← back to Domain Sniper
registrar-fingerprints.json
148 lines
{
"_about": "Public-registrar fingerprint database used by honeypot.js check phase to cross-reference WHOIS evidence against known drop-catch / aggregator operators. 'aggressive' flags operators with documented snipe / drop-catch infrastructure. Not exhaustive; expand as new actors surface.",
"_updated": "2026-05-19 (Dynadot promoted to aggressive after dusab.co snipe; nic.co .co WHOIS confirmed as leak channel)",
"_schema": {
"ianaId": "registrar IANA ID (from WHOIS 'Registrar IANA ID' field)",
"name": "canonical registrar name",
"nsPatterns": "regex patterns matched against authoritative NS root domains",
"country": "registrar country (ISO 3166)",
"aggressive": "true if known to operate drop-catch / aggregator infrastructure",
"notes": "freeform"
},
"operators": {
"433": {
"name": "OVH SAS",
"nsPatterns": ["^ns\\d+\\.ovh\\.net$", "^dns\\d+\\.ovh\\.net$"],
"country": "FR",
"aggressive": true,
"notes": "Confirmed snipe on butlr.app 2026-05-12 with ns112.ovh.net/dns112.ovh.net. Common destination for European drop-catchers. Cheap registrations make sniping economic."
},
"1606": {
"name": "NameBright / DropCatch",
"nsPatterns": ["^ns\\d+\\.namebrightdns\\.com$", "^ns\\d+\\.aftermarket\\.com$"],
"country": "US",
"aggressive": true,
"notes": "DropCatch.com is one of the three major drop-catch services. Owns hundreds of credentialed connections to TLD registries to race-grab pending-delete domains."
},
"1330": {
"name": "Pool.com / TurnCommerce",
"nsPatterns": ["^ns\\d+\\.poolregistry\\.com$", "^ns\\d+\\.parkingcrew\\.net$"],
"country": "US",
"aggressive": true,
"notes": "Pool.com is the second of the big-three drop-catchers. Long-tail dictionary-based filtering, immediate auction listing."
},
"64": {
"name": "Web.com / NameJet / SnapNames",
"nsPatterns": ["^ns\\d+\\.snapnames\\.com$", "^ns\\d+\\.namejet\\.com$", "^ns\\d+\\.web\\.com$"],
"country": "US",
"aggressive": true,
"notes": "Third major drop-catcher. NameJet auctions, SnapNames retail. Aggressive on premium .com / .net."
},
"609": {
"name": "Sav.com",
"nsPatterns": ["^ns\\d+\\.sav\\.com$"],
"country": "US",
"aggressive": true,
"notes": "Newer entrant, aggressive on short-form .com and short-LL.io / .ai snipes. Public auctions follow."
},
"1170": {
"name": "Above.com / Trellian",
"nsPatterns": ["^ns\\d+\\.above\\.com$", "^ns\\d+\\.trellian\\.com$"],
"country": "AU",
"aggressive": true,
"notes": "Long-tail drop-catch + parking + PPC monetization. Common destination for sniped names that get parked rather than auctioned."
},
"146": {
"name": "GoDaddy / GoDaddy Auctions",
"nsPatterns": ["^ns\\d+\\.domaincontrol\\.com$"],
"country": "US",
"aggressive": true,
"notes": "GoDaddy operates its own auction marketplace and TDNAM (after-market). Snipes through GoDaddy Auctions land at domaincontrol.com NS."
},
"472": {
"name": "Dynadot",
"nsPatterns": ["^ns\\d+\\.dynadot\\.com$", "^[a-z]+\\.ns\\.cloudflare\\.com$"],
"country": "US",
"aggressive": true,
"notes": "Promoted to aggressive 2026-05-19 after dusab.co snipe from honeypot batch 2026-05-12. The snipe came in via bucket C (nic.co WHOIS for .co) — only that bucket fired, CONTROL bucket was 0/10, so nic.co's WHOIS is confirmed leaking to a Dynadot-using aggregator. Snipe used Cloudflare NS (donna.ns.cloudflare.com) rather than Dynadot's own NS, which is the tell of a parker/aggregator shop. abuse@dynadot.com."
