WHOIS Lookup

Look up the public registration record for any domain. See the registrar, owner details, nameservers, creation date, expiry, and status codes — paired with DNS lookup for the full picture.

Domain lookup
Quick facts
Domain age --
Expires in --
Registrar --
Privacy guard --
Nameservers --
Domain status --
Recent lookups
No lookups yet this session
Enter a domain to begin
Type any domain name in the search box and click Look up WHOIS. The registration record will appear here as a structured dossier.
Try:

Registrant identity

The name, organization, and contact details of whoever registered the domain — unless hidden behind a privacy/proxy service.

Registration timeline

Exactly when the domain was first created, last updated, and when it's due to expire — useful for spotting brand-new domains used in phishing.

Nameservers & registrar

Which registrar the domain is parked at and which nameservers actually resolve it — often reveals the hosting provider or CDN behind a site.

Domain status codes explained

clientTransferProhibited
The registrar has locked the domain against unauthorized transfers to another registrar.
clientDeleteProhibited
The domain cannot be deleted without first removing this status — a common anti-hijacking safeguard.
clientUpdateProhibited
Registration details are locked and cannot be changed until this status is removed.
clientHold
The domain has been suspended by the registrar and will not resolve — often due to a policy or payment issue.
pendingTransfer
A transfer to a new registrar has been initiated and is awaiting completion.
redemptionPeriod
The domain has expired and entered a grace period before it becomes available for anyone to register.

WHOIS privacy/proxy services

Most registrars offer a free or paid privacy service that replaces your real name and address with the registrar's own proxy contact details in public WHOIS output.

GDPR redaction

Since 2018, ICANN requires registrars to redact registrant personal data for domains registered by individuals in the EU/EEA, regardless of whether a paid privacy add-on was purchased.

What stays visible regardless

The registrar name, creation/expiry dates, nameservers, and domain status codes remain public even with privacy protection enabled — only personal contact fields are hidden.

Why this matters for research

Investigators and abuse teams often rely on historical WHOIS records, from before privacy redaction became the default, to trace domains used in scams back to a registrant pattern.

WHOIS is being replaced by RDAP

Legacy WHOIS has no standardized output format — every registry can return differently structured plain text, which is why "raw WHOIS output" tools typically just dump a text blob. RDAP (Registration Data Access Protocol) is ICANN's structured, JSON-based successor with a defined schema across registries, and gTLD registries and registrars have been required to support it. This tool queries RDAP first for reliable structured data and falls back to legacy WHOIS text only where a registry hasn't migrated — which is also why the dossier above is labelled "queried via RDAP" even though the page is called WHOIS Lookup, the term most people still search for.

ccTLD registries set their own privacy rules

Country-code domains (.de, .ca, .io, .eu, and others) aren't governed by ICANN's gTLD policy — each national registry decides independently what to publish. Germany's .de registry, DENIC, has never published registrant personal data in public WHOIS at all, a policy that predates GDPR by years. This is why a ccTLD lookup can look structurally sparser or differently organized than a .com lookup from the exact same tool — it's a genuine policy difference, not a data gap on our end.

Registrar lock and privacy guard are different protections

These get conflated often but solve different problems. A registrar lock (the clientTransferProhibited-style status codes) prevents the domain from being transferred to another registrar without authorization — it protects against hijacking. WHOIS privacy/proxy protection hides your contact details from public view — it protects against exposure. A domain can have either, both, or neither; having one enabled says nothing about whether the other is also active.

Historical WHOIS still exists even after redaction

GDPR-driven redaction changed what's visible in a live lookup going forward, but it didn't retroactively erase WHOIS records captured before the policy took effect. Commercial historical-WHOIS archives that crawled and stored records pre-redaction still hold that older, unredacted data — which is a detail investigators and abuse-response teams rely on, and one that's easy to forget when assuming "privacy protection" means a domain's history was always hidden.

