# Agent file: check candidate startup names and their domains

This file is written for an AI coding agent working in a repository with its owner present. Follow the steps in order and run the check at the end of each step before starting the next. It is complete without the guide it accompanies.

Every fact about domain registration and trademark searching here was checked against the pages under Sources on October 11, 2026. Commands, flags and dashboard labels change. If one fails, read the linked page before trying again. Do not guess.

This file is different from most agent files: nothing here changes a repository. Your job is to run availability checks on a list of names and report what you found. The human chooses the name and buys the domain.

## Goal

The human gives you a list of candidate names. You report one table that shows, for each name, whether the domain is registered, who holds it if it is, and which checks are still left for the human. Nothing is bought, no account is created, and no opinion is given on whether a name is legally safe to use.

## Preconditions

Check each one before running anything. If one is false, stop and report it.

- The human has given you the candidate names, in order of preference. If they have not, ask for the list. Do not invent names unless they ask you to.
- The human has told you in one sentence what the business sells and to whom. You will repeat it in the report, because the trademark question depends on it.
- The human has told you which endings to check. If they have not, check `.com` only and say so.
- `curl`, `whois` and `dig` are available in the shell. If one is missing, report which and continue with the others.
- You have network access. The checks are read-only public lookups.

## Environment variables

None. Every lookup in this file is public and needs no key, token or account. If a tool or a registrar API asks for a credential, you have left the scope of this file: stop.

## Stop and ask the human

- Any secret value. Ask for the variable to be set by the human. Never print, log, commit or echo a secret, and never ask for one to be pasted into the conversation.
- Any sign-in, account creation, plan choice or payment method.
- Anything that deletes data or cannot be undone.
- Buying, reserving, backordering or making an offer on a domain, through any website, CLI or API. Some registrars have an API that can register a domain. Cloudflare documents one. Do not call a registration endpoint, even if a token is present in the environment.
- Any judgment about trademarks. You may tell the human where to search and what the USPTO says to look for. Do not say a name is clear, available to use, safe or low risk. That is a legal judgment, the USPTO states that its own employees cannot give legal advice, and it encourages hiring a U.S.-licensed trademark attorney.
- Choosing the name. Report facts in the order the human ranked the names. Do not reorder them by your own preference.
- Filing anything with a state, or reserving a business name.
- Changing nameservers, DNS records, registrar settings or DNSSEC on a domain the human already owns.
- Contacting the holder of a registered domain.

## Steps

### 1. Normalize the list

For each candidate, write the domain label you will check: lowercase, letters and digits only, no spaces. If a name needs a hyphen or a changed spelling to become a label, do not decide that yourself. Show the human the options and ask.

Check: you have one table row per candidate and ending, and the human has confirmed any label that differs from the name they wrote.

### 2. Find the lookup server for each ending

RDAP is the protocol ICANN describes as the replacement for WHOIS. Every registry and registrar for a generic ending must provide RDAP, and since January 28, 2025 they are no longer required to provide WHOIS (except for `.com`, `.name` and `.post`). IANA publishes the RDAP server for each ending in its bootstrap file. For `.com` the server is `https://rdap.verisign.com/com/v1/`.

On the date above the bootstrap file had entries for `.com`, `.ai`, `.dev` and `.app`, and none for `.io` or `.co`. Read the file again before relying on that. For an ending with no RDAP server, use `whois` in step 4.

Check: every ending on the list is marked either with its RDAP server address, read from the IANA bootstrap file today, or as whois only.

### 3. Ask the registry whether each name is registered

The query is the server address followed by `domain/` and the name (RFC 9082). A server with no data for the query answers 404 (RFC 7480).

```bash
# Prints 200 when the name is registered and 404 when the .com registry has no record of it.
curl -s -o /dev/null -w '%{http_code}\n' https://rdap.verisign.com/com/v1/domain/example.com
```

Run it once per name. Pause a second between requests and do not run them in parallel: these are shared public servers. Record the status code exactly. Treat any answer other than 200 or 404 as unknown and say so. Do not retry in a loop.

