WHOIS lookup
WHOIS Lookup
See what the registry holds for any domain — registrar, creation and expiry dates, nameservers, transfer lock and DNSSEC — queried over RDAP, straight from the source.
What This Tool Does
This tool asks the registry that operates the domain’s extension what it holds on record. For a .com that is Verisign; for a .uk it is Nominet. The right service is discovered through IANA’s bootstrap registry, so the answer always comes from the authoritative source rather than from a reseller’s cached copy.
It uses RDAP, not classic WHOIS. WHOIS was an unstructured text service on port 43 whose output every registry formatted differently, which is why older tools so often mangle dates or miss fields entirely. RDAP returns structured JSON with defined field names, so nothing here depends on guessing at someone else’s text layout.
Six things are checked: whether the name is registered and healthy, when it expires, whether transfer is locked, what nameservers the registry has on file, whether the zone is DNSSEC-signed, and whether registrant details are published or redacted.
How to Read Your Results
Registration
Whether the registry holds a record, and how long it has held one. Domain age is a mild trust signal — it is one of the few things about a website that cannot be faked retroactively. This row also surfaces the four status codes that mean the registration is in trouble right now, described below.
Expiry
Days until the registration lapses, from the registry’s own expiration event. Under 30 days is flagged. This matters more than a certificate expiring: when a domain lapses it stops resolving, which takes down the website and all email to the domain, and after a grace period the name can be registered by anyone.
The most common cause of an unplanned expiry is not forgetfulness but a declined card on an auto-renew subscription.
Transfer lock
Whether clientTransferProhibited or serverTransferProhibited is set. Locked is what you want. Unlocked means anyone with access to the registrar account can move the domain to a different registrar, and reversing a completed transfer is difficult.
Nameservers
What the registry has on file as authoritative for the zone. These are the delegation itself — the root of everything DNS does for this domain. If they are not what you expect, you are editing DNS records somewhere that nothing reads.
One nameserver is flagged as a warning: if it goes down, the domain stops resolving entirely. Two or more on separate infrastructure is standard.
DNSSEC
Whether the registry holds a delegation signer record, meaning the zone is signed and validating resolvers can detect tampered answers. Unsigned is not a fault and remains the majority position.
One practical warning if it is signed: changing DNS providers without updating the DS record breaks the domain completely rather than degrading gracefully. Validating resolvers return SERVFAIL and the site vanishes for a large share of users.
Registrant
Who the domain is registered to, when that is published. For most domains it is not, and the row says redacted. See the section on GDPR below.
Status codes
EPP status codes describe what the registry permits. Codes starting client were set by the registrar; codes starting server were set by the registry and cannot be removed by you. Most are protective. Four are alarms:
clientHoldandserverHold— the domain has been removed from DNS. The site and its email are down right now, regardless of how the DNS records look.redemptionPeriod— the registration already expired. It can be recovered, but at a redemption fee far above normal renewal, and the window is short.pendingDelete— queued for release. It can no longer be renewed or redeemed.
Common Problems and Fixes
The domain shows clientHold and the site is down
A hold removes the domain from DNS at the registry, so no amount of correct DNS configuration will bring it back. The usual causes are an unpaid renewal or a failed registrant email verification, which ICANN requires registrars to enforce. Log into the registrar, settle whatever is outstanding, and confirm the verification email. Removal of the hold is normally quick once the cause is cleared.
The registration has expired
Renew immediately. Most registrars hold an expired name for a grace period before it enters redemption, where recovery costs substantially more. Check the card on file at the same time — if auto-renew was on and the domain still expired, the payment failed and will fail again next cycle.
The nameservers are not the ones I set
The registry is authoritative about delegation, so what is shown here is where the internet actually looks. If you have been editing records at a different provider, none of those edits have had any effect. Either change the nameservers at the registrar to the provider you have been using, or move the records to the provider shown here. Afterwards, confirm with the DNS Checker, which shows what resolvers are returning rather than what the registry has on file.
The domain is unlocked
Turn the registrar lock on in the domain’s settings — it takes seconds and costs nothing. Then enable two-factor authentication on the registrar account itself. Domain hijacking almost always starts with a compromised registrar login rather than anything clever at the DNS layer.
No data is available for this extension
Some registries publish no RDAP service, or have not registered one with IANA. For those this tool reports nothing rather than guessing. The registry’s own website usually offers a lookup form, and that is the authoritative source in those cases.
