Look up the public registration record for any domain. See the registrar,
owner details, nameservers, creation date, expiry, and status codes —
paired with DNS lookup
for the full picture.
Domain lookup
Quick facts
Domain age--
Expires in--
Registrar--
Privacy guard--
Nameservers--
Domain status--
Recent lookups
No lookups yet this session
Enter a domain to begin
Type any domain name in the search box and click Look up WHOIS.
The registration record will appear here as a structured dossier.
Try:
Querying WHOIS database…
--
Registration record · queried via RDAP
Registration
Created
--
Updated
--
Expires
--
Registrar
--
Registrant
Registrant
--
Organisation
--
Email
--
Phone
--
Nameservers
Could not retrieve WHOIS data
This may be a private TLD, a domain that does not exist,
or a temporary network issue. Please check the domain and try again.
What a WHOIS record reveals
Registrant identity
The name, organization, and contact details of whoever registered the domain — unless hidden behind a privacy/proxy service.
Registration timeline
Exactly when the domain was first created, last updated, and when it's due to expire — useful for spotting brand-new domains used in phishing.
Nameservers & registrar
Which registrar the domain is parked at and which nameservers actually resolve it — often reveals the hosting provider or CDN behind a site.
Domain status codes explained
clientTransferProhibited
The registrar has locked the domain against unauthorized transfers to another registrar.
clientDeleteProhibited
The domain cannot be deleted without first removing this status — a common anti-hijacking safeguard.
clientUpdateProhibited
Registration details are locked and cannot be changed until this status is removed.
clientHold
The domain has been suspended by the registrar and will not resolve — often due to a policy or payment issue.
pendingTransfer
A transfer to a new registrar has been initiated and is awaiting completion.
redemptionPeriod
The domain has expired and entered a grace period before it becomes available for anyone to register.
Privacy implications of WHOIS
WHOIS privacy/proxy services
Most registrars offer a free or paid privacy service that replaces your real name and address with the registrar's own proxy contact details in public WHOIS output.
GDPR redaction
Since 2018, ICANN requires registrars to redact registrant personal data for domains registered by individuals in the EU/EEA, regardless of whether a paid privacy add-on was purchased.
What stays visible regardless
The registrar name, creation/expiry dates, nameservers, and domain status codes remain public even with privacy protection enabled — only personal contact fields are hidden.
Why this matters for research
Investigators and abuse teams often rely on historical WHOIS records, from before privacy redaction became the default, to trace domains used in scams back to a registrant pattern.
RDAP, ccTLDs, and other WHOIS edge cases
WHOIS is being replaced by RDAP
Legacy WHOIS has no standardized output format — every registry can return
differently structured plain text, which is why "raw WHOIS output" tools
typically just dump a text blob. RDAP (Registration Data Access Protocol) is
ICANN's structured, JSON-based successor
with a defined schema across
registries, and gTLD registries and registrars have been required to support
it. This tool queries RDAP first for reliable structured data and falls back
to legacy WHOIS text only where a registry hasn't migrated — which is also why
the dossier above is labelled "queried via RDAP" even though the page is
called WHOIS Lookup, the term most people still search for.
ccTLD registries set their own privacy rules
Country-code domains (.de, .ca, .io, .eu, and others) aren't governed by
ICANN's gTLD policy — each national registry decides independently what to
publish. Germany's .de registry, DENIC, has never published registrant
personal data in public WHOIS at all, a policy that predates GDPR by years.
This is why a ccTLD lookup can look structurally sparser or differently
organized than a .com lookup from the exact same tool — it's a genuine policy
difference, not a data gap on our end.
Registrar lock and privacy guard are different protections
These get conflated often but solve different problems. A registrar lock
(the clientTransferProhibited-style status codes) prevents the domain from
being transferred to another registrar without authorization — it protects
against hijacking. WHOIS privacy/proxy protection hides your contact details
from public view — it protects against exposure. A domain can have either,
both, or neither; having one enabled says nothing about whether the other is
also active.
Historical WHOIS still exists even after redaction
GDPR-driven redaction changed what's visible in a live lookup going forward,
but it didn't retroactively erase WHOIS records captured before the policy
took effect. Commercial historical-WHOIS archives that crawled and stored
records pre-redaction still hold that older, unredacted data — which is a
detail investigators and abuse-response teams rely on, and one that's easy to
forget when assuming "privacy protection" means a domain's history was always
hidden.
