Whois Lookup
Look up domain registration details including registrar and dates.
What is WHOIS lookup?
WHOIS is a protocol for querying databases that store registration information about domain names and IP addresses. A WHOIS lookup reveals who registered a domain, when it was registered and when it expires, which registrar was used, and the nameservers it points to. This information is publicly available for most domains, though privacy protection services can mask the registrant's personal details.
The WHOIS system dates back to the early days of the internet when ARPANET maintained a directory of network users. Today, domain registrars are required to maintain WHOIS records for their domains. ICANN (Internet Corporation for Assigned Names and Numbers) oversees the WHOIS system for generic top-level domains like .com, .org, and .net.
How ICANN and domain registries govern WHOIS
WHOIS data does not live in a single central database. Instead, each domain registry โ the organisation that manages a top-level domain (TLD) โ operates its own authoritative WHOIS service. Verisign runs the registry for .com and .net; the Public Interest Registry runs .org; each country has its own national registry for country-code TLDs such as .uk (Nominet) or .de (DENIC). Underneath the registry sits the registrar: a company like GoDaddy, Namecheap, or Google Domains that you pay to register a name. ICANN, the Internet Corporation for Assigned Names and Numbers, sets policy through its Registrar Accreditation Agreement (RAA), which requires accredited registrars to collect registration data and make a whois service publicly accessible on port 43.
For generic TLDs (.com, .org, .net, .info, and others), ICANN's Thick WHOIS policy โ phased in from 2014 and completed for all gTLDs โ moved full registrant data to the registry level so it is available from one authoritative source rather than being spread across hundreds of registrar databases. Country-code TLDs are governed independently and vary widely: some publish full contact details; others publish nothing beyond nameservers.
Information in a WHOIS record
- Registrant โ the person or organization that registered the domain.
- Registration date โ when the domain was first registered.
- Expiration date โ when the registration expires and must be renewed.
- Registrar โ the company through which the domain was registered (like GoDaddy, Namecheap).
- Nameservers โ the DNS servers that resolve the domain to an IP address.
Understanding WHOIS domain status codes
A WHOIS record includes one or more EPP (Extensible Provisioning Protocol) status codes that describe the current state of the domain. The most common codes are:
- clientTransferProhibited โ the registrar has locked the domain to prevent unauthorised transfer to another registrar. Most active domains carry this lock.
- clientUpdateProhibited โ changes to the domain's registration data are blocked at the registrar level.
- serverDeleteProhibited / serverTransferProhibited / serverUpdateProhibited โ registry-level locks, typically set for premium or sponsored domains.
- pendingTransfer โ a registrar-to-registrar transfer is in progress (usually takes five days).
- redemptionPeriod โ the domain has expired and the registrant has a grace window (typically 30 days) to restore it before it is released for public registration.
If you see only active without any lock codes, the domain could be transferred or modified easily โ a potential security risk the registrant should address.
GDPR and the redaction of WHOIS data since 2018
The enforcement of the EU General Data Protection Regulation (GDPR) on 25 May 2018 caused a fundamental change to public WHOIS data. Because the names, email addresses, phone numbers, and postal addresses of individual domain registrants are personal data under GDPR, registrars subject to European law were required to stop publishing them in unauthenticated WHOIS responses. Almost overnight, the registrant contact fields that had been publicly visible for decades were replaced with redacted for privacy or forwarding addresses managed by a privacy proxy service.
ICANN responded with a Temporary Specification (later made permanent as the 2019 Registration Data Policy) that defines which fields must remain public (domain name, registrar, creation and expiry dates, nameservers, status codes) and which must be redacted for natural persons. Organisations โ companies and other legal entities โ may still appear by name because their registration details are not personal data in the GDPR sense. This means a lookup for a major corporate domain will often still show a company name and country, while a lookup for a privately registered personal domain will show only the proxy's details. Law enforcement and accredited researchers can request non-public data through ICANN's System for Standardized Access/Disclosure (SSAD), though this process remains cumbersome and is still being developed.
