WHOIS Domain Lookup
Registration dates, registrar, status codes and nameservers from the registry's own RDAP service, with what each status code actually means for the domain.
This tool needs JavaScript: the registry is asked by the server, because a browser cannot reach RDAP across origins.
The registrable name. A URL or an email address works: everything before the @ and after the host is removed.
This is one of the few tools here that asks the server rather than your browser, because a browser cannot do it. Nothing you put in is stored; the request is rate limited by address and the answer is not cached.
Who holds a domain, when it was registered, when it expires, and whether it is locked. From the registry’s own RDAP service, which is the protocol that replaced WHOIS, rather than from scraping somebody’s web page.
The part worth reading is usually the status codes. clientTransferProhibited is not a warning, it is
the lock every sensible registrar sets. redemptionPeriod means the domain expired and is not yet
available. clientHold means the registrar has taken it out of DNS, which is why the site is down.
How to use
Put in a domain. A URL or an email address works: everything before the @ and after the host is
removed.
Example
Domain WORDPRESS.COM
Registrar MarkMonitor Inc.
Dates
registered 3 March 2000, 26 years ago
expires 3 March 2033, in 6 years
last changed 28 August 2023, 3 years ago
Status
client delete prohibited the registrar has locked deletion
client transfer prohibited the registrar has locked transfers, which is the normal, safe setting
server update prohibited the registry has locked changes to the record
Nameservers
ns1.wordpress.com
ns2.wordpress.com
DNSSEC signed
Registrant redacted, which has been the default since GDPR in 2018
Pitfalls
Contact details are redacted, and that is not a fault in the lookup. Since GDPR in 2018 registries publish the registrar, the dates and the status, and pass the rest only to parties with a legal reason to ask. A tool that shows you a registrant name for a European domain is showing you an old cache or a guess.
An expired domain is not an available domain. After expiry comes a grace period, then a redemption period where only the previous owner can recover it for a fee, then a few days of pending delete. The whole sequence can take 75 days.
The expiry date is the registration’s, not the site’s. Auto-renew usually means it never matters, until the card on file expires. Under 30 days is worth acting on.
ok status means no transfer lock. It reads like good news and is the one status worth changing:
a domain without clientTransferProhibited can be moved with the auth code alone.
Not every TLD publishes RDAP. Most ccTLDs do not, and for those the registry’s own WHOIS page is the only source. This says so rather than guessing at an endpoint.
The dates come from the registry, not the registrar. A registrar’s dashboard can show a different expiry because it renews internally before the registry record changes.
Nameservers here are the delegation, not the answer. They are what the registry has recorded. What actually resolves is whatever those servers say, which is a DNS lookup rather than a registration one.
Compatibility
RDAP over HTTPS, using IANA’s published bootstrap file to find which service answers for which top-level domain. The bootstrap is fetched once a day and kept in a transient, so a lookup is one request to the registry rather than a guess at a hostname.
This is one of the few tools on the site that asks the server, because a browser cannot query RDAP across origins and cannot speak port 43 at all.
Everything the server fetches goes through the same network guard the other server tools use: https only, the name checked before use, redirects followed by hand with the checks repeated on each hop, and the response capped. The endpoint is rate limited to 20 lookups a minute per address, the counter keyed by a salted hash, and nothing about the lookup is stored.
A 404 from the registry is reported as “not registered”, which is what it means, rather than as an error.