WHOIS Lookup
Domain registration, ownership history, age, expiry date, and nameservers — all in one query, parsed and organized.
Learn More
WHOIS is a public query protocol that lets anyone look up the registration details of a domain name. When someone registers a domain their contact information registration date expiry date nameservers and registrar details are stored in a global database. WHOIS provides a standardized way to query that database. The WHOIS system dates back to the early days of the internet when ARPANET administrators needed a directory of network users. Today WHOIS data is managed by domain registries (like Verisign for.com domains) and registrars (like Namecheap or GoDaddy). Each top-level domain (TLD) has its own WHOIS server and queries are routed to the appropriate server based on the domain extension. WHOIS data serves many legitimate purposes. Law enforcement uses it to investigate cybercrime and fraud. Businesses use it to verify domain ownership before acquisitions or partnerships. Security researchers use it to trace malicious domains. SEO professionals check domain age and registration history as part of site evaluation. While privacy regulations have limited the personal information visible in WHOIS results the technical and administrative data remains an essential part of internet infrastructure.
Every domain name has an expiration date set at the time of registration. When a domain expires it goes through a grace period (typically 30-45 days) during which the original owner can still renew it at the standard price. After that it enters a redemption period where renewal is possible but at a significantly higher cost. Finally it is released back to the public for anyone to register. To check when a domain expires perform a WHOIS lookup and look for the Registry Expiry Date or Expiration Date field. This shows the exact date and time (in UTC) when the domain registration lapses. Some registrars display this as Paid Through Date or Renewal Date. Monitoring domain expiry is critical for businesses. An expired domain means your website goes offline your email stops working and if someone else registers it you could lose your brand's online identity entirely. Set up auto-renewal with your registrar and register domains for multiple years to reduce this risk. For domains you do not own checking expiry dates can reveal acquisition opportunities — domains nearing expiration may become available soon.
WHOIS privacy protection (also called domain privacy or WHOIS proxy) replaces the domain owner's personal contact information in the WHOIS database with the details of a privacy service. Instead of seeing the registrant's name address phone number and email a WHOIS lookup shows the privacy company's information or generic placeholder data. Most registrars offer WHOIS privacy as a free or low-cost add-on. When enabled the privacy service acts as an intermediary — legitimate inquiries can still reach the domain owner through a forwarding address but spammers data harvesters and identity thieves cannot access personal details directly. The GDPR (General Data Protection Regulation) significantly changed the WHOIS landscape starting in 2018. European registrars are now required to redact personal information from WHOIS results by default making privacy protection largely automatic for domains registered through EU-based companies. ICANN the organization overseeing the domain name system has been working on a tiered access model that balances privacy with the legitimate needs of law enforcement and intellectual property holders. For businesses WHOIS privacy reduces spam protects against social engineering attacks and prevents competitors from easily identifying your domain portfolio. For individuals it is a basic privacy measure that prevents personal address and phone number exposure.
Frequently asked questions
A registry operates a top-level domain (TLD) — Verisign runs.com and.net PIR runs.org Nic.io runs.io. They maintain the authoritative database of every domain under that TLD. A registrar sells domains to end users — Namecheap Cloudflare Registrar GoDaddy etc. Registrars pay the registry a wholesale fee and charge you the retail price. WHOIS data is stored at the registry level; your registrar is the one you pay to renew.
Status codes are set either by your registrar (client*) or the registry (server*) to lock certain actions. clientTransferProhibited means your registrar has blocked outbound transfers — this is default and protects against unauthorized transfer. clientHold means the domain is suspended (usually for non-payment or ICANN verification failure). serverHold is a registry-level suspension and usually indicates a serious issue. A healthy domain typically shows 2-3 client* lock codes and nothing else.
Most registries impose a 60-day lock after registration or a previous transfer — you can't move the domain during that window. Outside that transfers are allowed but aggressive timing near expiry is risky: the transfer process takes 5-7 days and the losing registrar's policies apply. Best practice — initiate transfers at least 14 days before expiry or renew for a year first (the renewal period typically carries over to the new registrar). An EPP (auth) code from the current registrar is always required.
Since GDPR took effect in 2018 most registrars redact registrant personal data by default — name address phone email — replacing them with REDACTED FOR PRIVACY or similar placeholders. This applies regardless of whether you paid for WHOIS privacy. Technical data (nameservers registrar dates DNSSEC status) is still visible. For legitimate contact registrars provide an anonymized forwarding form — use it for legal notices trademark complaints or acquisition offers.
Not reliably anymore. Between GDPR redaction WHOIS privacy services and offshore registrars the registrant field rarely identifies a real person or company these days. What you CAN still trust: registration date (reveals domain age — useful for SEO trust signals) expiry date (for acquisition opportunities) nameservers (reveals hosting provider) DNSSEC status and registrar identity. For legal attribution or cybercrime investigation law enforcement can request unredacted data from the registrar.
More in Domain Health
Foundational integrity of your domain — TLS, DNS, ownership, and email authentication.