Ad blocker detected

We serve ads so we can keep our website running. Please disable your ad blockers.

I've disabled the ad blocker

Whois Lookup

Be the first to rate this tool
Processed instantly and never stored — we keep no copy of your input.

What is a WHOIS Lookup?

A WHOIS lookup retrieves the registration record for a domain name: who registered it, when it was registered, when it expires, which registrar manages it, and which name servers it uses. "WHOIS" (pronounced "who is") is both the name of this public directory data and the decades-old query protocol used to fetch it. Every time someone registers a .com, .org, .net, or country-code domain, the registrar records these details, and much of that record has historically been public by design — a transparency mechanism that lets anyone verify who stands behind a domain.

The most immediately useful fields are the dates. Creation date tells you how old the domain is — a domain registered ten years ago carries very different trust signals than one registered ten days ago, a fact that matters enormously when evaluating an unfamiliar online store or investigating a phishing link. Expiry date tells you when the current registration lapses; letting a domain expire is one of the most embarrassing and expensive mistakes a business can make, and high-value domains have been lost — then ransomed back — exactly this way. The registrar field identifies the company managing the registration (GoDaddy, Namecheap, Cloudflare, and hundreds of others), and the name server fields show where the domain's DNS is hosted.

WHOIS also carries domain status codes — terse EPP codes like clientTransferProhibited or serverHold that describe locks and holds on the domain. These codes matter during purchases, transfers, and disputes: a domain with clientTransferProhibited set cannot be transferred away until the owner removes the lock, which is normal security practice, while serverHold or clientHold means the registry has deactivated the domain in DNS — often over a legal dispute, abuse complaint, or billing failure.

One honest caveat shapes everything about WHOIS today: since the EU's GDPR took effect in 2018, registrars redact the personal contact details (name, email, phone, address) of most registrants. What you will typically see now is "redacted for privacy" or the registrar's privacy-proxy contact instead of the owner's real details. This killed the old use case of looking up a stranger's email address, but the dates, registrar, name servers, and status codes remain public and remain extremely useful. For IP addresses rather than domains, the parallel system is the regional internet registries' WHOIS (ARIN, RIPE, APNIC), which still publishes organization-level contact data — see our IP lookup tool for that side of the story.

Our free WHOIS lookup queries the appropriate registry and registrar WHOIS servers and presents the full record in a readable format: dates, registrar, name servers, status codes, and DNSSEC state. Your queries are processed instantly and never stored. It is the natural companion to our DNS lookup (what the domain points to) and our SSL lookup (whether its certificate is valid) — together, the three answer "who owns it, where does it go, and is it secure?"

How to Use the WHOIS Lookup Tool

Reading any domain's registration record takes seconds:

  1. Enter the domain name. Type the domain into the input field — example.com without https:// or paths. The tool supports generic TLDs (.com, .net, .org, .io) and most country-code TLDs.
  2. Run the lookup. Click the lookup button. The tool queries the registry WHOIS server for the TLD, follows any referral to the registrar's WHOIS server, and assembles the complete record — usually within a few seconds.
  3. Check the dates first. Note the creation date (domain age), the last-updated date (recent changes can signal a transfer or an ownership change), and the expiry date. If you own the domain, an expiry within 60 days means renew now; registrars typically allow renewal years in advance, and auto-renew exists for a reason.
  4. Review registrar and name servers. Confirm the registrar is who you expect — an unexpected registrar on your own domain is a takeover red flag. The name servers should match your DNS provider; a mismatch means someone changed where the domain resolves.
  5. Read the status codes. clientTransferProhibited is a healthy lock. serverHold, clientHold, serverDeleteProhibited in unusual combinations, or a pendingDelete/redemptionPeriod status each tell a specific story — the FAQ below decodes the common ones.
  6. Investigate further if needed. Cross-reference with our DNS lookup to see the domain's live records and our SSL lookup to check its certificate. For a domain you are thinking of buying, the age and history visible here are essential due diligence.

Key Features of the WHOIS Lookup

Registry + registrar records combined. For gTLDs, the tool queries both the thin registry record (dates, name servers, status) and the registrar's fuller record, merging them into one complete view instead of making you run two lookups.

Full date history. Creation, last-updated, and expiry dates are parsed and displayed prominently, with expiry highlighted when it approaches — because an expiring domain is the highest-stakes finding this tool produces.

Status code decoding. Raw EPP status codes are shown alongside plain-English explanations, so clientRenewProhibited or serverTransferProhibited actually mean something to non-specialists.

Registrar and reseller identification. See exactly which registrar holds the domain — critical when you need to initiate a transfer, file an abuse complaint, or recover a hijacked domain and must know who to contact.

