Spec 13 dotBrand TLDs

Build a circle of trust around your brand's domain.

Start with the domain customers should trust first, verify ownership, and use BrandSet™ to connect the related domains your brand operates. Your anchor can be a .brand name, .com, or any registered domain with working DNS.

1 Enter your primary domain2 Verify ownership3 Create your BrandSet™

Your namespace already has a record. Claiming decides who writes it.

Every active TLD in the DNS root is already indexed in ZoneProof - including yours. Today that record is a baseline built from public sources: IANA root data, your Registry Agreement, and published registry pages. It's honest, but it's an outside sketch, and outside sketches go stale. AI systems now answering questions about your brand's namespace work from whatever they can find; unclaimed, that means inference.

Claiming changes the authorship. You confirm control against authoritative records, and the record becomes first-party: your registration policy, operational endpoints, and namespace structure. Systems that query the index see confirmed data with its provenance labeled, instead of deductions about you.

For a namespace whose premise is that the suffix itself is the guarantee, discoverability is the missing half. You built the guarantee. The record is how software finds out.

A two-name zone is a complete map.

Stewards can extend their record down to the names: a listing of the delegated second-level domains in the zone. For most TLDs that's depth. For a dotBrand, it's something stronger: totality.

If your zone holds two delegated names and both are listed, then every name on the internet claiming to be you either appears in that list or provably does not. Phishers can register lookalikes in a hundred open TLDs; they can never appear in your zone. Presence becomes a lookup, absence becomes evidence, and the question "is this really the brand?" collapses into a query any system can run.

gTLD zone files are already publicly available through ICANN's centralized zone data service, so listing yours discloses nothing new. It makes existing public data structured and retrievable in context. A listed zone contains delegated names only, never WHOIS or registrant contact data. ZoneProof indexes names, not people.

Claiming and maintaining your namespace record is free, and always will be. Zone listing with scheduled refresh - Zone Sync - is a subscription priced by zone size, and plans start at $950/year for zones up to 10 names. Most dotBrands are in the smallest tier. See pricing.

Every launch inherits the record.

Brands running live services on their TLD are using the namespace exactly as designed: as infrastructure. Public dotBrand examples show the range:

American Express activates cards at m.amex.

Google concentrates safety guidance at safety.google, and Android's AI features live at ai.android.

AWS hosts PartyRock at partyrock.aws.

Honda launched an EV initiative at 0.honda.

Nike builds community experiences at swoosh.nike.

Marriott runs vacation ownership at a dedicated .marriott destination.

Sandvik organizes business units under names like mining.sandvik.

Weber Saint-Gobain unified country sites under names like cz.weber.

FAGE routes U.S. customers to usa.fage.

Lidl prints info.lidl on physical packaging.

Toyota consolidates global digital services under global.toyota.

Every one of these launches asked the public, and increasingly software, to trust an unfamiliar name on the strength of its suffix. A confirmed ZoneProof record with a listed zone completes that bet. The day a new name is delegated, it's present in your listed zone: discoverable as yours by any system consulting the index, with the namespace's Spec 13 policy attached.

Your namespace, in fields software can read

Spec 13 dotBrand status from the Registry AgreementRegistration policy: you, your affiliates, and no one elseYour listed zone: every delegated name, whether two or two thousandOperational endpoints you assert: official sites, machine-readable resources, well-known URIsProvenance labels for registry facts and claimant-asserted fields

Every field is labeled by provenance: registry facts from systems of record, and claimant-asserted fields confirmed by you. Results are always ZoneProof-indexed status: the record reflects what has been claimed, confirmed, and listed.

Names, not people

ZoneProof indexes delegated names only. It does not publish WHOIS, registrant contact data, or private business information.

Make it official.

Your TLD already has a record. Claim the record, confirm control, and put the pen in your hand - then list the zone, however small, and let every name in it carry the proof.

Claim your primary domain