I need to contact the owner but details are redacted
Use the registrar’s abuse contact, shown in the transcript, which registrars are obliged to monitor. Many registrars also forward a message to the registrant without disclosing their details. For a trademark or legal matter, the formal route is the registrar’s dispute process rather than direct contact.
What This Tool Cannot Tell You
- Who owns most domains. GDPR redaction is the default and this tool does not try to defeat it.
- Anything about extensions with no public RDAP. Roughly 1,200 TLDs are covered, but
.co,.me,.us,.euand several European country domains publish no discoverable service. Those report no data rather than a guess. - Whether an unregistered name is actually buyable. Reserved, premium and recently-expired names can all show no record and still be unavailable.
- Whether a domain is for sale. The registry has no view of the owner’s intentions.
- Registration history. Only the current record is published; previous owners and lapses are not part of it.
- Whether DNS actually works. The nameservers here are the delegation on file. What resolvers return is a different question — that is the DNS Checker.
Frequently Asked Questions
What is a WHOIS lookup?
It asks the registry that runs a top-level domain what it holds on record for a name: which registrar sponsors it, when it was created, when it expires, which nameservers it is delegated to, and what status codes are set.
This tool queries over RDAP, the standardised JSON protocol that replaced the old port-43 WHOIS text service. RDAP answers come straight from the authoritative registry rather than from an aggregator's copy.
Why can't I see who owns the domain?
Since GDPR took effect in 2018, registries and registrars withhold personal contact details by default. A redacted registrant is the normal result for the overwhelming majority of domains and says nothing suspicious about the owner.
This tool does not attempt to work around redaction. If you need to reach the owner, use the registrar's abuse contact shown in the transcript, or whatever contact details the site itself publishes. Organisations and some national registries still publish registrant data voluntarily, and where they do it appears here.
The lookup says there is no record. Does that mean the domain is free?
It usually does, but confirm at a registrar before making plans. A 404 from the registry means it holds no registration for that name right now.
Several things can make an apparently free name unbuyable anyway: it may be a reserved or premium name the registry holds back, it may have just expired and be sitting in a grace period before release, or it may be blocked by a trademark protection service. Availability itself is identical at every registrar, because they all query this same registry — only the price differs.
What does “transfer lock” mean and should I have it on?
Yes, unless you are actively moving the domain. The clientTransferProhibited status tells the registry to refuse transfer requests, which is the main defence against domain hijacking.
Without it, anyone who gets into your registrar account can move the name to another registrar, and once a transfer completes, getting it back is slow and frequently unsuccessful. Turn on the lock and enable two-factor authentication on the registrar account — a domain is usually the single most valuable asset in an online business, and it is often the least protected.
Why does the expiry date here differ from what my registrar shows?
The date shown here is the registry's, which is authoritative for when the name actually expires. Registrars often display their own internal renewal date, which can sit days or weeks earlier so they have time to process payment before the registry deadline.
If the two disagree by a large margin, or your registrar shows a date after the registry's, ask them about it directly — the registry date is the one that determines when the domain stops resolving.
What are the status codes?
EPP status codes describe what the registry will and will not allow. Codes beginning “client” were set by your registrar; codes beginning “server” were set by the registry itself and you cannot remove them.
Most prohibitions are protective and good to see: clientTransferProhibited, clientDeleteProhibited, clientUpdateProhibited. Four are serious problems — clientHold and serverHold remove the domain from DNS entirely, and redemptionPeriod and pendingDelete mean the registration has already lapsed. Those are flagged prominently in the results above.
Which domain extensions can this check?
Roughly 1,200 top-level domains, discovered through IANA's bootstrap registry — the mechanism RFC 9224 defines for finding the right RDAP service. That covers .com, .net, .org and most newer extensions.
Some registries run no public RDAP service or have not registered one with IANA, including .co, .me, .us, .eu and several European country domains. For those the tool reports that no data is available rather than guessing or falling back to a scraped source.
Is this the same as checking if a domain is for sale?
No. This reports what the registry holds, not what any marketplace is asking. A registered domain may still be for sale privately, and an unregistered one may be reserved by the registry and never offered at all.
The registration and expiry dates here are useful context for an approach — a name registered fifteen years ago and renewed continuously is unlikely to be casually released — but the registry has no idea whether the owner would sell.