WHOIS Lookup
Look up who registered a domain, when, through which registrar, and where its DNS is pointed — or find the organisation that owns an IP address and the address to report abuse to. Results come straight from the registries over RDAP, the modern replacement for WHOIS.
Try · · · — domains and IP addresses are detected automatically.
Raw RDAP response
Key takeaway: the single most useful field is the registration date. A shop, bank login or investment site whose domain was created three weeks ago is almost always a scam, and that one fact is visible here in two seconds regardless of how polished the site looks.
What WHOIS actually shows in 2026
WHOIS began as a plain-text directory of who owned what on the early internet, complete with names, postal addresses and phone numbers. That era is over. Since GDPR took effect, registries and registrars redact personal details on most domains by default, and privacy services replace the owner’s contact details with their own on many of the rest.
So the registrant field is usually empty, or shows a proxy service, and that is normal rather than suspicious. What remains public is still worth a great deal:
Registration date — when the domain was first created, which no privacy service hides. Expiry date — when it lapses, useful for spotting a business that has stopped paying attention. Registrar — the company it was bought through. Nameservers — where its DNS is hosted, which often reveals the platform behind a site. Status flags — the locks protecting it from unauthorised transfer, and whether a registry has suspended it.
RDAP, not classic WHOIS
This tool queries RDAP, which returns structured data over HTTPS instead of the free-form text the old port-43 WHOIS protocol produced. It is the format the registries themselves now consider authoritative, and because it is standardised, the fields here are exactly what the registry published — nothing reformatted or inferred.
The gap is coverage. Every generic TLD (.com, .net, .org and the rest) publishes RDAP, and many country domains do, but several national registries still offer only their own web form — .de, .it, .es, .ro, .ru, .ch and .at among them. When you look one of those up, this page will tell you so and send you to the registry that holds the record, rather than pretending the domain does not exist.
Using it to judge whether a site is trustworthy
Domain age is the fastest scam filter there is. Fraudulent shops, fake delivery-notice pages and investment scams run on domains registered days or weeks before the campaign, because the previous batch got taken down. A legitimate business that has traded for years has a domain with a matching history.
Read it alongside the rest of the picture, not alone. A brand-new domain for a brand-new business is perfectly normal; a brand-new domain impersonating an established bank is not. Things worth weighing:
| Signal | What it suggests |
|---|---|
| Registered days or weeks ago | Strong warning sign for anything taking payments or credentials. |
| Expiry only months away | Bought for a short campaign, or a business no longer investing in it. |
| Registrant redacted | Normal. Almost every domain looks like this now. |
| Nameservers at a free host | Neutral alone, weaker when paired with a very new domain. |
Status clientHold | The registrar has pulled it from DNS — often after an abuse report. |
If you are checking a site because something about it felt wrong, the scam test walks through the other signals, and how addresses get faked covers why the technical details in an email or link cannot be taken at face value either.
IP WHOIS is a different record
Enter an IP address instead and you are querying one of the five regional internet registries — ARIN, RIPE, APNIC, LACNIC or AFRINIC — rather than a domain registry. What comes back describes the network block: the organisation it is allocated to, the range it belongs to, the country of registration, and usually an abuse contact address.
That abuse address is the practical payoff. If an address is attacking your server or sending you spam, it is where a report actually goes. Note that the organisation shown is whoever holds the allocation, which for a hosting company is the host rather than their customer — and the country is the registration country, which is not always where the machine physically sits. For a more precise picture of a specific address, the IP reputation checker adds blacklist and network-type data on top.
Look up your home IP and you will see your provider, the network block you sit in and their abuse contact. You are not personally named — but every site you visit sees that address and can run the same lookup. A VPN replaces it with the provider’s address instead of yours.
PureVPN IPVanishAffiliate links. We do not rank by commission — compare providers yourself.
What this cannot tell you
Who the human owner is, in the overwhelming majority of cases. Redaction is the default and a privacy service is a normal purchase, not evidence of wrongdoing.
Who runs the website. The domain record describes the registration, not the operation. Whoever built and runs the site can be an entirely different party from whoever registered the name.
Where the site is hosted. Nameservers hint at the DNS provider, which is often not the web host. For the machine actually serving the pages, look up the IP that the domain resolves to — the DNS checker will give you that address.
Whether a domain is safe. Registration data is one input. Old domains get compromised and new ones are usually legitimate; treat age as a weighting, never as a verdict.
Frequently asked questions
Why is the registrant blank?
Because personal data is redacted by default under GDPR and equivalent rules, and because many owners buy privacy protection on top. For most domains registered by an individual, nobody is going to see a name here. Company-registered domains sometimes still show an organisation.
Can I find out who owns a domain anyway?
Sometimes, but not from this record. Registries release details to law enforcement and to properly filed legal requests, and some historical archives captured details from before redaction. If there is a genuine dispute, the registrar’s abuse contact and a formal complaint are the route that works.
Why does my country’s domain not work here?
A number of national registries never implemented RDAP and still publish only through their own web form. When that happens this page names the registry and links you to it. The record exists — it just is not available in a machine-readable form.
What does “not registered” mean?
The registry answered and has no record of that name, so it is available to buy. That answer only comes from registries that support RDAP; for the others, check with the registry directly.
Does looking up a domain tell the owner?
No. The query goes to the registry, not to the domain’s owner or its web server, and nothing about your lookup is passed on to them.
Why do the dates sometimes look wrong?
Registries report in UTC and occasionally record the date a record was migrated rather than the original creation date, which is why a few very old domains show a date in the 1990s that does not match their history. The “last changed” field also updates for routine administrative edits, not just ownership changes.
Related reading
- How DNS works
- What an ASN is
- How accurate IP geolocation is
- What your IP reveals
- IP spoofing explained
- Is this site a scam?
- What a proxy server does
- Remove yourself from data brokers