Frequently asked questions
“The dossier says "queried via RDAP" — is that the same as WHOIS?”
They're related but not identical. WHOIS is the original 1980s-era protocol for domain registration lookups, with no standardized data format — every registry could return slightly different, unstructured text. RDAP (Registration Data Access Protocol) is ICANN's modern replacement, returning structured, machine-readable JSON with a defined schema. ICANN has been requiring gTLD registries and registrars to support RDAP alongside legacy WHOIS, with RDAP increasingly becoming the primary lookup method — this tool queries RDAP first for structured, reliable data and falls back to traditional WHOIS text for registries that haven't migrated.
“Can I hide my identity from WHOIS lookups?”
Yes, for most domains — nearly all registrars offer a privacy/proxy service (often free) that substitutes their own proxy contact details for your real name, address, phone, and email in the public record. For registrants in the EU/EEA, ICANN policy requires this redaction by default since 2018, whether or not you specifically opted into a paid privacy product. What privacy protection does not hide is the registrar name, nameservers, creation/expiry dates, or domain status codes — those remain public regardless.
“Does WHOIS privacy protection cost extra?”
It depends entirely on the registrar. Many major registrars (Cloudflare, Namecheap, and others) now include WHOIS privacy free with every domain registration. Some older or budget registrars still charge a separate annual fee for it — worth checking before assuming it's automatically included, since a domain with privacy protection off by default is a common and avoidable exposure.
“Why do some domains show no registrant info at all, even without obvious privacy protection?”
A few possibilities: the domain may be registered under a corporate or institutional registrant that's a business entity rather than a person, so there's no individual data to redact in the first place; the TLD's registry may have its own policy of never publishing registrant contact data (several ccTLD registries operate this way by default — see the ccTLD section below); or the lookup may have hit a rate limit or partial response from the registry's RDAP/WHOIS server.
“Can WHOIS data be used to steal or hijack a domain?”
Not directly by reading it, but it can support a hijacking attempt. Publicly visible registrant contact details have historically been used in social-engineering attacks against registrars or registrant email accounts, and knowing the exact registrar lets an attacker target that registrar's specific support process. This is one of several reasons registrar locks (clientTransferProhibited and related status codes) and two-factor authentication on your registrar account matter — they defend against the account-takeover angle, since the raw WHOIS data itself has no mechanism to transfer a domain on its own. See our DNS Lookup tool's hijacking FAQ for how a compromised registrar account translates into an actual DNS-level attack.
“Is a newly registered domain automatically suspicious?”
Newly registered domains are statistically overrepresented in phishing and scam campaigns — attackers frequently register a fresh domain, use it briefly, and abandon it, since domain-reputation and blocklist systems need time to catch up to a new registration. That makes registration age a useful risk *signal*, not proof of malicious intent — plenty of legitimate businesses, product launches, and personal projects also register brand-new domains. Treat a domain registered days ago as a reason for more scrutiny, not an automatic red flag on its own.
“Why do .de or other ccTLD domains show different fields than .com?”
Country-code top-level domains (ccTLDs like .de, .ca, .io, .eu) are governed by their own national or territorial registry, not by ICANN's gTLD policy — each sets its own rules about what WHOIS/RDAP data it publishes. Germany's .de registry (DENIC), for example, has never published registrant personal data in public WHOIS by policy, well before GDPR existed. This is why a ccTLD lookup can look structurally different, or noticeably sparser, than a .com or .org lookup from the same tool.
“Can I request my WHOIS data be removed or corrected?”
Corrections go through your registrar, since they're the ones submitting the data to the registry — most registrar control panels let you edit registrant contact details directly, and the change propagates to WHOIS/RDAP typically within a day. Full removal isn't optional if you're the registrant of record without privacy protection enabled — ICANN requires accurate registrant data to exist somewhere in the system — but enabling your registrar's privacy/proxy service is the standard way to stop that data from being publicly visible while keeping the domain valid.
Community
Get the next leak test before it's news
Tool releases and research notes, sent when there's something worth reading. Nothing else.