FAQ
ZoneProof FAQ
01Why does this matter now?
Because discovery is moving from browsers to AI agents, and the trust signals namespaces spent decades building are invisible to them. An agent that cannot see registry screening treats a screened domain like any other string.
ZoneProof exists so that verification survives the handoff: indexed for every TLD, confirmed by the stewards who hold the pen.
02What does ZoneProof do?
ZoneProof publishes machine-readable records for internet namespaces. Every active delegated top-level domain starts with a baseline record built from public sources, including IANA root data, registry agreements, RDAP, WHOIS, and published policy materials.
Confirmed namespace stewards can claim the record, confirm control, and list first-party policy or zone data. ZoneProof makes it queryable by software, AI systems, and anyone who needs to know whether a domain's namespace carries registry-enforced verification requirements.
03What domains does ZoneProof cover?
ZoneProof covers active DNS root zone delegations by IANA: generic TLDs, country-code TLDs, and internationalized TLDs, plus registry-delegated second-level public-suffix zones such as co.uk or gov.au.
Namespace-level records exist for TLDs today. TLD landing pages such as /bank and /insurance are intended to explain the namespace to both stewards and registrants. Deeper zone listings and registrant-level records are being rolled out namespace by namespace.
04What is the difference between a namespace claim and a BrandSet™?
A namespace claim confirms who may author the ZoneProof record for a TLD or delegated namespace. It upgrades the record from a public-source baseline to a steward-maintained listing.
A BrandSet™ starts with a primary domain, verifies control through DNS, and connects other official domains verified by the same owner. Domain owners establish and maintain that relationship through BrandSet™ creation and verification.
ZoneProof indexes namespaces and domains, not people. It does not publish WHOIS, registrant contacts, private account data, or non-public eligibility files.
05Who can claim a namespace listing or create a BrandSet™?
The party with authoritative control of the namespace at that level can claim a listing.
The IANA database lists three contacts for every delegated TLD: sponsor, administrative contact, and technical contact. Each of these is eligible for claiming a TLD, although their permissions may vary.
Second-level public-suffix listings can be claimed by the entity that operates that zone, even if it differs from the parent TLD's manager.
A domain owner creates a BrandSet™ using the domain customers should trust first. The owner verifies the BrandSet™ by publishing the supplied DNS TXT record for the primary domain and each member domain.
Claiming confirms control of a namespace listing and authorization to maintain first-party data for it. It does not signal partnership with, certification by, or endorsement from ZoneProof.
06What does it cost to claim a namespace or create a BrandSet™?
Claiming a namespace listing is free. Creating and verifying a BrandSet™ for a primary domain is also free.
07How does someone claim a namespace or create a BrandSet™?
Namespace stewards use the claim flow to find a namespace listing, identify their organization, and provide their role with respect to that namespace. Domain owners use Create BrandSet™ and select the primary domain customers should trust.
ZoneProof confirms control via several methods. For TLD operators, confirmation through the contact of record with IANA or ICANN may be available.
Namespace verification may use a DNS TXT token. BrandSet™ verification uses the same supplied _domain-set TXT Name and Value for the primary domain and every member domain.
Once namespace confirmation succeeds, the record can be marked as confirmed and your organization can be shown as its confirmed operator. A verified BrandSet™ identifies its primary domain and verified member domains.
08Why claim a namespace or create a BrandSet™?
Because unclaimed namespace records are inferred, and confirmed namespace records are authoritative.
ZoneProof enables a registry operator to replace a public-source sketch with a current, first-party namespace record.
Unclaimed records are useful, but they can be stale or generic. Claiming gives the steward the pen: policy details, verification levels, official endpoints, and namespace-specific fields can be listed by the party responsible for the zone.
For credentialed TLDs, a namespace claim can also make delegated names discoverable. That means software can ask not just whether .bank is restricted, but whether a specific name is listed in the .bank zone.
Claiming also creates a notification channel if your namespace record changes, is disputed, or verification needs to be renewed.
A verified BrandSet™ gives software one primary domain, its verified related member domains, Brand Details, and an embeddable ZoneProof record.
09How does ZoneProof integrate with other MCP servers for my domain?
ZoneProof runs an MCP server at https://mcp.zoneproof.org/mcp. MCP-capable AI clients can connect to it alongside an organization's own MCP servers.
The integration model is complementary. ZoneProof answers namespace and verification questions, such as the registry's official website, whether a domain is in a restricted TLD, and what screening its registry enforces. Registries and registrants can operate their own MCP servers to answer more granular questions about their organization.
A ZoneProof listing can also point to other machine-readable endpoints, including /.well-known/ resources, a domain-owned MCP server, or llms.txt, so agents discovering a domain through ZoneProof know where to go next.
10How can I customize how ZoneProof responds to queries for my listing?
Within defined limits. ZoneProof records follow a published schema, and fields are classified by how they are sourced and verified. Some namespace fields come from public records, such as those published by IANA and ICANN, and cannot be edited by claimants. Other fields are asserted by the confirmed namespace claimant and labeled as such.
A confirmed namespace claimant can maintain claimant-asserted policy and operator fields. A BrandSet™ owner can maintain Brand Details such as organization information, specialties, public contact points, official endpoints, and social links.
You cannot alter verified facts, add promotional copy to query responses, or influence how ZoneProof characterizes other namespaces. That restraint is what makes a ZoneProof answer trustworthy.
11How do I report an issue with ZoneProof data accuracy?
Email [email protected] with the record in question and, where possible, a pointer to the authoritative source that contradicts it, such as an IANA entry, ICANN Registry Agreement, or RDAP response.
Reports are triaged against the applicable system of record. ZoneProof corrects its data to match authoritative sources rather than adjudicating disagreements itself. However, you may also submit issue reports if the public records are incorrect or out-of-date.
If the issue concerns a ZoneProof listing you do not control, the same channel can open a review and re-verification process.
12What if I want to expand the queries for my listing?
Listings may be expanded by adding metadata at the registry level or adding the TLD's zone file of delegated names.
For example, a credentialed TLD can list its zone so every screened name in that namespace becomes discoverable. A dotBrand can list the complete set of names under its control. A ccTLD can choose whether delegated-name listing fits its publication practices.
If the ZoneProof schema or MCP tools do not yet support a question you want answered about your namespace, you can request a schema extension.