Looked up a moment ago
Domains other visitors checked recently. Click one for its registry record and DNS.
One lookup, the whole registry record
This is roughly what you get back for google.com. Every result page also shows the raw registry response underneath, in case you want to check our parsing.
- Registrar, its IANA ID and the WHOIS or RDAP server that answered
- Created, last updated and expiry dates, with the renewal window
- Nameservers, EPP status flags and DNSSEC state
- Live A, AAAA, MX, TXT and SOA records for the apex
- The hosting IP, the ISP behind it and the ASN that announces it
- Registrant organisation and country, where the registry still shows them
Open the live record
How complete each field is
Measured across our recent lookups. Registrar, nameservers and dates are almost always there. The owner's name mostly is not, because of GDPR.
| Field | Returned | Note |
|---|---|---|
| Registrar | 100% | ICANN-accredited, always public |
| Nameservers | 99% | NS records from the registry |
| Expiry date | 98% | Renewal window included |
| Status flags | 97% | EPP codes |
| DNS records | 96% | A, MX, TXT, SOA resolved live |
| Registrant name | 28% | Redacted for most gTLDs since 2018 |
What WHOIS won't tell you
It is a registry record, not a search engine. Most limits got stricter after GDPR in 2018.
Hidden from a public lookup
- The owner's personal name, almost always redacted for gTLDs
- Their email or phone, only reachable through the registrar's relay form
- Past owners before the current one
- Whether the domain was ever suspended, hijacked or seized
- What anyone paid for it on the secondary market
Where to go instead
Old owners, sale records and infringement claims need a paid intelligence service or a court order to the registrar. Public WHOIS is a quick check, not a forensics tool.
To reach a hidden owner, use the contact form the registrar lists in the record. It forwards your message without revealing their address, and for abuse or legal matters registrars have to answer within a few business days.
How to look up a domain
Paste pretty much anything, we clean it up.
Type the domain into the box above, with or without www.. Subdomains work too: blog.example.com falls back to example.com for the registry record. You don't need to know the registrar first.
Got a URL? Copy just the host part. An email address? Take everything after the @. For country domains like example.co.uk, example.hr or example.de we route the question to the right national registry on our own.
WHOIS, RDAP and why owners are hidden
Two protocols, one privacy law, and a lot of redacted fields.
WHOIS is old. RFC 812 defined it in 1982 for ARPANET: plain text over TCP port 43, and every registry picked its own field names. Parsing it across 1,500+ TLDs is a mess, so in 2015 ICANN started pushing a replacement.
That replacement is RDAP (Registration Data Access Protocol). It runs over HTTPS, returns JSON with standard field names, handles international domain names cleanly and lets registrars show more data to verified abuse investigators than to anonymous users. Every gTLD registry has supported it since 2019 and most country registries followed. We ask RDAP first, fall back to WHOIS, and show the merged result.
GDPR and the redacted record
Until May 2018 anyone could read the owner's name, organisation, postal address, phone and email for any gTLD domain. Then GDPR arrived and ICANN made registries redact personal data for European owners. Most registrars simply redacted everyone, because checking "is this person in the EU?" per domain was harder. What stays public today:
- Registrar, technical contact and abuse email
- Country and state of the owner, no street address
- Organisation name, only if the owner ticked the "organisation" box
- Dates and status, which were never redacted
Country registries set their own rules. .de (DENIC) shows almost nothing. .hr (CARNet) and .fr (AFNIC) redact like ICANN does. .ru still shows the company name for business owners.
When a domain lookup actually helps
The jobs people use it for most.
Buying a domain
Check the expiry (is the seller about to lose it?), the registrar (is it hard to transfer away from?) and the status flags (is a serverHold blocking DNS?). A near expiry with no auto-renew can kill a deal mid-paperwork. We also flag domains whose owner published a _for-sale DNS record (RFC 10023), with the asking price or contact when there is one.
Checking a partner
The company you are about to wire money to registered its domain last week, through a registrar known for cheap bulk sign-ups? Call them first. Add the IP lookup of their site and you have a 30-second sanity check.
Hunting phishing
Phishing kits register hundreds of look-alikes like amazom-support.com or microssoft.help. WHOIS shows when each was created, the registrar and the nameservers. Group them by nameserver or registrar and the attacker's setup falls out.
Watching expirations
Waiting to backorder a drop? The status flags say exactly where a domain is: clientHold, autoRenewPeriod, redemptionPeriod, pendingDelete. For most gTLDs the drop comes about 75 days after expiry.
Moving to a new registrar
Before you start, the status should be ok with no clientTransferProhibited. If it is set, unlock it at the old registrar first. The expiry date tells you if you need to renew before the move, which some registrars require.
Protecting a brand
Search common typos of your brand across TLDs. Anything registered after your trademark may be actionable under UDRP or local law. Save the WHOIS record the day you find it, because registrars change fast.
Fixing email
Mail bouncing? Check the MX records on the result page, make sure the nameservers answer, and confirm SPF and DKIM exist. A lot of "mail is broken" tickets end with "someone changed the nameservers and nobody moved the DNS".
Due diligence
A startup pitches its brand, you look up the .com and it was registered in 2003 by an investor asking $250k. That changes the conversation. Age is one of the simplest signals of what a domain is worth.
Why some domains are worth millions
The creation date is the first thing buyers look at.
cars.com was registered in 1995 and reportedly went to Gannett for $872M in 2014. voice.com, also 1995, sold to Block.one for $30M in 2019. cryptocurrency.com, registered in 2018, went for low millions. The earlier the date, the fewer rivals, and a short generic .com from the 1990s simply can't be replaced. New endings like .app, .dev and .ai reset the clock with every release.
