What Is WHOIS? A Complete Guide to Domain Registration Lookups
Last Updated: October 2026
Key Takeaways
- ✓ WHOIS is a public database and query protocol that stores registration information for domain names and IP address blocks.
- ✓ A WHOIS lookup reveals the registrar, registration/expiry dates, name servers, domain status codes, and sometimes registrant contact details.
- ✓ GDPR and privacy services now redact personal information from most WHOIS records.
- ✓ RDAP (Registration Data Access Protocol) is the modern, structured replacement for the legacy WHOIS protocol.
- ✓ Five Regional Internet Registries (ARIN, RIPE NCC, APNIC, LACNIC, AfriNIC) manage IP address WHOIS data worldwide.
- ✓ WHOIS is a valuable tool for cybersecurity investigations, domain investment research, and network troubleshooting.
What Is WHOIS?
WHOIS (pronounced "who is") is both a query-response protocol and a public database system used to look up registration information for domain names and IP address blocks. When you register a domain name, your registrar is required to submit certain registration details to a central database. Anyone can query this database using a WHOIS lookup to find out who registered a domain, when it was registered, when it expires, and which name servers it uses.
The WHOIS protocol is defined in RFC 3912. It operates on TCP port 43 and returns plain-text results. Despite its simplicity — and its age — WHOIS remains one of the most widely used tools for domain research, network troubleshooting, and cybersecurity investigations.
WHOIS serves two distinct but related purposes. Domain WHOIS provides registration information for domain names (example.com) and is managed by domain registries and registrars. IP WHOIS provides allocation information for IP address blocks and Autonomous System Numbers (ASNs) and is managed by Regional Internet Registries (RIRs).
History of WHOIS
The WHOIS protocol has its roots in the earliest days of the internet:
- 1970s — ARPANET Origins
- WHOIS began as a simple directory service on ARPANET, the precursor to the modern internet. Elizabeth Feinler at the Network Information Center (NIC) at Stanford Research Institute maintained a text file listing the names and contact information of everyone connected to ARPANET. The WHOIS protocol formalized the ability to query this directory electronically.
- 1982 — RFC 812
- The first formal specification of the NICNAME/WHOIS protocol was published. It described a simple TCP-based protocol for querying the NIC database. At this time, the database contained a few hundred entries.
- 1985 — IANA Takes Over
- The Internet Assigned Numbers Authority (IANA) assumed responsibility for coordinating the domain name system and IP address allocation, inheriting the WHOIS database management role.
- 1998 — ICANN Established
- The Internet Corporation for Assigned Names and Numbers (ICANN) was created to oversee the domain name system. ICANN required registrars to collect and publish WHOIS data for all gTLD domain registrations, establishing the system we know today.
- 2004 — RFC 3912
- The current WHOIS protocol specification was published, updating and simplifying the earlier RFC 954. It defines the protocol as a simple TCP transaction: the client sends a query, the server responds with text, and the connection closes.
- 2018 — GDPR Impact
- The European Union's General Data Protection Regulation transformed WHOIS by requiring registrars to redact personal data from public WHOIS records for EU-based registrants. Many registrars extended this privacy protection globally, fundamentally changing the amount of data available through WHOIS.
- 2019–Present — RDAP Adoption
- ICANN mandated that all gTLD registries and registrars implement RDAP (Registration Data Access Protocol) as the successor to WHOIS. RDAP provides structured JSON responses, standardized data formats, and built-in support for differentiated access policies.
What Information Does WHOIS Reveal?
A WHOIS lookup for a domain name typically returns the following information (subject to privacy redaction):
- Registrar
- The ICANN-accredited registrar through which the domain was registered (e.g., GoDaddy, Namecheap, Cloudflare Registrar, Google Domains). The registrar manages the domain on behalf of the registrant.
- Registration Date (Created)
- The date the domain was first registered. Older registration dates generally indicate more established, trustworthy domains. A domain registered yesterday promoting a major brand is a strong phishing indicator.
- Expiry Date
- The date the domain registration expires. If not renewed before this date, the domain enters a grace period, then a redemption period, and eventually becomes available for re-registration.
