Domains

24 TLDs, checked live via RDAP

Code & packages

Handles and package names, checked live

Social

Handles we can verify from the browser

Not checked

Named, not guessed

These cannot be verified from your browser without a server or a paid API, so we do not check them. Showing what we can prove and naming what we cannot is the point -- none of these is ever reported as available.

  • GitLab The unauthenticated API cannot tell a free namespace from one held by a user, so a taken name would show as available.
  • Instagram, TikTok, YouTube No cross-origin access, and every handle returns the same app shell -- a taken name and a free one look identical.
  • X (Twitter) Returns the same response for every handle -- there is no way to tell taken from free.
  • Reddit Blocks browser requests outright (HTTP 403).
  • RubyGems A free gem name returns 404 with no CORS header, which the browser cannot tell apart from a network error.
  • US trademark (USPTO) No cross-origin access, and the API requires a key.

Privacy First: Every check -- domains, code registries, and Bluesky -- is sent directly from your browser to each provider (Verisign, GitHub, npm, PyPI, NuGet, Bluesky, and others). Nothing passes through a HathLab server, so no one -- not even us -- sees the names you are researching.