Skip to main content
dns

WHOIS Lookup

WHOIS Lookup helps you domain registration and ownership information, for authoritative DNS validation, resolver checks, and faster troubleshooting.

Enter a domain name or IP address

WHOISREGISTRARGoDaddyCREATED2015ACTIVEEXP: 2027

Advertisement · Anuncio

Advertisement · Anuncio

Technical Analysis & Guide

What It Does

WHOIS Lookup retrieves registration information for a domain name, including registrar, registration dates, expiration date, nameservers, and contact information (if not privacy-protected).

Illustration of dns concept

Why It Matters

  • →Domain Management: Track expiration dates to avoid losing your domain
  • →Verification: Confirm domain ownership and registrar details
  • →Investigation: Research suspicious domains or potential phishing sites
  • →Planning: Check if desired domains are available or when they expire

How to Read Results

  • Registrar: Company where the domain was registered
  • Creation Date: When the domain was first registered
  • Expiration Date: When the domain needs to be renewed
  • Nameservers: DNS servers authoritative for this domain

Technical Background

WHOIS is one of the oldest directory services on the internet. The current protocol, RFC 3912, is almost trivially simple: a client opens TCP port 43, sends a query string followed by CRLF, and the server returns free-form text before closing the connection. There is no authentication, no standard output schema, no character-set negotiation and no way to signal errors except through prose such as 'No match for'. Every registry and registrar formats its response differently, which is why WHOIS parsers rely on heuristics and why fields like the expiration date appear under labels such as 'Registry Expiry Date', 'paid-till' or 'expire'.

Domain data is split between two parties. The registry operates the TLD (for example the .com or .org database) and records the sponsoring registrar, name servers, EPP status codes and key dates. The registrar holds the customer relationship and the contact details. Status codes come from the EPP domain mapping in RFC 5731: clientTransferProhibited is a normal registrar lock, clientHold or serverHold remove the domain from the zone so it stops resolving, and redemptionPeriod or pendingDelete indicate that the name has expired and is on its way to being released. For gTLDs, an expired domain typically passes through an auto-renew grace period of up to 45 days, a 30-day redemption period and a 5-day pending-delete phase; ccTLDs set their own rules.

The Registration Data Access Protocol (RDAP) was designed to replace port 43. It runs over HTTPS and returns structured JSON (RFC 7480, 7481, 9082 and 9083), with an IANA bootstrap registry (RFC 9224) that tells clients which server is authoritative for each TLD, IP block or ASN. RDAP supports internationalized data, standard error codes and differentiated access, so authenticated parties can see more than anonymous users. ICANN made RDAP the definitive source for gTLD registration data and ended the contractual requirement for registries and registrars to run port-43 WHOIS on 28 January 2025, although many servers still answer.

Privacy has reshaped both protocols. Since the EU General Data Protection Regulation took effect in May 2018, registrars redact personal data of registrants by default, replacing names, addresses and emails with 'REDACTED FOR PRIVACY' or a web form or anonymized relay address. Legal entities may still appear, and many ccTLDs apply their own disclosure policies. IP address WHOIS is served by the five RIRs and remains largely public for network holders, including the abuse contact that should receive spam or attack reports.

This tool runs a standard WHOIS client for the domain or IPv4 address you enter, extracts the registrar, creation and expiration dates, name servers and any registrant fields that are not redacted, and shows the raw response below. It warns when the parsed expiration date is less than 30 days away or already in the past, and reports an informational status when the registry says the name is not found.

Common Errors and How to Fix Them

ProblemThe registrant name, email and address all read 'REDACTED FOR PRIVACY' and the lookup is assumed to be broken.
FixThat is GDPR-driven redaction, not an error. To reach the owner, use the registrar's contact form or anonymized email shown in the record; for abuse, write to the registrar abuse contact listed in the same output.
ProblemThe expiration date has moved one year forward even though nobody renewed the domain, so the team assumes it is safe.
FixMany gTLD registries auto-renew at expiry and the registrar can still delete the name during the grace period if the customer does not pay. Confirm the renewal and payment status in the registrar account, not just in WHOIS.
ProblemA query for www.example.com or mail.example.co.uk returns 'No match'.
FixWHOIS knows registrable domains, not hostnames. Query the name directly under the public suffix: example.com or example.co.uk.
ProblemThe domain suddenly stopped resolving and the status shows clientHold.
FixRegistrars apply clientHold for unpaid renewals, abuse complaints or unverified registrant email addresses under ICANN's accuracy rules. Check the registrant mailbox for a verification message and contact the registrar to lift the hold.
ProblemRepeated lookups return empty or truncated output from the registry.
FixPort-43 servers rate-limit aggressively. Wait a few minutes before retrying, or query the RDAP service for the TLD, which is now the authoritative source for gTLD data.
ProblemThe domain was not transferred because the status shows clientTransferProhibited.
FixThat registrar lock is a deliberate anti-hijacking protection. Unlock the domain in the current registrar panel, obtain the authorization (EPP) code, and start the transfer from the new registrar; remember that many TLDs block transfers for 60 days after registration or a previous transfer.

Frequently Asked Questions

What is the difference between WHOIS and RDAP?

WHOIS returns unstructured text over TCP port 43 with no authentication or standard format. RDAP returns structured JSON over HTTPS, supports internationalized data, standard error codes and tiered access, and uses an IANA bootstrap file to find the right server automatically. ICANN made RDAP the authoritative service for gTLD registration data in January 2025, while many ccTLDs still rely on classic WHOIS.

Why is the domain owner's information hidden?

Since GDPR took effect in 2018, registrars redact personal data of registrants by default, and most extend the practice worldwide rather than checking where each customer lives. Organization names and country are sometimes still shown. Legitimate requests for the underlying data, for example in trademark or legal cases, go to the registrar, which evaluates them case by case.

What happens after a domain expires?

For most gTLDs the name first enters an auto-renew grace period of up to 45 days, during which the owner can renew at the normal price, though the website and email may already be suspended. Next comes a 30-day redemption period with a restore fee, followed by five days of pending delete before the name becomes available to anyone. ccTLD timelines vary.

Can I look up an IP address with WHOIS?

Yes. IP WHOIS is served by the Regional Internet Registry responsible for the block, such as ARIN, RIPE NCC or LACNIC. It shows the organization holding the range, the CIDR allocation, sometimes the ASN, and an abuse contact. That abuse address is the right place to report spam, scanning or attacks originating from the IP.

Does the Updated Date mean the domain changed owner?

Not necessarily. The updated date changes whenever anything in the registration is modified: renewing, changing name servers, toggling the transfer lock or editing contacts. To spot an ownership change, compare the registrar name and creation date with an earlier record, and look for a recent transfer status in the history.

Academic Documentation

Protocol context and primary references

REST API Documentation

v1.0
GET /api/tools/whois
					curl -X POST https://epcybertools.com/api/tools/whois \
  -H "Content-Type: application/json" \
  -d '{"domain":"google.com"}'
				
					{
  "success": true,
  "results": [
    { "test": "Sample Check", "status": "pass", "message": "All clear" }
  ]
}
				
Rate Limit: 100 requests / 15 minutes
100-Day Max Lifespan
155d 5h 19m 58s
PQC Migration Target
1178d 5h 19m 58s