WHOIS Lookup
Look up the registration details of any domain name: the registrar, nameservers, creation date and more.
Fetching WHOIS data...
What is a WHOIS lookup?
A WHOIS lookup lets you find the registration details of a domain name. Every registered domain has data stored in a WHOIS database. With our free WHOIS tool you can retrieve that information instantly for more than 30 domain extensions.
The WHOIS system dates back to the 1980s and was originally designed as a public phone book for the internet. The protocol has since been modernized and adapted to privacy laws, but a WHOIS lookup is still an essential tool for website owners, domain investors, IT professionals and anyone who needs technical information about a domain name.
A WHOIS lookup shows you details such as:
- Registrar: the company the domain is registered with
- Nameservers: the DNS servers that handle the domain
- Creation date: when the domain was first registered
- Expiration date: when the registration expires
- Status: whether the domain is active, locked or available
- DNSSEC: whether DNS Security Extensions are enabled
- Last updated: when the domain details were last changed
- Registry Domain ID: the unique identifier at the registry
Supported domain extensions
Our WHOIS tool uses both the modern RDAP protocol and traditional WHOIS servers, so it supports a wide range of extensions. The tool automatically detects which protocol works best for the extension you enter and switches over seamlessly when needed.
| Protocol | Extensions |
|---|---|
| RDAP (modern) | .nl, .com, .net, .org, .dev, .app, .de, .uk, .info, .biz, .pl |
| WHOIS (traditional) | .be, .eu, .io, .fr, .it, .es, .at, .ch, .co, .au, .ca, .se, .dk, .no, .fi and more |
For every extension, the tool automatically picks the right WHOIS server or RDAP endpoint. That means you don't need any technical knowledge to run a WHOIS lookup: just enter the domain name and the tool does the rest.
WHOIS and privacy (GDPR)
Since the General Data Protection Regulation (GDPR) took effect in May 2018, the way WHOIS data is displayed has changed significantly. The regulation protects the personal data of EU citizens, which directly affects how much domain registration information is publicly visible.
SIDN, the registry for .nl domains, no longer shows any personal data in WHOIS results since the GDPR came into force. Names, addresses, phone numbers and email addresses of domain owners are no longer publicly visible. Other European registries such as EURid (.eu) and DNS Belgium (.be) have taken similar measures.
What can you still see after the GDPR?
- The registrar (the company the domain is registered with)
- The nameservers the domain uses
- The registration, expiration and last-updated dates
- The DNSSEC status and technical configuration
- Domain status codes (locked, active, etc.)
For international extensions such as .com, .net and .org, registrars like GoDaddy and Namecheap often offer WHOIS privacy services. These replace the real owner details with generic contact information from a privacy provider.
What do you use a WHOIS lookup for?
A WHOIS lookup comes in handy for many different purposes:
- Checking domain availability: see whether a domain name is already registered before you consider buying it
- Finding the registrar: find out which provider a domain is registered with, useful when transferring a domain
- Checking the DNS configuration: see which nameservers a domain uses to troubleshoot problems
- Keeping an eye on the expiration date: make sure your domain doesn't expire by accident by monitoring the expiration date
- Checking DNSSEC: verify whether DNS Security Extensions are active for better security
- Technical research: trace the DNS servers when you run into email or website configuration issues
- Researching a domain's history: see how old a domain is and when it was first registered
- Competitor analysis: find out which hosting and DNS infrastructure your competitors use
- Phishing detection: check whether a suspicious website was registered only recently
How does the WHOIS protocol work?
The traditional WHOIS protocol is a simple client-server protocol that has been around since 1982. It runs on TCP port 43 and exchanges information as unstructured text. When you run a WHOIS lookup, this is what happens:
- Your WHOIS client connects to the right WHOIS server
- The domain name is sent to the server as plain text
- The WHOIS server looks up the domain information in its database
- The server sends back the data it found as plain text
- The client parses the text it received and displays it in a readable form
The biggest drawback of traditional WHOIS is the lack of standardization. Every registry uses its own text format, which makes automated processing difficult.