- Updated Date
- The date the WHOIS record was last modified. This changes when the registrant updates contact information, changes name servers, renews the domain, or modifies any registration detail.
- Name Servers
- The authoritative DNS servers for the domain. These servers contain the DNS records (A, MX, CNAME, etc.) that control where the domain's traffic is directed. Common name servers include those from hosting providers (ns1.example-host.com), DNS providers (ns1.cloudflare.com), and registrars.
- Domain Status Codes
- EPP (Extensible Provisioning Protocol) status codes that indicate the current state and restrictions on the domain. These are discussed in detail below.
- Registrant Contact
- The person or organization that registered the domain. Under GDPR and with privacy services, this often shows "REDACTED FOR PRIVACY" or the privacy proxy's contact information instead of the actual registrant's details.
- Administrative and Technical Contacts
- Contacts responsible for administrative and technical management of the domain. These are also typically redacted when privacy protection is enabled.
- DNSSEC Status
- Indicates whether the domain has DNS Security Extensions enabled, which protects against DNS spoofing and cache poisoning attacks by digitally signing DNS records.
How to Perform a WHOIS Lookup
There are several ways to perform a WHOIS lookup:
Using Our Online Tool
The easiest method is to use our IP WHOIS Lookup tool. Enter a domain name or IP address and get formatted results instantly, with no software to install. The tool parses the raw WHOIS data into a readable format and highlights key fields like expiry date, registrar, and status codes.
Command-Line WHOIS
Most Unix-like operating systems (Linux, macOS) include a built-in whois command:
whois example.com— Queries the WHOIS database for domain registration information.whois 8.8.8.8— Queries the IP WHOIS database to find the organization that owns the IP block.whois -h whois.verisign-grs.com example.com— Queries a specific WHOIS server directly.
On Windows, there is no built-in WHOIS command, but you can use Microsoft's Sysinternals whois.exe tool or install it via a package manager like Chocolatey (choco install whois).
Web-Based WHOIS Services
ICANN provides an official WHOIS lookup at lookup.icann.org. Individual registries and registrars also provide WHOIS lookup pages. These web-based tools typically format the results more readably than raw command-line output.
WHOIS Privacy and Proxy Services
When you register a domain, ICANN historically required your name, email, phone number, and physical address to be published in the WHOIS database. This raised significant privacy concerns:
- Spam: Email addresses in WHOIS records are harvested by spammers, leading to massive volumes of unsolicited email.
- Harassment: Domain owners of controversial websites can be targeted using their published contact details.
- Identity theft: Personal details in WHOIS records can be used for social engineering attacks.
- Competitive intelligence: Competitors can discover domain acquisitions before they are publicly announced.
Privacy/Proxy Services
Most registrars offer WHOIS privacy protection (sometimes free, sometimes as a paid add-on) that replaces the registrant's personal information with the privacy service's contact details. The registrant retains full control of the domain; only the public WHOIS data is masked. Legitimate inquiries (law enforcement, intellectual property disputes) can still reach the registrant through the privacy service.
GDPR Impact
The EU's General Data Protection Regulation (GDPR), effective May 2018, fundamentally changed WHOIS. Under GDPR, personal data of EU residents cannot be published without a lawful basis. ICANN developed a "Temporary Specification for gTLD Registration Data" that allows registrars to redact registrant personal data from public WHOIS while maintaining it internally. Most registrars now redact personal data for all registrants worldwide, not just EU residents, as a practical compliance measure. The result is that modern WHOIS records typically show "REDACTED FOR PRIVACY" for name, email, phone, and address fields.
Domain Status Codes Explained
Domain status codes (EPP status codes) appear in WHOIS results and indicate what actions are allowed or prohibited on a domain. There are client-side codes (set by the registrar) and server-side codes (set by the registry):
Common Client-Side Status Codes
- clientTransferProhibited
- The registrar has locked the domain to prevent unauthorized transfers to a different registrar. This is the most common lock and is recommended for all domains. The registrant must explicitly request the registrar to remove this lock before initiating a transfer.
