WHOIS / RDAP

Loading tool…

About WHOIS / RDAP

Enter a domain, IP, or ASN and click Lookup RDAP. www is stripped to the apex. Private IPs are blocked. We query RDAP over HTTPS (registry, then the registrar record when a related link exists). You get created, last changed, and expires dates, every EPP status in plain English, DNSSEC flags, nameservers, and abuse contacts even when the registrant is redacted.

There is no port-43 WHOIS fallback. Country TLDs without RDAP will fail instead of using the old protocol. 429 from a registry is reported as a rate limit; wait and retry. Dates are as the registry publishes them, not a legal timestamp.

When to use it

Use it before a registrar transfer, or when the invoice date and the registry expires field do not match. That is also the look-up when you inherit a domain and need lock, hold, and abuse contacts without a port-43 client.

Paste a domain, a public IP, or an ASN. It is not a live A/MX table and not a TLS leaf. DNS Lookup and SSL Checker cover those. www is stripped to the apex before the query.

How to use WHOIS / RDAP

  1. 1Enter a domain, IP, or ASN. Private IPs are blocked. www is stripped to the apex.
  2. 2Click Lookup RDAP. RDAP over HTTPS. Odd ports are blocked.
  3. 3Read Error, Warning, Notice, and Pass. Lock, hold, expiry, and DNSSEC each have a why and a fix.
  4. 4Open the raw record if you need it. Nothing is stored after the response.

Domain, IP, and ASN

Domains use rdap.org, then Verisign for many .com names, then a related registrar RDAP URL when the record links one. Expiry under 0 days is critical, under 30 a warning, under 90 a notice. Age under 90 days is a notice. Lock, hold, delete, and transfer statuses are explained. DNSSEC is the RDAP secureDNS flag, not a live DNSKEY validation.

IPs and ASNs use rdap.org plus the five RIRs. Those reports are shorter: network or autnum status when the registry marks the object active. Contacts that privacy policy redacts show as Redacted for privacy. We do not invent an email.

How to read the results

Dates are Created, last changed, and Expires, plus Age (days) when the registry sent them. Statuses are EPP codes in plain English. DNSSEC is the secureDNS flag on the record. Open the raw record when you need the untranslated object.

On example.com you typically see a far expiry, registrar lock, DNSSEC signed, and a notice if both nameservers sit on one provider. A private or reserved address returns Private or reserved IP addresses are blocked.

Why this matters

clientTransferProhibited, shown here as registrar lock, is the registry flag that stops a transfer until someone clears it. Starting a move while that flag is on fails at the registry, not in your email thread.

An expires date under 0 days means the object is already past the registry deadline. Under 30 is the warning band; under 90 is a notice. Age under 90 days is a separate notice because many filters treat a new name as higher risk. Those bands are registry math, not a legal clock.

Limits and privacy

HTTPS RDAP on 443 only. No port-43 fallback. Private IPs and credentialed URLs never leave as a query. About 20 Lookup RDAP runs per minute on our side; a registry 429 is a wait-and-retry, not a stored report. No login.

Common mistakes

Pasting www.example.com and expecting a different record. The form strips www and queries the apex.

Reading Redacted for privacy as a missing registrar. The registrar and abuse fields can still be present when the registrant is hidden.

Using this page for A, MX, or SPF. Those answers come from Lookup DNS. A private IP fails here; a public IP is an RIR report, not a domain expiry.

FAQs

Why are contacts empty?
GDPR and ICANN privacy. We show Redacted for privacy instead of inventing an email.
Is there a WHOIS port 43 fallback?
No. Lookups use HTTPS RDAP only. Some country TLDs have no RDAP and will fail.
What if the registry returns 429?
We say the RDAP server rate-limited the lookup. Wait a moment and retry.
Is creation time a legal timestamp?
No. It is whatever the registry published in RDAP.
Do you check live DNSSEC?
No. We report the RDAP secureDNS flags (delegation signed or DS data). Use DNS Lookup for nameserver records.
Why does Lookup RDAP reject a private address?
Private or reserved addresses are blocked. A public IP goes to the RIR. A hostname such as example.com goes to the domain registry. DNS Lookup rejects IPs for the opposite reason: it wants a hostname.
What does All nameservers are on one provider mean?
A notice that every listed NS hostname shares one operator. example.com showed that notice and still passed lock, DNSSEC, and expiry. It is not a down flag. Split providers if you want that extra failure domain.
Does www change the RDAP record?
No. www is stripped to the apex before the query. example.com and www.example.com hit the same registry object. Use SSL Checker if you need the www SAN on the certificate.