RDAP, the modern successor
The IETF developed the Registration Data Access Protocol (RDAP) as the successor to WHOIS. RDAP solves the main problems:
- HTTPS instead of plain TCP: all communication is encrypted
- JSON instead of plain text: structured, machine-readable data
- Standardized format: every registry uses the same data structure
- Internationalization: full support for Unicode and non-Latin characters
- RESTful API: a modern API architecture with clear endpoints
Our WHOIS tool tries RDAP first by default and only falls back to traditional WHOIS when RDAP is not available for the extension in question.
WHOIS for .nl domain names
The Netherlands has its own registration system for .nl domains, run by SIDN (Stichting Internet Domeinregistratie Nederland). SIDN applies strict privacy rules that go further than many international registries.
What does SIDN WHOIS show?
- Domain name: the domain you looked up
- Status: whether the domain is active
- Registrar: the name of the registration company
- Nameservers: the DNS servers (often 2 to 4)
What does SIDN NOT show?
- The owner's name, address and contact details
- The registration date (when the domain was created)
- The expiration date (when the registration ends)
- The date of the last change
Other ways to get information about a .nl domain
- DNS lookup: use our DNS Lookup tool to find the nameservers and IP addresses
- Website analysis: check the footer or the terms and conditions for company details
- KVK register: Dutch companies have to list their website in the register of the Netherlands Chamber of Commerce (KVK)
- Contact form: get in touch directly through the website
Finding out who owns a domain
Modern privacy laws hide personal data, but there are still legal ways to find out who owns a domain when you have a valid reason.
Step 1: Run a WHOIS lookup. Start with a WHOIS lookup to see what information is available. For non-European extensions, contact details are sometimes still visible.
Step 2: Contact the registrar. The registrar holds the full owner details. Legitimate reasons for a request include:
- Interest in buying the domain
- Legal issues such as trademark infringement
- Technical problems the owner needs to fix
- Security incidents that need to be reported
Step 3: Analyze the website. Check the footer, the "About us" page, the privacy policy, the Chamber of Commerce number and social media profiles.
WHOIS when transferring a domain
A WHOIS lookup is essential when you transfer a domain to another registrar. Before a transfer, check:
- Transfer lock status: "clientTransferProhibited" has to be lifted first
- Expiration date: a domain must be valid for at least 14 more days
- Registration date: domains can only be transferred 60 days after registration
- Current registrar: check which provider the domain is with now
- Nameservers: write these down for a seamless handover
The transfer process step by step:
- Run a WHOIS lookup and check the status
- Unlock the domain at your current registrar
- Request the auth code (you receive it by email)
- Start the transfer at the new registrar
- Confirm the transfer by email (within 5 days)
- Transfer complete (takes 5 to 7 days)
WHOIS vs RDAP: the difference
WHOIS and RDAP serve the same purpose, but the differences between them are significant:
| Aspect | WHOIS (traditional) | RDAP (modern) |
|---|---|---|
| Protocol | TCP on port 43 | HTTPS (port 443) |
| Security | Unencrypted plain text | TLS/SSL encryption |
| Data format | Unstructured text | Structured JSON |
| Standardization | Each registry has its own format | Uniform RFC 7483 standard |
| Internationalization | Limited Unicode support | Full Unicode/IDN support |
| Machine-readable | Hard to parse | Easy to process |
| Privacy controls | Basic on/off | Granular access control |
Domain status codes explained
A WHOIS lookup often shows status codes that tell you what can and cannot happen to a domain:
| Status Code | Meaning |
|---|---|
OK or Active |
The domain is active and has no restrictions |
clientTransferProhibited |
Transfers to another registrar are blocked, which protects against unwanted transfers |
clientUpdateProhibited |
Changes to the domain details are blocked |
clientDeleteProhibited |
The domain cannot be deleted |
clientHold |
The registrar has put the domain on hold (often for non-payment), so the website and email are offline |
serverTransferProhibited |
The registry has blocked transfers (legal disputes or fraud) |
serverHold |
The registry has put the domain on hold (policy violation) |
pendingDelete |
The domain is in the deletion phase and can often still be restored |
pendingTransfer |
A transfer to another registrar is in progress (usually takes 5 to 7 days) |
redemptionPeriod |
The domain has expired and can only be restored by the original owner |
WHOIS data for cybersecurity
Security professionals rely heavily on WHOIS information to detect and investigate cyber threats. WHOIS data is a key part of threat intelligence.