- clientDeleteProhibited
- Prevents the registrar from deleting the domain. Used to protect valuable domains from accidental or unauthorized deletion.
- clientUpdateProhibited
- Prevents changes to the domain's registration data (name servers, contacts, DNSSEC keys) through the registrar. This is part of the "registrar lock" feature.
- clientHold
- The registrar has suspended the domain, removing it from the DNS. The domain will not resolve. This may be applied for non-payment, abuse complaints, or legal disputes.
Common Server-Side Status Codes
- serverTransferProhibited
- Set by the registry to prevent domain transfers. Applied during dispute resolution (UDRP proceedings), within 60 days of registration or transfer, or at the request of law enforcement.
- serverHold
- The registry has suspended the domain. Like clientHold, the domain will not resolve. This is more serious because only the registry (not the registrar) can remove it.
- redemptionPeriod
- The domain has been deleted by the registrar and is in a 30-day redemption period. During this time, the original registrant can restore the domain (usually for a fee higher than normal renewal). The domain does not resolve during this period.
- pendingDelete
- The redemption period has ended and the domain is scheduled for deletion and release. This typically lasts 5 days, after which the domain becomes available for new registration on a first-come, first-served basis.
- ok
- No restrictions on the domain. It is active and can be transferred, updated, or deleted. This is the default state for a domain without any locks applied.
The 5 Regional Internet Registries (RIRs)
IP address WHOIS data is managed by five Regional Internet Registries, each responsible for allocating IP address blocks and ASNs within their geographic region:
- ARIN — American Registry for Internet Numbers
- Covers the United States, Canada, and parts of the Caribbean. ARIN's WHOIS database is queried at whois.arin.net and provides detailed information about IP address allocations to ISPs, corporations, and government agencies in North America.
- RIPE NCC — Réseaux IP Européens Network Coordination Centre
- Covers Europe, the Middle East, and parts of Central Asia. RIPE NCC operates the most comprehensive IP WHOIS database, including detailed abuse contact information. Queried at whois.ripe.net.
- APNIC — Asia-Pacific Network Information Centre
- Covers the Asia-Pacific region including East Asia, South Asia, Southeast Asia, and Oceania. Queried at whois.apnic.net.
- LACNIC — Latin America and Caribbean Network Information Centre
- Covers Latin America and the Caribbean. Based in Montevideo, Uruguay. Queried at whois.lacnic.net.
- AfriNIC — African Network Information Centre
- Covers the entire African continent. Based in Ebene, Mauritius. Queried at whois.afrinic.net. AfriNIC is the newest of the five RIRs, established in 2004.
RDAP: The Modern Successor to WHOIS
RDAP (Registration Data Access Protocol) was developed to address the many limitations of the aging WHOIS protocol. RDAP is defined in RFCs 7480–7484 and represents a fundamental modernization of registration data access:
- Structured data: RDAP returns JSON instead of plain text, making it machine-parseable. Every WHOIS implementation formats data slightly differently; RDAP provides standardized field names and structures.
- Internationalization: RDAP supports Unicode natively, properly handling non-ASCII characters in registrant names, organization names, and addresses that WHOIS often garbled.
- Differentiated access: RDAP supports authentication and authorization, allowing registries to provide more detailed data to verified users (law enforcement, intellectual property investigators) while showing redacted data to the general public.
- Standardized error responses: RDAP defines proper HTTP status codes and error objects, unlike WHOIS which returns free-form text error messages.
- Bootstrapping: RDAP includes a standardized mechanism for automatically finding the correct server for any query, whereas WHOIS required hard-coded server lists or chaining between referral servers.
- HTTPS-based: RDAP uses HTTPS, providing encrypted, authenticated communication. WHOIS operates over unencrypted TCP on port 43.
ICANN has required all gTLD registries and registrars to implement RDAP since August 2019. While WHOIS remains widely available, RDAP is the recommended method for programmatic access to registration data.
