Skip to content
Extend.Domains

Data & privacy

What leaves your browser, and what does not

There is no Extend.Domains server. Nothing you look up passes through us, because there is no “us” in the request path — your browser talks to public endpoints directly, and that is the whole architecture.

The short version

No backend

Not a single request goes to a server we run. There isn't one.

No account

Nothing to sign up for, nothing to sign in to, no identifier of any kind.

No analytics

No telemetry, no crash reporting, no usage pings — in the extension or on this website.

No API keys

Every source is a free, keyless public endpoint. That is why they were chosen.

No page content

The page you are reading is never uploaded anywhere. The only thing that travels is the domain name itself.

No personal registrant data

RDAP redacts it post-GDPR, and the panel does not display or request any of it.

Every request the extension makes

Six sources, all public, all fetched from the extension's background context — never from the page you are on, and never from the panel.

SourceHostWhat is sent
DNS recordscloudflare-dns.com · dns.googlethe registrable domain

NS, A, MX and TXT, plus TXT at _dmarc. Cloudflare is asked first; Google is the per-query fallback. These two hosts are the extension's only declared host permissions.

Registry bootstrapdata.iana.orgnothing but the request itself

IANA's public map of which RDAP server runs which TLD, fetched once and cached for 24 hours. A stale copy is preferred over none.

Registration recordthe registry's own RDAP serverthe registrable domain

Verisign for .com, Nominet for .uk, and so on — resolved from the bootstrap, queried directly. rdap.org is used only when the bootstrap has no entry for that TLD.

Site previewthe domain being looked upan ordinary page request for its root

Range: bytes=0-32768, a 4-second timeout, and reading stops at </head>. It is the same request your browser would make if you visited the site — because it is one.

Archive historyarchive.org · web.archive.orgthe registrable domain

The availability API asked for the snapshot closest to 1990, which is provably the earliest one. The CDX API is a slow fallback.

Faviconyour browser's cache, or the domain itselfnothing extra on Chrome

Chrome draws it from the favicon cache it already has. Firefox points an <img> at the site's /favicon.ico and hides it if that fails.

Requests are capped at two at a time per host, concurrent lookups of the same name share a single in-flight request, and a name already in the local cache issues nothing at all.

What is stored, and where

Lookup cache
One record per registrable domain in the extension’s local storage, expiring 24 hours after its first write. Sources merge into it as they arrive. Only conclusive registry answers are cached — a failure is never written down as a fact.
Recent lookups
The last twelve names, so the chips at the bottom of the panel work. The ✕ on that card deletes the list.
Your preferences
Theme, registrar, sidebar layout, scoring weights, detection toggles.
Nothing else, and nowhere else
All of it is extension-local storage in your own browser profile. It is never synchronised, never transmitted, and uninstalling the extension removes it.

Why each permission is asked for

storage
Your settings and the 24-hour lookup cache.
contextMenus
The Look up “…” item on a selection. This is also the one lookup path that needs no site access at all.
cloudflare-dns.com
…and dns.google — the two DNS-over-HTTPS resolvers. These are the only hosts the extension declares up front.
Access to page content
Two jobs: noticing that you selected something that looks like a domain, and fetching the domain root for the preview card. On Firefox this is opt-in and the extension works without it (via the right-click menu); on Chrome it is listed as optional so you can restrict and re-grant it whenever you like.
sidePanel
Chrome only — the panel itself.
favicon
Chrome only — draws the site icon from the cache your browser already has, instead of making a request for it.

Registry lookups need no permission at all

RDAP servers are arbitrary hosts that cannot be enumerated in advance, so they are fetched under ordinary CORS rules — which works because the RDAP standard requires those servers to allow it. A registry that breaks that rule simply renders as “unknown”.

Affiliate disclosure

When a name’s nameservers show it is listed for sale on Atom.com, the panel shows a Buy now on Atom.com button. That link carries an affiliate referral code, and the developer may earn a commission if you buy through it. It is the only monetised link in the extension.

It is on by default
You can turn it off under Buy now button in the settings page. Turning it off changes nothing else — no other behaviour is tied to it.
It costs no extra request
The listing is read from the DNS answer the lookup already has. Nothing is fetched from Atom.com to decide whether to show the button, and nothing is sent until you click it.
Nothing about you is attached
The referral code identifies the developer, not you. It is the same code for everyone, carries no identifier, and is visible in the link before you click it.
It never changes what you are told
The registry answer, the DNS records, the score and the archive date are what they are. No source is weighted, reordered or softened because a name happens to be listed.

This website

Static pages, no cookies
Every page here is prerendered and served as static files. No cookies are set, no analytics or tracking scripts are loaded, and there is no server-side logic that sees you.
The demo looks nothing up
The animated panel on the home page and the sample panels in the docs render fixed fixtures shipped with the site. They make no network requests.
Your theme choice
Stored in your browser’s local storage so the page does not flash on the next visit. It never leaves the machine.
Getting in touch
There is no contact form to submit — writing to info@extenddomains.com opens your own mail client, and an email tells us whatever your mail client normally tells a recipient.

Verify any of this yourself

The extension is open source and ships unminified — you can read every fetch in the repository, or watch them in your browser’s network inspector while you use it. If something here does not match what you see, that is a bug worth reporting.