WHOIS
Both an old lookup protocol and the everyday name for public domain registration data The information kept about a domain and its owner. Full definition of registration data: who registered a name, through which registrar A company that registers domain names for customers with the registry. Full definition of registrar, and when. For gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD other than .com, .name and .post, the duty to run WHOIS ended on 28 January 2025, and RDAP Registration Data Access Protocol The modern protocol for looking up domain registration data, replacing WHOIS. Full definition of RDAP replaced it. Some ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD still use WHOIS.
- category
- Registration data and privacy
WHOIS is the long-standing way to check who is behind a domain name A readable internet name made of labels separated by dots. Full definition of domain name: which registrar manages it, when it was registered and when it expires. The word names both an old lookup protocol and, in everyday use, the public record itself. For most generic top-level domains a newer protocol, RDAP, has taken over, but WHOIS has not disappeared.
What WHOIS is
The protocol is described in RFC Request for Comments A numbered document in the series recording the internet's technical standards and practices. Full definition of RFC 3912 (September 2004). A program connects to a server on port 43 The network port of the classic text-based WHOIS service, no longer mandatory for most gTLDs. Full definition of port 43, sends a line of text such as a domain name, and gets plain text back. The RFC is frank about its limits: no internationalisation, no access control, no integrity protection and no confidentiality. It should carry only information “intended to be accessible to everyone”; with no access control, every user gets the same answer.
ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN’s wider term for public lookup services for gTLD data is RDDS Registration Data Directory Services ICANN's umbrella name for public lookup services for registration data, formerly WHOIS and now RDAP. Full definition of RDDS: WHOIS on port 43, web WHOIS and now RDAP.
From WHOIS to RDAP: what changed
The main dates:
- 26 August 2019: every gTLD registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry and registrar had to run an RDAP service.
- 28 January 2025: the WHOIS sunset The end, on 28 January 2025, of the obligation for most gTLDs to offer WHOIS. Full definition of WHOIS sunset.
- 21 August 2025: the February 2024 version of the gTLD RDAP Profile ICANN's technical rules for how gTLD registries and registrars must implement RDAP. Full definition of gTLD RDAP Profile became mandatory, the day the Registration Data Policy ICANN's policy on collecting, publishing and disclosing gTLD registration data. Full definition of Registration Data Policy took effect.
ICANN lists four advantages of RDAP: internationalisation, secure access, authoritative service discovery, and differentiated access, so different users can see different data. A query is a web address sent over HTTPS Hypertext Transfer Protocol Secure The encrypted version of the protocol web browsers use to load pages. Full definition of HTTPS; the answer is structured data that programs can read. The data itself is the same.
Discovery works through the RDAP bootstrap The IANA lists that tell RDAP clients which server holds the data for a TLD. Full definition of RDAP bootstrap: IANA Internet Assigned Numbers Authority The functions that coordinate the root zone, IP addresses and protocol numbers. Full definition of IANA publishes lists matching each TLD top-level domain The last part of a domain name, after the final dot. Full definition of TLD to its RDAP server, so a tool knows which server to ask. The gTLD RDAP Profile, two ICANN documents written with registries and registrars, makes every gTLD answer in the same format.
The sunset is narrower than it sounds. From 28 January 2025, gTLD registries and registrars are no longer required to run WHOIS on port 43 or on the web, except for .com, .name and .post (as of October 2026). Providers may still run it by choice.
How to look up a domain today
The simplest route is ICANN Lookup ICANN's free web tool that looks up public registration data through RDAP. Full definition of ICANN Lookup at lookup.icann.org. It sends an RDAP query and shows the live answer from the registry and registrar; ICANN does not store RDAP lookup data. As of October 2026, if RDAP is unavailable for a gTLD domain, it offers an optional WHOIS lookup after a captcha, and it shows the raw RDAP answer at the bottom of the page.
For TLDs that still run port 43, a classic WHOIS client may work, though some registries restrict access.