Phishing detection
- Checking the registration date: newly registered domains (less than 30 days old) are suspicious
- Spotting bulk registrations: cybercriminals often register dozens of similar domains at once
- Recognizing registrar patterns: some registrars are abused for malicious purposes more often than others
- Nameserver clustering: groups of malicious sites often share the same DNS infrastructure
Brand protection
- Typosquatting: domains with misspelled brand names
- Cybersquatting: registering brand-related domains to profit from them
- Trademark infringement: unauthorized use of protected trademarks
Tools like our SSL Check work together with WHOIS data to verify whether a website is legitimate.
Tips for WHOIS lookups
1. Check more than one source. Not every WHOIS tool uses the same servers. Getting incomplete data? Try a second tool or check directly with the registry.
2. Keep caching in mind. WHOIS results are often cached for a few hours. Wait 15 to 30 minutes after a change before you check.
3. Combine it with a DNS lookup. Use WHOIS for the registration details and our DNS Lookup tool for the current DNS records. Together they give you a complete picture of a domain.
4. Monitor your own domains. Check regularly that the right nameservers are active, DNSSEC is configured correctly and the expiration date is far enough away.
5. Read "not found" correctly. It can mean the domain is not registered, the name contains a typo, or the WHOIS server is temporarily unreachable.
6. Respect rate limits. WHOIS servers enforce strict rate limits (often 10 to 50 queries per minute). Spread large numbers of lookups over time.
7. Use WHOIS for SEO research. When you buy an expired domain, check how old it is. Older domains (5+ years) are often worth more for SEO.
8. Document important lookups. For legal matters or security incidents, take screenshots of the WHOIS results. WHOIS data can change, and historical information is not always available later.
9. Watch out for premium and reserved domains. Some domains show WHOIS data but are not for sale because the registry has reserved them or offers them as premium domains at higher prices.
10. Convert IDNs. Domains with special characters (such as émilie.nl) have to be converted to Punycode for WHOIS lookups. Our tool does this automatically, but not every tool supports it.
Want to register a domain of your own with solid privacy and security? At Theory7 you get free WHOIS privacy, automatic renewal and full control over your domain status codes. Use our WHOIS lookup tool first to check whether the domain name you want is still available, and combine it with our SSL Check for a complete security overview of your website.
Frequently asked questions
What is WHOIS?
WHOIS is a public protocol for looking up the registration details of domain names. You can think of it as a phone book for the internet. Every domain registration stores data that you can retrieve through WHOIS, such as the registrar, nameservers and registration dates.
Can I see who owns a domain name?
Since the GDPR took effect, the personal details of domain owners are hidden in many cases. For .nl domains, SIDN no longer shows any personal data. You can still see the registrar, nameservers and registration date. Want to find out who the owner is? Contact the domain's registrar.
Which domain extensions can I look up?
Our WHOIS tool supports more than 30 domain extensions. Popular ones are .nl, .com, .net, .org, .be, .eu and .de. We use both the modern RDAP protocol and traditional WHOIS servers to cover as many extensions as possible.
What is the difference between WHOIS and RDAP?
RDAP (Registration Data Access Protocol) is the modern successor to the traditional WHOIS protocol. RDAP uses HTTPS and returns structured JSON data, while WHOIS is an unstructured text protocol on port 43. Our tool tries RDAP first and automatically falls back to WHOIS when RDAP is not available.
How many lookups can I do?
You can run up to 10 WHOIS lookups per minute. Results are cached for 1 hour, so repeat lookups are fast and the registries are not queried more than necessary. This is a free tool, no sign-up required.