Domain Name Due Diligence: Ownership, WHOIS & Look-alikes
Domains are the part of a company's IP that everyone uses and no one reviews. The business runs on them — the website, the email, the login — yet they are often registered in an individual's personal account, set to auto-renew on a card that will expire, or shadowed by look-alike domains someone else controls. Domain due diligence confirms the company actually holds the names its brand depends on, and that no one else is exploiting them.
Does the company actually control the domain?
The first question is ownership, and it is less obvious than it sounds. A domain's registrant — visible, at least in part, through WHOIS — should be the company, not a founder's personal account, a former agency, or a developer who registered it years ago. Control living in a personal inbox is a single point of failure: if that person leaves or the relationship sours, the company can lose its primary domain. Confirm the registrant, the registrar account, and who holds the login.
Read the WHOIS and registrar record
WHOIS and registrar data tell you the registrar, the creation and expiry dates, and the domain's status codes. The status codes matter more than people expect: a domain with registrar and transfer locks in place is protected against hijacking and accidental transfer, while one with no locks is exposed. Note whether privacy protection masks the registrant — common and legitimate, but it means ownership must be confirmed another way during diligence.
Expiry is a business-continuity risk
An expired domain does not fail politely — the website and email go dark, and after a grace period anyone can register it. Check the expiry date on every critical domain and whether auto-renew is on and tied to a live payment method. A flagship domain expiring within the deal horizon, or renewing on a card no one monitors, is exactly the kind of quiet risk diligence exists to surface. Long registration horizons and locked status are the signs of a domain managed as an asset rather than an afterthought.
Look-alikes and brand abuse
Around any real brand sits a halo of typosquat and look-alike domains: a swapped letter, a different TLD, an added hyphen. Some are defensive registrations the company holds itself; others belong to third parties running phishing, ad parking, or counterfeit sales off the brand's reputation. Surfacing these variants shows both the gaps in the company's defensive registrations and the active abuse it faces. A brand with dozens of unowned near-matches has a standing security and reputation exposure the buyer should price in.
Coverage across TLDs and markets
A company that sells internationally but holds only its .com has left its brand open in the country-code domains that matter in its markets. Map which TLDs the company owns against where it does business, and note the ccTLDs a competitor or squatter could take. This is not about owning every extension — it is about the ones a customer would plausibly type.
Small asset, outsized failure mode
Domains are cheap and easy to overlook, which is exactly why their failure modes are severe — a lapsed name or a personal-account registration can take a company offline or hand its brand to someone else overnight. Confirm ownership, lock status, expiry and look-alikes as part of any IP review; the checks take minutes and catch problems that are painful to fix after closing. This is general information, not legal advice.