---
id: "whois"
kind: "glossary-term"
title: "WHOIS"
language: "en"
category: "Registration data and privacy"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/whois/"
translations:
  es: "https://tldlog.com/es/glosario/whois/"
  de: "https://tldlog.com/de/glossar/whois/"
  fr: "https://tldlog.com/fr/glossaire/whois/"
  it: "https://tldlog.com/it/glossario/whois/"
  pt-BR: "https://tldlog.com/pt/glossario/whois/"
  ru: "https://tldlog.com/ru/glossariy/whois/"
  zh-Hans: "https://tldlog.com/zh/cihui/whois/"
---

# WHOIS

Both an old lookup protocol and the everyday name for public domain registration data: who registered a name, through which registrar, and when. For gTLDs other than .com, .name and .post, the duty to run WHOIS ended on 28 January 2025, and RDAP replaced it. Some ccTLDs still use WHOIS.

WHOIS is the long-standing way to check who is behind a domain name: which registrar manages it, when it was registered and when it expires. The word names both an old lookup protocol and, in everyday use, the public record itself. For most generic top-level domains a newer protocol, RDAP, has taken over, but WHOIS has not disappeared.

## What WHOIS is

The protocol is described in RFC 3912 (September 2004). A program connects to a server on port 43, sends a line of text such as a domain name, and gets plain text back. The RFC is frank about its limits: no internationalisation, no access control, no integrity protection and no confidentiality. It should carry only information "intended to be accessible to everyone"; with no access control, every user gets the same answer.

ICANN's wider term for public lookup services for gTLD data is RDDS: WHOIS on port 43, web WHOIS and now RDAP.

## From WHOIS to RDAP: what changed

The main dates:

- 26 August 2019: every gTLD registry and registrar had to run an RDAP service.
- 28 January 2025: the WHOIS sunset.
- 21 August 2025: the February 2024 version of the gTLD RDAP Profile became mandatory, the day the Registration Data Policy took effect.

ICANN lists four advantages of RDAP: internationalisation, secure access, authoritative service discovery, and differentiated access, so different users can see different data. A query is a web address sent over HTTPS; the answer is structured data that programs can read. The data itself is the same.

Discovery works through the RDAP bootstrap: IANA publishes lists matching each TLD to its RDAP server, so a tool knows which server to ask. The gTLD RDAP Profile, two ICANN documents written with registries and registrars, makes every gTLD answer in the same format.

The sunset is narrower than it sounds. From 28 January 2025, gTLD registries and registrars are no longer required to run WHOIS on port 43 or on the web, except for .com, .name and .post (as of October 2026). Providers may still run it by choice.

## How to look up a domain today

The simplest route is ICANN Lookup at lookup.icann.org. It sends an RDAP query and shows the live answer from the registry and registrar; ICANN does not store RDAP lookup data. As of October 2026, if RDAP is unavailable for a gTLD domain, it offers an optional WHOIS lookup after a captcha, and it shows the raw RDAP answer at the bottom of the page.

For TLDs that still run port 43, a classic WHOIS client may work, though some registries restrict access.

Some data is visible only to approved users. ICANN asks people to check ICANN Lookup first, then use RDRS for participating registrars or the registrar's own disclosure process, which every gTLD registry and registrar must link from its homepage.

An example: someone checks example.com. The tool finds the .com RDAP server through the bootstrap list, then follows the link to the registrar's server. Under the Registration Data Policy the answer shows the registrar, dates, status codes and name servers, while the registrant's name, street and phone are marked as redacted where redaction applies.

## What you will and will not see

Under ICANN's Registration Data Policy (in effect since 21 August 2025, revised on 12 May 2026), a gTLD record always shows the domain name, the registrar with its IANA ID, its abuse email and phone, the creation and expiry dates and the status codes. Name servers and DNSSEC data appear if collected, and the registrant's country is always shown.

Personal data must be hidden where the law requires it, and may be hidden for a commercially reasonable purpose. Then the registrant's name, street, postal code and phone are redacted, and the field says so: ICANN Lookup shows "The RDAP server redacted the value". Instead of an email address, the registrar publishes an anonymised address or a web form. The registrant can consent to publication. With a privacy or proxy service, the service's details appear instead.

Redaction began with ICANN's Temporary Specification, adopted in May 2018 and effective 25 May 2018, the day the GDPR began to apply.

## WHOIS history and reverse searches

RDAP shows only current data. WHOIS history, past copies of records, is kept by private companies that collected answers over the years; registries and registrars do not publish it.

A reverse WHOIS search starts from an owner's details, such as a name or email, and finds the linked domains. Basic RDAP cannot do this. RFC 9536 (April 2024) defines an optional extension, but registries should check whether the law allows it, and sensitive data must stay limited to authorised users. Because most names and emails have been redacted since 2018, archives built from public answers hold less contact data.

## ccTLD lookups such as .es

ICANN's sunset and policy cover gTLDs; each ccTLD sets its own rules.

For .es, Red.es runs the registry databases under Orden ITC/1542/2005, and access to personal data in them follows data protection law. As of October 2026, IANA lists whois.nic.es as the .es WHOIS server and no RDAP server; for .com it lists both.

For .eu, as of October 2026, EURid's web WHOIS shows only email and language for individuals, and adds company, city, region and country for organisations. As of October 2026, the NIS2 Directive requires EU member states, each through its own national law, to make registries and registrars publish non-personal registration data without undue delay and answer lawful access requests within 72 hours. For a specific ccTLD, check with its registry or a registrar.

## Sources

- [ICANN Update: Launching RDAP; Sunsetting WHOIS](https://www.icann.org/en/announcements/details/icann-update-launching-rdap-sunsetting-whois-27-01-2025-en)
- [Registration Data Access Protocol (RDAP) FAQs](https://www.icann.org/en/contracted-parties/registry-operators/registration-data-access-protocol/rdap-faqs-31-08-2018-en)
- [Registration Data Policy](https://www.icann.org/en/contracted-parties/consensus-policies/registration-data-policy)
- [Delegation Record for .ES (IANA Root Zone Database)](https://www.iana.org/domains/root/db/es.html)

## related terms

- [RDAP](https://tldlog.com/glossary/rdap/)
- [privacy/proxy service](https://tldlog.com/glossary/privacy-proxy-service/)
- [redaction](https://tldlog.com/glossary/redaction/)
- [Registration Data Policy](https://tldlog.com/glossary/registration-data-policy/)
- [port 43](https://tldlog.com/glossary/port-43/)