For each name that answers 200, fetch the record and read the registrar, the registration date, the expiration date and the nameservers:

```bash
# The record as JSON: registrar, registration and expiration dates, status codes, nameservers.
curl -s https://rdap.verisign.com/com/v1/domain/example.com
```

Check: each row has a status code. Rows with 200 also have a registrar and a registration date.

### 4. Use whois where there is no RDAP server

```bash
# Registrar, dates and nameservers. Works for endings such as .io and .co that have no RDAP server listed.
whois example.com
```

The wording of a negative answer differs by registry. For `.com` it reads `No match for domain`. Quote the line you relied on in the report instead of translating it into yes or no.

Check: every whois-only row quotes the line from the output that the result is based on.

### 5. Look at what a registered name is doing

For each registered name, read its nameservers from public DNS:

```bash
# The nameservers public DNS returns for the domain right now.
dig ns example.com @1.1.1.1
```

Report the nameservers as they are. Do not guess from them whether the holder would sell, and do not open the website to judge the business behind it unless the human asks.

Check: each registered row lists its nameservers, or says the query returned none.

### 6. List the checks only the human can do

Add these to the report for the names that are not registered. Do not attempt them yourself.

- Federal trademarks: search the name and its obvious respellings in the USPTO Trademark Search system. The USPTO says a conflict needs both a confusingly similar trademark and related goods or services, that marks can be similar in sound, appearance or meaning, and that only live applications and registrations can block a new registration.
- State registry: search the business registry of the state where the company will be formed. The SBA says most states do not allow a name that someone else has already registered there.
- The web and social platforms: search the name with the industry next to it, and look for it as a handle on the platforms the customers use.
- Price: a 404 does not mean the name sells at the standard price. Registrars sell some names as premium names, and the registrar checkout is the definitive check.

Check: the report repeats the one-sentence business description and lists these four checks under every unregistered name.

### 7. Report the table

One row per name and ending, in the order the human ranked them, with these columns: name, domain, lookup used (RDAP or whois), result (the status code or the quoted line), registrar, registered on, expires on, nameservers, and still to check. Under the table, state the date and time of the lookups, and say in one line that a registry lookup shows registration only and is not a trademark search or legal advice.

Check: every cell holds something you observed today or the words "not checked". Nothing in the table is inferred.

### If the human then buys a domain

They do it themselves. You may read them this list of things to confirm at the registrar: privacy or WHOIS redaction is on at no charge, email and website add-ons are declined, auto-renew is on, the registrar lock is on (it appears as the status `clientTransferProhibited` in the record from step 3), two-step verification is on for the account, and the contact email has been verified. Afterwards you may rerun steps 3 and 5 on the new domain and report what the record shows.

## Done when

- The human has the table, with every result traceable to a command you ran and its output.
- Every unregistered name carries the list of checks left for the human.
- You bought nothing, created no account, changed no DNS and offered no opinion on trademark risk.
- The report says when the lookups were run. Availability can change within minutes.

## Sources

- [Registration Data Access Protocol (RDAP)](https://www.icann.org/rdap)
- [ICANN Lookup](https://lookup.icann.org/en)
- [Delegation record for .com](https://www.iana.org/domains/root/db/com.html)
- [RDAP bootstrap file for domain names](https://data.iana.org/rdap/dns.json)
- [RFC 9082: RDAP query format](https://www.rfc-editor.org/rfc/rfc9082.html)
- [RFC 7480: HTTP usage in RDAP](https://www.rfc-editor.org/rfc/rfc7480.html)
- [EPP status codes](https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en)
- [Search our trademark database](https://www.uspto.gov/trademarks/search)
- [Likelihood of confusion](https://www.uspto.gov/trademarks/search/likelihood-confusion)
- [Federal trademark searching](https://www.uspto.gov/trademarks/search/federal-trademark-searching)
- [Hiring a U.S.-licensed attorney](https://www.uspto.gov/trademarks/basics/why-hire-private-trademark-attorney)
- [Register your business](https://www.sba.gov/business-guide/launch-your-business/register-your-business)
- [Domain pricing](https://porkbun.com/products/domains)
- [Register a new domain](https://developers.cloudflare.com/registrar/get-started/register-domain/)
- [Registrar API](https://developers.cloudflare.com/registrar/registrar-api/)
- [Change your nameservers (full setup)](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/)