Using WHOIS for Cybersecurity
WHOIS data is an essential tool in cybersecurity investigations. Security analysts use WHOIS to:
Investigating Phishing Domains
When a suspected phishing URL is reported, analysts check the WHOIS record for red flags: a very recent registration date (phishing domains are typically registered hours or days before an attack), use of free or cheap registrars with lax abuse policies, registration details that do not match the impersonated organization, and name servers associated with known malicious infrastructure or bulletproof hosting providers.
Finding Abuse Contacts
WHOIS records include abuse contact information for the registrar and hosting provider. When a domain is involved in spam, malware distribution, or phishing, security teams contact these abuse desks to request takedown. The abuse contact email is one of the few fields consistently available even in post-GDPR WHOIS records.
Threat Intelligence and Attribution
By analyzing WHOIS data across multiple malicious domains, analysts can identify patterns: shared registrant information, common name servers, registration through the same registrar on the same date, or similar registration patterns. This helps attribute campaigns to specific threat actors and discover related infrastructure.
Historical WHOIS Data
Services like DomainTools and SecurityTrails archive historical WHOIS records, allowing analysts to see past ownership, name server changes, and registration details even after privacy was enabled. This is valuable for tracking infrastructure changes over time and connecting domains that were later anonymized.
WHOIS for Domain Investors
Domain investors (sometimes called "domainers") use WHOIS data extensively in their business:
- Expiry date monitoring: Track domains approaching expiry to acquire them through drop catching services or expired domain auction platforms. Valuable domains that are not renewed become available for re-registration.
- Registration age assessment: Older domains are generally more valuable for SEO purposes. A domain registered in 1998 carries more authority than one registered last month.
- Ownership research: Before making an offer on a domain, investors research the registrant to understand whether the domain is actively used, parked, or abandoned.
- Portfolio management: Domain investors use WHOIS monitoring to track their own portfolio expiry dates and ensure renewals are processed on time.
- Dispute research: When considering a domain for purchase, investors check for trademark conflicts by reviewing the registrant history and any past UDRP proceedings.
Frequently Asked Questions
What is a WHOIS lookup?
A WHOIS lookup is a query to a public database that stores registration information for domain names and IP address blocks. It reveals the registrar, registration and expiry dates, name servers, domain status codes, and sometimes registrant contact details.
Is WHOIS information public?
Historically, all WHOIS data was fully public. Since GDPR took effect in 2018, registrars redact personal information for registrants, and many registrars apply similar privacy protections globally. Technical data like name servers, status codes, and dates typically remains visible.
What is the difference between WHOIS and RDAP?
WHOIS is the legacy protocol (RFC 3912) returning unstructured plain text. RDAP is its modern replacement, returning structured JSON with standardized fields, internationalization support, and built-in access control. RDAP is now mandatory for all gTLD registries and registrars.
How do I find out who owns a domain name?
Perform a WHOIS lookup using our IP WHOIS Lookup tool, the command-line whois tool, or a web-based service. If the registrant has enabled privacy, personal details will be replaced with the privacy service's contact information, but you can still see the registrar, dates, and name servers.
What do domain status codes mean?
Domain status codes indicate the current state of a domain. Common codes include clientTransferProhibited (registrar lock preventing transfers), serverHold (suspended by registry), redemptionPeriod (recently deleted, restorable for a fee), pendingDelete (will be released soon), and ok (no restrictions).
What are the 5 Regional Internet Registries?
The five RIRs are ARIN (North America), RIPE NCC (Europe, Middle East, Central Asia), APNIC (Asia-Pacific), LACNIC (Latin America and Caribbean), and AfriNIC (Africa). Each manages IP address and ASN allocation within its region.
Can WHOIS help identify phishing or scam websites?
Yes. WHOIS data can reveal suspicious indicators such as a very recent registration date, use of certain registrars, discrepancies with the claimed organization, and name servers associated with known malicious infrastructure.
What is WHOIS privacy protection?
WHOIS privacy replaces the registrant's personal contact information in the WHOIS database with the privacy service's details. This protects the domain owner from spam, harassment, and identity theft while maintaining a valid contact path for legitimate inquiries.