Skip to main content

WHOIS Lookup

Look up a domain's registration record: when it was created, when it expires, which registrar holds it, and where to report abuse.

Enter a domain such as example.com to see who registered it and when it expires.

This tool queries an external service to answer your request. Only the value you enter — such as a domain or IP address — is sent. Your other data stays on your device.

This tool reads public records — DNS, WHOIS and certificate data that registries and servers publish openly. It sends nothing to the host you enter and changes nothing there. Use it on infrastructure you own or are authorised to look into.

About the WHOIS Lookup

Every registered domain has a registration record, and this reads it: when the name was first registered, when it was last changed, when it expires, which registrar it sits with, and which name servers it points at. Fields are parsed and labelled rather than dumped as raw WHOIS text, so you can find the expiry date without reading a screenful of a protocol from 1982.

The most common reason to look is timing. A domain's expiry date tells you when it lapses if nobody renews it — useful whether you are watching a name you want, or checking that one you own is not about to disappear because the card on file expired. The creation date is the other commonly used field: a domain registered three weeks ago that is emailing you about an invoice is worth a second look, and domain age is one of the few signals about a site that cannot be faked after the fact.

Expect the owner's name to be blank, and do not read that as a fault. Since GDPR came into force, most registries redact the registrant name, email, phone and postal address from public WHOIS by default. That redaction is the registry complying with the law, not this tool failing to find something — and any service claiming to show you the personal details behind a redacted modern record is either showing you stale pre-2018 data or making it up. What does remain public, and is usually what you actually need, is the registrar and its abuse contact: the address to write to about a domain being used for phishing or fraud.

The status codes are worth understanding too. clientTransferProhibited is normal and good — it is a lock preventing the domain being moved without the owner's consent. pendingDelete and redemptionPeriod mean the registration has lapsed and is on its way back to the pool, which is the window people watch when they want a name.

How to use the WHOIS Lookup

  1. Enter the domain

    Type the domain name — example.com. A full web address works; the scheme, path and www. prefix are removed for you.

  2. Run the lookup

    Complete the verification check and press Look up WHOIS. The record is fetched from the registry at that moment rather than from a cache.

  3. Read the dates first

    Registration, last-updated and expiry are grouped at the top, because they are what most people came for. The expiry date is when the name lapses if nobody renews it.

  4. Use the registrar for abuse

    If you are reporting misuse, the registrar abuse email is the address that can act. The registrant contact is usually redacted and, where it is not, is rarely the right place to write.

Frequently asked questions

Why is the owner's name blank?

Because the registry redacted it, which is now the default for most domains. Since GDPR took effect in 2018, registries and registrars have removed personal registrant details from public WHOIS unless the owner explicitly opts in to publishing them. The record you are seeing is complete — the fields are genuinely empty at the source. Any service that claims to reveal them is either serving pre-2018 data or inventing it.

How do I contact the owner of a domain then?

Three routes work in practice. Many registrars run an anonymised forwarding address that reaches the owner without exposing them. The domain itself often has a contact page or a role address such as hostmaster@ that goes somewhere staffed. And for genuine abuse — phishing, fraud, malware — the registrar abuse email shown here is the correct destination, and registrars are obliged to act on it.

What does clientTransferProhibited mean? Is something wrong?

Nothing is wrong; it is a good sign. It is a registrar lock that stops the domain being transferred to another registrar without the owner deliberately unlocking it, and it exists to prevent domain hijacking. Most well-maintained domains carry it. You only need to remove it when you are genuinely moving the domain, and you should put it straight back afterwards.

The expiry date has passed but the domain still works. Why?

Expiry is the start of a process, not the end of one. After it passes, most domains enter a grace period of around 30 days during which the owner can renew normally, then a redemption period of about another 30 during which recovery costs considerably more. Only after that does the name go to pending-delete and eventually return to the pool. A domain showing redemptionPeriod or pendingDelete in its status is genuinely on its way out.

Does this show the same thing as the registrar's own WHOIS page?

It shows the registry record, parsed into fields. A registrar's own page sometimes shows a little more for domains it manages itself, and raw WHOIS output sometimes contains free-text notes that do not fit any field. We deliberately do not return the raw text, because the parsed fields carry the same information in a form you can actually read.

Do you keep a record of the domains I look up?

No. The domain is sent to the lookup service and is not written to our database or our logs. We count that a WHOIS lookup happened so we know the tool is used, with no record of the domain, of who asked, or of what came back.