WHOIS Domain Lookup

Registration dates, registrar, status codes and nameservers from the registry's own RDAP service, with what each status code actually means for the domain.

This tool needs JavaScript: the registry is asked by the server, because a browser cannot reach RDAP across origins.

The registrable name. A URL or an email address works: everything before the @ and after the host is removed.

Result

This is one of the few tools here that asks the server rather than your browser, because a browser cannot do it. Nothing you put in is stored; the request is rate limited by address and the answer is not cached.

Who holds a domain, when it was registered, when it expires, and whether it is locked. From the registry’s own RDAP service, which is the protocol that replaced WHOIS, rather than from scraping somebody’s web page.

The part worth reading is usually the status codes. clientTransferProhibited is not a warning, it is the lock every sensible registrar sets. redemptionPeriod means the domain expired and is not yet available. clientHold means the registrar has taken it out of DNS, which is why the site is down.

How to use

Put in a domain. A URL or an email address works: everything before the @ and after the host is removed.

Example

Domain                                     WORDPRESS.COM
Registrar                                  MarkMonitor Inc.

Dates
  registered                               3 March 2000, 26 years ago
  expires                                  3 March 2033, in 6 years
  last changed                             28 August 2023, 3 years ago

Status
  client delete prohibited                 the registrar has locked deletion
  client transfer prohibited               the registrar has locked transfers, which is the normal, safe setting
  server update prohibited                 the registry has locked changes to the record

Nameservers
  ns1.wordpress.com
  ns2.wordpress.com

DNSSEC                                     signed
Registrant                                 redacted, which has been the default since GDPR in 2018

Pitfalls

Contact details are redacted, and that is not a fault in the lookup. Since GDPR in 2018 registries publish the registrar, the dates and the status, and pass the rest only to parties with a legal reason to ask. A tool that shows you a registrant name for a European domain is showing you an old cache or a guess.

An expired domain is not an available domain. After expiry comes a grace period, then a redemption period where only the previous owner can recover it for a fee, then a few days of pending delete. The whole sequence can take 75 days.

The expiry date is the registration’s, not the site’s. Auto-renew usually means it never matters, until the card on file expires. Under 30 days is worth acting on.

ok status means no transfer lock. It reads like good news and is the one status worth changing: a domain without clientTransferProhibited can be moved with the auth code alone.

Not every TLD publishes RDAP. Most ccTLDs do not, and for those the registry’s own WHOIS page is the only source. This says so rather than guessing at an endpoint.

The dates come from the registry, not the registrar. A registrar’s dashboard can show a different expiry because it renews internally before the registry record changes.

Nameservers here are the delegation, not the answer. They are what the registry has recorded. What actually resolves is whatever those servers say, which is a DNS lookup rather than a registration one.

Compatibility

RDAP over HTTPS, using IANA’s published bootstrap file to find which service answers for which top-level domain. The bootstrap is fetched once a day and kept in a transient, so a lookup is one request to the registry rather than a guess at a hostname.

This is one of the few tools on the site that asks the server, because a browser cannot query RDAP across origins and cannot speak port 43 at all.

Everything the server fetches goes through the same network guard the other server tools use: https only, the name checked before use, redirects followed by hand with the checks repeated on each hop, and the response capped. The endpoint is rate limited to 20 lookups a minute per address, the counter keyed by a salted hash, and nothing about the lookup is stored.

A 404 from the registry is reported as “not registered”, which is what it means, rather than as an error.

Frequently asked questions

Why is the registrant hidden?
Privacy law. Registries stopped publishing personal contact details in 2018, and most now redact them for everyone rather than trying to work out who is in scope.
How do I contact the owner?
Through the registrar’s abuse or contact address, or through the anonymised forwarding address in the record when there is one. That is the route the redaction was designed to leave open.
Is WHOIS dead?
The protocol is on the way out: ICANN has been retiring the requirement to run port 43 in favour of RDAP. The word will outlive the protocol by about a decade.
Can I see the history of a domain?
Not here, and not from the registry: RDAP shows the current record. Historical WHOIS is a commercial service built from archived snapshots.
Why does a .co.uk or .de lookup fail?
Those registries do not publish an RDAP service. Their own WHOIS pages are the only public source, and this tool says so rather than pretending.
Weekly drops

New tools, when there are new tools

One email when something worth using ships. No schedule to fill, so no filler.

Your address goes nowhere else, and one click unsubscribes.