
A domain query has two useful outcomes. If the registry has no record for the label, the name is not registered. If it returns a domain object, the name is registered, and the object’s status codes say more: whether it is active, in a redemption period, or pending delete. That last distinction is why an expiring domain is reported as taken rather than free.
Country-code extensions are far less uniform, because they sit outside ICANN’s registry contracts and the January 2025 sunset doesn’t bind them. Some serve RDAP, some serve only WHOIS, some serve nothing you would want to depend on. Where a registry doesn’t expose availability in a way we trust, we leave the extension out. That is part of why the number is 532 rather than the full root zone.
Three outcomes, and only three:
Unverified is the one that matters. Most tools collapse it into “available”, because “available” is what users want to see. We hide it. If we can’t prove a name is free, we don’t say it is — the reasoning behind that choice is worth its own page.
Because a round is dozens of real network round-trips to a dozen or more different registries, some of them slow, and because registries rate-limit RDAP — as they should. A shared public read interface that nobody throttled would be a shared public read interface that nobody could use.
That is the honest cost of the design. A tool that returns hundreds of answers the instant you stop typing is not doing this, because this cannot be done that fast. Seconds per round is the price of the answer being true when you read it.
Two things. The row is struck through and counted, so you can see how crowded the space is rather than only seeing the survivors.
And the shape of the name — compound, cut, coinage, real word on a fitting extension — is fed back into the next round. If every two-word .com in a field is gone, the second round stops proposing more of them. That feedback is the difference between running the same search twice and actually narrowing.
For exactly what the product collects and keeps while doing all this, the privacy policy is the authority, not this page. See also how it works end to end.
Webault asks the registry for each extension whether a name is registered, rather than asking DNS whether it resolves. Anything that isn’t a clear “not registered” from an open extension is marked unverified and hidden.
Every name in a round is looked up at the registry that operates its extension before it reaches you. Taken names are struck through and counted. Names the registry can’t confirm are marked unverified and never shown as free.
Registrar APIs are fast and convenient, and they are one hop further from the record. Some also cache. The answer Webault wants is the one from the source.
Yes. That’s the trade. Hiding a free name is a smaller failure than showing a taken one as free. Run the round again and unverified names are checked again.
No. A registry lookup is a read. Nobody is notified, and nothing is held.
By YBM Labs. Last reviewed . Terms used here are defined in the glossary.