Rajan had a 94% match rate. Three touches to Bitly went to bitly.com. Bitly's team operates on bit.ly. Nobody got the emails. Here is what he found when he went through all 340 records.
Rajan had been running the enrichment pipeline for three weeks — 94% match rate, every domain resolved, every website loaded. His VP called it a solid run.
"We sent the Bitly sequence to bitly.com. Their team operates on bit.ly. Nobody got the emails."
Rajan pulled the record. His tool had returned bitly.com with a confidence score of 91. The domain resolved. The website was real. What the tool hadn't caught: Bitly's team didn't receive email at bitly.com. They received it at bit.ly — Libya's country code functioning as the last two letters of the company name.
The emails had gone to bitly.com, which accepted them on a catch-all and routed them to nothing. Three touches. Zero replies. No bounces.
"I'm going through the whole list."
A domain hack is a domain name in which the top-level domain — and sometimes the second-level domain — forms a functional part of a word, phrase, or brand when read together with the rest of the domain, repurposing a country code TLD from its geographic designation into a linguistic element that gives the full string a meaning its parts would not have individually. The first registered example was inter.net in 1992.
Bitly was not the only .ly company. Rajan found two more — a scheduling tool on buffer.ly, an analytics platform on sharp.ly. Both .com domains resolved. Neither had active MX records. He opened a new column: "Governance risk." In 2010, Libya's ccTLD registry suspended several .ly domains without warning for violating Libyan content policies. Real businesses disrupted because their domain was controlled by a foreign government whose priorities had nothing to do with theirs.
Six records — all developer tools, APIs, technical infrastructure. All six had .com addresses returned with high confidence. Four loaded real websites. Two redirected straight to the .io. In all six cases, team email lived on .io. In all six, his sequences had delivered to a .com that accepted connections and routed nothing. .io matched computing's abbreviation for Input/Output. In developer tooling verticals, .io signals credibility, not compromise.
Four records, all AI tooling companies. This time, Rajan ran manual MX lookups on each before correcting anything. Two returned active Google Workspace records. Two returned nothing — defensive registrations, held to block competitors, no mail infrastructure ever built. The domains had accepted SMTP connections because they were live, then routed messages nowhere because no mail exchange existed to receive them. No bounce. Confirmed delivery to an inbox never configured.
Colombia's ccTLD, adopted widely enough by 2010 that .co stopped reading as "Colombian company" and started reading as "early-stage tech." The .com loaded, the redirect looked clean. Something made him run the MX check. Empty. He corrected all three. .co is broad enough that the .com defensive registration always looks legitimate.
Montenegro's ccTLD adopted by personal productivity tools because .me is a complete English word. Rajan recognised one company — he had met someone at a conference eight months earlier. He found the email he had sent manually, to a .me address, and the reply he received the next morning. Then he looked at what his pipeline had sent: three touches to the .com, no replies. He corrected both records and followed up on the original thread.
Guernsey's ccTLD repurposed as "good game" — the shorthand of competitive gaming culture. Claire had been on a call with a contact at one of the accounts who mentioned offhand that their team email used .gg. Rajan pulled the record, found a second. He told Claire there were two. She replied: "Both?"
Tuvalu's ccTLD used by major streaming companies because .tv matched television. Rajan followed the redirect chain in his browser. Status 301. Location: .tv. The tool had resolved the source of a redirect, not the destination. The destination was where the team was.
A podcast host on .fm, a morning productivity tool on .am. Federated States of Micronesia and Armenia administering the ccTLDs that matched broadcast frequency designations the audio industry had used for a century. Those companies had found strings that matched something precise and universally understood. The domain hack had not been a workaround. It had been the most accurate name they could have chosen. First time in four days he thought the convention was clever.
A login tool on sign.in — India's ccTLD completing a verb phrase. A venture capital research platform on .vc — Saint Vincent and the Grenadines' ccTLD as the industry abbreviation. The .in record had the highest confidence score of any record he corrected. The tool had tagged it as India-market-focused and returned the .com as the global primary. Both wrong. Both corrected. Twenty-three total.
The 23 were not randomly distributed across 340. They clustered in exactly the verticals the list targeted — developer tools, AI, gaming, audio, video, early-stage SaaS. Industries where .com scarcity was most acute when these companies were founded, and where founders chose alternative TLDs deliberately — not as compromise but as primary brand identity.
The enrichment tool's .com weighting was correct for a general dataset. Most companies in a general dataset do operate on .com. Rajan's list was not general. It was technology-weighted — and in technology-weighted lists, domain-hack companies cluster in exactly the categories you are trying to reach.
94% match rate. Not 94% accurate. 94% confident. Different claims. The tool had not failed. The assumption underneath it had.
A confidence score tells you how well the tool resolved a match. It does not tell you whether that domain is where the team actually operates.
Rajan added MX verification on any .com result from a technology-adjacent vertical before any record entered a sequence. In three months: 31 additional domain-hack catches across three list builds. Thirty-one conversations that were going to start wrong, started right.
"The .gg gaming analytics company. Sent from the right address. Got a reply this morning. First one we've had from that account."
Rajan read it. He typed "good" and went back to the next list.
His note in the investigation document: a confidence score tells you how well the tool resolved a match. It does not tell you whether that domain is where the team actually operates. Different claims. Different failure rates in different verticals.
Rajan learned that in four days. The next list did not take four days.
The .com exists. The website loads. The score is high. The MX records are empty. Nobody figures it out until a rep named Claire gets a tip on a call and thinks to check.
FindCompanyDomain resolves company names to verified, MX-confirmed operational domains — including domain-hack addresses on .ly, .io, .ai, .gg, .co, .tv, and other ccTLDs — so the domain you sequence on is the one the team actually receives mail at.