For a buyer the record gives three answers at once: how old the domain is, whether it changed hands recently (a big gap between creation and last update), and whether it sits locked at a decent registrar. For past prices, NameBio and published for-sale records fill in the rest.
More about domains and WHOIS records
What people ask after their first lookup. Skim what is interesting, skip the rest.
DNS in 60 seconds
A domain is a readable name for an IP address. When you type example.com, your resolver asks the root servers who runs .com, asks them who serves example.com, then asks those nameservers for the IP. Each answer is cached for the TTL the owner set. The tree goes root, TLD, second level, subdomains. You don't own a domain, you rent it: a yearly fee to the registrar, who pays a smaller one to the registry.
Registry, registrar, registrant
The registry runs the TLD: Verisign for .com and .net, PIR for .org, Identity Digital (formerly Donuts) for hundreds of new gTLDs, CARNet for .hr, DENIC for .de. The registrar is who you pay, like GoDaddy, Namecheap, Tucows or Cloudflare Registrar. The registrant is the legal owner. The registry keeps the master record, the registrar holds the contract, the registrant picks nameservers and contacts, and ICANN writes the rules for all of them.
gTLD vs ccTLD
Generic TLDs are open to anyone. The original seven were .com, .net, .org, .edu, .gov, .mil and .int, and the 2012 round added hundreds more (.app, .dev, .blog, .shop, .tech). Country-code TLDs follow ISO 3166 codes: .de, .hr, .uk (with the older .co.uk), .co (Colombia, now used worldwide). Each country registry sets its own rules on who can register, prices, transfers and what WHOIS shows. Some want a local presence (.de, .ca), others sell to anyone (.io, .me, .tv, .co).
From registration to drop
You register for 1 to 10 years. After expiry comes about 30 days of grace, where the old owner renews at the normal price. Then about 30 days of redemption, where only the old owner can get it back, usually with a hefty restore fee. Then 5 locked days of pending delete, and the domain drops back into the pool. Backorder services grab good names the second they release. The whole run after expiry is roughly 75 days for most gTLDs.
EPP status flags
EPP (Extensible Provisioning Protocol) is how registrars and registries talk to each other. The flags in WHOIS tell you where a domain stands:
ok: nothing special, the domain is activeclientTransferProhibited: locked by the registrar, the normal defaultclientHold: in the zone but not resolvingserverHold: the same, set by the registry, often a legal actionautoRenewPeriod: just expired, in the grace windowredemptionPeriod: still renewable, but expensivependingDelete: drops in 5 days, no renewal possible
Nameservers, glue and DNSSEC
Nameservers answer for the domain, and the parent zone records which ones they are (.com knows example.com uses ns1 and ns2.examplehost.com). If the nameservers live inside the domain itself, like ns1.example.com, the registry publishes glue records with their IPs so resolvers don't go in circles. DNSSEC signs the answers. The public key (DS record) sits at the registry, so a resolver can prove a reply really came from the right nameserver and wasn't changed on the way.
Privacy services
Before GDPR, privacy was a paid add-on, usually $5 to $15 a year: the registrar put its own contact in place of yours and forwarded the mail. Now the same redaction is free and on by default for gTLDs. The catch is you can't just copy an owner's email from WHOIS any more. You use the registrar's relay form instead.
International names and punycode
DNS only takes ASCII. Names like café.com, пример.рф or 例子.中国 are stored in Punycode, so café.com becomes xn--caf-dma.com. Browsers show the Unicode form, while DNS, WHOIS and certificates carry the punycode one. Our lookup takes both and shows both.
The DNS records on the result page
- A and AAAA: the IPv4 and IPv6 addresses the domain points to
- MX: the servers that accept its email
- NS: the nameservers, which should match the registry
- TXT: free text, used for SPF, DKIM and ownership checks
- SOA: the zone's master record with serial number and refresh timers
- CAA: which certificate authorities may issue SSL for the domain
Age, history and value
Older domains tend to carry more SEO weight, because links built up over years count more than fresh ones. A creation date in the 1990s is a hard signal. The last-updated date is softer: it can mean a transfer, a contact change or just a renewal. NameBio collects past sales, which is the most useful input when you value a name. ICANN doesn't set prices, the market does.
Why two WHOIS tools disagree
The truth sits at the registry. A tool asks either the registry (RDAP or WHOIS), the registrar, or a scraper. Registrars can lag the registry by a few minutes, and scrapers cache for hours or days. We ask the registry, so a domain you registered a minute ago shows up here as soon as the registry has it.
Moving a domain to another registrar
Five steps. Unlock it at the current registrar (clear clientTransferProhibited). Ask for the auth code, sometimes called the EPP code. Start the transfer at the new registrar with that code. Approve the confirmation email from the old registrar, or wait 5 days for automatic approval. The registry updates the registrar field and you pay for one extra year, added to your current expiry, so no time is lost. ICANN blocks transfers in the first 60 days after a registration or a previous transfer.
Questions we get a lot
What is a domain WHOIS lookup?
Why is the registrant name redacted?
What is the difference between WHOIS and RDAP?
Does this work for ccTLDs like .hr, .de or .co.uk?
Can I see the DNS records?
Is this tool free?
How fresh is the data?
Can I find expired or deleted domains?
redemptionPeriod or pendingDelete, the last windows before it drops. Once it is fully deleted the registry returns nothing at all.