DNSSEC visibility. The record shows whether DNSSEC is configured (look for DS records / signedDelegation status), telling you whether the domain's DNS answers are cryptographically protected against spoofing.

Private by design. No account, no signup. Your lookups are processed instantly and never stored or logged.

Status codeSet byWhat it means
clientTransferProhibitedRegistrar (at owner's request)Normal security lock — domain cannot be transferred away. Expected on any well-managed domain.
clientUpdateProhibited / clientDeleteProhibitedRegistrarExtra locks against unauthorized changes or deletion. Common on valuable domains.
serverHold / clientHoldRegistry / registrarDomain deactivated in DNS — it will not resolve. Often legal, abuse, or billing issues.
pendingDeleteRegistryPast redemption; deletion imminent. The 5-day final stage before the name is released.
redemptionPeriodRegistryExpired and in the ~30-day grace window where the original owner can still recover it (for a fee).
ok / active—No locks or holds. Normal for a freshly registered, unlocked domain — but also means it can be transferred immediately if credentials leak.

WHOIS Lookup Use Cases

Developers and IT administrators

The problem: Your company owns 60 domains across three registrars, bought over a decade by different people. Renewal notices go to a former employee's email. One Friday, the marketing site goes dark: a domain expired.

How this tool helps: Audit every domain you are responsible for with a WHOIS lookup: confirm the expiry dates, verify the registrar listed is the one you actually use, and check that transfer locks are on. Build the findings into a spreadsheet with renewal reminders set 60 and 30 days out — and enable auto-renew everywhere. Ten minutes of WHOIS auditing prevents the most preventable outage in IT.

SEO specialists and domain investors

The problem: You are evaluating an expired or aftermarket domain for a new project. Sellers claim "aged domain, clean history" — but age alone means little if the domain spent years hosting spam, and a domain dropped and re-registered last month is not "aged" at all.

How this tool helps: The creation date reveals the true registration history (a recent creation date on a supposedly "10-year-old" domain means it was dropped and re-registered, resetting its history). The last-updated date can hint at recent transfers. Combined with archive and backlink research, WHOIS dates are the foundation of domain due diligence — never pay a premium for age without verifying it here first.

Security researchers and cautious consumers

The problem: You received a link to an unfamiliar store with a too-good-to-be-true deal, or a security alert references a suspicious domain. The padlock is present, the site looks professional — but something feels off.

How this tool helps: Look up the domain: a creation date of last week for a site claiming "20 years in business" is a blazing red flag. Check whether the name servers and registrar look legitimate versus bulletproof-hosting patterns, and note privacy-redacted contacts (normal for legitimate small sites, but combined with a days-old domain, suspicious). WHOIS will not prove a site is a scam, but domain age is one of the most reliable single signals investigators use — pair it with our SSL lookup to check whether the certificate is equally fresh.

How to Read a WHOIS Record, Field by Field

A raw WHOIS record is a wall of labeled lines. Here is what each section actually tells you, in the order you will usually encounter it.

Domain name and registry domain ID. The exact registered name and the registry's internal identifier. Check the spelling character by character when investigating suspicious domains — homograph attacks use lookalike characters (Cyrillic "а" for Latin "a") that are invisible at a glance but obvious in the raw record.

Registrar and IANA ID. The company managing the registration, plus its ICANN-assigned numeric ID. This is who you contact for transfers, disputes, and abuse reports about the registration itself (as opposed to content hosted on the domain, which is the host's problem). The registrar URL and abuse contact usually appear nearby.

Creation, updated, and expiry dates. The three dates that matter most. Creation date establishes domain age — the single most useful trust signal in the record. The updated date's most recent change often corresponds to a transfer, a contact update, or a renewal; a very recent updated date on an old domain can indicate it just changed hands. Expiry date drives renewal planning: professionals set reminders at 60 and 30 days and enable auto-renew, because the grace-period economics (redemption fees of $100–$250) punish procrastination severely.

Name servers. Where the domain's DNS is delegated. These should match your DNS provider's name servers exactly. Unexpected name servers on your own domain mean the delegation was changed — investigate immediately, because whoever controls DNS controls the domain's traffic and email. When evaluating someone else's domain, the name servers reveal their infrastructure choices (Cloudflare, Route 53, a budget host's defaults).

Domain status codes. The EPP codes covered in the table above. Read them as the domain's current legal/technical state: locks (clientTransferProhibited) are healthy, holds (serverHold, clientHold) mean deactivation, and pendingDelete / redemptionPeriod mean the name is in the expiry pipeline. During a purchase, the status must be clear of transfer prohibitions before money changes hands.

DNSSEC fields. Look for DS (Delegation Signer) records or a signed-delegation status. Their presence means the domain's DNS answers are cryptographically signed, protecting resolvers against cache poisoning and spoofing. Their absence is normal for most small sites but worth noting for high-value domains — DNSSEC adoption remains depressingly low despite the protocol being finalized nearly two decades ago.

