Data & privacy
What leaves your browser, and what does not
There is no Extend.Domains server. Nothing you look up passes through us, because there is no “us” in the request path — your browser talks to public endpoints directly, and that is the whole architecture.
The short version
No backend
Not a single request goes to a server we run. There isn't one.
No account
Nothing to sign up for, nothing to sign in to, no identifier of any kind.
No analytics
No telemetry, no crash reporting, no usage pings — in the extension or on this website.
No API keys
Every source is a free, keyless public endpoint. That is why they were chosen.
No page content
The page you are reading is never uploaded anywhere. The only thing that travels is the domain name itself.
No personal registrant data
RDAP redacts it post-GDPR, and the panel does not display or request any of it.
Every request the extension makes
Six sources, all public, all fetched from the extension's background context — never from the page you are on, and never from the panel.
| Source | Host | What is sent |
|---|---|---|
| DNS records | cloudflare-dns.com · dns.google | the registrable domain NS, A, MX and TXT, plus TXT at _dmarc. Cloudflare is asked first; Google is the per-query fallback. These two hosts are the extension's only declared host permissions. |
| Registry bootstrap | data.iana.org | nothing but the request itself IANA's public map of which RDAP server runs which TLD, fetched once and cached for 24 hours. A stale copy is preferred over none. |
| Registration record | the registry's own RDAP server | the registrable domain Verisign for .com, Nominet for .uk, and so on — resolved from the bootstrap, queried directly. rdap.org is used only when the bootstrap has no entry for that TLD. |
| Site preview | the domain being looked up | an ordinary page request for its root Range: bytes=0-32768, a 4-second timeout, and reading stops at </head>. It is the same request your browser would make if you visited the site — because it is one. |
| Archive history | archive.org · web.archive.org | the registrable domain The availability API asked for the snapshot closest to 1990, which is provably the earliest one. The CDX API is a slow fallback. |
| Favicon | your browser's cache, or the domain itself | nothing extra on Chrome Chrome draws it from the favicon cache it already has. Firefox points an <img> at the site's /favicon.ico and hides it if that fails. |
Requests are capped at two at a time per host, concurrent lookups of the same name share a single in-flight request, and a name already in the local cache issues nothing at all.
What is stored, and where
- Lookup cache
- One record per registrable domain in the extension’s local storage, expiring 24 hours after its first write. Sources merge into it as they arrive. Only conclusive registry answers are cached — a failure is never written down as a fact.
- Recent lookups
- The last twelve names, so the chips at the bottom of the panel work. The ✕ on that card deletes the list.
- Your preferences
- Theme, registrar, sidebar layout, scoring weights, detection toggles.
- Nothing else, and nowhere else
- All of it is extension-local storage in your own browser profile. It is never synchronised, never transmitted, and uninstalling the extension removes it.
Why each permission is asked for
storage- Your settings and the 24-hour lookup cache.
contextMenus- The Look up “…” item on a selection. This is also the one lookup path that needs no site access at all.
cloudflare-dns.com- …and
dns.google— the two DNS-over-HTTPS resolvers. These are the only hosts the extension declares up front. - Access to page content
- Two jobs: noticing that you selected something that looks like a domain, and fetching the domain root for the preview card. On Firefox this is opt-in and the extension works without it (via the right-click menu); on Chrome it is listed as optional so you can restrict and re-grant it whenever you like.
sidePanel- Chrome only — the panel itself.
favicon- Chrome only — draws the site icon from the cache your browser already has, instead of making a request for it.
Registry lookups need no permission at all
Links that leave the extension
The research links, the register button and the archive link open third-party sites in a new tab. Those are ordinary outbound links: nothing is sent ahead of your click, and none of those three carry a referral or affiliate code. They do carry a utm_source=extenddomains.com parameter, so the destination can see the visit came from here — that is the only thing appended, and once you are on their site their own privacy policy applies.
There is one exception, and it is the next section: the Buy now button that appears on a name listed for sale does carry a referral code.
Affiliate disclosure
When a name’s nameservers show it is listed for sale on Atom.com, the panel shows a Buy now on Atom.com button. That link carries an affiliate referral code, and the developer may earn a commission if you buy through it. It is the only monetised link in the extension.
- It is on by default
- You can turn it off under Buy now button in the settings page. Turning it off changes nothing else — no other behaviour is tied to it.
- It costs no extra request
- The listing is read from the DNS answer the lookup already has. Nothing is fetched from Atom.com to decide whether to show the button, and nothing is sent until you click it.
- Nothing about you is attached
- The referral code identifies the developer, not you. It is the same code for everyone, carries no identifier, and is visible in the link before you click it.
- It never changes what you are told
- The registry answer, the DNS records, the score and the archive date are what they are. No source is weighted, reordered or softened because a name happens to be listed.
This website
- Static pages, no cookies
- Every page here is prerendered and served as static files. No cookies are set, no analytics or tracking scripts are loaded, and there is no server-side logic that sees you.
- The demo looks nothing up
- The animated panel on the home page and the sample panels in the docs render fixed fixtures shipped with the site. They make no network requests.
- Your theme choice
- Stored in your browser’s local storage so the page does not flash on the next visit. It never leaves the machine.
- Getting in touch
- There is no contact form to submit — writing to info@extenddomains.com opens your own mail client, and an email tells us whatever your mail client normally tells a recipient.
Verify any of this yourself
The extension is open source and ships unminified — you can read every fetch in the repository, or watch them in your browser’s network inspector while you use it. If something here does not match what you see, that is a bug worth reporting.