flexmydomain

Escrow

Buy or sell a domain at any registrar without trusting the other side. The buyer's bitcoin is locked where nobody can take it alone: not the buyer, not the seller, not us. The seller transfers the domain straight to the buyer, the registrar's usual way, and the buyer's confirmation pays the seller. If the two disagree, an arbiter checks the registry's record and decides. If the domain never arrives, the buyer gets the money back.

Open an escrow

Both sides generate a key here. We never see either of them.

  1. 1

    The trade

  2. 2

    The arbiter

    An arbiter holds one key of three and decides a dispute: if the two of you disagree about the transfer, it checks the registry's record and asks each of you, in private, for proof. It never holds the domain, and co-signs a payout with you or with your counterparty, never alone. We read both sides' published arbiter lists and offer only the ones you both accept. A side with no list accepts only this site's arbiter.

  3. 3

    The invite

    Your Nostr key signs the terms above, and the invite carries a fresh key for this trade to your counterparty. Nothing is published, and nothing is paid, until you both accept. After funding, the buyer tells the seller where to send the domain in your private chat.

  4. 4

    Swap one message each way, then publish

    The escrow address needs both your keys, so neither of you can make it alone. Your invite carries yours to your counterparty, and their reply brings theirs back. Neither message holds a secret.

Already in an escrow? Connect, and your escrows open here, on any device.

Open one with a recovery string instead

Invited privately? Escrow invites sent to your account show here.

What we can and cannot do

We canWe cannot
Refuse to show your listingRemove it from the relays
Refuse to arbitrateMove a single satoshi by ourselves
Publish a ruling you disagree withFreeze, seize or reverse a payment
Read the registry's public record of your domainTouch your domain: it goes straight from the seller to the buyer
Ask you for read-only proof in a disputeRead your chat with the other side: only the two of you can
Stop running this siteTake your key or your history

There is no leaf in the script tree an arbiter key can spend by itself. That is a property of the output, asserted by a test that spends every leaf against Bitcoin Core. If we vanish, the timeout path refunds the buyer with recover.html, offline, from a file.

What you trust the arbiter with is its judgement in a dispute. It decides from the registry's public record (RDAP, the modern WHOIS: the registrar, its locks, and when the domain last moved) and from read-only proof each side shows it in their own private chat with it, such as a registrar API key that can only read. Every ruling is published with its reason, signed with the arbiter's key, so a bad one is on the record for good. Transfer details and codes pass only between the buyer and the seller.

The rules the arbiter follows

  • After funding, the buyer tells the seller where to send the domain, and the seller transfers it within the transfer window: a move to the buyer's account at the same registrar, or a transfer code for the buyer's own registrar. If the seller doesn't say it is sent in time, the buyer is refunded.
  • When the domain is in the buyer's account, the buyer confirms, which pays the seller. If the seller cancels, the buyer is refunded.
  • If either side asks, the arbiter decides: it reads the registry's record, asks each side for read-only proof, and co-signs the payout the evidence supports, release to the seller or refund to the buyer, with its reason published.
  • A seller whose buyer won't confirm asks for a ruling before the timelock: after it, the buyer can take the money back alone.

Connect