Registrant contact (usually redacted). Since GDPR, expect "redacted for privacy" or proxy-service details. Do not treat redaction as suspicious — it is the default for legitimate registrations now. What is worth noting is inconsistency: a domain claiming to be a major corporation but registered last month through a privacy proxy deserves the same skepticism as any other young, anonymous domain.

Reading a WHOIS record is a two-minute skill that pays off for years: it turns every unfamiliar domain from a black box into a dated, attributed, verifiable entity. Combine it with our DNS lookup (where the domain points) and SSL lookup (whether it is secured) for the complete picture.

Frequently Asked Questions

What information does a WHOIS lookup show?

A WHOIS lookup shows a domain's registration record: the registrar, the creation/registration date, the last-updated date, the expiry date, the authoritative name servers, the domain status codes (locks and holds), and DNSSEC status. Before 2018 it also showed the registrant's name, email, phone, and address; since GDPR, registrars redact personal data for most registrants, so you will usually see "redacted for privacy" or a privacy-proxy contact instead.

Why is the owner's contact information hidden?

The EU's General Data Protection Regulation (GDPR), effective May 2018, made publishing personal data without a lawful basis illegal — and WHOIS contact details are personal data. ICANN's temporary specification required registrars to redact registrant contact fields for individuals (and in practice, for most organizations too). Law enforcement, IP lawyers, and security researchers can still request access through formal channels, but casual public access to owner identities is gone. The dates, registrar, name servers, and status codes remain public.

What is the difference between WHOIS and RDAP?

RDAP (Registration Data Access Protocol) is the modern, standardized successor to WHOIS, defined in RFC 7480–7485. WHOIS is a 1980s-era plain-text protocol with no standard output format — every registrar formats records differently, which is why parsing them is notoriously messy. RDAP returns structured JSON over HTTPS with standardized fields, built-in internationalization, and support for tiered access (public vs. authenticated queries). ICANN required registrars and registries to offer RDAP by 2019, and it is gradually replacing WHOIS, though the WHOIS name persists in common usage.

What happens when a domain expires?

Expiry is not instant deletion — it is a multi-stage process. First comes the auto-renew grace period (typically up to 45 days), during which the owner can renew at the normal price and the domain usually keeps working. Next is the redemption grace period (about 30 days), when the domain stops resolving and recovery requires a steep redemption fee (often $100–$250). Then comes pending delete (5 days), after which the domain is released and anyone can register it — this is when drop-catching services and speculators pounce. The lesson: renew early, enable auto-renew, and keep your registrar contact email current.

How can I tell if a domain is old or newly registered?

Check the creation date in the WHOIS record — it is the authoritative answer. Be aware of one subtlety: if a domain expired and was re-registered, the creation date resets to the new registration, so a "vintage" domain name with a 2025 creation date was dropped at some point. Also compare the creation date against the site's claims: a store advertising "trusted since 2010" on a domain created six months ago is misrepresenting itself, and that discrepancy alone is worth knowing before you enter payment details.

What does clientTransferProhibited mean? Should I worry?

No — it is good news. clientTransferProhibited is a registrar-level lock the owner enabled (often by default) that prevents unauthorized transfers of the domain to another registrar. Any well-managed domain should have it set. It only becomes an obstacle during a legitimate transfer or sale, when the owner must temporarily remove it and provide the authorization (EPP) code. If you are buying a domain and the seller cannot or will not remove this lock, walk away.

Can I find out who owns a domain with privacy protection?

Not through public WHOIS — that is the point of privacy protection. The record will show the proxy service's contact details instead. Legitimate paths exist: many registrars forward messages to the owner via a proxy contact form, you can make an offer through an aftermarket broker, and parties with legal standing (trademark holders via UDRP proceedings, law enforcement via court order) can compel disclosure. Anyone offering to "unmask" a private WHOIS record for a fee is almost certainly running a scam.

How is domain WHOIS different from IP WHOIS?

Domain WHOIS (registries and registrars) covers domain names: registration dates, registrar, name servers. IP WHOIS (the five Regional Internet Registries — ARIN, RIPE, APNIC, LACNIC, AFRINIC) covers IP address allocations: which organization holds a block of addresses, with abuse and technical contacts that are generally still public. If you need to identify who operates a server at an IP address — for an abuse report, for example — use our IP lookup tool, which queries the RIR databases.

Share

Similar tools

Reverse IP Lookup

Take an IP and try to look for the domain/host associated with it.

8
0
DNS Lookup

Find A, AAAA, CNAME, MX, NS, TXT, SOA DNS records of a host.

33
0
IP Lookup

Get approximate IP details.

22
0

Popular Tools