Verifying Company Domains
Markdown--- name: verifying-company-domains description: Discovers and verifies websites and domains owned or controlled by a target company and its verified acquisitions, subsidiaries, and brands, using legal-page fingerprinting and dual-pass search verification. Use when conducting Stage 2 of a company research workflow, after Stage 1 has produced a verified entity list, to build a confirmed table of current company-owned domains before proceeding to app, GitHub, brand-portal, or font research. --- # Verifying Company Domains Stage 2 of a multi-stage research workflow. Finds and verifies current, company-owned websites and domains for a target company and its Stage-1-verified acquisitions, subsidiaries, and brands. Does not research apps, GitHub, brand portals, or fonts — those are later stages.
- Confirm inputs: target name, primary domain, cutoff date (if any), and Stage 1's verified entity list.
- Ask: "May I research web domains for the target company and its verified acquisitions and brands?" Wait for a yes, unless already authorized for this stage or the full investigation.
- Fingerprint the primary domain's legal pages, then run two distinct search passes per entity.
- Verify ownership for every candidate before including it.
- Output the domain table, note what the recheck covered, and ask permission before moving to app research.
- Target company name (verified legal name preferred)
- Primary domain
- Cutoff date, if specified
- Stage 1's verified list of legal names, former names, acquisitions, subsidiaries, and brands
If the verified list is missing: request it, or if the user only wants domain research for a specific named entity, perform only the identity checks needed for that request. Never treat an unverified name as an owned entity — do not search for or report its domains as owned until verified.
Progress:
- Step 1: Get/confirm permission
- Step 2: Build search list from all verified names/brands
- Step 3: Fingerprint known sites' legal pages
- Step 4: First discovery pass (per entity)
- Step 5: Verify ownership of each candidate
- Step 6: Second discovery pass, different terms/operators/sources
- Step 7: Handle any newly discovered entities (verify, update register, queue other assets)
- Step 8: Normalize, deduplicate, finalize register
- Step 9: Report table + recheck note + ask permission to proceed
Step 1: Permission
Ask the exact question above unless the user has already authorized this stage or the entire investigation. Do not proceed without a clear yes.
Step 2: Build the Search List
Compile every verified legal name, former name, acquired company, subsidiary, brand, known domain, and relevant email-domain variant from Stage 1. This is the seed list for all searches. Each acquired company and brand must be searched separately — do not batch them into one generic pass.
Step 3: Inspect Known Sites (Legal-Page Fingerprinting)
For the primary domain and any other already-known site, inspect: homepage, footer, privacy policy, terms of use, legal notice, cookie policy, accessibility page, contact page, copyright notice.
Extract:
- Exact legal name and address
- Telephone number
- Email domain
- Copyright wording
- Privacy-controller / data-controller wording
- Registration or tax identifiers
- Trademark language
- Group-company names mentioned in privacy or terms text
Step 4: First Discovery Pass
For each item in the search list, search for corporate, product, brand, regional, campaign, acquired-company, inherited, and legacy sites. Use exact-phrase queries and operators, adapted to the company's actual legal suffix, country, and language — don't run every pattern mechanically. Useful patterns:
"Exact Legal Company Name" -site:primarydomain.com"Exact Legal Company Name" privacy"Exact Legal Company Name" "Terms of Use""Exact Legal Company Name" copyright"Exact Legal Company Name" domain OR website"Exact company address" -site:primarydomain.com"Exact telephone number" -site:primarydomain.com"Exact privacy policy phrase" -site:primarydomain.com"Exact copyright phrase" -site:primarydomain.com"© [Company Name]",Copyright [Company Name],[Company Name] All Rights Reserved(try recent year variants)intext:"Company LLC" -site:company.comallintext:"Company LLC" privacysite:.com "Company LLC"(and equivalent for relevant TLDs)"owned and operated by","this website is operated by","property of"+ company name
Matching privacy or terms text is a discovery lead, not proof of ownership — every candidate still requires Step 5.
Step 5: Verify Ownership
For each candidate domain, determine:
- Who currently operates it (per its own legal/privacy/terms pages)
- Whether that operator is still owned or controlled by the target today
- Whether the site has been divested — separate current sites from historical/sold sites
Strong evidence (sufficient on its own, cross-checked):
- Explicit official link between sites
- Current privacy policy or terms page naming the operator
- Corporate filing naming the domain
- Confirmed operation by a verified owned company
Supporting evidence (use only alongside strong evidence):
- Copyright statements, redirects, matching contact details
Weak/insufficient evidence (never enough alone):
- Similar branding, naming, or page design
- Shared hosting
- Search-result association
- Shared agencies or backlinks
Never assign a former or acquired company's domain to the target merely because the target acquired that business — verify current operation independently.
