WHOIS / RDAP Lookup

Owner, registrar, dates, nameservers and abuse contact for any domain or IP, via RDAP.

Who is behind a domain or an IP, in fields you can actually read. RDAP is the modern, structured replacement for the wall of WHOIS text, so we hand you the registrar, the dates, the nameservers and the abuse contact, not a formatting puzzle. Then we read the signals that matter: a domain registered last week is a phishing tell, an expiry a few weeks out is a problem waiting to happen, a missing registrar lock is an open door. Since GDPR the owner's name is usually redacted, which is normal, but what stays public is what you need. It runs through our own service, the raw JSON is one click away, and nothing is logged.

Queries run through the PacketNebula lookup service. We log nothing.

The signals worth reading first

A registration record is more than a list of dates once you know what to look at. The age is the big one: a domain registered three days ago that turns up in a phishing email is the single loudest fraud signal there is, and we flag it. Then the expiry, because a lapse takes the site and its mail down, the registrar lock, which blocks the easiest hijack, and whether DNSSEC is on. We read those for you at the top, then list the registrar, nameservers and the raw record underneath.

Why the owner is usually hidden

Do not expect a name and email for most domains. Since GDPR, registries redact personal contact data, so you see the registrar and the dates but rarely the person. That is the law working as intended. The abuse address normally stays public, which is what you need to report something. For an IP it is different: the org and the abuse contact for the block are right there. Need the DNS records that go with a domain? The DNS lookup tool picks up where this leaves off.

Frequently asked questions

What is the difference between WHOIS and RDAP?

They answer the same question (who registered this domain or IP) but RDAP is the modern replacement. WHOIS is unstructured text that every registry formats its own way; RDAP returns clean JSON with defined fields. ICANN has been moving registries onto RDAP for years. We speak RDAP and hand you a readable summary plus the raw record.

Why are the registrant name and email blank?

Privacy law, mostly GDPR. Since 2018 registries redact personal contact details from public data, so for most domains you see the registrar and the dates but not the owner. That is expected, not a failure. The abuse contact is usually still published, which is the one you need to report something.

Can I look up an IP address too?

Yes. Paste an IP and we query the regional registry (ARIN, RIPE, APNIC and so on) for the block it sits in: the range, the organization that holds it, and the abuse contact. That is how you find out who really owns the address hammering your firewall.

Why does some TLD return nothing?

Not every TLD runs an RDAP server yet, and a few ccTLDs still expose only legacy WHOIS or nothing public. When that happens you get an honest "no RDAP record" instead of a guess. The big gTLDs (.com, .net, .org) and the major registries are fully covered.

Is the query private?

The domain or IP goes to our small service, which relays it to the registry over RDAP and returns the answer. Nothing about what you look up is logged or kept.