},
"1479": {
"name": "NameSilo",
"nsPatterns": ["^ns\\d+\\.namesilo\\.com$", "^ns\\d+\\.dnsowl\\.com$"],
"country": "US",
"aggressive": false,
"notes": "Retail registrar. Cheap renewals. Not a known aggregator."
},
"1861": {
"name": "Porkbun",
"nsPatterns": ["^curitiba\\.ns\\.porkbun\\.com$", "^salvador\\.ns\\.porkbun\\.com$", "^maceio\\.ns\\.porkbun\\.com$", "^fortaleza\\.ns\\.porkbun\\.com$", "^ns\\d*\\.porkbun\\.com$"],
"country": "US",
"aggressive": false,
"notes": "Retail-friendly registrar. Not an aggregator."
},
"1068": {
"name": "Namecheap",
"nsPatterns": ["^dns\\d+\\.registrar-servers\\.com$"],
"country": "US",
"aggressive": false,
"notes": "Retail registrar. Not a primary aggregator but resold to many."
},
"1910": {
"name": "Cloudflare Registrar",
"nsPatterns": ["^[a-z]+\\.ns\\.cloudflare\\.com$"],
"country": "US",
"aggressive": false,
"notes": "Wholesale-pricing retail registrar. No aftermarket activity."
},
"69": {
"name": "Tucows / OpenSRS / Hover",
"nsPatterns": ["^ns\\d+\\.tucows\\.com$", "^ns\\d+\\.hover\\.com$", "^ns\\d+\\.domainpeople\\.com$"],
"country": "CA",
"aggressive": false,
"notes": "Wholesale platform reselling through many small registrars. Identity-of-actual-actor is downstream."
},
"81": {
"name": "Gandi",
"nsPatterns": ["^ns\\d+\\.gandi\\.net$"],
"country": "FR",
"aggressive": false,
"notes": "Retail-focused European registrar. Not an aggregator."
},
"269": {
"name": "Key-Systems / RRPproxy",
"nsPatterns": ["^ns\\d+\\.rrpproxy\\.net$", "^ns\\d+\\.key-systems\\.net$"],
"country": "DE",
"aggressive": true,
"notes": "Wholesale + drop-catch via RRPproxy. Frequently fronts for European aftermarket buyers; volume drop-catch credentials at .com/.net registries."
},
"1390": {
"name": "Hexonet / 1API",
"nsPatterns": ["^ns\\d+\\.hexonet\\.net$", "^ns\\d+\\.ispapi\\.net$"],
"country": "DE",
"aggressive": true,
"notes": "Drop-catch + reseller platform. Volume credentials; common back-end for resellers running automated drop sniping."
},
"49": {
"name": "GMO Internet",
"nsPatterns": ["^[a-z]+\\.dnsv\\.jp$", "^ns\\d+\\.gmointernet\\.com$", "^ns\\d+\\.onamae\\.com$"],
"country": "JP",
"aggressive": true,
"notes": "Onamae.com — dominant .JP registrar with aggressive aftermarket. Snipes short stems likely to resell to Japanese market."
},
"1659": {
"name": "Crazy Domains / Dreamscape Networks",
"nsPatterns": ["^ns\\d+\\.crazydomains\\.com$", "^ns\\d+\\.syrahost\\.com$"],
"country": "AU",
"aggressive": true,
"notes": "AU-region drop-catch + aftermarket. Aggressive on .com.au and short generic .com."
},
"2487": {
"name": "Internet.bs / Internet Domain Service BS",
"nsPatterns": ["^[a-z]+\\.internet\\.bs$", "^dns\\d+\\.internetbs\\.net$"],
"country": "BS",
"aggressive": true,
"notes": "Bahamas-domiciled, anonymity-friendly. Used as a snipe destination when actor wants to obscure attribution; WHOIS often privacy-protected."
}
}
}