Observed Signal · Jul 30, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Neutral
RDAP Replaces WHOIS; 404 Responses Can Be Misleading
The legacy WHOIS protocol has been replaced by RDAP (RFC 9083), which returns JSON and is required for gTLD registries. Post-GDPR, RDAP generally omits registrant personal data, leaving operational fields (registrar, dates, status, DNSSEC) as the most useful outputs. The article describes a common tooling trap: rdap.org acts as a router using IANA's RDAP bootstrap, and if a TLD is not listed there rdap.org returns 404 for every name under that TLD, which can be mistaken for availability. The two-part fix is (1) consult IANA's dns.json to know which TLDs have RDAP services and (2) use DNS (NS records) to detect delegation for TLDs without RDAP; when neither proves registration, return an unknown/null rather than a false available result. The author also notes an Apify Actor (Domain Scraper) used for runnable examples and pricing details for domain queries.
Protocol-level change with operational implications for domain tooling and automation; useful for security auditing, sales qualification and toolbuilders, but not a high-impact AdTech industry shift.
Track Cloudflare Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- RDAP replaced WHOIS and is standardized as RFC 9083; it returns JSON.
- gTLD registries are required to run RDAP services.
- Post-GDPR, RDAP returns no registrant personal data for most TLDs; operational fields remain available (registrar, dates, status, DNSSEC).
- rdap.org routes queries using IANA's RDAP bootstrap; if a TLD is not in the bootstrap, rdap.org returns 404 for all names under that TLD, causing false 'available' results.
- Fix recommended: fetch IANA's https://data.iana.org/rdap/dns.json to know which TLDs have RDAP, and use DNS NS records to detect delegation for TLDs lacking RDAP; the author demonstrates tooling using an Apify Actor (Domain Scraper).
Connected Companies & Entities
7 Entities mapped“linear.app CloudFlare, Inc. 2030-05-09 8.2 google cloudflare reject...”
“Combine that with a DNS lookup and you get the thing people actually want, which is what a company runs on: ... mail provider ... google...”
“domain registrar expires age mail dns dmarc stripe.com SafeNames Ltd. 2027-09-11 30...”
“domain registrar expires age mail dns dmarc linear.app CloudFlare, Inc. 2030-05-09 8...”
“domain registrar expires age mail dns dmarc vercel.com Amazon Registrar, Inc. 2029-10-04 26...”
“rdap.org/domain/notion.so 404...”
“rdap.org/domain/github.io 404...”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Rethinking Digital Risk Protection: Detection vs Disruption
This analysis argues that 'Digital Risk Protection' (DRP) is an overused, inconsistently defined category—many vendors label monitoring-only products as DRP while genuine protection requires confirmed removal of external threats. Canonically, DRP covers external brand impersonation across domains, social, mobile apps, phone vishing, credential leaks and scam listings. The market splits between detection (mature, data-driven signal matching) and disruption (coordination-heavy takedowns requiring registrars, platforms and carriers). Vendor capabilities vary widely: some excel at OSINT/dark-web detection but not takedowns, while dedicated DRP vendors differ in operational quality. The author emphasizes evidence-package quality and 'explainable verification' as critical inputs to takedown speed, and notes Australia’s Scams Prevention Framework (SPF) shifts procurement toward disruption outcomes. The piece ends with a practical evaluation checklist for buyers focused on coverage, removal rates, escalation relationships and recurrence detection.
Free ReDoS Checker and API to Detect Catastrophic Regexes
A developer tutorial and announcement for ReDoScan, a REST API and free web checker built by Hudson Enterprises LLC that detects ReDoS (regular expression denial-of-service) vulnerabilities caused by catastrophic backtracking in backtracking-based regex engines. The service offers static analysis (fast, rule-based risk badges) and an optional dynamic timing mode that measures runtime growth and classifies it (safe / polynomial / exponential). Key endpoints include /scan, /scan-batch (up to 200 patterns) and /known-evil (public corpus). The API is available via a RapidAPI listing with a free tier (1,500 scans/month); paid tiers provide higher monthly scan quotas. The article explains how to integrate ReDoScan into CI/CD gates, caveats about coverage (not a full SAST) and recommended usage patterns for batch CI and deeper audits.
MCP Spec Imminent; Email Authentication Is Weakening
The author scanned 671,693 domains (Tranco forward-DNS snapshot 2026-07-25) and reports widespread weaknesses in email authentication as the MCP spec is about to land. Key findings: 634,220 domains publish SPF, 468,749 publish DMARC, but DMARC enforcement fell by 0.42 percentage points last month despite 9,173 net new DMARC domains; a large share of those records are non-enforcing `p=none` or inert (no working `rua=`). Enforcement correlates with prominence: top-1k sites are far more protected than the long tail. Self-hosted MX is the single largest inbound category (22.79%), exceeding Google Workspace and Microsoft 365. The author warns agentic email products amplify risk through concentrated volume, unaudited SPF includes, and missing telemetry, and gives concrete diagnostic commands and remediation steps.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