“The dossier says "queried via RDAP" — is that the same as WHOIS?”
They're related but not identical. WHOIS is the original 1980s-era protocol for domain registration lookups, with no standardized data format — every registry could return slightly different, unstructured text. RDAP (Registration Data Access Protocol) is ICANN's modern replacement, returning structured, machine-readable JSON with a defined schema. ICANN has been requiring gTLD registries and registrars to support RDAP alongside legacy WHOIS, with RDAP increasingly becoming the primary lookup method — this tool queries RDAP first for structured, reliable data and falls back to traditional WHOIS text for registries that haven't migrated.
“Can I hide my identity from WHOIS lookups?”
Yes, for most domains — nearly all registrars offer a privacy/proxy service (often free) that substitutes their own proxy contact details for your real name, address, phone, and email in the public record. For registrants in the EU/EEA, ICANN policy requires this redaction by default since 2018, whether or not you specifically opted into a paid privacy product. What privacy protection does not hide is the registrar name, nameservers, creation/expiry dates, or domain status codes — those remain public regardless.
“Does WHOIS privacy protection cost extra?”
It depends entirely on the registrar. Many major registrars (Cloudflare, Namecheap, and others) now include WHOIS privacy free with every domain registration. Some older or budget registrars still charge a separate annual fee for it — worth checking before assuming it's automatically included, since a domain with privacy protection off by default is a common and avoidable exposure.
“Why do some domains show no registrant info at all, even without obvious privacy protection?”
A few possibilities: the domain may be registered under a corporate or institutional registrant that's a business entity rather than a person, so there's no individual data to redact in the first place; the TLD's registry may have its own policy of never publishing registrant contact data (several ccTLD registries operate this way by default — see the ccTLD section below); or the lookup may have hit a rate limit or partial response from the registry's RDAP/WHOIS server.
“Can WHOIS data be used to steal or hijack a domain?”
Not directly by reading it, but it can support a hijacking attempt. Publicly visible registrant contact details have historically been used in social-engineering attacks against registrars or registrant email accounts, and knowing the exact registrar lets an attacker target that registrar's specific support process. This is one of several reasons registrar locks (clientTransferProhibited and related status codes) and two-factor authentication on your registrar account matter — they defend against the account-takeover angle, since the raw WHOIS data itself has no mechanism to transfer a domain on its own. See our DNS Lookup tool's hijacking FAQ for how a compromised registrar account translates into an actual DNS-level attack.
“Is a newly registered domain automatically suspicious?”
Newly registered domains are statistically overrepresented in phishing and scam campaigns — attackers frequently register a fresh domain, use it briefly, and abandon it, since domain-reputation and blocklist systems need time to catch up to a new registration. That makes registration age a useful risk *signal*, not proof of malicious intent — plenty of legitimate businesses, product launches, and personal projects also register brand-new domains. Treat a domain registered days ago as a reason for more scrutiny, not an automatic red flag on its own.
“Why do .de or other ccTLD domains show different fields than .com?”
Country-code top-level domains (ccTLDs like .de, .ca, .io, .eu) are governed by their own national or territorial registry, not by ICANN's gTLD policy — each sets its own rules about what WHOIS/RDAP data it publishes. Germany's .de registry (DENIC), for example, has never published registrant personal data in public WHOIS by policy, well before GDPR existed. This is why a ccTLD lookup can look structurally different, or noticeably sparser, than a .com or .org lookup from the same tool.
“Can I request my WHOIS data be removed or corrected?”
Corrections go through your registrar, since they're the ones submitting the data to the registry — most registrar control panels let you edit registrant contact details directly, and the change propagates to WHOIS/RDAP typically within a day. Full removal isn't optional if you're the registrant of record without privacy protection enabled — ICANN requires accurate registrant data to exist somewhere in the system — but enabling your registrar's privacy/proxy service is the standard way to stop that data from being publicly visible while keeping the domain valid.

Community

Get the next leak test before it's news

Tool releases and research notes, sent when there's something worth reading. Nothing else.

At least 10 characters.