Step 6: Second Discovery Pass (Mandatory)
Run this even if the first pass found nothing. Use genuinely different queries: vary name forms, search operators, TLDs, legal identifiers, and sources. Search each acquired company and brand separately again. Follow official links found on newly discovered sites. Add any missed domains only after independently verifying them per Step 5.
Step 7: Handle Newly Discovered Entities
If a site reveals a company or brand not in Stage 1's list:
- Verify its relationship to the target and its current ownership/control.
- Update the entity register with this new, verified entity.
- Search its domains now, within this authorized stage.
- Correct any earlier findings this affects.
- Queue its non-domain digital assets (apps, GitHub, brand portals, fonts) for later authorized stages — do not research them now.
Step 8: Normalize and Deduplicate
- Strip protocol,
www, paths, and query parameters — reduce to root domains. - Keep genuinely distinct country domains (e.g.,
company.dealongsidecompany.com). - Do not list subdomains unless the user asks.
- Check whether a redirect's destination is currently owned before counting it; don't count multiple URLs on the same root domain as separate sites.
- Use N/A for a verified owned asset with no verified site.
- Keep historical/inactive domains in a clearly separate, labeled section — never mixed into the current table.
Step 9: Report and Pause
Output the table (format below), a one-line recheck note, and then ask: "May I proceed to app research?" Do not begin the next stage without explicit authorization.
Asset name | Type | Domain | Status | Source
- One row per verified current domain, 1–2 source links per row.
- Historical/inactive domains: separate labeled section, same column format, status marked "Historical" or "Inactive."
- Exclude unverified candidates entirely from both tables — do not list them as "unconfirmed" rows.
- Recheck note: one line stating what the second pass covered and whether it found additions.
Input: Microsoft Corporation; primary domain microsoft.com. Stage 1 verified GitHub and LinkedIn as acquisitions. User has authorized this stage.
Process: Inspect microsoft.com legal pages. Inspect GitHub's privacy statement (operator: GitHub, Inc.) and LinkedIn's company documents (parent: Microsoft). Run first pass per entity. Run second pass with varied terms/TLDs on "GitHub" and "LinkedIn" plus legal-phrase searches. No new domains or entities surface. Normalize and dedupe.
Output:
| Asset name | Type | Domain | Status | Source |
|---|---|---|---|---|
| Microsoft | Corporate | microsoft.com | Current | microsoft.com/en-us/legal |
| GitHub | Acquired company | github.com | Current | github.com/site/privacy |
| Acquired company | linkedin.com | Current | linkedin.com/legal/privacy-policy |
Recheck note: Second pass varied entity names and TLDs for GitHub and LinkedIn; no additional domains or entities found.
May I proceed to app research?
- Treat legal-page fingerprinting (exact legal name, address, phone, email domain, copyright/privacy wording) as the primary discovery method — it's more reliable than brand-similarity searching.
- Always run the second pass with genuinely different queries, even when the first pass looked thorough or found nothing.
- Search each acquired company/brand individually — never rely on one generic search covering the whole portfolio.
- Prefer current primary sources (the site's own legal pages) over secondary mentions.
- When dates or ownership claims conflict, resolve them if possible; otherwise state the evidence gap explicitly rather than guessing.
- Maintain an internal domain verification register (candidate, associated entity, operator, evidence links, status) throughout the cycle.
- Do not include partners, customers, suppliers, distributors, licensees, minority (non-controlling) investments, parent-owned sister companies, sold businesses, unrelated lookalikes, or agency-owned sites.
- Do not accept matching privacy/terms/copyright text alone as proof of common ownership — always cross-check official links and current legal identity.
- Do not assign an acquired company's former/legacy domains to the target automatically.
- Do not skip the second search pass, even after a strong first-pass result.
- Do not list multiple URLs on the same root domain as separate assets.
- Do not silently fold a newly discovered entity's other assets (apps, GitHub, fonts, etc.) into this stage — verify the entity and its domains only, and queue the rest.
- Do not proceed to app research (or any next stage) without explicit permission after presenting the table.
**Assumptions:**
- "Verified" throughout means confirmed per Stage 1's standard or this skill's ownership-evidence rules, not merely mentioned.
- The agent has live web search capability and can render/inspect page content (footers, legal pages).
- Cutoff date, if given, bounds what counts as "current" versus "historical."