בס״ד

WHOIS Lookup

A WHOIS lookup returns the registration record for a domain name: the registrar that manages it, the dates it was created, last updated and expires, the nameservers it is delegated to, and the EPP status codes showing whether it is locked, on hold or pending deletion. Since GDPR, most registrars redact the registrant's personal contact details.

How do I run a WHOIS lookup from the command line?

$ curl https://dnsx.dev/whois/example.com

What is a WHOIS lookup?

A WHOIS lookup queries the public registration record a registry holds for a domain name. That record is created when the domain is registered and updated whenever it is renewed, transferred or locked, so it is the authoritative statement of who manages the name, when it expires, and where it is delegated, independent of anything the domain's own DNS or website says.

DNSX queries the registry live for every lookup, returns the full record rather than a summary, and requires no account, no captcha and no rate-limit paywall. The same data is available as JSON from curl https://dnsx.dev/whois/example.com.

Who owns a domain, and why is the owner usually hidden?

WHOIS and RDAP return the registrant on record, but for most domains that field no longer names a person. Following GDPR, ICANN's Temporary Specification of 2018 and the Registration Data Policy that replaced it require registrars to redact personal contact details from public output, so a lookup typically shows the registrar, the registrant's country and state, and an anonymised forwarding address rather than a name and email.

What remains fully visible is everything technical: the registrar, the creation, updated and expiry dates, the nameservers, the EPP status codes, the DNSSEC state, and organisational registrant details where the registrant is a company rather than an individual. Many registrars also sell a privacy service that substitutes a proxy contact even where redaction would not otherwise apply.

When does a domain expire, and what happens next?

The expiry date is carried in the registration record. Passing it does not release the name. For most gTLDs the domain enters an auto-renew grace period of roughly 30 to 45 days during which the registrant can still renew at the normal price, though the registrar will usually have stopped resolving it.

After that comes a 30-day redemption period, during which only the original registrant can restore the name and the registry charges a redemption fee well above the renewal price. Then a five-day pending-delete window, in which nothing can be done at all, before the name drops and becomes available for anyone to register. The status codes autoRenewPeriod, redemptionPeriod and pendingDelete identify which stage a domain is in.

What do the EPP status codes mean?

EPP status codes describe the current state of a domain at the registry. Codes prefixed client are set by the registrar; codes prefixed server are set by the registry and the registrar cannot remove them. A domain normally carries several at once.

Status codeWhat it means
okThe default state. No pending operations and no locks. Because no transfer lock is set, arguably less protected than a domain showing clientTransferProhibited.
clientTransferProhibitedA registrar-set lock blocking transfer to another registrar. Normal and desirable; the registrant removes it from the registrar control panel before a legitimate transfer.
clientDeleteProhibitedA registrar-set lock blocking deletion of the domain, protecting against accidental or unauthorised removal.
clientUpdateProhibitedA registrar-set lock blocking changes to the registration record, including nameserver and contact changes.
clientHoldThe registrar has asked the registry to remove the domain from the zone. The domain stops resolving entirely while this is set. The usual causes are non-payment or an abuse complaint.
serverTransferProhibitedA registry-set transfer lock. Applied automatically for 60 days after a registration or a change of registrant, and cannot be lifted by the registrar.
autoRenewPeriodThe domain passed its expiry date and is in the grace window, typically 30 to 45 days, in which it can still be renewed at the normal price.
redemptionPeriodThe domain was deleted after expiry. For 30 days only the original registrant can restore it, and the registry charges a redemption fee.
pendingDeleteRedemption has ended. After a five-day window the name is purged from the registry and becomes available for registration by anyone.
inactiveNo nameservers are delegated at the registry, so the domain cannot resolve regardless of any DNS configured elsewhere.

What is RDAP, and has it replaced WHOIS?

RDAP, the Registration Data Access Protocol, is the structured JSON successor to WHOIS, standardised in RFC 7480 through RFC 7484. It carries the same registration data over HTTPS with defined field names, consistent date formats, internationalisation support and standardised access controls, so it can be parsed reliably instead of scraped.

RDAP has replaced WHOIS as the authoritative interface at all five Regional Internet Registries and at gTLD registries under ICANN's RDAP requirement. Legacy WHOIS output is still served by many registries for compatibility, but it is free-form text with no guaranteed schema and is being retired.

What do the WHOIS fields and status codes mean?

RDAP Transition

RDAP (Registration Data Access Protocol) is replacing legacy WHOIS with structured JSON responses, HTTPS transport, and standardized access controls mandated by ICANN for all registries.

Domain Lifecycle

Domains progress through stages: registration, active use, expiration, grace period (30-45 days), redemption period (30 days at premium cost), and pending delete before becoming available again.

Transfer Locks

The clientTransferProhibited status prevents unauthorized domain transfers. Most registrars enable this by default. It must be removed before initiating a legitimate transfer to a new registrar.

WHOIS Privacy

Privacy protection replaces personal registrant details with proxy information. Since GDPR, most registrars automatically redact personal data for European registrants from public WHOIS results.

Nameserver Delegation

WHOIS data includes the authoritative nameservers for a domain. These NS records in the registry determine which DNS servers control the domain's zone and handle all DNS queries for it.

EPP Status Codes

EPP (Extensible Provisioning Protocol) codes describe domain states. Client-level codes are set by registrars, server-level codes by registries. Multiple codes can be active simultaneously on a single domain.

Frequently Asked Questions

What is a WHOIS lookup?
A WHOIS lookup queries a public database to retrieve registration information about a domain name. This includes the registrar (the company where the domain was registered), creation and expiration dates, nameserver configuration, and domain status codes. WHOIS data is maintained by domain registries and registrars and is available for most top-level domains (TLDs) including .com, .net, .org, and country-code TLDs.
Is WHOIS data public?
Historically, WHOIS data including registrant contact information was fully public. However, since the introduction of GDPR in 2018, most registrars redact personal information from WHOIS results for domains registered by individuals in the EU and often globally. You can still see the registrar name, registration and expiration dates, nameservers, and domain status codes. Many registrars also offer WHOIS privacy protection services that replace personal details with proxy information.
What are domain status codes?
Domain status codes (also called EPP status codes) indicate the current state of a domain. Common codes include: clientTransferProhibited (prevents unauthorized transfers), clientDeleteProhibited (prevents accidental deletion), serverHold (domain is suspended by the registry), pendingDelete (domain is being deleted), and redemptionPeriod (domain can still be recovered after expiration). The "ok" status means no restrictions are in place. Multiple status codes can be active simultaneously.
How do I find when a domain expires?
Use our WHOIS lookup tool to check the expiration date of any domain. Enter the domain name and look for the "Expires" date in the results. Most domains are registered for 1-10 years and must be renewed before expiration. After a domain expires, it enters a grace period (typically 30-45 days), then a redemption period (another 30 days at higher cost), and finally becomes available for anyone to register.
What is RDAP?
RDAP (Registration Data Access Protocol) is the modern replacement for the traditional WHOIS protocol. RDAP provides structured, machine-readable JSON responses instead of free-form text, supports standardized authentication and access control, uses HTTPS for secure queries, and offers better internationalization support. ICANN has mandated that all registries and registrars support RDAP, and it is gradually replacing legacy WHOIS as the primary domain registration lookup protocol.

Related Tools