Some data is visible only to approved users. ICANN asks people to check ICANN Lookup first, then use RDRS Registration Data Request Service ICANN's free service for requesting hidden gTLD registration data from participating registrars. Full definition of RDRS for participating registrars or the registrar’s own disclosure process, which every gTLD registry and registrar must link from its homepage.
An example: someone checks example.com. The tool finds the .com RDAP server through the bootstrap list, then follows the link to the registrar’s server. Under the Registration Data Policy the answer shows the registrar, dates, status codes and name server A server that holds a domain's DNS records and answers lookups. Full definition of name server, while the registrant The person or organization that holds a domain name registration. Full definition of registrant’s name, street and phone are marked as redacted where redaction Hiding personal data from public domain registration lookups. Full definition of redaction applies.
What you will and will not see
Under ICANN’s Registration Data Policy (in effect since 21 August 2025, revised on 12 May 2026), a gTLD record always shows the domain name, the registrar with its IANA registrar ID The unique number that identifies an ICANN-accredited registrar. Full definition of IANA registrar ID, its abuse email and phone, the creation and expiry dates and the status codes. Name servers and DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC data appear if collected, and the registrant’s country is always shown.
Personal data must be hidden where the law requires it, and may be hidden for a commercially reasonable purpose. Then the registrant’s name, street, postal code and phone are redacted, and the field says so: ICANN Lookup shows “The RDAP server redacted the value”. Instead of an email address, the registrar publishes an anonymised address or a web form. The registrant can consent to publication. With a privacy or proxy service, the service’s details appear instead.
Redaction began with ICANN’s Temporary Specification ICANN's 2018 emergency rules for WHOIS under the GDPR. Full definition of Temporary Specification, adopted in May 2018 and effective 25 May 2018, the day the GDPR General Data Protection Regulation The European Union data protection law that led to hiding personal data in WHOIS. Full definition of GDPR began to apply.
WHOIS history and reverse searches
RDAP shows only current data. WHOIS history Archived past registration records of a domain, sold by private data companies. Full definition of WHOIS history, past copies of records, is kept by private companies that collected answers over the years; registries and registrars do not publish it.
A reverse WHOIS A search for all domains whose records contain a given name, email or phone number. Full definition of reverse WHOIS search starts from an owner’s details, such as a name or email, and finds the linked domains. Basic RDAP cannot do this. RFC 9536 (April 2024) defines an optional extension, but registries should check whether the law allows it, and sensitive data must stay limited to authorised users. Because most names and emails have been redacted since 2018, archives built from public answers hold less contact data.
ccTLD lookups such as .es
ICANN’s sunset and policy cover gTLDs; each ccTLD sets its own rules.
For .es, Red.es The Spanish public body that manages the .es domain through its unit Dominios.es. Full definition of Red.es runs the registry databases under Orden ITC/1542/2005, and access to personal data in them follows data protection law. As of October 2026, IANA lists whois.nic.es as the .es WHOIS server and no RDAP server; for .com it lists both.
For .eu, as of October 2026, EURid The nonprofit registry that runs .eu under contract with the European Commission. Full definition of EURid’s web WHOIS shows only email and language for individuals, and adds company, city, region and country for organisations. As of October 2026, the NIS2 Directive on measures for a high common level of cybersecurity across the Union A European Union cybersecurity directive with rules on accurate domain registration data. Full definition of NIS2 Directive requires EU member states, each through its own national law, to make registries and registrars publish non-personal registration data without undue delay and answer lawful access requests within 72 hours. For a specific ccTLD, check with its registry or a registrar.
Sources
- ICANN Update: Launching RDAP; Sunsetting WHOIS, opens another website in a new tab
- Registration Data Access Protocol (RDAP) FAQs, opens another website in a new tab
- Registration Data Policy, opens another website in a new tab
- Delegation Record for .ES (IANA Root Zone Database), opens another website in a new tab