RDAP โ the modern replacement for the WHOIS protocol
The classic WHOIS protocol (RFC 3912) dates from 1985. It delivers plain-text responses with no authentication, no standardised field names, and no way to distinguish between a human reading it and a harvesting bot. The IETF designed RDAP (Registration Data Access Protocol, RFC 7480โ7484) as the authoritative successor. RDAP responses are structured JSON, making them machine-readable without fragile text parsing. RDAP supports authentication so registries can provide different levels of detail to different requesters (anonymous users, registrars, law enforcement, etc.), and it includes internationalised domain name support for non-ASCII characters. ICANN required all gTLD registries and registrars to support RDAP from 26 August 2019. This tool queries RDAP rather than legacy WHOIS to provide accurate, structured results.
Legitimate uses for WHOIS and RDAP lookups
WHOIS lookups serve a wide range of legitimate purposes:
- Domain availability and expiry monitoring โ checking whether a name is taken and when it might expire so you can register it or backorder it.
- Brand protection โ companies monitor WHOIS records for newly registered lookalike domains (typosquatting or brand abuse) that could be used for phishing or counterfeit goods.
- Due diligence when buying a domain โ verifying registration history, identifying the true registrar, and confirming the domain is not subject to legal disputes.
- DNS troubleshooting โ confirming which nameservers are authoritative for a domain, which is the first step in diagnosing DNS propagation issues.
- Security research and incident response โ identifying the registrar of a malicious domain so an abuse report can be filed, or confirming whether a suspicious site was registered recently (a new domain can be a phishing indicator).
How to use this tool
Enter a domain name (like example.com) and the tool queries the WHOIS database for that domain's registration record. The results show the registrant information (if not privacy-protected), registration and expiration dates, registrar details, and nameservers. Use this to check domain availability, verify ownership, or research when a domain might become available.
Domain privacy protection
Most registrars offer WHOIS privacy protection (also called domain privacy or WHOIS guard) that replaces the registrant's personal information with the privacy service's details. This prevents spam, identity theft, and unwanted solicitation. With GDPR regulations in Europe, many registrars now automatically redact personal information from WHOIS records.
Common misconceptions about WHOIS
- "WHOIS always shows the real owner." โ Not since 2018. GDPR redaction and privacy proxy services mean most personal domains now show only the proxy service's contact details, not the registrant's identity.
- "WHOIS is real-time." โ WHOIS data can lag behind actual changes by hours or even days while registrars and registries synchronise records.
- "One WHOIS query covers all TLDs." โ There is no single global WHOIS server. Each registry runs its own service; a query for a .uk domain goes to Nominet's WHOIS, not Verisign's.
- "WHOIS and DNS are the same." โ DNS maps a domain name to an IP address and handles mail routing. WHOIS/RDAP is the administrative record of who registered the name and with whom โ two completely separate systems.
Frequently asked questions
Is WHOIS information always accurate?
ICANN requires registrants to provide accurate contact information, but enforcement is inconsistent. Privacy protection services legally mask the data. Some domain owners provide deliberately inaccurate information (which technically violates the registration agreement and could result in domain suspension). GDPR has further complicated accuracy requirements by requiring data minimization.
Can I find out who owns any domain?
For domains without privacy protection, yes โ the registrant's name, organization, email, and sometimes phone number are publicly visible. For privacy-protected domains, you will see the privacy service's information instead. Some country-code TLDs (like .de for Germany) have stricter privacy rules and may not display registrant details at all.
What is the difference between WHOIS and RDAP?
WHOIS (RFC 3912) is a plain-text query protocol from 1985 with no standardised output format. RDAP (Registration Data Access Protocol) is its IETF-standardised successor, introduced in 2019. RDAP returns structured JSON, supports authentication-based access tiers, and handles internationalised domain names. ICANN has required all gTLD registries to support RDAP since August 2019. This tool queries RDAP endpoints for accurate, structured results.
Why does the lookup show a privacy service instead of the real registrant?
Since GDPR came into force in May 2018, registrars are required to redact the personal contact details (name, email, phone, address) of individual domain registrants in public WHOIS and RDAP responses. The registrar typically substitutes a privacy proxy service's details. If the domain was registered by a company rather than an individual, the organisation name and country may still appear, since company registration data is not personal data under GDPR.